Unsolved

This post is more than 5 years old

27 Posts

1692

January 21st, 2008 14:00

My HijackThis log ... please help

Hi -
 
My Dell Dimension 8300 has had major problems over the last few months. Here is my log.
 
Thoughts?
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:28 AM, on 1/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\MTV Networks\URGE\UrgeMS.exe
C:\Program Files\SiteAdvisor\4608\SiteAdv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [acefbcde] rundll32.exe "C:\WINDOWS\system32\wwcdaxgw.dll",b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} -
O23 - Service: McAfee Application Installer Cleanup (0040631200672703) (0040631200672703mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\004063~1.EXE
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\msmjbtgv.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 7607 bytes
 

27 Posts

January 22nd, 2008 18:00

part 10

C:\WINDOWS\system32\bwlduotn.dll

C:\WINDOWS\system32\cxqusjwx.dll

C:\WINDOWS\system32\f02WtR

C:\WINDOWS\system32\gindshny.dll

C:\WINDOWS\system32\hfduvdpb.dll

C:\WINDOWS\system32\horkkjba.dll

C:\WINDOWS\system32\jkswqxrs.dll

C:\WINDOWS\system32\jsdtjfbp.dll

C:\WINDOWS\system32\mcrh.tmp

C:\WINDOWS\SYSTEM32\mlnmp.bak1

C:\WINDOWS\SYSTEM32\mlnmp.bak2

C:\WINDOWS\SYSTEM32\mlnmp.ini

C:\WINDOWS\SYSTEM32\mlnmp.ini2

C:\WINDOWS\system32\mroujrsr.dll

C:\WINDOWS\system32\pfqqytfx.dll

C:\WINDOWS\system32\pmnlm.dll

C:\WINDOWS\SYSTEM32\rqtwa.bak1

C:\WINDOWS\SYSTEM32\rqtwa.bak2

C:\WINDOWS\SYSTEM32\rqtwa.ini

C:\WINDOWS\SYSTEM32\rqtwa.ini2

C:\WINDOWS\SYSTEM32\rqtwa.tmp

C:\WINDOWS\SYSTEM32\sklqxnyy.ini

C:\WINDOWS\SYSTEM32\wgxadcww.ini

C:\WINDOWS\system32\wwcdaxgw.dll

C:\WINDOWS\SYSTEM32\xwjsuqxc.ini

C:\WINDOWS\system32\ycxollfe.dll

C:\WINDOWS\SYSTEM32\ynhsdnig.ini

C:\WINDOWS\system32\yxukijya.dll

C:\WINDOWS\system32\yynxqlks.dll

F:\Autorun.inf

 

.

(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))

 

.

-------\LEGACY_DOMAINSERVICE

 

 

(((((((((((((((((((((((((   Files Created from 2007-12-22 to 2008-01-22  )))))))))))))))))))))))))))))))

.

 

2008-01-22 11:27 . 2004-08-03 23:00 260,272     --a------   C:\cmldr

2008-01-22 11:27 . 2007-10-19 09:16 211   --a------   C:\Boot.bak

2008-01-22 11:23 . 2000-08-31 08:00 51,200      --a------   C:\WINDOWS\Nircmd.exe

2008-01-21 11:41 . 2008-01-21 11:41

d--------   C:\Program Files\Trend Micro

2008-01-18 11:09 . 2008-01-21 10:36 692,515     --ahs----   C:\WINDOWS\SYSTEM32\hleyhkut.ini

2008-01-16 10:57 . 2008-01-18 11:04 760,330     --ahs----   C:\WINDOWS\SYSTEM32\btpavxep.ini

2008-01-14 09:27 . 2008-01-16 10:49 746,061     --ahs----   C:\WINDOWS\SYSTEM32\dguulbls.ini

2008-01-08 10:04 . 2008-01-14 09:21 722,710     --ahs----   C:\WINDOWS\SYSTEM32\ogmfnasi.ini

2008-01-07 10:02 . 2008-01-08 10:02 722,590     --ahs----   C:\WINDOWS\SYSTEM32\fxtluwst.ini

2008-01-02 09:55 . 2008-01-07 09:56 795,757     --ahs----   C:\WINDOWS\SYSTEM32\xlccohde.ini

