Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware - IE opening randomly [RESOLVED]


  • This topic is locked This topic is locked

#1
mmullins

mmullins

    New Member

  • Member
  • Pip
  • 9 posts
I have a laptop that was infested with spyware and ran a few fixer tools (combofix, vundofix, etc.) which seems to have removed most of the issues i was having but, while im browsing the web (with firefox) IE will randomly pop up with a blank page and never load anything. i have attempted several things found on google. i was hoping someone could take a look at my HijackThis log with the hopes that someone would see something that i dont. any help is greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:45:38 PM, on 2/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\WinVNC\WinVNC.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DESKTOP\PROCEXP.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\mstsc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {de9f9b1a-90eb-482f-99f1-4e28470171d5} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [SpybotDeletingA8292] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6275] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.thomashospital.com/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1005.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = admin
O17 - HKLM\Software\..\Telephony: DomainName = admin
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = admin
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = admin
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: VNC Server (winvnc) - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\WinVNC.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
  • 0

Advertisements


#2
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi,

I understand that you need help in order to get rid of the malware that is present on your system - But you need to help us first..
I notice that you never scanned with an Antivirus previously before starting this thread - because you don't even have an Antivirus installed!
This is somewhat suicidal in today's digital world.
That's why I want you to install one first!!

* Please install Avira Antivirus: http://www.free-av.com/
This is a free Antivirus.

Perform a full scan with Avira and let it delete everything it is finding.
Then reboot.
After reboot, open your Avira and select "reports".
There doubleclick the report from the Full scan you have done. Click the "Report File" button and copy and paste this report in your next reply together with a new HijackThislog.
Then we'll start from there, because it really makes no sense otherwise that we clean this up manually if an Antivirusscan is not present which should be able to deal with most and prevent further reinfection.
  • 0

#3
mmullins

mmullins

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
thanks for the reply. for the record i used trend micro HouseCall prior to posting in this forum. to adhere to your request i have installed avira and the requested logs are listed below. thanks again for the help.



AntiVir PersonalEdition Classic
Report file date: Saturday, February 02, 2008 01:11

Scanning for 1089295 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: L19472-037-2

Version information:
BUILD.DAT : 270 15603 Bytes 9/19/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 8/23/2007 20:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 8/16/2007 19:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 8/14/2007 22:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 8/21/2007 19:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 07:07:03
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 12/14/2007 07:07:04
ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 1/25/2008 07:07:05
ANTIVIR3.VDF : 7.0.2.82 259072 Bytes 2/1/2008 07:07:05
AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 2/2/2008 07:07:08
AVWINLL.DLL : 1.0.0.7 14376 Bytes 2/26/2007 17:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 7/18/2007 14:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 20:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 2/2/2008 07:07:09
AVREG.DLL : 7.0.1.6 30760 Bytes 7/18/2007 14:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 8/28/2007 19:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 7/18/2007 14:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 3/8/2007 18:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 8/7/2007 19:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 8/21/2007 19:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 7/23/2007 16:37:21

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: Saturday, February 02, 2008 01:11

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'hamachi.exe' - '1' Module(s) have been scanned
Scan process 'DLG.exe' - '1' Module(s) have been scanned
Scan process 'TosBtHSP.exe' - '1' Module(s) have been scanned
Scan process 'TosA2dp.exe' - '1' Module(s) have been scanned
Scan process 'TosBtMng.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'WUSB54GC.exe' - '1' Module(s) have been scanned
Scan process 'WLService.exe' - '1' Module(s) have been scanned
Scan process 'winvnc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
Scan process 'NicConfigSvc.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'BAsfIpM.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
Scan process 'SUPERAntiSpyware.exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'point32.exe' - '1' Module(s) have been scanned
Scan process 'quickset.exe' - '1' Module(s) have been scanned
Scan process 'iFrmewrk.exe' - '1' Module(s) have been scanned
Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
Scan process 'SynTPLpr.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'ZCfgSvc.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'WLKEEPER.exe' - '1' Module(s) have been scanned
Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned
Scan process 'EvtEng.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
49 processes with 49 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!

