deocder Posted November 19, 2009 Report Share Posted November 19, 2009 Wow, I can usually clean things out myself, but I need some help on this one!I ran Combofix and then HiJackThis and then the uninstall_list.txt. All logs are as follows:ComboFix 09-11-18.06 - Customer 11/18/2009 22:45.1.1 - x86Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1216 [GMT -5:00]Running from: c:\documents and settings\Customer\My Documents\Downloads\ComboFix.exeAV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} * Resident AV is active. ADS - system32: deleted 12 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\docume~1\Customer\LOCALS~1\Temp\SolidWorksLicTemp.0001.dir.0020\~dec142.tmpc:\docume~1\Customer\LOCALS~1\Temp\SolidWorksLicTemp.0001.dir.0020\~df394b.tmpc:\documents and settings\Customer\Application Data\inst.exec:\documents and settings\Customer\Desktop\Security Tool.lnkc:\documents and settings\Customer\Local Settings\Temp\SolidWorksLicTemp.0001.dir.0020\~dec142.tmpc:\documents and settings\Customer\Local Settings\Temp\SolidWorksLicTemp.0001.dir.0020\~df394b.tmpc:\documents and settings\Customer\Start Menu\Programs\Security Tool.lnkc:\windows\system32\AutoRun.infc:\windows\system32\duyasuwi.dllc:\windows\system32\fiworize.dllc:\windows\system32\hivotugu.dllc:\windows\system32\jalopeya.exec:\windows\system32\kamukufo.dllc:\windows\system32\likulida.dllc:\windows\system32\nuzadayi.dllc:\windows\system32\pipibuju.dllc:\windows\system32\rumapabo.dllc:\windows\system32\siwipuyo.dllc:\windows\system32\subadeji.dllc:\windows\system32\vetuyija.dllc:\windows\system32\vikewami.dllc:\windows\system32\yabonoke.dllc:\windows\system32\zetojusu.dllc:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . failed to deletec:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . failed to delete----- BITS: Possible infected sites -----hxxp://82.98.231.102.((((((((((((((((((((((((( Files Created from 2009-10-19 to 2009-11-19 ))))))))))))))))))))))))))))))).2009-11-19 02:48 . 2009-11-19 02:48 -------- d-----w- c:\program files\Trend Micro2009-11-18 05:11 . 2009-11-18 05:45 -------- d-----w- c:\program files\Spybot - Search & Destroy2009-11-18 05:11 . 2009-11-18 05:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy2009-11-17 04:49 . 2009-11-17 04:49 -------- d-----w- C:\VundoFix Backups2009-11-17 04:45 . 2009-11-17 04:45 79488 ----a-w- c:\documents and settings\Customer\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll2009-11-17 02:35 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2009-11-17 02:35 . 2009-11-17 02:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes2009-11-17 02:35 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys2009-11-17 02:35 . 2009-11-17 02:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware2009-11-16 05:27 . 2009-11-16 05:27 -------- d-----w- c:\documents and settings\Customer\Application Data\Malwarebytes2009-11-15 22:41 . 2007-11-26 15:38 238848 ----a-w- c:\windows\UNBOC.EXE2009-11-15 22:41 . 2007-05-08 22:01 208896 ----a-w- c:\windows\CMDLIC.DLL2009-11-15 22:41 . 2009-11-15 22:45 -------- d-----w- c:\documents and settings\All Users\Application Data\BOC4252009-11-15 22:41 . 2009-11-15 22:41 -------- d-----w- c:\program files\Comodo2009-11-15 22:39 . 2009-11-15 22:40 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe2009-11-15 22:36 . 2009-11-15 22:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes2009-11-15 22:09 . 2008-04-14 04:13 57399 -c--a-w- c:\windows\system32\dllcache\cplexe.exe2009-11-15 22:09 . 2004-08-04 11:00 18944 -c--a-w- c:\windows\system32\dllcache\cprofile.exe2009-11-15 22:09 . 2004-08-04 11:00 56320 -c--a-w- c:\windows\system32\dllcache\convlog.exe2009-11-15 22:09 . 2004-08-04 11:00 33792 -c--a-w- c:\windows\system32\dllcache\controt.dll2009-11-15 22:09 . 2004-08-04 11:00 20480 -c--a-w- c:\windows\system32\dllcache\counters.dll2009-11-15 22:07 . 2009-11-15 22:07 -------- d-----w- c:\windows\system32\xircom2009-11-15 22:07 . 2009-11-15 22:07 -------- d-----w- c:\windows\system32\wbem\snmp2009-11-15 22:07 . 2009-11-15 22:07 -------- d-----w- c:\program files\microsoft frontpage2009-11-15 22:07 . 2008-04-14 11:42 221184 ----a-w- c:\windows\system32\wmpns.dll2009-11-15 22:05 . 2008-04-14 11:41 7168 -c--a-w- c:\windows\system32\dllcache\bitsprx4.dll2009-11-15 22:05 . 2008-04-14 11:41 7168 ----a-w- c:\windows\system32\bitsprx4.dll2009-11-15 21:44 . 2008-04-14 03:05 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys2009-11-15 21:36 . 2004-08-04 11:00 24661 ----a-w- c:\windows\system32\spxcoins.dll2009-11-15 21:36 . 2004-08-04 11:00 13312 ----a-w- c:\windows\system32\irclass.dll2009-11-15 21:34 . 2009-11-15 21:34 -------- d-s---w- c:\windows\system32\config\systemprofile\History2009-11-15 16:32 . 2009-11-15 16:32 -------- d--h--w- c:\documents and settings\Default User.WINDOWS.02009-11-15 16:32 . 2009-11-15 16:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS.02009-11-15 16:16 . 2009-11-15 22:04 -------- d-----w- c:\windows\system32\oobe2009-11-15 16:16 . 2009-11-15 16:26 -------- d-----w- c:\windows\L2Schemas2009-11-15 16:16 . 2009-11-15 16:26 -------- d-----w- c:\windows\system32\scripting2009-11-10 02:09 . 2009-11-10 02:16 -------- d-----w- c:\program files\CrackUtil2009-11-09 01:50 . 2009-11-09 01:50 53248 ----a-r- c:\documents and settings\Customer\Application Data\Microsoft\Installer\{F574616C-4C15-49CE-9C98-E998CD80264A}\ARPPRODUCTICON.exe2009-11-08 04:18 . 2009-11-08 04:38 -------- d-----w- c:\windows\system32\Adobe2009-11-04 15:30 . 2009-11-04 15:30 16384 ----a-w- c:\documents and settings\Customer\Application Data\blank.exe2009-10-31 22:04 . 2009-11-09 01:45 256 ----a-w- c:\documents and settings\Customer\pool.bin2009-10-31 21:39 . 2009-11-09 02:54 256 ----a-w- c:\windows\system32\pool.bin2009-10-31 21:39 . 2009-10-31 21:39 -------- d-----w- c:\documents and settings\Customer\Application Data\Research In Motion2009-10-31 21:22 . 2007-01-18 14:24 26496 ----a-r- c:\windows\system32\drivers\RimSerial.sys2009-10-31 21:21 . 2009-11-09 01:50 -------- d-----w- c:\program files\Common Files\Research In Motion2009-10-31 21:20 . 2009-10-31 21:20 -------- d-----w- c:\program files\Research In Motion2009-10-29 03:08 . 2009-10-29 03:08 -------- d-----w- c:\program files\Rosetta Stone2009-10-29 03:07 . 2009-10-29 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\RosettaStoneLtdBackup2009-10-29 02:57 . 2009-10-29 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet2009-10-29 02:56 . 2009-10-29 02:56 -------- d-----w- c:\program files\Common Files\Macrovision Shared2009-10-29 02:55 . 2009-10-29 04:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Rosetta Stone2009-10-23 16:55 . 2009-10-23 16:56 -------- d-----w- c:\documents and settings\Customer\tmp.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-11-19 04:22 . 2009-05-30 21:30 -------- d-----w- c:\documents and settings\All Users\Application Data\RetroExp2009-11-15 22:36 . 2007-03-03 06:36 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat2009-11-15 22:21 . 2007-03-08 23:32 109304 ----a-w- c:\documents and settings\Customer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT2009-11-15 22:02 . 2007-03-03 06:33 23348 ----a-w- c:\windows\system32\emptyregdb.dat2009-11-12 00:33 . 2007-03-03 00:15 102400 ----a-w- c:\windows\DUMP66b8.tmp2009-11-10 01:50 . 2007-03-04 00:16 -------- d-----w- c:\documents and settings\Customer\Application Data\uTorrent2009-11-08 06:31 . 2008-06-23 17:03 -------- d-----w- c:\documents and settings\Customer\Application Data\dvdcss2009-11-04 16:16 . 2009-11-04 16:16 4527419 ----a-w- c:\documents and settings\Customer\Application Data\Black Eyed Peas - Meet Me Halfway.zip2009-09-24 15:09 . 2009-10-01 01:22 3858432 ----a-w- c:\documents and settings\Customer\Application Data\Mozilla\Firefox\Profiles\rmnyn9v3.default\extensions\[email protected]\plugins\npRACtrl.dll2009-08-30 13:44 . 2009-08-30 13:44 507904 ----a-r- c:\windows\system32\btwapi.dll2009-08-27 04:01 . 2009-08-27 04:01 39936 ----a-w- c:\windows\system32\drivers\CDAC11BA.EXE2009-08-27 04:01 . 2009-08-27 04:01 30720 ---h--r- c:\windows\CdaC13BA.EXE2009-08-27 04:01 . 2009-08-27 04:01 112128 ---h--r- c:\windows\CdaC14BA.DLL2009-08-27 04:01 . 2009-08-27 04:01 8864 ----a-w- c:\windows\system32\drivers\CDAC15BA.SYS2009-08-27 02:59 . 2009-08-27 02:59 152576 ----a-w- c:\documents and settings\Customer\Application Data\Sun\Java\jre1.6.0_15\lzma.dll2001-09-28 21:00 . 2007-08-31 17:56 164864 ----a-w- c:\program files\UNWISE.EXE2004-03-15 22:51 . 2004-03-15 22:51 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll2003-05-01 14:36 . 2003-05-01 14:36 114688 ----a-w- c:\program files\internet explorer\plugins\LV7ActiveXControl.dll2006-01-23 14:32 . 2006-01-23 14:32 131072 ----a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll2007-02-08 15:48 . 