Did all 3 in safe mode.
No joy.
Main Topics
Browse All TopicsI have NOD32 anti-virus that has been VERY good to me. I can not delete or remove this one virus. I have included my combo fix and HiJackThis log. I went into safe mode and ran malwarebytes and spybot but it did not help with this.
"C:\WINDOWS\system32\winlo
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:59:36 PM, on 7/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchos
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateServic
C:\Program Files\LogMeIn\x86\RaMaint.
C:\Program Files\LogMeIn\x86\LogMeIn.
C:\Program Files\LogMeIn\x86\LMIGuard
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\LogMeIn\x86\LogMeInS
C:\Program Files\Google\GoogleToolbar
C:\WINDOWS\system32\ctfmon
C:\Program Files\Skype\Phone\Skype.ex
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LogMeIn\x86\LMIGuard
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepa
C:\WINDOWS\system32\wscntf
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\LogMeIn\x86\LogMeIn.
C:\Program Files\LogMeIn\x86\LMIGuard
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.ex
C:\Program Files\Google\Common\Google
C:\DOCUME~1\COMPAQ~1\LOCAL
C:\Program Files\Trend Micro\HijackThis\HijackThi
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-7
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-5
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInS
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.ex
O4 - HKUS\S-1-5-21-1695938045-3
O4 - HKUS\S-1-5-21-1695938045-3
O4 - S-1-5-21-1695938045-312014
O4 - S-1-5-21-1695938045-312014
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-1
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-4
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-4
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateServic
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.
--
End of file - 8299 bytes
ComboFix 09-07-14.08 - Administrator 07/15/2009 15:15.1.2 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.
Running from: c:\documents and settings\Administrator\Des
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D
.
((((((((((((((((((((((((((
.
c:\recycler\S-1-5-21-11760
c:\windows\system32\AutoRu
D:\Autorun.inf
.
((((((((((((((((((((((((((
.
-------\Legacy_TDSSSERV.SY
-------\Service_TDSSserv.s
-------\Service_TDSSserv.s
((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 ))))))))))))))))))))))))))
.
2009-07-15 19:02 . 2009-07-15 19:02 -------- d-----w- c:\documents and settings\Compaq_Owner\Appl
2009-07-15 02:43 . 2009-07-15 02:43 -------- d-----w- c:\documents and settings\Administrator\Loc
2009-07-15 02:33 . 2009-07-15 02:33 -------- d-----w- c:\documents and settings\Administrator\App
2009-07-15 02:33 . 2009-07-13 17:36 38160 ----a-w- c:\windows\system32\driver
2009-07-15 02:33 . 2009-07-15 02:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-15 02:33 . 2009-07-13 17:36 19096 ----a-w- c:\windows\system32\driver
2009-07-15 02:33 . 2009-07-15 02:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-15 02:16 . 2009-07-15 02:16 -------- d-----w- c:\documents and settings\Administrator\Doc
2009-06-22 01:10 . 2009-05-19 05:36 2884832 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
.
((((((((((((((((((((((((((
.
2009-07-15 19:04 . 2006-01-24 03:06 40768 -c--a-w- c:\documents and settings\Compaq_Owner\Loca
2009-07-15 19:03 . 2008-11-26 23:11 -------- d-----w- c:\documents and settings\Compaq_Owner\Appl
2009-07-15 19:03 . 2008-11-26 23:10 -------- d-----w- c:\documents and settings\Compaq_Owner\Appl
2009-07-15 11:19 . 2008-11-20 21:18 -------- d-----w- c:\program files\LogMeIn
2009-07-15 02:33 . 2008-11-20 20:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-14 00:08 . 2008-01-03 22:02 0 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLds.DAT
2009-07-14 00:04 . 2008-01-04 04:22 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-06-14 22:21 . 2006-01-16 17:43 -------- d-----w- c:\program files\WildTangent
2009-05-19 05:36 . 2009-06-22 01:10 28 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 1484856 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 25 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 97072 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 142040 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 30512 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 111920 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-07 15:32 . 2004-08-04 05:00 345600 ----a-w- c:\windows\system32\locals
2009-04-29 04:56 . 2004-08-04 05:00 827392 ----a-w- c:\windows\system32\winine
2009-04-29 04:55 . 2004-08-04 05:00 78336 ----a-w- c:\windows\system32\ieenco
2009-04-17 12:26 . 2004-08-04 05:00 1847168 ----a-w- c:\windows\system32\win32k
2009-06-15 01:21 . 2008-09-03 12:40 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcm
.