2008-01-01 09:10 . 2008-01-02 09:50 693,597     --ahs----   C:\WINDOWS\SYSTEM32\nifwmpvo.ini

2007-12-29 12:00 . 2008-01-01 09:08 693,477     --ahs----   C:\WINDOWS\SYSTEM32\dplveflw.ini

2007-12-25 10:48 . 2007-12-29 11:54 737,234     --ahs----   C:\WINDOWS\SYSTEM32\nvblndla.ini

2007-12-23 10:27 . 2007-12-25 10:45 808,531     --ahs----   C:\WINDOWS\SYSTEM32\xfjvohnq.ini

 

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-21 19:00  ---------   d-----w     C:\Program Files\McAfee

2007-11-26 17:24  ---------   d-----w     C:\Program Files\Common Files\McAfee

2004-10-04 01:02  28,312      ----a-w     C:\Program Files\blomster.zip

2004-10-03 20:30  34,719      ----a-w     C:\Program Files\willingrace.ZIP

2004-10-03 20:30  34,113      ----a-w     C:\Program Files\parkland.zip

2004-10-03 20:30  172,953     ----a-w     C:\Program Files\marketingscript.zip

2004-10-03 20:30  15,121      ----a-w     C:\Program Files\jarman.zip

2004-10-03 20:30  11,338      ----a-w     C:\Program Files\thebends.zip

2004-10-03 20:29  7,232 ----a-w     C:\Program Files\alphashapes.zip

2004-10-03 20:29  62,916      ----a-w     C:\Program Files\cheltpress.zip

2004-10-03 20:29  36,945      ----a-w     C:\Program Files\adria.zip

2004-10-03 20:29  35,290      ----a-w     C:\Program Files\4990810.zip

2004-10-03 20:29  197,999     ----a-w     C:\Program Files\28dayslater.zip

2004-10-03 20:28  47,501      ----a-w     C:\Program Files\lmshippychick.zip

2004-05-11 17:33  27,652,458  ----a-w     C:\Program Files\nero63110.exe

2004-05-01 22:38  9,324,503   ----a-w     C:\Program Files\jfsetup.exe

2003-12-03 20:40  16,251,072  ----a-w     C:\Program Files\AdbeRdr60_enu_full.exe

2003-11-28 18:13  1,955,904   ----a-w     C:\Program Files\ppviewer.exe

1999-03-14 15:47  53,720      ----a-w     C:\Program Files\AbcKids.ttf

1998-09-29 17:54  673,280     ----a-w     C:\Program Files\I_view32.exe

.

 

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{34809A2B-2580-430F-87FA-4C7609E1848D}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77701e16-9bfe-4b63-a5b4-7bd156758a37}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85168A5E-1A30-43C5-8E7F-669D03146A4C}]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

 