Starting to scan the registry.
The registry was scanned ( '37' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\windows.vir.bac_a02532
[DETECTION] Is the Trojan horse TR/Zapchast.DT.1
[INFO] The file was moved to '48121851.qua'!
C:\Documents and Settings\Administrator\Desktop\Tools\OiUninstaller.exe
[DETECTION] Contains detection pattern of the dropper DR/PurityScan.GR
[WARNING] The file was ignored!
C:\Program Files\SDFix\backups\backups.zip
[0] Archive type: ZIP
--> backups/backup-20080125-231949-152-source.html
[DETECTION] Is the Trojan horse TR/Click.HTML.IFrame.DN
[WARNING] The file was ignored!
C:\QooBox\Quarantine\catchme2008-01-27_140429.42.zip
[0] Archive type: ZIP
--> kcoziqcs.dll
[DETECTION] Is the Trojan horse TR/Vundo.DWB
--> ssttr.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '48181d3c.qua'!
C:\QooBox\Quarantine\C\Program Files\Temporary\kernInst.exe.vir
[DETECTION] Is the Trojan horse TR/Agent.edq
[INFO] The file was moved to '48161dd5.qua'!
C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir
[DETECTION] Is the Trojan horse TR/Dldr.Agent.hvj.1
[INFO] The file was moved to '47d61da6.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\awtstuu.dll.vir
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '48181df0.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\bnsxoxsu.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.dvc.6
[INFO] The file was moved to '48171de9.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\brqplmof.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '48151dee.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\cgrfapva.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '48161de6.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\cslpnusr.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '48101df4.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\jljeyggm.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.dvc.6
[INFO] The file was moved to '480e1dee.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\kcoziqcs.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.DWB
[INFO] The file was moved to '48131de7.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\qijiomsa.dll.vir
[DETECTION] Is the Trojan horse TR/Vundo.DWB
[INFO] The file was moved to '480e1def.qua'!
C:\QooBox\Quarantine\C\WINDOWS\system32\ssttr.dll.vir
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '48181dfb.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP220\A0020467.exe
[DETECTION] Contains detection pattern of the dropper DR/PurityScan.GP
[INFO] The file was moved to '47d41dc7.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP220\A0020468.exe
[DETECTION] Is the Trojan horse TR/Dldr.Purity.BV.7
[INFO] The file was moved to '47d41dcb.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP220\A0020492.dll
[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen
[INFO] The file was moved to '47d41dcd.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP222\A0022559.dll
[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen
[INFO] The file was moved to '47d41dd4.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP222\A0022560.dll
[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen
[INFO] The file was moved to '47d41dd6.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP222\A0022561.dll
[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen
[INFO] The file was moved to '47d41dd8.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022752.exe
[DETECTION] Is the Trojan horse TR/Dldr.Agent.hvj.1
[INFO] The file was moved to '47d41ddf.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022758.dll
[DETECTION] Is the Trojan horse TR/Vundo.dvc.6
[INFO] The file was moved to '47d41de1.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022759.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '47d41de5.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022760.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '47d41de7.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022761.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] The file was moved to '47d41de9.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022762.dll
[DETECTION] Is the Trojan horse TR/Vundo.dvc.6
[INFO] The file was moved to '47d41dea.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022763.dll
[DETECTION] Is the Trojan horse TR/Vundo.DWB
[INFO] The file was moved to '47d41deb.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022766.exe
[DETECTION] Is the Trojan horse TR/Agent.edq
[INFO] The file was moved to '47d41ded.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022777.dll
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '47d41df1.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022778.dll
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '47d41df2.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022779.dll
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '47d41df4.qua'!
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP223\A0022788.dll
[DETECTION] Is the Trojan horse TR/Vundo.DWB
[INFO] The file was moved to '47d41df6.qua'!
C:\WINDOWS\system32\ahuaxmep.dll
[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen
[INFO] The file was moved to '48192027.qua'!
C:\WINDOWS\system32\ilkwrelk.dll
[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen
[INFO] The file was moved to '480f204d.qua'!
C:\WINDOWS\system32\drivers\parvdmm.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
[DETECTION] Is the Trojan horse TR/Dldr.VB.cge
[INFO] The file was moved to '48142081.qua'!


End of the scan: Saturday, February 02, 2008 01:48
Used time: 36:56 min

The scan has been done completely.

3343 Scanning directories
210408 Files were scanned
37 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
34 files were moved to quarantine
0 files were renamed
3 Files cannot be scanned
210371 Files not concerned
3074 Archives were scanned
5 Warnings
0 Notes

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:57:16 AM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\WinVNC\WinVNC.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {de9f9b1a-90eb-482f-99f1-4e28470171d5} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [SpybotDeletingA8292] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6275] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O14 - IERESET.INF: START_PAGE_URL=http://www.thomashospital.com/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1005.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = admin
O17 - HKLM\Software\..\Telephony: DomainName = admin
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = admin
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = admin
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: VNC Server (winvnc) - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\WinVNC.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe

--
End of file - 6730 bytes
  • 0

#4
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi,

TrendMicro housecall is an online scanner - it's no Antivirus installed on your pc, preventing future infections. That's why an Antivirus needs to be installed, because how would you prevent malware?

