Combofix is optimized to run in normal mode, so no need to run it in safe mode unless that's the only mode the pc could boot into.
Combofix seems to have taken care of it. It deleted lots of files/folders belonging to the Antivirus XP 2008.
Is the pc still having problems?
Also clean your temp folders.
Download and run ATF Cleaner by Atribune.
http://www.atribu
Do
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser,
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
OR:
CCleaner:
http://ww





by: john6216Posted on 2008-08-14 at 13:27:20ID: 22233943
Here is the same log without having to open the attachment. 1752 [GMT -8:00] ktop\Combo Fix.exe
(((((((((( ((( Other Deletions )))))))))))))))))))))))))) )))))))))) )))))))))) )))
lication Data\rhccfkj0e5ft nloader\qm gr0.dat nloader\qm gr1.dat Data\rhccfkj0e5ft \systempro file\Appli cation Data\rhccfkj0e5ft s\Byc06.sy s kj0e5ft.ex e j0e5ft.bmp
(((((((((( ((( Drivers/Services )))))))))))))))))))))))))) )))))))))) )))))))))) )))
)))))
lication Data\Windows Desktop Search lication Data\SiteAdvisor lication Data\Share-to-Web Upload Folder \systempro file\Appli cation Data\SiteAdvisor Data\U3 CALS~1 he\tcpip.s ys he\mswsock .dll he\tcpip6. sys he\dnsapi. dll he\afd.sys he\jscript .dll he\vbscrip t.dll he\scrobj. dll he\scrrun. dll he\wscript .exe he\cscript .exe he\wshext. dll
(((((((((( (((( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) )))))) Data\SiteAdvisor s\tcpip.sy s s\afd.sys s\tcpip6.s ys
(((((((((( ( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) ))))
E\Microsof t\Windows\ CurrentVer sion\Run] ystem32\ct fmon.exe" [2008-04-14 05:42 15360]
RE\Microso ft\Windows \CurrentVe rsion\Run] [2002-04-17 11:42 69632] " [2008-01-22 22:09 468288] Try.exe" [2008-01-22 22:09 87360] eAdv.exe" [2007-08-28 12:07 36640]
are\Micros oft\Window s\CurrentV ersion\Run Once] C:\WINDOWS \Installer \TSClientM siTrans\ts cuinst.vbs " [2007-10-30 15:36 13801] INDOWS\Ins taller\TSC lientMsiTr ans\tscdsb l.bat" [2008-01-18 20:43 2247]
or\DevDtct 2.exe [2008-05-28 13:07:33 114688] NsCatCom.e xe [2008-02-28 13:55:48 327680]
re\microso ft\windows \currentve rsion\expl orer\Shell ExecuteHoo ks] 532071A8BC C5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dl l" [2008-03-25 05:56 303616]
re\microso ft\windows \currentve rsion\grou p policy\state\S-1-5-21-2587 96451-1422 996371-404 5565041-11 15\Scripts \Logon\[u] 0[/u]\[u]0 [/u]]
re\microso ft\windows \currentve rsion\grou p policy\state\S-1-5-21-2587 96451-1422 996371-404 5565041-11 70\Scripts \Logon\[u] 0[/u]\[u]0 [/u]]
ocuments and Settings^All Users^Start Menu^Programs^Startup^Adob e Acrobat Speed Launcher.lnk] e Acrobat Speed Launcher.lnk e Acrobat Speed Launcher.lnkCommon Startup
ocuments and Settings^All Users^Start Menu^Programs^Startup^WinZ ip Quick Pick.lnk] ip Quick Pick.lnk ip Quick Pick.lnkCommon Startup