2007-02-08 15:48 133920 ----a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll2008-02-28 18:30 . 2008-07-13 04:36 8784 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll2008-02-28 18:33 . 2008-07-13 04:36 245408 ----a-w- c:\program files\mozilla firefox\plugins\unicows.dll2009-08-10 14:44 . 2009-08-10 14:44 3 --sha-w- c:\windows\system32\dadozive.dll2009-08-17 02:23 . 2009-08-17 02:23 6144 --sha-w- c:\windows\system32\domasuro.dll2009-08-11 03:41 . 2009-08-11 03:41 3 --sha-w- c:\windows\system32\johuvuki.dll2009-08-10 15:07 . 2009-08-10 15:07 3 --sha-w- c:\windows\system32\kemukoma.dll2009-08-10 14:44 . 2009-08-10 14:44 3 --sha-w- c:\windows\system32\kuyijovi.dll2009-08-11 03:41 . 2009-08-11 03:41 3 --sha-w- c:\windows\system32\legimizu.dll2009-08-11 03:41 . 2009-08-11 03:41 3 --sha-w- c:\windows\system32\mibedoja.dll2009-08-10 14:44 . 2009-08-10 14:44 3 --sha-w- c:\windows\system32\yitebuza.dll2009-08-10 15:07 . 2009-08-10 15:07 3 --sha-w- c:\windows\system32\zasiyove.dll2009-08-10 15:07 . 2009-08-10 15:07 3 --sha-w- c:\windows\system32\zufihuno.dll.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]"Google Update"="c:\documents and settings\Customer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-27 133104]"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-06 280779]"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064]"EPSON Stylus Photo R340 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE" [2005-04-26 98304]"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440]"FixCamera"="c:\windows\FixCamera.exe" [2007-02-10 20480]"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-03-12 949376]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]"RetroExpress"="c:\progra~1\IOMEGA~1\RETROS~1\RetroExpress.exe" [2008-12-11 9499928]"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336]"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-20 77824]"BOC-425"="c:\progra~1\Comodo\CBOClean\BOC425.exe" [2007-11-26 342272]"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\UHSPyXdvY.exe" [2009-11-17 1312080][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-12 44544]"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-14 99840]c:\documents and settings\Customer\Start Menu\Programs\Startup\Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]SolidWorks Task Scheduler Engine.lnk - c:\program files\SolidWorks\swScheduler\swBOEngine.exe [2006-7-19 192512]Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-3-1 3450608]c:\documents and settings\All Users\Start Menu\Programs\Startup\Device Detector 2.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2007-6-17 114688]Iomega StorCenter.lnk - c:\program files\Iomega StorCenter\sohoclient.exe [2009-5-30 1865040][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]"NoSMConfigurePrograms"= 1 (0x1)[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]"ForceClassicControlPanel"= 1 (0x1)"NoSMConfigurePrograms"= 1 (0x1)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"= 0 (0x0)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\system32\\sessmgr.exe"="c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="c:\\Program Files\\uTorrent\\utorrent.exe"="c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"c:\\temp\\HP_WebRelease\\Setup\\HPZnet01.exe"="c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"="c:\\WINDOWS\\system32\\mmc.exe"="c:\\crack\\airserv-ng.exe"="c:\\Program Files\\SolarWinds\\Engineer's Toolset\\Config-Transfer.exe"="c:\\Program Files\\SolarWinds\\Engineer's Toolset\\SNMP-Brute-Force-Attack.exe"="c:\\Program Files\\Iomega StorCenter\\retrospect\\Retrospect.exe"="c:\\Program Files\\Iomega StorCenter\\retrospect\\retrorun.exe"="c:\\Documents and Settings\\Customer\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"="c:\\Documents and Settings\\Customer\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"="c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"="c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016"500:UDP"= 500:UDP:@xpsp2res.dll,-22017R0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\system32\drivers\nipbcfk.sys [2/15/2007 5:23 PM 15136]R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [3/11/2008 10:24 PM 15424]R2 ANSYS FLEXlm license manager;ANSYS FLEXlm license manager;c:\program files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exe [5/21/2008 12:04 PM 1327104]R2 BOCore;BOCore;c:\program files\Comodo\CBOClean\BOCore.exe [11/15/2009 5:41 PM 73472]R2 Bwcdrv;BUFFALO Wireless Configuration;c:\windows\system32\drivers\BWCDRV.SYS [12/21/2003 3:21 AM 19840]R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]R2 ni488enumsvc;NI-488.2 Enumeration Service;c:\windows\system32\nipalsm.exe [2/16/2007 10:21 AM 12696]R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2/2/2007 9:36 AM 37376]R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2/2/2007 9:37 AM 21504]R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2/2/2007 10:55 AM 674304]R2 nidevldu;NI Device Loader;c:\windows\system32\nipalsm.exe [2/16/2007 10:21 AM 12696]R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2/2/2007 10:57 AM 50688]R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2/2/2007 9:37 AM 30208]R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmkl.sys [2/22/2007 11:18 AM 11552]R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2/2/2007 9:38 AM 111616]R2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2/23/2007 10:25 AM 11552]R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [5/24/2008 11:34 PM 2368]R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/25/2007 9:13 PM 24652]R3 nidimk;nidimk;c:\windows\system32\drivers\nidimkl.sys [2/21/2007 10:20 PM 11552]R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2kl.sys [2/21/2007 10:39 PM 11552]R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstskl.sys [2/25/2007 8:12 PM 11552]S3 ATHER;Atheros AR5000 Based Wireless Network Adapter Service;c:\windows\system32\drivers\ar5210b.sys [5/28/2007 12:48 PM 276981]S3 CBBCM43;BUFFALO WLI-CB-XXX Series Wireless LAN Adapter;c:\windows\system32\drivers\BCMWL5.SYS [7/11/2005 12:46 AM 372480]S3 DW90USB;DW90USB Device;c:\windows\system32\drivers\DW90USB.SYS [6/17/2007 6:50 AM 39096]S3 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.sys [1/11/2007 10:18 AM 20256]S3 ni1006k;NI PXI-1006 Chassis Pilot;c:\windows\system32\drivers\ni1006k.sys [2/22/2007 11:40 AM 25888]S3 ni1045k;NI PXI-1045 Chassis Pilot;c:\windows\system32\drivers\ni1045kl.sys [2/22/2007 11:43 AM 11552]S3 ni488lock;NI-488.2 Locking Service;c:\windows\system32\drivers\ni488lock.sys [2/26/2007 12:40 PM 16672]S3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrkl.sys [2/22/2007 6:18 PM 11552]S3 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfkl.sys [2/25/2007 8:12 PM 11552]S3 nidsark;nidsark;c:\windows\system32\drivers\nidsarkl.sys [2/23/2007 5:43 PM 11552]S3 nidwgk;nidwgk;c:\windows\system32\drivers\nidwgkl.sys [2/23/2007 10:32 PM 11552]S3 niemrk;niemrk;c:\windows\system32\drivers\niemrkl.sys [2/25/2007 7:13 PM 11552]S3 niesrk;niesrk;c:\windows\system32\drivers\niesrkl.sys [2/25/2007 7:13 PM 11552]S3 nifslk;nifslk;c:\windows\system32\drivers\nifslkl.sys [2/22/2007 1:21 PM 11552]S3 nigplk;nigplk;c:\windows\system32\drivers\nigplkl.sys [2/23/2007 4:20 PM 11552]S3 nihsdrk;nihsdrk;c:\windows\system32\drivers\nihsdrkl.sys [2/24/2007 1:10 AM 11552]S3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrkl.sys [2/25/2007 8:10 PM 11552]S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [12/18/2006 12:55 PM 14464]S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [12/18/2006 12:55 PM 151683]S3 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpkl.sys [2/22/2007 1:26 PM 11552]S3 ninshsdk;ninshsdk;c:\windows\system32\drivers\ninshsdkl.sys [2/23/2007 5:25 PM 11552]S3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [2/15/2007 11:00 PM 11552]S3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [2/15/2007 11:00 PM 11552]S3 nipsdk;nipsdk;c:\windows\system32\drivers\nipsdkl.sys [2/23/2007 10:19 PM 11552]S3 nipxigpk;NI PXI Generic Chassis Pilot;c:\windows\system32\drivers\nipxigpk.sys [2/22/2007 11:45 AM 20768]S3 nirfsa2k;nirfsa2k;c:\windows\system32\drivers\niRFSA2kl.sys [2/24/2007 4:19 AM 11552]S3 niscdk;niscdk;c:\windows\system32\drivers\niscdkl.sys [2/26/2007 4:31 PM 11552]S3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigkl.sys [2/25/2007 7:11 PM 11552]S3 nisftk;nisftk;c:\windows\system32\drivers\nisftkl.sys [2/24/2007 12:17 AM 11552]S3 nisldk;nisldk;c:\windows\system32\drivers\nisldkl.sys [2/23/2007 10:05 PM 11552]S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2/22/2007 11:34 AM 86304]S3 nispdk;nispdk;c:\windows\system32\drivers\nispdkl.sys [2/26/2007 4:31 PM 11552]S3 nisrcdk;nisrcdk;c:\windows\system32\drivers\nisrcdkl.sys [2/23/2007 10:28 