------- Sigcheck -------
[7] 2004-08-04 05:00 502272 01C3346C241652F43AED8E2149
[7] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F041188
[-] 2008-10-23 19:48 507904 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\winlog
[7] 2004-08-04 05:00 295424 B60C877D16D9C880B952FDA04A
[7] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684
[-] 2008-10-23 19:48 295424 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\termsr
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"swg"="c:\program files\Google\GoogleToolbar
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
"ctfmon.exe"="c:\windows\s
"Skype"="c:\program files\Skype\Phone\Skype.ex
[HKEY_LOCAL_MACHINE\SOFTWA
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-04-23 1443072]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInS
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
c:\documents and settings\LogMeInRemoteUser
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-16 27136]
c:\documents and settings\Administrator\Sta
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-16 27136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\softwa
"NoActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\softwa
2008-10-17 01:35 87352 ----a-w- c:\windows\system32\LMIini
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adob
backup=c:\windows\pss\Adob
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Comp
backup=c:\windows\pss\Comp
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Koda
backup=c:\windows\pss\Koda
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODA
backup=c:\windows\pss\KODA
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Micr
backup=c:\windows\pss\Micr
[HKEY_LOCAL_MACHINE\softwa
"Viewpoint Manager Service"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"navapsvc"=2 (0x2)
"MDM"=2 (0x2)
"LiveUpdate"=3 (0x3)
"IDriverT"=3 (0x3)
"comHost"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"ccISPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"ANIWZCSdService"=2 (0x2)
[HKEY_LOCAL_MACHINE\softwa
"FirewallOverride"=dword:0
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"c:\\Program Files\\Compaq Connections\\5577497\\Prog
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolloa
"c:\\Program Files\\Common Files\\AOL\\1138757663\\ee
"c:\\Program Files\\Common Files\\AOL\\1138757663\\ee
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.e
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Bonjour\\mDNSRespon
"c:\\Program Files\\iTunes\\iTunes.exe"
"c:\\Program Files\\Skype\\Phone\\Skype
R1 epfwtdir;epfwtdir;c:\windo
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [4/23/2008 2:58 PM 472320]
R2 IntuitUpdateService;Intuit
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.s
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32
R3 MSHUSBVideo;NX6000/NX3000/
S4 LMIRfsClientNP;LMIRfsClien
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\Vie
[HKEY_LOCAL_MACHINE\softwa
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\softwar
\Shell\AutoRun\command - explorer.exe "http://www.FestivalDisney
[HKEY_CURRENT_USER\softwar
\Shell\AutoRun\command - c:\windows\system32\RunDLL
[HKEY_CURRENT_USER\softwar
\Shell\AutoRun\command - K:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-07-06 c:\windows\Tasks\AppleSoft
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/sear
mStart Page = hxxp://ie.redirect.hp.com/
mSearch Bar = hxxp://ie.redirect.hp.com/
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/sear
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Offic
Trusted Zone: turbotax.com
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Appl
FF - prefs.js: browser.search.selectedEng
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721
FF - plugin: c:\documents and settings\Compaq_Owner\Appl
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.d
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoin
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-15 15:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(872)
c:\windows\system32\Ati2ev
c:\windows\system32\LMIini
c:\windows\system32\LMIRfs
- - - - - - - > 'explorer.exe'(3524)
c:\windows\system32\WPDShS
c:\windows\system32\Portab
c:\windows\system32\Portab
c:\windows\system32\LMIRfs
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
c:\program files\LogMeIn\x86\ramaint.
c:\program files\LogMeIn\x86\LogMeIn.
c:\program files\LogMeIn\x86\LMIGuard
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\LogMeIn\x86\LMIGuard
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\LogMeIn\x86\LogMeIn.
c:\program files\LogMeIn\x86\LMIGuard
.
**************************
.
Completion time: 2009-07-15 15:34 - machine was rebooted [Compaq_Owner]
ComboFix-quarantined-files
Pre-Run: 50,478,583,808 bytes free
Post-Run: 50,410,614,784 bytes free
234 --- E O F --- 2009-06-16 00:36
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Download Kaspersky Boot CD from here: http://dnl-eu10.kaspersky-
Let us know, how it goes. You had the TDSS rootkit in your computer, by the way.
Hope it helps.
Just ran combo fix in normal mode and this is the log.
ComboFix 09-07-14.08 - Compaq_Owner 07/16/2009 16:08.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.
Running from: c:\documents and settings\Compaq_Owner\Desk
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D
.
((((((((((((((((((((((((((
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Dow
c:\documents and settings\All Users\Application Data\Microsoft\Network\Dow
----- BITS: Possible infected sites -----
hxxp://download.esd.intuit
Infected copy of c:\windows\system32\winlog
Restored copy from - c:\windows\system32\winlog
.