Anyway,

* Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
  • 0

#5
mmullins

mmullins

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
as stated above, i have already ran combofix. heres the log

BTW, i'm not trying to argue with you i just wanted to clarify that i had done an AV scan. Is it common practice for people on this forum to try to insult new members? just because someone has 2 posts doesnt make them an idiot or mean they dont have knowledge of computers. thanks for taking a look at the logs.


ComboFix 08-01-23.1C - Administrator 2008-01-27 12:24:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.179 [GMT -6:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Application Data\WNSXS~1
C:\Documents and Settings\Administrator\My Documents\pos1000.tmp
C:\Documents and Settings\Administrator\My Documents\pos1001.tmp
C:\Documents and Settings\Administrator\My Documents\pos1002.tmp
C:\Documents and Settings\Administrator\My Documents\pos1003.tmp
C:\Documents and Settings\Administrator\My Documents\pos1004.tmp
C:\Documents and Settings\Administrator\My Documents\pos1005.tmp
C:\Documents and Settings\Administrator\My Documents\pos1006.tmp
C:\Documents and Settings\Administrator\My Documents\pos1007.tmp
C:\Documents and Settings\Administrator\My Documents\pos1008.tmp
C:\Documents and Settings\Administrator\My Documents\pos1009.tmp
C:\Documents and Settings\Administrator\My Documents\pos100A.tmp
C:\Documents and Settings\Administrator\My Documents\pos100B.tmp
C:\Documents and Settings\Administrator\My Documents\pos100C.tmp
C:\Documents and Settings\Administrator\My Documents\pos100D.tmp
C:\Documents and Settings\Administrator\My Documents\pos100E.tmp
C:\Documents and Settings\Administrator\My Documents\pos100F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1010.tmp
C:\Documents and Settings\Administrator\My Documents\pos1011.tmp
C:\Documents and Settings\Administrator\My Documents\pos1012.tmp
C:\Documents and Settings\Administrator\My Documents\pos1013.tmp
C:\Documents and Settings\Administrator\My Documents\pos1014.tmp
C:\Documents and Settings\Administrator\My Documents\pos1015.tmp
C:\Documents and Settings\Administrator\My Documents\pos1016.tmp
C:\Documents and Settings\Administrator\My Documents\pos1017.tmp
C:\Documents and Settings\Administrator\My Documents\pos1018.tmp
C:\Documents and Settings\Administrator\My Documents\pos1019.tmp
C:\Documents and Settings\Administrator\My Documents\pos101A.tmp
C:\Documents and Settings\Administrator\My Documents\pos101B.tmp
C:\Documents and Settings\Administrator\My Documents\pos101C.tmp
C:\Documents and Settings\Administrator\My Documents\pos101D.tmp
C:\Documents and Settings\Administrator\My Documents\pos101E.tmp
C:\Documents and Settings\Administrator\My Documents\pos101F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1020.tmp
C:\Documents and Settings\Administrator\My Documents\pos1021.tmp
C:\Documents and Settings\Administrator\My Documents\pos1022.tmp
C:\Documents and Settings\Administrator\My Documents\pos1023.tmp
C:\Documents and Settings\Administrator\My Documents\pos1024.tmp
C:\Documents and Settings\Administrator\My Documents\pos1025.tmp
C:\Documents and Settings\Administrator\My Documents\pos1026.tmp
C:\Documents and Settings\Administrator\My Documents\pos1027.tmp
C:\Documents and Settings\Administrator\My Documents\pos1028.tmp
C:\Documents and Settings\Administrator\My Documents\pos1029.tmp
C:\Documents and Settings\Administrator\My Documents\pos102A.tmp
C:\Documents and Settings\Administrator\My Documents\pos102B.tmp
C:\Documents and Settings\Administrator\My Documents\pos102C.tmp
C:\Documents and Settings\Administrator\My Documents\pos102D.tmp
C:\Documents and Settings\Administrator\My Documents\pos102E.tmp
C:\Documents and Settings\Administrator\My Documents\pos102F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1030.tmp
C:\Documents and Settings\Administrator\My Documents\pos1031.tmp
C:\Documents and Settings\Administrator\My Documents\pos1032.tmp
C:\Documents and Settings\Administrator\My Documents\pos1033.tmp
C:\Documents and Settings\Administrator\My Documents\pos1034.tmp
C:\Documents and Settings\Administrator\My Documents\pos1035.tmp
C:\Documents and Settings\Administrator\My Documents\pos1036.tmp
C:\Documents and Settings\Administrator\My Documents\pos1037.tmp
C:\Documents and Settings\Administrator\My Documents\pos1038.tmp
C:\Documents and Settings\Administrator\My Documents\pos1039.tmp
C:\Documents and Settings\Administrator\My Documents\pos103A.tmp