PM 11552]S3 nissrk;nissrk;c:\windows\system32\drivers\nissrkl.sys [2/25/2007 7:13 PM 11552]S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2kl.sys [2/22/2007 8:17 PM 11552]S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrkl.sys [2/23/2007 3:14 AM 11552]S3 niswdk;niswdk;c:\windows\system32\drivers\niswdkl.sys [2/23/2007 8:44 PM 11552]S3 nitiork;nitiork;c:\windows\system32\drivers\nitiorkl.sys [2/23/2007 3:54 PM 11552]S3 nitnr2k;nitnr2k;c:\windows\system32\drivers\nitnr2kl.sys [2/24/2007 12:09 AM 11552]S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2/22/2007 10:42 AM 11552]S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2/23/2007 10:25 AM 11552]S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrkl.sys [2/25/2007 7:13 PM 11552]S3 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrkl.sys [2/25/2007 7:13 PM 11552]S3 nixsrkw;nixsrkw;c:\windows\system32\drivers\nixsrkw.sys [2/25/2007 7:13 PM 11552]S3 SolarWinds TFTP Server;SolarWinds TFTP Server;c:\program files\SolarWinds\Engineer's Toolset\SolarWinds TFTP Server.exe [12/5/2007 8:58 AM 61440]S3 SUSTUCAM;Susteen USB Cable Modem Driver;c:\windows\system32\drivers\sustucam.sys [2/19/2008 10:01 PM 38016]S3 SUSTUCAU;Susteen USB Cable USB Driver;c:\windows\system32\drivers\sustucau.sys [2/19/2008 9:56 PM 20096]S3 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.sys [2/25/2007 7:11 PM 27936]--- Other Services/Drivers In Memory ---*NewlyCreated* - NIPALK*Deregistered* - mbr.Contents of the 'Scheduled Tasks' folder2009-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1284227242-839522115-1003Core.job- c:\documents and settings\Customer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-27 04:22]2009-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1284227242-839522115-1003UA.job- c:\documents and settings\Customer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-27 04:22]2009-11-19 c:\windows\Tasks\SDMsgUpdate (SD).job- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2008-03-18 12:53]..------- Supplementary Scan -------.uStart Page = hxxp://google.daemonsearch.com/intl/IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000LSP: c:\windows\system32\imon.dllTrusted Zone: aol.com\freeFF - ProfilePath - c:\documents and settings\Customer\Application Data\Mozilla\Firefox\Profiles\rmnyn9v3.default\FF - prefs.js: browser.startup.homepage - www.google.comFF - plugin: c:\documents and settings\Customer\Application Data\Mozilla\Firefox\Profiles\rmnyn9v3.default\extensions\[email protected]\plugins\npRACtrl.dllFF - plugin: c:\documents and settings\Customer\Application Data\Mozilla\plugins\npgoogletalk.dllFF - plugin: c:\documents and settings\Customer\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dllFF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dllFF - plugin: c:\program files\Google\Picasa3\npPicasa3.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\NpPopup.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dllFF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll---- FIREFOX POLICIES ----c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);.- - - - ORPHANS REMOVED - - - -BHO-{ae2fa5e1-9f3b-4347-b4d4-457c66f91400} - wedaleza.dllWebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)HKLM-Run-hovagetab - c:\windows\system32\pipibuju.dllHKLM-Run-geririzuje - likulida.dllSharedTaskScheduler-{a5326c12-4dc1-4e68-825e-565914579a55} - c:\windows\system32\pipibuju.dllSSODL-fufavomud-{a5326c12-4dc1-4e68-825e-565914579a55} - c:\windows\system32\pipibuju.dll**************************************************************************catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-11-18 23:21Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.--------------------- LOCKED REGISTRY KEYS ---------------------[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]@Denied: (Full) (LocalSystem)"OOBETimer"=hex:7f,63,3e,be,ec,25,8e,19,be,a7,92,c6.--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'winlogon.exe'(648)c:\windows\system32\Ati2evxx.dll- - - - - - - > 'lsass.exe'(704)c:\windows\system32\imon.dll- - - - - - - > 'explorer.exe'(3740)c:\program files\Stardock\ObjectDock\DockShellHook.dllc:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTJBNS2.dllc:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTIntrfc.dllc:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTConfig.DLLc:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\JBNSRES.DLLc:\windows\system32\wpdshserviceobj.dllc:\program files\WinSCP3\DragExt.dllc:\windows\system32\ieframe.dllc:\windows\system32\portabledevicetypes.dllc:\windows\system32\portabledeviceapi.dll.------------------------ Other Running Processes ------------------------.c:\windows\system32\Ati2evxx.exec:\windows\system32\Drivers\bwcsrv.exec:\windows\system32\drivers\CDAC11BA.EXEc:\program files\FolderSize\FolderSizeSvc.exec:\program files\Java\jre6\bin\jqs.exec:\windows\system32\lkcitdl.exec:\windows\system32\lkads.exec:\windows\system32\lktsrv.exec:\program files\National Instruments\MAX\nimxs.exec:\program files\National Instruments\Shared\Security\nidmsrv.exec:\windows\system32\nisvcloc.exec:\program files\National Instruments\Shared\Tagger\tagsrv.exec:\program files\Eset\nod32krn.exec:\windows\system32\HPZipm12.exec:\progra~1\IOMEGA~1\RETROS~1\retrorun.exec:\windows\system32\wscntfy.exec:\windows\system32\Ati2evxx.exec:\progra~1\IOMEGA~1\RETROS~1\retrospect.exec:\progra~1\MICROS~4\rapimgr.exec:\docume~1\Customer\LOCALS~1\Temp\SolidWorksLicTemp.0001.**************************************************************************.Completion time: 2009-11-18 23:32 - machine was rebootedComboFix-quarantined-files.txt 2009-11-19 04:32Pre-Run: 5,346,938,880 bytes freePost-Run: 5,858,193,408 bytes free- - End Of File - - D2B4EF27468E41704552B6D3EE1A90EF_________________________________________________________________________________________________Logfile of Trend Micro HijackThis v2.0.2Scan saved at 12:06:03 AM, on 11/19/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exeC:\Program Files\Comodo\CBOClean\BOCORE.exeC:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exeC:\WINDOWS\system32\Drivers\bwcsrv.exeC:\WINDOWS\system32\drivers\CDAC11BA.EXEC:\Program Files\FolderSize\FolderSizeSvc.exeC:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\lkcitdl.exeC:\WINDOWS\system32\lkads.exeC:\WINDOWS\system32\lktsrv.exeC:\Program Files\National Instruments\MAX\nimxs.exeC:\WINDOWS\system32\nipalsm.exeC:\Program Files\National Instruments\Shared\Security\nidmsrv.exeC:\WINDOWS\system32\nisvcloc.exeC:\Program Files\National Instruments\Shared\Tagger\tagsrv.exeC:\Program Files\Eset\nod32krn.exeC:\WINDOWS\system32\HPZipm12.exeC:\PROGRA~1\IOMEGA~1\RETROS~1\retrorun.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\WINDOWS\system32\nipalsm.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\VistaDrive\VistaDrive.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\WINDOWS\FixCamera.exeC:\Program Files\Eset\nod32kui.exeC:\PROGRA~1\IOMEGA~1\RETROS~1\RetroExpress.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\WINDOWS\vsnpstd3.exeC:\WINDOWS\tsnpstd3.exeC:\PROGRA~1\Comodo\CBOClean\BOC425.exeC:\PROGRA~1\IOMEGA~1\RETROS~1\retrospect.exeC:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exeC:\Program Files\Microsoft ActiveSync\wcescomm.exeC:\PROGRA~1\MICROS~4\rapimgr.exeC:\Program Files\Olympus\DeviceDetector\DevDtct2.exeC:\Program Files\Iomega StorCenter\sohoclient.exeC:\Program Files\SolidWorks\swScheduler\swBOEngine.exeC:\Program Files\Stardock\ObjectDock\ObjectDock.exeC:\DOCUME~1\Customer\LOCALS~1\Temp\SolidWorksLicTemp.0001C:\WINDOWS\explorer.exeC:\WINDOWS\system32\notepad.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/intl/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLLO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dllO4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exeO4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exeO4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICEO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\IOMEGA~1\RETROS~1\RetroExpress.exe /hO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exeO4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [bOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exeO4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\UHSPyXdvY.exe" /runcleanupscriptO4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exeO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automountO4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Customer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /cO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')O4 - S-1-5-18 Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exe (User 'SYSTEM')O4 - S-1-5-18 Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (User 'SYSTEM')O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')O4 - .DEFAULT Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exe (User 'Default user')O4 - .DEFAULT Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (User 'Default user')O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exeO4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exeO4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exeO4 - Global Startup: Iomega StorCenter.lnk = C:\Program Files\Iomega StorCenter\sohoclient.exeO8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dllO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dllO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dllO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLLO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} (EModelNonVersionSpecificViewControl Class) - http://www.3dpublisher.net/SWService/eDrawingsEnglish.