27 Posts

January 22nd, 2008 18:00

part 5

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\23032

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\23270

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\24996

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\25043

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\25736

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\26106

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\26410

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\26664

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\26777

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\26869

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\27414

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\27503

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\27505

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\27515

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\28065

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\28383

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\28413

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\28812

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\29642

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\297534

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\30604

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\30754

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\308156

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\31262

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\31409

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32052

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32242

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32541

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32639

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32680

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32812

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\32883

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34123

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34186

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34237

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34374

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34388

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34637

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\34706

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\348760

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\35000

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\35047

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\35150

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\35178

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\35554

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\356660

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\36072

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\36079

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\36834

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\387961

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\38865

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\38868

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\398397

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\39897

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\39947

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\39972

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41115

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41243

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\4142

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41421

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41499

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41507

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41529

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41532

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41533

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\41641

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\42034

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\4226

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\43098

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\43638

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\43880

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44228

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44249

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44271

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44293

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44306

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44315

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44458

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44492

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44571

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44769

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\44878

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\45521

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\45642

27 Posts

January 22nd, 2008 18:00

part 7

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\73876

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\7482

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\7518

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\7521

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\7553

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\76119

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\7690

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\7720

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\77468

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\78220

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\78600

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\80193

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\80639

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\80670

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\81551

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\81705

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\81721

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\82071

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\82292

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\82511

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\82646

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\8290

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\83139

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\83216

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\83505

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\83743

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\84876

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\85418

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\86140

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\86173

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\86354

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\86379

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\86423

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\87185

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\87325

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\87385

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\87499

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\87995

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\89075

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\8941

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\90009

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\90358

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\91224

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\91231

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\92855

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\93110

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\93212

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\93462

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\93811

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\93921

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\94125

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\94789

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\94846

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95610

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95615

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95645

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95678

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95704

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95717

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95741

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95825

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\95873

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\96961

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\97499

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\97518

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\97524

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\98034

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\9805

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\98248

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\99163

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\9974

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\dynamic\ustat\31b1.dat

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\ads.cdf

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\business_promo.htm

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\buttondir.txt

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\components.cdf

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_1000.res

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_2000.res

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_3000.res

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bar.res

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar1.res

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar10.res

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar11.res

C:\Documents and Settings\Kelley Davis\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar12.res

27 Posts

January 22nd, 2008 19:00

Here's the new ComboFix log:

ComboFix 08-01-21.7 - Bryan Davis 2008-01-22 16:27:29.2 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.653 [GMT -5:00]
Running from: C:\Documents and Settings\Bryan Davis\Desktop\ComboFix.exe
.
(((((((((((((((((((((((((   Files Created from 2007-12-22 to 2008-01-22  )))))))))))))))))))))))))))))))
.
2008-01-22 11:27 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-01-22 11:27 . 2007-10-19 09:16 211 --a------ C:\Boot.bak
2008-01-22 11:23 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-21 11:41 . 2008-01-21 11:41   d-------- C:\Program Files\Trend Micro
2008-01-18 11:09 . 2008-01-21 10:36 692,515 --ahs---- C:\WINDOWS\SYSTEM32\hleyhkut.ini
2008-01-16 10:57 . 2008-01-18 11:04 760,330 --ahs---- C:\WINDOWS\SYSTEM32\btpavxep.ini
2008-01-14 09:27 . 2008-01-16 10:49 746,061 --ahs---- C:\WINDOWS\SYSTEM32\dguulbls.ini
2008-01-08 10:04 . 2008-01-14 09:21 722,710 --ahs---- C:\WINDOWS\SYSTEM32\ogmfnasi.ini
2008-01-07 10:02 . 2008-01-08 10:02 722,590 --ahs---- C:\WINDOWS\SYSTEM32\fxtluwst.ini
2008-01-02 09:55 . 2008-01-07 09:56 795,757 --ahs---- C:\WINDOWS\SYSTEM32\xlccohde.ini
2008-01-01 09:10 . 2008-01-02 09:50 693,597 --ahs---- C:\WINDOWS\SYSTEM32\nifwmpvo.ini
2007-12-29 12:00 . 2008-01-01 09:08 693,477 --ahs---- C:\WINDOWS\SYSTEM32\dplveflw.ini
2007-12-25 10:48 . 2007-12-29 11:54 737,234 --ahs---- C:\WINDOWS\SYSTEM32\nvblndla.ini
2007-12-23 10:27 . 2007-12-25 10:45 808,531 --ahs---- C:\WINDOWS\SYSTEM32\xfjvohnq.ini
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 19:00 --------- d-----w C:\Program Files\McAfee
2007-11-26 17:24 --------- d-----w C:\Program Files\Common Files\McAfee
2007-11-14 07:26 450,560 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\SYSTEM32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\lsasrv.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2007-10-30 09:55 3,065,856 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 22:40 222,720 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2004-10-04 01:02 28,312 ----a-w C:\WINDOWS\Fonts\blomster.zip
2004-10-04 01:02 28,312 ----a-w C:\Program Files\blomster.zip
2004-10-03 20:30 34,719 ----a-w C:\WINDOWS\Fonts\willingrace.ZIP
2004-10-03 20:30 34,719 ----a-w C:\Program Files\willingrace.ZIP
2004-10-03 20:30 34,113 ----a-w C:\WINDOWS\Fonts\parkland.zip
2004-10-03 20:30 34,113 ----a-w C:\Program Files\parkland.zip
2004-10-03 20:30 172,953 ----a-w C:\WINDOWS\Fonts\marketingscript.zip
2004-10-03 20:30 172,953 ----a-w C:\Program Files\marketingscript.zip
2004-10-03 20:30 15,121 ----a-w C:\WINDOWS\Fonts\jarman.zip
2004-10-03 20:30 15,121 ----a-w C:\Program Files\jarman.zip
2004-10-03 20:30 11,338 ----a-w C:\WINDOWS\Fonts\thebends.zip
2004-10-03 20:30 11,338 ----a-w C:\Program Files\thebends.zip
2004-10-03 20:29 7,232 ----a-w C:\WINDOWS\Fonts\alphashapes.zip
2004-10-03 20:29 7,232 ----a-w C:\Program Files\alphashapes.zip
2004-10-03 20:29 62,916 ----a-w C:\WINDOWS\Fonts\cheltpress.zip
2004-10-03 20:29 62,916 ----a-w C:\Program Files\cheltpress.zip
2004-10-03 20:29 36,945 ----a-w C:\WINDOWS\Fonts\adria.zip
2004-10-03 20:29 36,945 ----a-w C:\Program Files\adria.zip
2004-10-03 20:29 35,290 ----a-w C:\WINDOWS\Fonts\4990810.zip
2004-10-03 20:29 35,290 ----a-w C:\Program Files\4990810.zip
2004-10-03 20:29 197,999 ----a-w C:\WINDOWS\Fonts\28dayslater.zip
2004-10-03 20:29 197,999 ----a-w C:\Program Files\28dayslater.zip
2004-10-03 20:28 47,501 ----a-w C:\WINDOWS\Fonts\lmshippychick.zip
2004-10-03 20:28 47,501 ----a-w C:\Program Files\lmshippychick.zip
2004-05-11 17:33 27,652,458 ----a-w C:\Program Files\nero63110.exe
2004-05-01 22:38 9,324,503 ----a-w C:\Program Files\jfsetup.exe
2003-12-03 20:40 16,251,072 ----a-w C:\Program Files\AdbeRdr60_enu_full.exe
2003-11-28 18:13 1,955,904 ----a-w C:\Program Files\ppviewer.exe
1999-03-14 15:47 53,720 ----a-w C:\Program Files\AbcKids.ttf
1998-09-29 17:54 673,280 ----a-w C:\Program Files\I_view32.exe
.
(((((((((((((((((((((((((((((   snapshot@2008-01-22_12.10.48.37   )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-22 15:13:23 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2008-01-22 19:29:33 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2008-01-22 15:13:23 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2008-01-22 19:29:33 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2008-01-22 19:29:33 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 12:58 1339392]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-02 17:20 68856]
"Uniblue SpyEraser"="" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 03:06 7311360]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2007-06-28 09:59:56 54512]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 22:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--a------ 2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
--a------ 2002-04-03 01:01 135264 C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2003-08-06 02:04 114741 C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DropBoxUtility]
--a------ 2007-08-24 00:40 258048 C:\Program Files\DropBox\DropBox\DropBox.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
--a------ 2003-08-13 11:27 28672 C:\WINDOWS\System32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2002-03-18 06:00 188416 C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iRiver Updater]
--a------ 2004-07-01 16:20 212992 C:\Updater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
--a------ 2002-07-16 08:21 28672 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a------ 2006-11-07 15:41 8192 C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-12-10 03:06 7311360 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2005-12-10 03:06 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-12-10 03:06 1519616 C:\WINDOWS\SYSTEM32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--------- 2003-08-26 20:47 204800 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2003-11-19 08:54 77824 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-06-28 17:50 1258744 c:\program files\valve\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-02 17:20 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2003-11-19 08:56 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 01:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 02:00 90112 C:\WINDOWS\UpdReg.EXE
S2 EBIGTPJQ;EBIGTPJQ;C:\WINDOWS\system32\ebigtpjq.fmi []
.
Contents of the 'Scheduled Tasks' folder
"2006-07-29 23:00:14 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2006-07-29 23:00:12 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe.4158 0
"2007-08-17 16:14:34 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-22 16:28:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-22 16:30:07
ComboFix-quarantined-files.txt  2008-01-22 21:29:34
ComboFix2.txt  2008-01-22 17:11:14
.
2008-01-16 15:56:52 --- E O F --- 

4 Apprentice

 • 

20.5K Posts

January 22nd, 2008 19:00

Something has messed up the format of your ComboFix log posts. You should be using the same forum posting settings as you did to post your HijackThis log.