C:\Documents and Settings\Administrator\My Documents\pos103B.tmp
C:\Documents and Settings\Administrator\My Documents\pos103C.tmp
C:\Documents and Settings\Administrator\My Documents\pos103D.tmp
C:\Documents and Settings\Administrator\My Documents\pos103E.tmp
C:\Documents and Settings\Administrator\My Documents\pos103F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1040.tmp
C:\Documents and Settings\Administrator\My Documents\pos1041.tmp
C:\Documents and Settings\Administrator\My Documents\pos1042.tmp
C:\Documents and Settings\Administrator\My Documents\pos1043.tmp
C:\Documents and Settings\Administrator\My Documents\pos1044.tmp
C:\Documents and Settings\Administrator\My Documents\pos1045.tmp
C:\Documents and Settings\Administrator\My Documents\pos1046.tmp
C:\Documents and Settings\Administrator\My Documents\pos1047.tmp
C:\Documents and Settings\Administrator\My Documents\pos1048.tmp
C:\Documents and Settings\Administrator\My Documents\pos1049.tmp
C:\Documents and Settings\Administrator\My Documents\pos104A.tmp
C:\Documents and Settings\Administrator\My Documents\pos104B.tmp
C:\Documents and Settings\Administrator\My Documents\pos104C.tmp
C:\Documents and Settings\Administrator\My Documents\pos104D.tmp
C:\Documents and Settings\Administrator\My Documents\pos104E.tmp
C:\Documents and Settings\Administrator\My Documents\pos104F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1050.tmp
C:\Documents and Settings\Administrator\My Documents\pos1051.tmp
C:\Documents and Settings\Administrator\My Documents\pos1052.tmp
C:\Documents and Settings\Administrator\My Documents\pos1053.tmp
C:\Documents and Settings\Administrator\My Documents\pos1054.tmp
C:\Documents and Settings\Administrator\My Documents\pos1055.tmp
C:\Documents and Settings\Administrator\My Documents\pos1056.tmp
C:\Documents and Settings\Administrator\My Documents\pos1057.tmp
C:\Documents and Settings\Administrator\My Documents\pos1058.tmp
C:\Documents and Settings\Administrator\My Documents\pos1059.tmp
C:\Documents and Settings\Administrator\My Documents\pos105A.tmp
C:\Documents and Settings\Administrator\My Documents\pos105B.tmp
C:\Documents and Settings\Administrator\My Documents\pos105C.tmp
C:\Documents and Settings\Administrator\My Documents\pos105D.tmp
C:\Documents and Settings\Administrator\My Documents\pos105E.tmp
C:\Documents and Settings\Administrator\My Documents\pos105F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1060.tmp
C:\Documents and Settings\Administrator\My Documents\pos1061.tmp
C:\Documents and Settings\Administrator\My Documents\pos1062.tmp
C:\Documents and Settings\Administrator\My Documents\pos1063.tmp
C:\Documents and Settings\Administrator\My Documents\pos1064.tmp
C:\Documents and Settings\Administrator\My Documents\pos1065.tmp
C:\Documents and Settings\Administrator\My Documents\pos1066.tmp
C:\Documents and Settings\Administrator\My Documents\pos1067.tmp
C:\Documents and Settings\Administrator\My Documents\pos1068.tmp
C:\Documents and Settings\Administrator\My Documents\pos1069.tmp
C:\Documents and Settings\Administrator\My Documents\pos106A.tmp
C:\Documents and Settings\Administrator\My Documents\pos106B.tmp
C:\Documents and Settings\Administrator\My Documents\pos106C.tmp
C:\Documents and Settings\Administrator\My Documents\pos106D.tmp
C:\Documents and Settings\Administrator\My Documents\pos106E.tmp
C:\Documents and Settings\Administrator\My Documents\pos106F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1070.tmp
C:\Documents and Settings\Administrator\My Documents\pos1071.tmp
C:\Documents and Settings\Administrator\My Documents\pos1072.tmp
C:\Documents and Settings\Administrator\My Documents\pos1073.tmp
C:\Documents and Settings\Administrator\My Documents\pos1074.tmp
C:\Documents and Settings\Administrator\My Documents\pos1075.tmp
C:\Documents and Settings\Administrator\My Documents\pos1076.tmp
C:\Documents and Settings\Administrator\My Documents\pos1077.tmp
C:\Documents and Settings\Administrator\My Documents\pos1078.tmp
C:\Documents and Settings\Administrator\My Documents\pos1079.tmp
C:\Documents and Settings\Administrator\My Documents\pos107A.tmp
C:\Documents and Settings\Administrator\My Documents\pos107B.tmp
C:\Documents and Settings\Administrator\My Documents\pos107C.tmp
C:\Documents and Settings\Administrator\My Documents\pos107D.tmp
C:\Documents and Settings\Administrator\My Documents\pos107E.tmp
C:\Documents and Settings\Administrator\My Documents\pos107F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1080.tmp
C:\Documents and Settings\Administrator\My Documents\pos1081.tmp