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1237771195828O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1237771178421O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLLO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exeO23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exeO23 - Service: BUFFALO Wireless Configuration Service (bwcsrv) - Unknown owner - C:\WINDOWS\system32\Drivers\bwcsrv.exeO23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXEO23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exeO23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exeO23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exeO23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exeO23 - Service: NI-488.2 Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exeO23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exeO23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exeO23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exeO23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exeO23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exeO23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exeO23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exeO23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\PROGRA~1\IOMEGA~1\RETROS~1\retrorun.exeO23 - Service: SolarWinds TFTP Server - SolarWinds - C:\Program Files\SolarWinds\Engineer's Toolset\SolarWinds TFTP Server.exeO23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exeO23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe--End of file - 14053 bytes_________________________________________________________________________________________________µTorrentAcrobat.comAcrobat.comAdobe AIRAdobe AIRAdobe Common File InstallerAdobe Flash Player 10 PluginAdobe Help Center 2.1Adobe Photoshop Elements 5.0Adobe Premiere Elements 3.0Adobe Premiere Elements 3.0Adobe Premiere Elements 3.0 TemplatesAdobe Reader 9.1.3Adobe Shockwave Player 11.5ArcSoft VideoImpression 2Arial CD Ripper v1.9.4Atheros Wireless LAN MiniPCI card DriverATI - Software Uninstall UtilityATI Control PanelATI Display DriverBlackBerry Desktop Software 4.5BlackBerry Desktop Software 4.5BlackBerry Device Software UpdaterBOCleanCASHFLOW® THE E-GAMECCleaner (remove only)CD Wave Editor version 1.96.1CD/DVD Drive Acoustic SilencerCda Product Service - shared componentCommView for WiFiConexant AC-Link AudioCOSMOSMotion 2007 SP0COSMOSWorks 2007 SP0CrackUtilCreative Jukebox DriverCreative Removable Disk ManagerCreative System InformationCreative Zen MicroDiagram DesignerDWGeditorDYNACAM Student EditionEasy Mobile SoftEDraw Flowchart 3eDrawings 2007EduTraderEPSON Printer SoftwareEPSON TWAIN 5eSignalexPressit S.E. 2.2Family Tree Maker 2006ffdshow (remove only)Folder Size for WindowsForms WizardFOURBAR Student EditionFoxit PDF EditorGanttPV 0.7GE MiniCam ProGlowingWorld 3.0Google Talk PluginHijackThis 2.0.2HP Deskjet Printer Driver Software 9.0HP Image Zone 4.7HP Photosmart, Officejet and Deskjet 7.0.AHP PSC & OfficeJet 4.7HP PSC & Officejet 4.7 Corporate EditionImTOO DVD Ripper UltimateIomega StorCenterIVI Shared ComponentsJava 6 Update 15Java 6 Update 3Java 6 Update 5Java 6 Update 7Java SE Runtime Environment 6 Update 1LAME V3.97 + RazorLame 1.1.5a (PfP)Magic ISO Maker v5.5 (build 0265)Malwarebytes' Anti-MalwareMathType 5Memorex exPressit Label Design StudioMicrosoft .NET Framework 1.1Microsoft .NET Framework 2.0 Service Pack 1Microsoft .NET Framework 3.0 Service Pack 1Microsoft .NET Framework 3.5Microsoft .NET Framework 3.5Microsoft ActiveSyncMicrosoft Money 2007Microsoft Money Shared LibrariesMicrosoft Office Access MUI (English) 2007Microsoft Office Access Setup Metadata MUI (English) 2007Microsoft Office Enterprise 2007Microsoft Office Enterprise 2007Microsoft Office Excel MUI (English) 2007Microsoft Office Groove MUI (English) 2007Microsoft Office Groove Setup Metadata MUI (English) 2007Microsoft Office InfoPath MUI (English) 2007Microsoft Office OneNote MUI (English) 2007Microsoft Office Outlook MUI (English) 2007Microsoft Office PowerPoint MUI (English) 2007Microsoft Office Proof (English) 2007Microsoft Office Proof (French) 2007Microsoft Office Proof (Spanish) 2007Microsoft Office Proofing (English) 2007Microsoft Office Publisher MUI (English) 2007Microsoft Office Shared MUI (English) 2007Microsoft Office Shared Setup Metadata MUI (English) 2007Microsoft Office Word MUI (English) 2007Microsoft Visual C++ 2005 RedistributableMicrosoft Visual C++ 2005 RedistributableMotorola Driver InstallationMotorola Phone ToolsMozilla Firefox (3.5.5)My HP GamesNational Instruments SoftwareNero 8 Lite 8.3.6.0NETGEAR Print Server UtilityNetwork Stumbler 0.4.0 (remove only)NOD32 antivirus systemNOD32 FiX v2.1NotePad++ 3.6ObjectDockOlympus Digital Wave PlayerPDFCreatorPenguins!PENTAX USB DISK DevicePersonal Financial StatementPicasa 3PowerISOQuicken 2009QuickTimeRealPlayerRetrospect Express HD 2.5Rosetta Stone Version 3RPM Life PlannerSIXBAR Student EditionSkype™ 4.1SmartDraw 2008SnagIt 8SolarWinds Engineer's Toolset v9SolidWorks 2007 SP0SolidWorks Explorer 2007 sp0SolidWorks Installation ManagerSpybot - Search & DestroyStar Wars 3D Screensaver 1.3Systems of Nonlinear EquationsThe Rosetta StoneTI Connect 1.6TI NoteFolio CreatorTubeTilla FreeTurboTax 2008TurboTax 2008 WinPerFedFormsetTurboTax 2008 WinPerProgramHelpTurboTax 2008 WinPerReleaseEngineTurboTax 2008 WinPerTaxSupportTurboTax 2008 WinPerUserEducationTurboTax 2008 wrapperUpdate for Outlook Junk Email Filter 2007 (KB924884)USB Storage Adapter FX (MXO)Vendedores PerrosVideoLAN VLC media player 0.8.6hViewpoint Media PlayerWinampWinRAR archiverWinSCP 3.8.2Yamp v 2.3 Link to post Share on other sites
Rorschach112 Posted November 19, 2009 Report Share Posted November 19, 2009 you shouldn't run combofix yourself, it is a dangerous tool to useOpen notepad and copy/paste the text in the quotebox below into it:Collect::c:\windows\system32\pool.binc:\windows\system32\dadozive.dllc:\windows\system32\domasuro.dllc:\windows\system32\johuvuki.dllc:\windows\system32\kemukoma.dllc:\windows\system32\kuyijovi.dllc:\windows\system32\legimizu.dllc:\windows\system32\mibedoja.dllc:\windows\system32\yitebuza.dllc:\windows\system32\zasiyove.dllc:\windows\system32\zufihuno.dllSuspect::Save this as CFScript.txtRefering to the picture above, drag CFScript.txt into ComboFix.exeWhen finished, it shall produce a log for you. Post that log in your next reply.**Note** When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.Ensure you are connected to the internet and click OK on the message box. Link to post Share on other sites
deocder Posted November 20, 2009 Author Report Share Posted November 20, 2009 Rorschach112, I have followed your directions. Thank you! Here is the output:ComboFix 09-11-19.05 - Customer 11/19/2009 23:06.2.1 - x86Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1432 [GMT -5:00]Running from: c:\documents and settings\Customer\Desktop\ComboFix.exeCommand switches used :: c:\documents and settings\Customer\Desktop\CFScript.txtfile zipped: c:\windows\system32\dadozive.dllfile zipped: c:\windows\system32\domasuro.dllfile zipped: c:\windows\system32\johuvuki.dllfile zipped: c:\windows\system32\kemukoma.dllfile zipped: c:\windows\system32\kuyijovi.dllfile zipped: c:\windows\system32\legimizu.dllfile zipped: c:\windows\system32\mibedoja.dllfile zipped: c:\windows\system32\pool.binfile zipped: c:\windows\system32\yitebuza.dllfile zipped: c:\windows\system32\zasiyove.dllfile zipped: c:\windows\system32\zufihuno.dll.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\docume~1\Customer\LOCALS~1\Temp\SolidWorksLicTemp.0001.dir.0000\~dec142.tmpc:\docume~1\Customer\LOCALS~1\Temp\SolidWorksLicTemp.0001.dir.0000\~df394b.tmpc:\documents and settings\Customer\Local Settings\Temp\SolidWorksLicTemp.0001.dir.0000\~dec142.tmpc:\documents and settings\Customer\Local Settings\Temp\SolidWorksLicTemp.0001.dir.0000\~df394b.tmpc:\windows\system32\dadozive.dllc:\windows\system32\domasuro.dllc:\windows\system32\johuvuki.dllc:\windows\system32\kemukoma.dllc:\windows\system32\kuyijovi.dllc:\windows\system32\legimizu.dllc:\windows\system32\mibedoja.dllc:\windows\system32\pool.binc:\windows\system32\yitebuza.dllc:\windows\system32\zasiyove.dllc:\windows\system32\zufihuno.dll.