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 ))))))))))))))))))))))))))
.
2009-07-15 20:20 . 2009-07-15 20:19 102664 ----a-w- c:\windows\system32\driver
2009-07-15 20:19 . 2009-07-15 20:21 -------- d-----w- c:\documents and settings\Compaq_Owner\.hou
2009-07-15 19:59 . 2009-07-15 19:59 -------- d-----w- c:\program files\Trend Micro
2009-07-15 19:02 . 2009-07-15 19:02 -------- d-----w- c:\documents and settings\Compaq_Owner\Appl
2009-07-15 02:43 . 2009-07-15 02:43 -------- d-----w- c:\documents and settings\Administrator\Loc
2009-07-15 02:33 . 2009-07-15 02:33 -------- d-----w- c:\documents and settings\Administrator\App
2009-07-15 02:33 . 2009-07-13 17:36 38160 ----a-w- c:\windows\system32\driver
2009-07-15 02:33 . 2009-07-15 02:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-15 02:33 . 2009-07-13 17:36 19096 ----a-w- c:\windows\system32\driver
2009-07-15 02:33 . 2009-07-15 02:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-15 02:16 . 2009-07-15 02:16 -------- d-----w- c:\documents and settings\Administrator\Doc
2009-06-22 01:10 . 2009-05-19 05:36 2884832 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
.
((((((((((((((((((((((((((
.
2009-07-16 20:00 . 2008-11-26 23:11 -------- d-----w- c:\documents and settings\Compaq_Owner\Appl
2009-07-16 20:00 . 2008-11-26 23:10 -------- d-----w- c:\documents and settings\Compaq_Owner\Appl
2009-07-16 19:57 . 2008-11-20 21:18 -------- d-----w- c:\program files\LogMeIn
2009-07-15 20:00 . 2006-01-16 18:07 -------- d-----w- c:\program files\Google
2009-07-15 19:04 . 2006-01-24 03:06 40768 -c--a-w- c:\documents and settings\Compaq_Owner\Loca
2009-07-15 02:33 . 2008-11-20 20:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-14 00:08 . 2008-01-03 22:02 0 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLds.DAT
2009-07-14 00:04 . 2008-01-04 04:22 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2009-06-14 22:21 . 2006-01-16 17:43 -------- d-----w- c:\program files\WildTangent
2009-05-19 05:36 . 2009-06-22 01:10 28 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 1484856 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 25 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 97072 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 142040 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 30512 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-19 05:36 . 2009-06-22 01:10 111920 ------w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\
2009-05-07 15:32 . 2004-08-04 05:00 345600 ----a-w- c:\windows\system32\locals
2009-04-29 04:56 . 2004-08-04 05:00 827392 ----a-w- c:\windows\system32\winine
2009-04-29 04:55 . 2004-08-04 05:00 78336 ----a-w- c:\windows\system32\ieenco
2009-06-15 01:21 . 2008-09-03 12:40 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcm
.
------- Sigcheck -------
[7] 2004-08-04 05:00 295424 B60C877D16D9C880B952FDA04A
[7] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684
[-] 2008-10-23 19:48 295424 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\termsr
.
((((((((((((((((((((((((((
.