Please launch HijackThis and place a checkmark next to the following:

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O20 - Winlogon Notify: urqqpmm - urqqpmm.dll (file missing)


Close all windows except Hijackthis and click "Fix Checked".
Close HijackThis.

* Close any open browsers. Disconnect from the internet.
* Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix.
Double click ComboFix.exe and follow the prompts.
You will temporarily lose the Desktop while the scan is running. Once the scan is done your Desktop will return to normal.

When finished, it will produce a log for you. Do not copy the log to Word. Copy/paste that Notepad copy of the log in your next reply along with a fresh HijackThis log.

Notes:
* Do not mouseclick ComboFix's window while it's running. That may cause it to stall.
* ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
* Don't forget to enable your anti-virus before coming back online to post your logs.

Note: The above instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use.


Message Edited by Bugbatter on 01-22-2008 04:06 PM

27 Posts

January 22nd, 2008 19:00

Hi -
Here's the latest Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:37:17 PM, on 1/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\SiteAdvisor\4608\SiteAdv.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O2 - BHO: (no name) - {34809A2B-2580-430F-87FA-4C7609E1848D} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: (no name) - {85168A5E-1A30-43C5-8E7F-669D03146A4C} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [acefbcde] rundll32.exe "C:\WINDOWS\system32\wwcdaxgw.dll",b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} -
O20 - Winlogon Notify: awtqr - C:\WINDOWS\
O20 - Winlogon Notify: pmnlm - C:\WINDOWS\
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8858 bytes

27 Posts

January 22nd, 2008 21:00

I have no idea what TeaTimer is ... I've never heard of it.

4 Apprentice

 • 

20.5K Posts

January 22nd, 2008 21:00

Please review these instructions as posted in my initial reply:

QUOTE:
"Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using."


At what point did you enable TeaTimer?

4 Apprentice

 • 

20.5K Posts

January 22nd, 2008 22:00

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

27 Posts

January 23rd, 2008 10:00

Here's the latest ComboFix log:

ComboFix 08-01-21.7 - Bryan Davis 2008-01-23  7:25:45.3 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.657 [GMT -5:00]
Running from: C:\Documents and Settings\Bryan Davis\Desktop\ComboFix.exe
.
(((((((((((((((((((((((((   Files Created from 2007-12-23 to 2008-01-23  )))))))))))))))))))))))))))))))
.
2008-01-22 11:27 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-01-22 11:27 . 2007-10-19 09:16 211 --a------ C:\Boot.bak
2008-01-22 11:23 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-21 11:41 . 2008-01-21 11:41   d-------- C:\Program Files\Trend Micro
2008-01-18 11:09 . 2008-01-21 10:36 692,515 --ahs---- C:\WINDOWS\SYSTEM32\hleyhkut.ini
2008-01-16 10:57 . 2008-01-18 11:04 760,330 --ahs---- C:\WINDOWS\SYSTEM32\btpavxep.ini
2008-01-14 09:27 . 2008-01-16 10:49 746,061 --ahs---- C:\WINDOWS\SYSTEM32\dguulbls.ini
2008-01-08 10:04 . 2008-01-14 09:21 722,710 --ahs---- C:\WINDOWS\SYSTEM32\ogmfnasi.ini
2008-01-07 10:02 . 2008-01-08 10:02 722,590 --ahs---- C:\WINDOWS\SYSTEM32\fxtluwst.ini
2008-01-02 09:55 . 2008-01-07 09:56 795,757 --ahs---- C:\WINDOWS\SYSTEM32\xlccohde.ini
2008-01-01 09:10 . 2008-01-02 09:50 693,597 --ahs---- C:\WINDOWS\SYSTEM32\nifwmpvo.ini
2007-12-29 12:00 . 2008-01-01 09:08 693,477 --ahs---- C:\WINDOWS\SYSTEM32\dplveflw.ini
2007-12-25 10:48 . 2007-12-29 11:54 737,234 --ahs---- C:\WINDOWS\SYSTEM32\nvblndla.ini
2007-12-23 10:27 . 2007-12-25 10:45 808,531 --ahs---- C:\WINDOWS\SYSTEM32\xfjvohnq.ini
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 19:00 --------- d-----w C:\Program Files\McAfee
2007-11-26 17:24 --------- d-----w C:\Program Files\Common Files\McAfee
2007-11-14 07:26 450,560 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\SYSTEM32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\lsasrv.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2007-10-30 09:55 3,065,856 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 22:40 222,720 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2004-10-04 01:02 28,312 ----a-w C:\WINDOWS\Fonts\blomster.zip
2004-10-04 01:02 28,312 ----a-w C:\Program Files\blomster.zip
2004-10-03 20:30 34,719 ----a-w C:\WINDOWS\Fonts\willingrace.ZIP
2004-10-03 20:30 34,719 ----a-w C:\Program Files\willingrace.ZIP
2004-10-03 20:30 34,113 ----a-w C:\WINDOWS\Fonts\parkland.zip
2004-10-03 20:30 34,113 ----a-w C:\Program Files\parkland.zip
2004-10-03 20:30 172,953 ----a-w C:\WINDOWS\Fonts\marketingscript.zip
2004-10-03 20:30 172,953 ----a-w C:\Program Files\marketingscript.zip
2004-10-03 20:30 15,121 ----a-w C:\WINDOWS\Fonts\jarman.zip
2004-10-03 20:30 15,121 ----a-w C:\Program Files\jarman.zip
2004-10-03 20:30 11,338 ----a-w C:\WINDOWS\Fonts\thebends.zip
2004-10-03 20:30 11,338 ----a-w C:\Program Files\thebends.zip
2004-10-03 20:29 7,232 ----a-w C:\WINDOWS\Fonts\alphashapes.zip
2004-10-03 20:29 7,232 ----a-w C:\Program Files\alphashapes.zip
2004-10-03 20:29 62,916 ----a-w C:\WINDOWS\Fonts\cheltpress.zip
2004-10-03 20:29 62,916 ----a-w C:\Program Files\cheltpress.zip
2004-10-03 20:29 36,945 ----a-w C:\WINDOWS\Fonts\adria.zip
2004-10-03 20:29 36,945 ----a-w C:\Program Files\adria.zip
2004-10-03 20:29 35,290 ----a-w C:\WINDOWS\Fonts\4990810.zip
2004-10-03 20:29 35,290 ----a-w C:\Program Files\4990810.zip
2004-10-03 20:29 197,999 ----a-w C:\WINDOWS\Fonts\28dayslater.zip
2004-10-03 20:29 197,999 ----a-w C:\Program Files\28dayslater.zip
2004-10-03 20:28 47,501 ----a-w C:\WINDOWS\Fonts\lmshippychick.zip
2004-10-03 20:28 47,501 ----a-w C:\Program Files\lmshippychick.zip
2004-05-11 17:33 27,652,458 ----a-w C:\Program Files\nero63110.exe
2004-05-01 22:38 9,324,503 ----a-w C:\Program Files\jfsetup.exe
2003-12-03 20:40 16,251,072 ----a-w C:\Program Files\AdbeRdr60_enu_full.exe
2003-11-28 18:13 1,955,904 ----a-w C:\Program Files\ppviewer.exe
1999-03-14 15:47 53,720 ----a-w C:\Program Files\AbcKids.ttf
1998-09-29 17:54 673,280 ----a-w C:\Program Files\I_view32.exe
.
(((((((((((((((((((((((((((((   snapshot@2008-01-22_12.10.48.37   )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-22 15:13:23 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2008-01-23 12:25:54 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2008-01-22 15:13:23 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2008-01-23 12:25:54 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2008-01-23 12:25:54 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{34809A2B-2580-430F-87FA-4C7609E1848D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77701e16-9bfe-4b63-a5b4-7bd156758a37}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85168A5E-1A30-43C5-8E7F-669D03146A4C}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 12:58 1339392]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-02 17:20 68856]
"Uniblue SpyEraser"="" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 03:06 7311360]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"acefbcde"="C:\WINDOWS\system32\wwcdaxgw.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2007-06-28 09:59:56 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqr]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 22:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--a------ 2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
--a------ 2002-04-03 01:01 135264 C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2003-08-06 02:04 114741 C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DropBoxUtility]
--a------ 2007-08-24 00:40 258048 C:\Program Files\DropBox\DropBox\DropBox.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
--a------ 2003-08-13 11:27 28672 C:\WINDOWS\System32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2002-03-18 06:00 188416 C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iRiver Updater]
--a------ 2004-07-01 16:20 212992 C:\Updater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
--a------ 2002-07-16 08:21 28672 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a------ 2006-11-07 15:41 8192 C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-12-10 03:06 7311360 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2005-12-10 03:06 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-12-10 03:06 1519616 C:\WINDOWS\SYSTEM32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--------- 2003-08-26 20:47 204800 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2003-11-19 08:54 77824 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-06-28 17:50 1258744 c:\program files\valve\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-02 17:20 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2003-11-19 08:56 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 01:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 02:00 90112 C:\WINDOWS\UpdReg.EXE
S2 EBIGTPJQ;EBIGTPJQ;C:\WINDOWS\system32\ebigtpjq.fmi []
.
Contents of the 'Scheduled Tasks' folder
"2006-07-29 23:00:14 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2006-07-29 23:00:12 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe.4158 0
"2007-08-17 16:14:34 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-23 07:32:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-23  7:33:43
ComboFix-quarantined-files.txt  2008-01-23 12:33:13
ComboFix2.txt  2008-01-22 21:30:08
ComboFix3.txt  2008-01-22 17:11:14
.
2008-01-16 15:56:52 --- E O F --- 