C:\Documents and Settings\Administrator\My Documents\pos1082.tmp
C:\Documents and Settings\Administrator\My Documents\pos1083.tmp
C:\Documents and Settings\Administrator\My Documents\pos1084.tmp
C:\Documents and Settings\Administrator\My Documents\pos1085.tmp
C:\Documents and Settings\Administrator\My Documents\pos1086.tmp
C:\Documents and Settings\Administrator\My Documents\pos1087.tmp
C:\Documents and Settings\Administrator\My Documents\pos1088.tmp
C:\Documents and Settings\Administrator\My Documents\pos1089.tmp
C:\Documents and Settings\Administrator\My Documents\pos108A.tmp
C:\Documents and Settings\Administrator\My Documents\pos108B.tmp
C:\Documents and Settings\Administrator\My Documents\pos108C.tmp
C:\Documents and Settings\Administrator\My Documents\pos108D.tmp
C:\Documents and Settings\Administrator\My Documents\pos108E.tmp
C:\Documents and Settings\Administrator\My Documents\pos108F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1090.tmp
C:\Documents and Settings\Administrator\My Documents\pos1091.tmp
C:\Documents and Settings\Administrator\My Documents\pos1092.tmp
C:\Documents and Settings\Administrator\My Documents\pos1093.tmp
C:\Documents and Settings\Administrator\My Documents\pos1094.tmp
C:\Documents and Settings\Administrator\My Documents\pos1095.tmp
C:\Documents and Settings\Administrator\My Documents\pos1096.tmp
C:\Documents and Settings\Administrator\My Documents\pos1097.tmp
C:\Documents and Settings\Administrator\My Documents\pos1098.tmp
C:\Documents and Settings\Administrator\My Documents\pos1099.tmp
C:\Documents and Settings\Administrator\My Documents\pos109A.tmp
C:\Documents and Settings\Administrator\My Documents\pos109B.tmp
C:\Documents and Settings\Administrator\My Documents\pos109C.tmp
C:\Documents and Settings\Administrator\My Documents\pos109D.tmp
C:\Documents and Settings\Administrator\My Documents\pos109E.tmp
C:\Documents and Settings\Administrator\My Documents\pos109F.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A0.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A1.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A2.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A3.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A4.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A5.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A6.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A7.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A8.tmp
C:\Documents and Settings\Administrator\My Documents\pos10A9.tmp
C:\Documents and Settings\Administrator\My Documents\pos10AA.tmp
C:\Documents and Settings\Administrator\My Documents\pos10AB.tmp
C:\Documents and Settings\Administrator\My Documents\pos10AC.tmp
C:\Documents and Settings\Administrator\My Documents\pos10AD.tmp
C:\Documents and Settings\Administrator\My Documents\pos10AE.tmp
C:\Documents and Settings\Administrator\My Documents\pos10AF.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B0.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B1.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B2.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B3.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B4.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B5.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B6.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B7.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B8.tmp
C:\Documents and Settings\Administrator\My Documents\pos10B9.tmp
C:\Documents and Settings\Administrator\My Documents\pos10BA.tmp
C:\Documents and Settings\Administrator\My Documents\pos10BB.tmp
C:\Documents and Settings\Administrator\My Documents\pos10BC.tmp
C:\Documents and Settings\Administrator\My Documents\pos10BD.tmp
C:\Documents and Settings\Administrator\My Documents\pos10BE.tmp
C:\Documents and Settings\Administrator\My Documents\pos10BF.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C0.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C1.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C2.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C3.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C4.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C5.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C6.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C7.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C8.tmp
C:\Documents and Settings\Administrator\My Documents\pos10C9.tmp
C:\Documents and Settings\Administrator\My Documents\pos10CA.tmp