((((((((((((((((((((((((( Files Created from 2009-10-20 to 2009-11-20 ))))))))))))))))))))))))))))))).2009-11-19 02:48 . 2009-11-19 02:48 -------- d-----w- c:\program files\Trend Micro2009-11-18 05:11 . 2009-11-18 05:45 -------- d-----w- c:\program files\Spybot - Search & Destroy2009-11-18 05:11 . 2009-11-18 05:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy2009-11-17 04:49 . 2009-11-17 04:49 -------- d-----w- C:\VundoFix Backups2009-11-17 04:45 . 2009-11-17 04:45 79488 ----a-w- c:\documents and settings\Customer\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll2009-11-17 02:35 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2009-11-17 02:35 . 2009-11-17 02:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes2009-11-17 02:35 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys2009-11-17 02:35 . 2009-11-17 02:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware2009-11-16 05:27 . 2009-11-16 05:27 -------- d-----w- c:\documents and settings\Customer\Application Data\Malwarebytes2009-11-15 22:41 . 2007-11-26 15:38 238848 ----a-w- c:\windows\UNBOC.EXE2009-11-15 22:41 . 2007-05-08 22:01 208896 ----a-w- c:\windows\CMDLIC.DLL2009-11-15 22:41 . 2009-11-15 22:45 -------- d-----w- c:\documents and settings\All Users\Application Data\BOC4252009-11-15 22:41 . 2009-11-15 22:41 -------- d-----w- c:\program files\Comodo2009-11-15 22:39 . 2009-11-15 22:40 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe2009-11-15 22:36 . 2009-11-15 22:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes2009-11-15 22:09 . 2008-04-14 04:13 57399 -c--a-w- c:\windows\system32\dllcache\cplexe.exe2009-11-15 22:09 . 2004-08-04 11:00 18944 -c--a-w- c:\windows\system32\dllcache\cprofile.exe2009-11-15 22:09 . 2004-08-04 11:00 56320 -c--a-w- c:\windows\system32\dllcache\convlog.exe2009-11-15 22:09 . 2004-08-04 11:00 33792 -c--a-w- c:\windows\system32\dllcache\controt.dll2009-11-15 22:09 . 2004-08-04 11:00 20480 -c--a-w- c:\windows\system32\dllcache\counters.dll2009-11-15 22:07 . 2009-11-15 22:07 -------- d-----w- c:\windows\system32\xircom2009-11-15 22:07 . 2009-11-15 22:07 -------- d-----w- c:\windows\system32\wbem\snmp2009-11-15 22:07 . 2009-11-15 22:07 -------- d-----w- c:\program files\microsoft frontpage2009-11-15 22:07 . 2008-04-14 11:42 221184 ----a-w- c:\windows\system32\wmpns.dll2009-11-15 22:05 . 2008-04-14 11:41 7168 -c--a-w- c:\windows\system32\dllcache\bitsprx4.dll2009-11-15 22:05 . 2008-04-14 11:41 7168 ----a-w- c:\windows\system32\bitsprx4.dll2009-11-15 21:44 . 2008-04-14 03:05 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys2009-11-15 21:36 . 2004-08-04 11:00 24661 ----a-w- c:\windows\system32\spxcoins.dll2009-11-15 21:36 . 2004-08-04 11:00 13312 ----a-w- c:\windows\system32\irclass.dll2009-11-15 21:34 . 2009-11-15 21:34 -------- d-s---w- c:\windows\system32\config\systemprofile\History2009-11-15 16:32 . 2009-11-15 16:32 -------- d--h--w- c:\documents and settings\Default User.WINDOWS.02009-11-15 16:32 . 2009-11-15 16:32 -------- d-----w- c:\documents and settings\All Users.WINDOWS.02009-11-15 16:16 . 2009-11-15 22:04 -------- d-----w- c:\windows\system32\oobe2009-11-15 16:16 . 2009-11-15 16:26 -------- d-----w- c:\windows\L2Schemas2009-11-15 16:16 . 2009-11-15 16:26 -------- d-----w- c:\windows\system32\scripting2009-11-10 02:09 . 2009-11-10 02:16 -------- d-----w- c:\program files\CrackUtil2009-11-09 01:50 . 2009-11-09 01:50 53248 ----a-r- c:\documents and settings\Customer\Application Data\Microsoft\Installer\{F574616C-4C15-49CE-9C98-E998CD80264A}\ARPPRODUCTICON.exe2009-11-08 04:18 . 2009-11-08 04:38 -------- d-----w- c:\windows\system32\Adobe2009-11-04 15:30 . 2009-11-04 15:30 16384 ----a-w- c:\documents and settings\Customer\Application Data\blank.exe2009-10-31 22:04 . 2009-11-09 01:45 256 ----a-w- c:\documents and settings\Customer\pool.bin2009-10-31 21:39 . 2009-10-31 21:39 -------- d-----w- c:\documents and settings\Customer\Application Data\Research In Motion2009-10-31 21:22 . 2007-01-18 14:24 26496 ----a-r- c:\windows\system32\drivers\RimSerial.sys2009-10-31 21:21 . 2009-11-09 01:50 -------- d-----w- c:\program files\Common Files\Research In Motion2009-10-31 21:20 . 2009-10-31 21:20 -------- d-----w- c:\program files\Research In Motion2009-10-29 03:08 . 2009-10-29 03:08 -------- d-----w- c:\program files\Rosetta Stone2009-10-29 03:07 . 2009-10-29 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\RosettaStoneLtdBackup2009-10-29 02:57 . 2009-10-29 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet2009-10-29 02:56 . 2009-10-29 02:56 -------- d-----w- c:\program files\Common Files\Macrovision Shared2009-10-29 02:55 . 2009-10-29 04:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Rosetta Stone2009-10-23 16:55 . 2009-10-23 16:56 -------- d-----w- c:\documents and settings\Customer\tmp.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-11-20 04:22 . 2009-05-30 21:30 -------- d-----w- c:\documents and settings\All Users\Application Data\RetroExp2009-11-20 03:59 . 2007-03-04 00:25 -------- d-----w- c:\program files\ESET2009-11-15 22:36 . 2007-03-03 06:36 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat2009-11-15 22:21 . 2007-03-08 23:32 109304 ----a-w- c:\documents and settings\Customer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT2009-11-15 22:02 . 2007-03-03 06:33 23348 ----a-w- c:\windows\system32\emptyregdb.dat2009-11-12 00:33 . 2007-03-03 00:15 102400 ----a-w- c:\windows\DUMP66b8.tmp2009-11-10 01:50 . 2007-03-04 00:16 -------- d-----w- c:\documents and settings\Customer\Application Data\uTorrent2009-11-08 06:31 . 2008-06-23 17:03 -------- d-----w- c:\documents and settings\Customer\Application Data\dvdcss2009-11-04 16:16 . 2009-11-04 16:16 4527419 ----a-w- c:\documents and settings\Customer\Application Data\Black Eyed Peas - Meet Me Halfway.zip2009-09-24 15:09 . 2009-10-01 01:22 3858432 ----a-w- c:\documents and settings\Customer\Application Data\Mozilla\Firefox\Profiles\rmnyn9v3.default\extensions\[email protected]\plugins\npRACtrl.dll2009-08-30 13:44 . 2009-08-30 13:44 507904 ----a-r- c:\windows\system32\btwapi.dll2009-08-27 04:01 . 2009-08-27 04:01 39936 ----a-w- c:\windows\system32\drivers\CDAC11BA.EXE2009-08-27 04:01 . 2009-08-27 04:01 30720 ---h--r- c:\windows\CdaC13BA.EXE2009-08-27 04:01 . 2009-08-27 04:01 112128 ---h--r- c:\windows\CdaC14BA.DLL2009-08-27 04:01 . 2009-08-27 04:01 8864 ----a-w- c:\windows\system32\drivers\CDAC15BA.SYS2009-08-27 02:59 . 2009-08-27 02:59 152576 ----a-w- c:\documents and settings\Customer\Application Data\Sun\Java\jre1.6.0_15\lzma.dll2001-09-28 21:00 . 2007-08-31 17:56 164864 ----a-w- c:\program files\UNWISE.EXE2004-03-15 22:51 . 2004-03-15 22:51 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll2003-05-01 14:36 . 2003-05-01 14:36 114688 ----a-w- c:\program files\internet explorer\plugins\LV7ActiveXControl.dll2006-01-23 14:32 . 2006-01-23 14:32 131072 ----a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll2007-02-08 15:48 . 2007-02-08 15:48 133920 ----a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll2008-02-28 18:30 . 2008-07-13 04:36 8784 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll2008-02-28 18:33 . 2008-07-13 04:36 245408 ----a-w- c:\program files\mozilla firefox\plugins\unicows.dll.((((((((((((((((((((((((((((( SnapShot@2009-11-19_04.21.38 ))))))))))))))))))))))))))))))))))))))))).+ 2009-11-20 04:20 . 2009-11-20 04:20 16384 c:\windows\Temp\Perflib_Perfdata_b8.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]"Google Update"="c:\documents and settings\Customer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-27 133104]"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-06 280779]"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064]"EPSON Stylus Photo R340 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE" [2005-04-26 98304]"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440]"FixCamera"="c:\windows\FixCamera.exe" [2007-02-10 20480]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]"RetroExpress"="c:\progra~1\IOMEGA~1\RETROS~1\RetroExpress.exe" [2008-12-11 9499928]"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336]"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-20 77824]"BOC-425"="c:\progra~1\Comodo\CBOClean\BOC425.exe" [2007-11-26 342272]"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\UHSPyXdvY.exe" [2009-11-17 1312080][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-12 44544]"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-14 99840]c:\documents and settings\Customer\Start Menu\Programs\Startup\Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]SolidWorks Task Scheduler Engine.lnk - c:\program files\SolidWorks\swScheduler\swBOEngine.exe [2006-7-19 192512]Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-3-1 3450608]c:\documents and settings\All Users\Start Menu\Programs\Startup\Device Detector 2.