re\microso ft\shared tools\msconfig\startupreg\ Adobe Reader Speed Launcher]
re\microso ft\shared tools\msconfig\startupreg\ atchk]
re\microso ft\shared tools\msconfig\startupreg\ BuildBU]
re\microso ft\shared tools\msconfig\startupreg\ ECenter] her.exe
re\microso ft\shared tools\msconfig\startupreg\ HotKeysCmd s] exe
re\microso ft\shared tools\msconfig\startupreg\ IAAnotif]
re\microso ft\shared tools\msconfig\startupreg\ IgfxTray] ay.exe
re\microso ft\shared tools\msconfig\startupreg\ ISUSPM Startup] L~1\UPDATE ~1\ISUSPM. exe
re\microso ft\shared tools\msconfig\startupreg\ ISUSSchedu ler] Service\is sch.exe
re\microso ft\shared tools\msconfig\startupreg\ OmniForm OFPA]
re\microso ft\shared tools\msconfig\startupreg\ OmniFormRe minder] O~1.1\EReg \Ereg.exe
re\microso ft\shared tools\msconfig\startupreg\ PDVDDXSrv]
re\microso ft\shared tools\msconfig\startupreg\ Persistenc e] rs.exe
re\microso ft\shared tools\msconfig\startupreg\ RoxioDragT oDisc] rgToDsc.ex e
re\microso ft\shared tools\msconfig\startupreg\ SoundMAXPn P]
re\microso ft\shared tools\msconfig\startupreg\ SunJavaUpd ateSched] \jusched.e xe
re\microso ft\shared tools\msconfig\services]
re\microso ft\securit y center\Monitoring\McAfeeAn tiVirus] 00000001
ess\parame ters\firew allpolicy\ standardpr ofile\Auth orizedAppl ications\L ist] gr.exe"= EXE"= .exe"= XPPS.EXE"= =
ess\parame ters\firew allpolicy\ standardpr ofile\Glob allyOpenPo rts\List] 009
WS\system3 2\Drivers\ DLARTL_M.S YS [2006-08-11 08:35] C:\Program Files\McAfee\Managed VirusScan\VScan\EngineServ er.exe [2007-12-01 11:30] xe [2008-01-22 22:09] xe [2007-06-12 15:09]
kj0e5ft.ex e 0e5ft.exe
lication Data\Mozilla\Firefox\Profi les\upz0eo ie.default \
********** ********** ********** ********** ********
********** ********** ********** ********** ******** S.EXE .EXE or\DM1Serv ice.exe SFUSVC.exe ervice.exe indexer.ex e 1\VScan\Mc Shield.exe xe ice.exe ********** ********** ********** ********** ******** .txt 2008-08-14 20:14:36
ComboFix 08-08-13.05 - Administrator 2008-08-14 12:10:08.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.
Running from: C:\Documents and Settings\Administrator\Des
.
((((((((((((((((((((((((((
.
C:\Documents and Settings\Administrator\App
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Dow
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Dow
C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
C:\Documents and Settings\clerk\Application
C:\Program Files\rhccfkj0e5ft
C:\WINDOWS\system32\config
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\lphc9f
C:\WINDOWS\system32\phc9fk
C:\WINDOWS\system32\x64
----- BITS: Possible infected sites -----
http://10.30.30.2:8530
.
((((((((((((((((((((((((((
.
-------\Legacy_BYC06
-------\Legacy_TCPSR
-------\Service_Byc06
-------\Service_tcpsr
((((((((((((((((((((((((( Files Created from 2008-07-14 to 2008-08-14 ))))))))))))))))))))))))))
.