27 Posts

January 23rd, 2008 10:00

Here's the HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:24, on 2008-01-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SiteAdvisor\4608\SiteAdv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O2 - BHO: (no name) - {34809A2B-2580-430F-87FA-4C7609E1848D} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: (no name) - {85168A5E-1A30-43C5-8E7F-669D03146A4C} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [acefbcde] rundll32.exe "C:\WINDOWS\system32\wwcdaxgw.dll",b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} -
O20 - Winlogon Notify: awtqr - C:\WINDOWS\
O20 - Winlogon Notify: pmnlm - C:\WINDOWS\
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 8798 bytes

27 Posts

January 23rd, 2008 10:00

I ran HijackThis again this morning and will post the log contents shortly.
 
But, I could not get ComboFix to run at first. The blue "ComboFix is preparing to run" screen appears and just sat there ... even after nearly 30 minutes.
 
Also, when I started machine this morning for the first time, I noticed a few things:
  • Overall, the machine ran very slowly. When the blue "Windows is starting up" screen appeared, it was on-screen for much longer than usual.
  • When I did receive the list of IDs that I could use to sign onto the machine, I clicked on my ID and it took much longer than usual to get to my desktop.
  • Once on my desktop, I received a window with this message: "C:\windows\system32\wwcdaxgw.dll. The specified module could not be found."
  • In the directions to use ComboFix, it talks about the appearance and clock settings changing. This didn't happen yesterday when I ran CF twice, but when I booted up my machine this a.m., I saw many things did look different (clock format, taskbar color, missing icons from system tray).
  • When I was using the machine yesterday after running CF, it was running great and as it "should" be. It seemed really messed up this morning when I first started it ... ran very slow, I couldn't restore the internet connection; couldn't get IE to appear, let alone use and when I restarted the machine, it took a very long time on the "Saving your settings" screen.

As for HijackThis, when I ran it this a.m., it did NOT have O20 - Winlogon Notify: urqqpmm - urqqpmm.dll (file missing) to check off. The R3 - URLSearch ... was there, but not the 020.

I just re-booted the machine and it's now running more like it should (although I still received the " "C:\windows\system32\wwcdaxgw.dll. The specified module could not be found." message). The clock format is still different (as expected), but the taskbar now looks as it used to, the internet connection has been restored and ComboFix is running.

I'm using my work laptop to post this since I couldn't get my home machine to connect to the internet. Once I receive the log from CF, I'll post the contents of that and the HijackThis log. (I didn't want to have to re-type this post on my home machine).

4 Apprentice

 • 

20.5K Posts

January 23rd, 2008 11:00

I do not understand why you ran HijackThis and ComboFix again before addressing the TeaTimer issue.
You can go ahead and fix this on your own, or I can help you. It is counter-productive and dangerous for you to be running these tools when not instructed to do so.

You said that you have never heard of Teatimer. Someone apparently enabled it on that computer. If you are going to work with me, we will have to take care of that because it conflicts with HijackThis.