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2007-6-17 114688]Iomega StorCenter.lnk - c:\program files\Iomega StorCenter\sohoclient.exe [2009-5-30 1865040][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]"NoSMConfigurePrograms"= 1 (0x1)[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]"ForceClassicControlPanel"= 1 (0x1)"NoSMConfigurePrograms"= 1 (0x1)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"= 0 (0x0)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\system32\\sessmgr.exe"="c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="c:\\Program Files\\uTorrent\\utorrent.exe"="c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"c:\\temp\\HP_WebRelease\\Setup\\HPZnet01.exe"="c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"="c:\\WINDOWS\\system32\\mmc.exe"="c:\\crack\\airserv-ng.exe"="c:\\Program Files\\SolarWinds\\Engineer's Toolset\\Config-Transfer.exe"="c:\\Program Files\\SolarWinds\\Engineer's Toolset\\SNMP-Brute-Force-Attack.exe"="c:\\Program Files\\Iomega StorCenter\\retrospect\\Retrospect.exe"="c:\\Program Files\\Iomega StorCenter\\retrospect\\retrorun.exe"="c:\\Documents and Settings\\Customer\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"="c:\\Documents and Settings\\Customer\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"="c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"="c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016"500:UDP"= 500:UDP:@xpsp2res.dll,-22017R0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\system32\drivers\nipbcfk.sys [2/15/2007 5:23 PM 15136]R2 ANSYS FLEXlm license manager;ANSYS FLEXlm license manager;c:\program files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exe [5/21/2008 12:04 PM 1327104]R2 BOCore;BOCore;c:\program files\Comodo\CBOClean\BOCore.exe [11/15/2009 5:41 PM 73472]R2 Bwcdrv;BUFFALO Wireless Configuration;c:\windows\system32\drivers\BWCDRV.SYS [12/21/2003 3:21 AM 19840]R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]R2 ni488enumsvc;NI-488.2 Enumeration Service;c:\windows\system32\nipalsm.exe [2/16/2007 10:21 AM 12696]R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2/2/2007 9:36 AM 37376]R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2/2/2007 9:37 AM 21504]R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2/2/2007 10:55 AM 674304]R2 nidevldu;NI Device Loader;c:\windows\system32\nipalsm.exe [2/16/2007 10:21 AM 12696]R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2/2/2007 10:57 AM 50688]R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2/2/2007 9:37 AM 30208]R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmkl.sys [2/22/2007 11:18 AM 11552]R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2/2/2007 9:38 AM 111616]R2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2/23/2007 10:25 AM 11552]R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [5/24/2008 11:34 PM 2368]R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/25/2007 9:13 PM 24652]R3 nidimk;nidimk;c:\windows\system32\drivers\nidimkl.sys [2/21/2007 10:20 PM 11552]R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2kl.sys [2/21/2007 10:39 PM 11552]R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstskl.sys [2/25/2007 8:12 PM 11552]S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/24/2007 8:13 PM 721904]S3 ATHER;Atheros AR5000 Based Wireless Network Adapter Service;c:\windows\system32\drivers\ar5210b.sys [5/28/2007 12:48 PM 276981]S3 CBBCM43;BUFFALO WLI-CB-XXX Series Wireless LAN Adapter;c:\windows\system32\drivers\BCMWL5.SYS [7/11/2005 12:46 AM 372480]S3 DW90USB;DW90USB Device;c:\windows\system32\drivers\DW90USB.SYS [6/17/2007 6:50 AM 39096]S3 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.sys [1/11/2007 10:18 AM 20256]S3 ni1006k;NI PXI-1006 Chassis Pilot;c:\windows\system32\drivers\ni1006k.sys [2/22/2007 11:40 AM 25888]S3 ni1045k;NI PXI-1045 Chassis Pilot;c:\windows\system32\drivers\ni1045kl.sys [2/22/2007 11:43 AM 11552]S3 ni488lock;NI-488.2 Locking Service;c:\windows\system32\drivers\ni488lock.sys [2/26/2007 12:40 PM 16672]S3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrkl.sys [2/22/2007 6:18 PM 11552]S3 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfkl.sys [2/25/2007 8:12 PM 11552]S3 nidsark;nidsark;c:\windows\system32\drivers\nidsarkl.sys [2/23/2007 5:43 PM 11552]S3 nidwgk;nidwgk;c:\windows\system32\drivers\nidwgkl.sys [2/23/2007 10:32 PM 11552]S3 niemrk;niemrk;c:\windows\system32\drivers\niemrkl.sys [2/25/2007 7:13 PM 11552]S3 niesrk;niesrk;c:\windows\system32\drivers\niesrkl.sys [2/25/2007 7:13 PM 11552]S3 nifslk;nifslk;c:\windows\system32\drivers\nifslkl.sys [2/22/2007 1:21 PM 11552]S3 nigplk;nigplk;c:\windows\system32\drivers\nigplkl.sys [2/23/2007 4:20 PM 11552]S3 nihsdrk;nihsdrk;c:\windows\system32\drivers\nihsdrkl.sys [2/24/2007 1:10 AM 11552]S3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrkl.sys [2/25/2007 8:10 PM 11552]S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [12/18/2006 12:55 PM 14464]S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [12/18/2006 12:55 PM 151683]S3 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpkl.sys [2/22/2007 1:26 PM 11552]S3 ninshsdk;ninshsdk;c:\windows\system32\drivers\ninshsdkl.sys [2/23/2007 5:25 PM 11552]S3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [2/15/2007 11:00 PM 11552]S3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [2/15/2007 11:00 PM 11552]S3 nipsdk;nipsdk;c:\windows\system32\drivers\nipsdkl.sys [2/23/2007 10:19 PM 11552]S3 nipxigpk;NI PXI Generic Chassis Pilot;c:\windows\system32\drivers\nipxigpk.sys [2/22/2007 11:45 AM 20768]S3 nirfsa2k;nirfsa2k;c:\windows\system32\drivers\niRFSA2kl.sys [2/24/2007 4:19 AM 11552]S3 niscdk;niscdk;c:\windows\system32\drivers\niscdkl.sys [2/26/2007 4:31 PM 11552]S3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigkl.sys [2/25/2007 7:11 PM 11552]S3 nisftk;nisftk;c:\windows\system32\drivers\nisftkl.sys [2/24/2007 12:17 AM 11552]S3 nisldk;nisldk;c:\windows\system32\drivers\nisldkl.sys [2/23/2007 10:05 PM 11552]S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2/22/2007 11:34 AM 86304]S3 nispdk;nispdk;c:\windows\system32\drivers\nispdkl.sys [2/26/2007 4:31 PM 11552]S3 nisrcdk;nisrcdk;c:\windows\system32\drivers\nisrcdkl.sys [2/23/2007 10:28 PM 11552]S3 nissrk;nissrk;c:\windows\system32\drivers\nissrkl.sys [2/25/2007 7:13 PM 11552]S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2kl.sys [2/22/2007 8:17 PM 11552]S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrkl.sys [2/23/2007 3:14 AM 11552]S3 niswdk;niswdk;c:\windows\system32\drivers\niswdkl.sys [2/23/2007 8:44 PM 11552]S3 nitiork;nitiork;c:\windows\system32\drivers\nitiorkl.sys [2/23/2007 3:54 PM 11552]S3 nitnr2k;nitnr2k;c:\windows\system32\drivers\nitnr2kl.sys [2/24/2007 12:09 AM 11552]S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2/22/2007 10:42 AM 11552]S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2/23/2007 10:25 AM 11552]S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrkl.sys [2/25/2007 7:13 PM 11552]S3 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrkl.sys [2/25/2007 7:13 PM 11552]S3 nixsrkw;nixsrkw;c:\windows\system32\drivers\nixsrkw.sys [2/25/2007 7:13 PM 11552]S3 SolarWinds TFTP Server;SolarWinds TFTP Server;c:\program files\SolarWinds\Engineer's Toolset\SolarWinds TFTP Server.exe [12/5/2007 8:58 AM 61440]S3 SUSTUCAM;Susteen USB Cable Modem Driver;c:\windows\system32\drivers\sustucam.sys [2/19/2008 10:01 PM 38016]S3 SUSTUCAU;Susteen USB Cable USB Driver;c:\windows\system32\drivers\sustucau.sys [2/19/2008 9:56 PM 20096]S3 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.sys [2/25/2007 7:11 PM 27936]--- Other Services/Drivers In Memory ---*NewlyCreated* - NIPALK.Contents of the 'Scheduled Tasks' folder2009-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1284227242-839522115-1003Core.job- c:\documents and settings\Customer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-27 04:22]2009-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1284227242-839522115-1003UA.job- c:\documents and settings\Customer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-27 04:22]2009-11-20 c:\windows\Tasks\SDMsgUpdate (SD).job- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2008-03-18 12:53]..