+ 2009-07-15 20:29 . 2009-07-15 20:29 24576 c:\windows\Installer\nlsdl
+ 2009-07-15 20:29 . 2009-07-15 20:29 57856 c:\windows\Installer\mfcm8
+ 2009-07-15 20:29 . 2009-07-15 20:29 69632 c:\windows\Installer\mfcm8
+ 2009-07-15 20:29 . 2009-07-15 20:29 96256 c:\windows\Installer\atl80
+ 2009-07-15 20:00 . 2009-07-15 20:00 24064 c:\windows\Installer\1ff61
+ 2004-08-04 05:00 . 2008-04-14 00:12 507904 c:\windows\system32\winlog
- 2004-08-04 05:00 . 2008-10-23 19:48 507904 c:\windows\system32\winlog
+ 2004-08-04 05:00 . 2008-04-14 00:12 507904 c:\windows\system32\dllcac
+ 2009-07-15 20:29 . 2009-07-15 20:29 126208 c:\windows\Installer\TmDbg
+ 2009-07-15 20:29 . 2009-07-15 20:29 626688 c:\windows\Installer\msvcr
+ 2009-07-15 20:29 . 2009-07-15 20:29 548864 c:\windows\Installer\msvcp
+ 2009-07-15 20:29 . 2009-07-15 20:29 479232 c:\windows\Installer\msvcm
+ 2009-07-15 20:29 . 2009-07-15 20:29 159168 c:\windows\Installer\libex
+ 2009-07-15 20:29 . 2009-07-15 20:29 1093120 c:\windows\Installer\mfc80
+ 2009-07-15 20:29 . 2009-07-15 20:29 1101824 c:\windows\Installer\mfc80
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"swg"="c:\program files\Google\GoogleToolbar
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
"ctfmon.exe"="c:\windows\s
"Skype"="c:\program files\Skype\Phone\Skype.ex
[HKEY_LOCAL_MACHINE\SOFTWA
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-04-23 1443072]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInS
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
c:\documents and settings\LogMeInRemoteUser
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-16 27136]
c:\documents and settings\Administrator\Sta
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-1-16 27136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\softwa
"NoActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\softwa
2008-10-17 01:35 87352 ----a-w- c:\windows\system32\LMIini
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adob
backup=c:\windows\pss\Adob
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Comp
backup=c:\windows\pss\Comp
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Koda
backup=c:\windows\pss\Koda
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODA
backup=c:\windows\pss\KODA
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Micr
backup=c:\windows\pss\Micr
[HKEY_LOCAL_MACHINE\softwa
"Viewpoint Manager Service"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"navapsvc"=2 (0x2)
"MDM"=2 (0x2)
"LiveUpdate"=3 (0x3)
"IDriverT"=3 (0x3)
"comHost"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccProxy"=2 (0x2)
"ccISPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"ANIWZCSdService"=2 (0x2)
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusOverride"=dword:
"FirewallOverride"=dword:0
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"c:\\Program Files\\Compaq Connections\\5577497\\Prog
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolloa
"c:\\Program Files\\Common Files\\AOL\\1138757663\\ee
"c:\\Program Files\\Common Files\\AOL\\1138757663\\ee
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.e
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Bonjour\\mDNSRespon
"c:\\Program Files\\iTunes\\iTunes.exe"
"c:\\Program Files\\Skype\\Phone\\Skype
R1 epfwtdir;epfwtdir;c:\windo
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [4/23/2008 2:58 PM 472320]
R2 IntuitUpdateService;Intuit
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.s
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32
R3 MSHUSBVideo;NX6000/NX3000/
S4 LMIRfsClientNP;LMIRfsClien
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\Vie
[HKEY_LOCAL_MACHINE\softwa
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-07-06 c:\windows\Tasks\AppleSoft
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/sear
mStart Page = hxxp://ie.redirect.hp.com/
mSearch Bar = hxxp://ie.redirect.hp.com/
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/sear
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Offic
Trusted Zone: turbotax.com
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Appl
FF - prefs.js: browser.search.selectedEng
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721
FF - plugin: c:\documents and settings\Compaq_Owner\Appl
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Java\jre1.5.0_09\bin
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.d
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoin
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-16 16:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(872)
c:\windows\system32\Ati2ev
c:\windows\system32\LMIini
c:\windows\system32\LMIRfs
- - - - - - - > 'explorer.exe'(1484)
c:\windows\system32\WPDShS
c:\windows\system32\Portab
c:\windows\system32\Portab
c:\windows\system32\LMIRfs
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
c:\program files\LogMeIn\x86\ramaint.
c:\program files\LogMeIn\x86\LogMeIn.
c:\program files\LogMeIn\x86\LMIGuard
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\LogMeIn\x86\LMIGuard
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\LogMeIn\x86\LogMeIn.
c:\program files\LogMeIn\x86\LMIGuard
.
**************************
.
Completion time: 2009-07-16 16:28 - machine was rebooted
ComboFix-quarantined-files
ComboFix2.txt 2009-07-15 19:34
Pre-Run: 50,072,076,288 bytes free
Post-Run: 50,071,777,280 bytes free
246 --- E O F --- 2009-06-16 00:36
You can use the System File Checker for this:
open a command prompt and do:
sfc /scannow
This will start the File Checker and Windows will check all the system files and replace any corrupt or missing files with fresh copies. This might require a Windows XP CD. That should bring back your system into a perfect working condition again (provided there are no more viruses left).
Business Accounts
Answer for Membership
by: JeremySBrownPosted on 2009-07-15 at 13:31:40ID: 24863828
Try scanning with the following:
g/mbam.php
r.com/comb ofix/how-t o-use-comb ofix
1. Malwarebytes' Anti-Malware
http://www.malwarebytes.or
2. Combofix
http://www.bleepingcompute
3. Dr. Web Anti-Virus
http://www.freedrweb.com/