While both TeaTimer and SpyBot are closed:
Download ResetTeaTimer.bat to remove all entries set by TeaTimer (and preventing TeaTimer from restoring them upon reactivation).

http://downloads.subratam.org/ResetTeaTimer.bat

Alternate link:
http://www.bleepingcomputer.com/files/lonny/ResetTeaTimer.bat

Right click and save link as
Save it as resetteatimer.bat
Save it to your Desktop

1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
5) Restart your computer.

Double click on resetteatimer.bat and wait for it to finish

Since it will not be needed again, delete ResetTeaTimer.bat after you run it.
When we are COMPLETELY finished with ALL your fixes, you can turn TeaTimer back on again via SpyBot's tools resident page.

Open HijackThis and click on the "Open the Misc Tools section" button.
Click on the "Open Uninstall Manager" button.
Click the "Save List" button. After you click the "Save List" button, you will be asked where to save the file. Select a place to save it. The list should open in notepad.
Copy and paste that list here.

On the other hand, if you prefer to handle this on your own, let me know so I can close this case and devote more time to helping others.

27 Posts

January 23rd, 2008 12:00

Excuse me ... I have every intention of working with you and am not trying to be difficult as I very much need help with my computer. I'm following your directions, in which you asked about teatime (which I googled and found out it was part of spybot and I was not aware of that) and then you told me to run hijackthis and then combofix per your post of 01-22-2008 05:24 PM :

Please review these instructions as posted in my initial reply:

QUOTE:
"Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using."
 
At what point did you enable TeaTimer?

 
In no way does this post nor the post of 01-22-2008 06:07 PM indicate to me that I had to do anything with teatime ... you merely asked about it.
 
I appreciate your help, but I do not appeciate the tone of your last post.
 
I will follow your latest instructions and report back.
 
Thank you.

27 Posts

January 23rd, 2008 12:00

Here is the List from HijackThis:
 
3D Groove Playback Engine
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player ActiveX
Adobe Reader 7.0.5 Language Support
Adobe Reader 7.0.9
Adobe® Photoshop® Album Starter Edition 3.0
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AOL Instant Messenger
ArcSoft Camera Suite 2.1
AviSynth 2.5
BCM V.92 56K Modem
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities PhotoStitch
Canon Utilities ZoomBrowser EX
Citrix ICA Web Client
DAO
Dell Digital Jukebox Driver
Dell Media Experience
Dell Picture Studio - Dell Image Expert
Dell Solution Center
DellSupport
DivX Codec
DropBox
DS21Patch
DVD Shrink 3.2
DVDSentry
EarthLink Setup Files
FlashFXP
Google Toolbar for Internet Explorer
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB910998)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB926239)
hp deskjet 5550 series
hp deskjet 5550 series (Remove only)
hp print screen utility
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet
iriver Music Manager
iRiver Updater
ISOX Creator
Java 2 Runtime Environment, SE v1.4.2
Macromedia Dreamweaver 8
Macromedia Extension Manager
Macromedia Fireworks 8
Macromedia Flash 8
Macromedia Flash 8 Video Encoder
Macromedia Shockwave Player
Magic ISO Maker v5.3 (build 0216)
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2003
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Standard Edition 2003
Microsoft Picture It! Photo 7.0
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Windows Journal Viewer
Microsoft Works 2003 Setup Launcher
Microsoft Works 7.0
Microsoft Works Suite Add-in for Microsoft Word
Modem Helper
MSN
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
Musicmatch® Jukebox
Nero Suite
NeroVision Express Content
NVIDIA Drivers
Paint Shop Pro 7
PCFriendly
PowerDVD
Quake 4(TM)
Quake III Arena
Quake III Arena Point Release 1.31
Quake III Arena Point Release 1.32
QuickTime
RealOne Player
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Shockwave
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Sound Blaster Live!
Spybot - Search & Destroy
Steam
Uniblue RegistryBooster 2
Uniblue SpyEraser
Uniblue System Tweaker
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
URGE
WavePad Uninstall
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
Yahoo! Address AutoComplete
Yahoo! Anti-Spy
Yahoo! Browser Services
Yahoo! Messenger
Yahoo! Music Jukebox
 
No Events found!

Top