------- Supplementary Scan -------.uStart Page = hxxp://google.daemonsearch.com/intl/IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000Trusted Zone: aol.com\freeFF - ProfilePath - c:\documents and settings\Customer\Application Data\Mozilla\Firefox\Profiles\rmnyn9v3.default\FF - prefs.js: browser.startup.homepage - www.google.comFF - plugin: c:\documents and settings\Customer\Application Data\Mozilla\Firefox\Profiles\rmnyn9v3.default\extensions\[email protected]\plugins\npRACtrl.dllFF - plugin: c:\documents and settings\Customer\Application Data\Mozilla\plugins\npgoogletalk.dllFF - plugin: c:\documents and settings\Customer\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dllFF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dllFF - plugin: c:\program files\Google\Picasa3\npPicasa3.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\NpPopup.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dllFF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll---- FIREFOX POLICIES ----c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);.**************************************************************************catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-11-19 23:20Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.--------------------- LOCKED REGISTRY KEYS ---------------------[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]@Denied: (Full) (LocalSystem)"OOBETimer"=hex:7f,63,3e,be,ec,25,8e,19,be,a7,92,c6.--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'winlogon.exe'(644)c:\windows\system32\Ati2evxx.dll- - - - - - - > 'explorer.exe'(2540)c:\program files\Stardock\ObjectDock\DockShellHook.dllc:\windows\system32\ieframe.dllc:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTJBNS2.dllc:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTIntrfc.dllc:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTConfig.DLLc:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\JBNSRES.DLLc:\windows\system32\wpdshserviceobj.dllc:\program files\WinSCP3\DragExt.dllc:\windows\system32\portabledevicetypes.dllc:\windows\system32\portabledeviceapi.dll.------------------------ Other Running Processes ------------------------.c:\windows\system32\Ati2evxx.exec:\windows\system32\Drivers\bwcsrv.exec:\windows\system32\drivers\CDAC11BA.EXEc:\program files\FolderSize\FolderSizeSvc.exec:\program files\Java\jre6\bin\jqs.exec:\windows\system32\lkcitdl.exec:\windows\system32\lkads.exec:\windows\system32\lktsrv.exec:\program files\National Instruments\MAX\nimxs.exec:\program files\National Instruments\Shared\Security\nidmsrv.exec:\windows\system32\nisvcloc.exec:\program files\National Instruments\Shared\Tagger\tagsrv.exec:\windows\system32\HPZipm12.exec:\progra~1\IOMEGA~1\RETROS~1\retrorun.exec:\windows\system32\Ati2evxx.exec:\windows\system32\wscntfy.exec:\progra~1\IOMEGA~1\RETROS~1\retrospect.exec:\progra~1\MICROS~4\rapimgr.exec:\docume~1\Customer\LOCALS~1\Temp\SolidWorksLicTemp.0001.**************************************************************************.Completion time: 2009-11-19 23:31 - machine was rebootedComboFix-quarantined-files.txt 2009-11-20 04:31ComboFix2.txt 2009-11-19 04:32Pre-Run: 5,930,323,968 bytes freePost-Run: 5,891,457,024 bytes free- - End Of File - - EA371C67F515C8D1B1F4AC7BB66A5FF3 Link to post Share on other sites
Rorschach112 Posted November 20, 2009 Report Share Posted November 20, 2009 hiDownload TFC to your desktopOpen the file and close any other windows.It will close all programs itself when run, make sure to let it run uninterrupted.Click the Start button to begin the process. The program should not take long to finish its jobOnce its finished it should reboot your machine, if not, do this yourself to ensure a complete cleanPlease download Malwarebytes' Anti-Malware from HereDouble Click mbam-setup.exe to install the application.Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.If an update is found, it will download and install the latest version.Once the program has loaded, select "Perform Quick Scan", then click Scan. The scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to view the results.Make sure that everything is checked, and click Remove Selected.When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply.Extra Note:If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.Go to Kaspersky website and perform an online antivirus scan.Read through the requirements and privacy statement and click on Accept button.It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.When the downloads have finished, click on Settings.Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programsArchivesMail databases[*]Click on My Computer under Scan.[*]Once the scan is complete, it will display the results. Click on View Scan Report.[*]You will see a list of infected items there. Click on Save Report As....[*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here. Link to post Share on other sites
deocder Posted November 21, 2009 Author Report Share Posted November 21, 2009 I followed your directions and here's what came out:Malwarebytes' Anti-Malware 1.41Database version: 3204Windows 5.1.2600 Service Pack 311/20/2009 9:30:16 PMmbam-log-2009-11-20 (21-30-16).txtScan type: Quick ScanObjects scanned: 123226Time elapsed: 7 minute(s), 59 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 0Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:(No malicious items detected)--------------------------------------------------------------------------------KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, November 21, 2009 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, November 21, 2009 01:52:22 Records in database: 3252670--------------------------------------------------------------------------------Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yesScan area - My Computer: C:\ D:\Scan statistics: Objects scanned: 170033 Threats found: 9 Infected objects found: 30 Suspicious objects found: 0 Scan duration: 04:06:35File name / Threat / Threats countC:\Qoobox\Quarantine\C\WINDOWS\system32\duyasuwi.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\kamukufo.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\likulida.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\nuzadayi.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\pipibuju.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\rumapabo.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\siwipuyo.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\vetuyija.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\vikewami.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\Qoobox\Quarantine\C\WINDOWS\system32\zetojusu.dll.vir Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000157.dll Infected: Trojan.Win32.Monder.cvau 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000158.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000159.dll Infected: Trojan.Win32.Genome.bnjd 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000169.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000309.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000313.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000314.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000315.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000316.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000317.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000318.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000320.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000321.dll Infected: Packed.Win32.TDSS.aa 1C:\System Volume Information\_restore{FBC59DCF-F02A-4957-A8BB-08E1F11FA41A}\RP2\A0000323.dll Infected: Packed.Win32.TDSS.aa 1D:\PROGRAMS\Crossloop\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b 1D:\PROGRAMS\Crossloop\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.h 1D:\PROGRAMS\mbrfix\MbrFix.exe Infected: not-a-virus:RiskTool.Win32.MBRFix.a 1D:\PROGRAMS\ultravnc\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ac 1D:\PROGRAMS\vncserver\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1D:\PROGRAMS\vncserver\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1Selected area has been scanned. Link to post Share on other sites
Rorschach112 Posted November 21, 2009 Report Share Posted November 21, 2009 hiCLICK HERE to download the HijackThis Installer:Save HJTInstall.exe to your desktop.Double-click on HJTInstall.exe to run the program.By default it will install to C:\Program Files\Trend Micro\HijackThis.Accept the license agreement by clicking the "I Accept" button.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.Click "Save log" to save the log file and then the log will open in Notepad.Click on "Edit -> Select All" then click on "Edit -> Copy" to copy the entire contents of the log.Come back here to this thread and paste the log in your next reply.Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required. Link to post Share on other sites