2008-08-14 11:00 . 2008-08-14 11:00 <DIR> d-------- C:\Documents and Settings\Administrator\App
2008-08-14 11:00 . 2008-08-14 11:00 <DIR> d-------- C:\Documents and Settings\Administrator\App
2008-08-14 11:00 . 2008-08-14 11:00 <DIR> d-------- C:\Documents and Settings\Administrator\App
2008-08-13 17:46 . 2008-08-14 08:29 <DIR> d-------- C:\WINDOWS\system32\config
2008-08-13 17:45 . 2008-08-13 17:46 <DIR> d-------- C:\Program Files\Microsoft Common
2008-08-11 13:06 . 2008-08-11 13:20 <DIR> d-------- C:\Documents and Settings\clerk\Application
2008-07-21 15:11 . 2008-07-21 15:11 <DIR> d-------- C:\Documents and Settings\TEMP.CLERK.001
2008-07-21 15:11 . 2008-07-21 15:11 <DIR> d--hs---- C:\Documents and Settings\TEMP.CLERK.000\LO
2008-07-21 15:11 . 2008-07-21 15:11 <DIR> d-------- C:\Documents and Settings\TEMP.CLERK.000
2008-07-15 11:48 . 2008-07-11 18:23 40,448 --a------ C:\SEABA Totals 2008.xls
2008-07-15 11:48 . 2008-07-08 12:21 34,304 --a------ C:\AKHeli Totals 2008.xls
2008-07-15 11:48 . 2008-07-07 16:24 25,600 --a------ C:\TGR Totals 2008.xls
2008-07-15 04:29 . 2008-06-20 03:51 361,600 --------- C:\WINDOWS\system32\dllcac
2008-07-15 04:29 . 2008-06-20 09:46 245,248 --------- C:\WINDOWS\system32\dllcac
2008-07-15 04:29 . 2008-06-20 03:08 225,856 --------- C:\WINDOWS\system32\dllcac
2008-07-15 04:29 . 2008-06-20 09:46 147,968 --------- C:\WINDOWS\system32\dllcac
2008-07-15 04:29 . 2008-06-20 03:40 138,496 --------- C:\WINDOWS\system32\dllcac
2008-07-14 18:22 . 2008-05-09 02:53 512,000 --------- C:\WINDOWS\system32\dllcac
2008-07-14 18:22 . 2008-05-09 02:53 430,080 --------- C:\WINDOWS\system32\dllcac
2008-07-14 18:22 . 2008-05-09 02:53 180,224 --------- C:\WINDOWS\system32\dllcac
2008-07-14 18:22 . 2008-05-09 02:53 172,032 --------- C:\WINDOWS\system32\dllcac
2008-07-14 18:22 . 2008-05-08 03:24 155,648 --------- C:\WINDOWS\system32\dllcac
2008-07-14 18:22 . 2008-05-09 00:45 135,168 --------- C:\WINDOWS\system32\dllcac
2008-07-14 18:22 . 2008-05-09 02:53 90,112 --------- C:\WINDOWS\system32\dllcac
.
((((((((((((((((((((((((((
.
2008-08-11 20:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-05 19:09 --------- d-----w C:\Documents and Settings\clerk\Application
2008-06-23 22:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\driver
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\driver
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\driver
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"ctfmon.exe"="C:\WINDOWS\s
[HKEY_LOCAL_MACHINE\SOFTWA
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe"
"MVS Splash"="C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
"McAfee Managed Services Tray"="C:\Program Files\McAfee\Managed VirusScan\Agent\StartMyagt
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6173\Sit
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
[HKEY_USERS\.DEFAULT\Softw
"TSClientMSIUninstaller"="
"TSClientAXDisabler"="C:\W
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetect
Scanner File Utility.lnk - C:\Program Files\Kyocera\FileUtility\
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2008-03-25 05:59:00 123904]
[hkey_local_machine\softwa
"{56F9679E-7826-4C84-81F3-
[HKEY_LOCAL_MACHINE\softwa
"Script"=DriveMappings.cmd
[HKEY_LOCAL_MACHINE\softwa
"Script"=DriveMappings.cmd
[HKLM\~\startupfolder\C:^D
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adob
backup=C:\WINDOWS\pss\Adob
[HKLM\~\startupfolder\C:^D
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZ
backup=C:\WINDOWS\pss\WinZ
[HKEY_LOCAL_MACHINE\softwa
--------- 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\softwa
--------- 2007-06-12 15:09 408344 C:\Program Files\Intel\AMT\atchk.exe
[HKEY_LOCAL_MACHINE\softwa
--------- 2004-02-19 05:23 61440 c:\dell\bldbubg.exe
[HKEY_LOCAL_MACHINE\softwa
--------- 2007-05-24 05:03 17920 C:\dell\E-Center\EULALaunc
[HKEY_LOCAL_MACHINE\softwa
--------- 2007-06-28 13:21 162328 C:\WINDOWS\system32\hkcmd.
[HKEY_LOCAL_MACHINE\softwa
--------- 2007-07-26 17:03 178712 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\softwa
--------- 2007-06-28 13:21 141848 C:\WINDOWS\system32\igfxtr
[HKEY_LOCAL_MACHINE\softwa
--------- 2004-07-27 14:50 221184 C:\PROGRA~1\COMMON~1\INSTA
[HKEY_LOCAL_MACHINE\softwa
--------- 2004-07-27 14:50 81920 C:\Program Files\Common Files\InstallShield\Update
[HKEY_LOCAL_MACHINE\softwa
--------- 2003-05-20 21:13 40960 C:\Program Files\ScanSoft\OmniForm 5.1\OFPA.exe
[HKEY_LOCAL_MACHINE\softwa
-r------- 2003-03-13 21:41 729088 C:\PROGRA~1\ScanSoft\OMNIF
[HKEY_LOCAL_MACHINE\softwa
--------- 2006-10-20 15:23 118784 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\softwa
--------- 2007-06-28 13:21 137752 C:\WINDOWS\system32\igfxpe
[HKEY_LOCAL_MACHINE\softwa
--------- 2006-08-17 07:00 1116920 C:\Program Files\Roxio\Drag-to-Disc\D
[HKEY_LOCAL_MACHINE\softwa
--------- 2007-09-24 17:12 1036288 C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\softwa
--------- 2005-11-10 11:03 36975 C:\Program Files\Java\jre1.5.0_06\bin
[HKEY_LOCAL_MACHINE\softwa
"stllssvr"=3 (0x3)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"OmniForm Printer"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"UNS"=2 (0x2)
"LMS"=2 (0x2)
"atchksrv"=2 (0x2)
"ASFAgent"=2 (0x2)
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.
"C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc
"C:\\WINDOWS\\system32\\LE
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
[HKLM\~\services\sharedacc
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22
R1 DLARTL_M;DLARTL_M;C:\WINDO
R2 EngineServer;EngineServer;
R2 myAgtSvc;McAfee Virus and Spyware Protection Service;C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.e
S4 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe [2007-01-23 01:58]
S4 atchksrv;Intel(R) Active Management Technology System Status Service;C:\Program Files\Intel\AMT\atchksrv.e
S4 LMS;Intel(R) Active Management Technology Local Management Service;C:\Program Files\Intel\AMT\LMS.exe [2007-06-12 15:09]
S4 UNS;Intel(R) Active Management Technology User Notification Service;C:\Program Files\Intel\AMT\UNS.exe [2007-06-12 15:09]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-lphc9fkj0e5ft - C:\WINDOWS\system32\lphc9f
HKLM-Run-SMrhccfkj0e5ft - C:\Program Files\rhccfkj0e5ft\rhccfkj
MSConfigStartUp-Acrobat Assistant 7 - C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
MSConfigStartUp-Google Desktop Search - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\App
**************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-14 12:12:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCE
C:\WINDOWS\system32\LEXPPS
C:\Program Files\Olympus\DeviceDetect
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Kyocera\FileUtility\
C:\Program Files\SiteAdvisor\6173\SAS
C:\WINDOWS\system32\search
C:\PROGRA~1\McAfee\MANAGE~
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtTry.e
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
.
**************************
.
Completion time: 2008-08-14 12:14:39 - machine was rebooted
ComboFix-quarantined-files
Pre-Run: 54,677,200,896 bytes free
Post-Run: 52,666,130,432 bytes free
201 --- E O F --- 2008-07-16 11:01:32