deocder Posted November 22, 2009 Author Report Share Posted November 22, 2009 Here is the Hijack This log file:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 1:52:11 AM, on 11/22/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exeC:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exeC:\Program Files\Comodo\CBOClean\BOCORE.exeC:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exeC:\WINDOWS\system32\Drivers\bwcsrv.exeC:\WINDOWS\system32\drivers\CDAC11BA.EXEC:\Program Files\FolderSize\FolderSizeSvc.exeC:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\lkcitdl.exeC:\WINDOWS\system32\lkads.exeC:\WINDOWS\system32\lktsrv.exeC:\Program Files\National Instruments\MAX\nimxs.exeC:\WINDOWS\system32\nipalsm.exeC:\Program Files\National Instruments\Shared\Security\nidmsrv.exeC:\WINDOWS\system32\nisvcloc.exeC:\Program Files\National Instruments\Shared\Tagger\tagsrv.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\HPZipm12.exeC:\PROGRA~1\IOMEGA~1\RETROS~1\retrorun.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\WINDOWS\system32\nipalsm.exeC:\WINDOWS\VistaDrive\VistaDrive.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exeC:\WINDOWS\FixCamera.exeC:\PROGRA~1\IOMEGA~1\RETROS~1\RetroExpress.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\WINDOWS\vsnpstd3.exeC:\WINDOWS\tsnpstd3.exeC:\PROGRA~1\Comodo\CBOClean\BOC425.exeC:\WINDOWS\system32\wscntfy.exeC:\PROGRA~1\IOMEGA~1\RETROS~1\retrospect.exeC:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exeC:\Program Files\Microsoft ActiveSync\wcescomm.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\PROGRA~1\MICROS~4\rapimgr.exeC:\Program Files\Olympus\DeviceDetector\DevDtct2.exeC:\Program Files\Iomega StorCenter\sohoclient.exeC:\Program Files\SolidWorks\swScheduler\swBOEngine.exeC:\Program Files\Stardock\ObjectDock\ObjectDock.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\DOCUME~1\Customer\LOCALS~1\Temp\SolidWorksLicTemp.0001C:\Program Files\Java\jre6\bin\java.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\WINDOWS\System32\svchost.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/intl/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLLO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dllO4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exeO4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\IOMEGA~1\RETROS~1\RetroExpress.exe /hO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exeO4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [bOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exeO4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\UHSPyXdvY.exe" /runcleanupscriptO4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exeO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automountO4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Customer\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /cO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')O4 - S-1-5-18 Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exe (User 'SYSTEM')O4 - S-1-5-18 Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (User 'SYSTEM')O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')O4 - .DEFAULT Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exe (User 'Default user')O4 - .DEFAULT Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (User 'Default user')O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exeO4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exeO4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exeO4 - Global Startup: Iomega StorCenter.lnk = C:\Program Files\Iomega StorCenter\sohoclient.exeO8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dllO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dllO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dllO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLLO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} (EModelNonVersionSpecificViewControl Class) - http://www.3dpublisher.net/SWService/eDrawingsEnglish.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1237771195828O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1237771178421O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLLO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exeO23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exeO23 - Service: BUFFALO Wireless Configuration Service (bwcsrv) - Unknown owner - C:\WINDOWS\system32\Drivers\bwcsrv.exeO23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXEO23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exeO23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments, Inc. - C:\WINDOWS\system32\lkads.exeO23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments, Inc. - C:\WINDOWS\system32\lktsrv.exeO23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exeO23 - Service: NI-488.2 Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exeO23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exeO23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exeO23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exeO23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exeO23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corp. - C:\WINDOWS\system32\nisvcloc.exeO23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments, Inc. - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exeO23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: Retrospect Express HD Helper (RetroExp Helper) - EMC Corporation - C:\PROGRA~1\IOMEGA~1\RETROS~1\rthlpsvc.exeO23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\PROGRA~1\IOMEGA~1\RETROS~1\retrorun.exeO23 - Service: SolarWinds TFTP Server - SolarWinds - C:\Program Files\SolarWinds\Engineer's Toolset\SolarWinds TFTP Server.exeO23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exeO23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe--End of file - 14169 bytes Link to post Share on other sites
Rorschach112 Posted November 22, 2009 Report Share Posted November 22, 2009 Your logs are cleanFollow these steps to uninstall Combofix and tools used in the removal of malwareUninstall ComboFixRemove Combofix now that we're done with it.Please press the Windows Key and R on your keyboard. This will bring up the Run... command.Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")Please follow the prompts to uninstall Combofix.You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.Download OTC to your desktop and run itClick Yes to beginning the Cleanup process and remove these components, including this application.You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :http://www.adobe.com/products/acrobat/readstep2.htmlPlease download JavaRa to your desktop and unzip it to its own folderRun JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.Accept any prompts. Open JavaRa.exe again and select Search For Updates.Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer. Below I have included a number of recommendations for how to protect your computer against malware infections.Keep Windows updated by regularly checking their website at :http://windowsupdate.microsoft.com/This will ensure your computer has always the latest security updates available installed on your computer.SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.Make Internet Explorer more secureClick Start > RunType Inetcpl.cpl & click OKClick on the Security tabClick Reset all zones to default levelMake sure the Internet Zone is selected & Click Custom levelIn the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".Next Click OK, then Apply button and then OK to exit the Internet Properties page.[*]TFC - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.[*]MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.[*]Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop upblocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from HereIf you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.NoScript - for blocking ads and other potential website attacksMcAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling[*]Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.[*]ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.[*]FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.[*] Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.[*]Please read my guide on how to prevent malware and about safe computing hereThank you for your patience, and performing all of the procedures requested. Link to post Share on other sites
deocder Posted November 23, 2009 Author Report Share Posted November 23, 2009 I have followed the instructions and everything looks good! Thank you so much for guiding me through this process. Your help is greatly appreciated! Link to post Share on other sites
Rorschach112 Posted November 23, 2009 Report Share Posted November 23, 2009 Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. Link to post Share on other sites
Recommended Posts