C:\Documents and Settings\Administrator\My Documents\pos10CB.tmp
C:\Documents and Settings\Administrator\My Documents\pos10CC.tmp
C:\Documents and Settings\Administrator\My Documents\pos10CD.tmp
C:\Documents and Settings\Administrator\My Documents\pos10CE.tmp
C:\Documents and Settings\Administrator\My Documents\pos10CF.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D0.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D1.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D2.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D3.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D4.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D5.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D6.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D7.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D8.tmp
C:\Documents and Settings\Administrator\My Documents\pos10D9.tmp
C:\Documents and Settings\Administrator\My Documents\pos10DA.tmp
C:\Documents and Settings\Administrator\My Documents\pos10DB.tmp
C:\Documents and Settings\Administrator\My Documents\pos10DC.tmp
C:\Documents and Settings\Administrator\My Documents\pos10DD.tmp
C:\Documents and Settings\Administrator\My Documents\pos10DE.tmp
C:\Documents and Settings\Administrator\My Documents\pos10DF.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E0.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E1.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E2.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E3.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E4.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E5.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E6.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E7.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E8.tmp
C:\Documents and Settings\Administrator\My Documents\pos10E9.tmp
C:\Documents and Settings\Administrator\My Documents\pos10EA.tmp
C:\Documents and Settings\Administrator\My Documents\pos10EB.tmp
C:\Documents and Settings\Administrator\My Documents\pos10EC.tmp
C:\Documents and Settings\Administrator\My Documents\pos10ED.tmp
C:\Documents and Settings\Administrator\My Documents\pos10EE.tmp
C:\Documents and Settings\Administrator\My Documents\pos10EF.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F0.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F1.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F2.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F3.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F4.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F5.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F6.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F7.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F8.tmp
C:\Documents and Settings\Administrator\My Documents\pos10F9.tmp
C:\Documents and Settings\Administrator\My Documents\pos10FA.tmp
C:\Documents and Settings\Administrator\My Documents\pos10FB.tmp
C:\Documents and Settings\Administrator\My Documents\pos10FC.tmp
C:\Documents and Settings\Administrator\My Documents\pos10FD.tmp
C:\Documents and Settings\Administrator\My Documents\pos10FE.tmp
C:\Documents and Settings\Administrator\My Documents\pos10FF.tmp
C:\Documents and Settings\Administrator\My Documents\pos1100.tmp
C:\Documents and Settings\Administrator\My Documents\pos1101.tmp
C:\Documents and Settings\Administrator\My Documents\pos1102.tmp
C:\Documents and Settings\Administrator\My Documents\pos1103.tmp
C:\Documents and Settings\Administrator\My Documents\pos1104.tmp
C:\Documents and Settings\Administrator\My Documents\pos1105.tmp
C:\Documents and Settings\Administrator\My Documents\pos1106.tmp
C:\Documents and Settings\Administrator\My Documents\pos1107.tmp
C:\Documents and Settings\Administrator\My Documents\pos1108.tmp
C:\Documents and Settings\Administrator\My Documents\pos1109.tmp
C:\Documents and Settings\Administrator\My Documents\pos110A.tmp
C:\Documents and Settings\Administrator\My Documents\pos110B.tmp
C:\Documents and Settings\Administrator\My Documents\pos110C.tmp
C:\Documents and Settings\Administrator\My Documents\pos110D.tmp
C:\Documents and Settings\Administrator\My Documents\pos110E.tmp
C:\Documents and Settings\Administrator\My Documents\pos110F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1110.tmp
C:\Documents and Settings\Administrator\My Documents\pos1111.tmp
C:\Documents and Settings\Administrator\My Documents\pos1112.tmp
C:\Documents and Settings\Administrator\My Documents\pos1113.tmp
C:\Documents and Settings\Administrator\My Documents\pos1114.tmp
C:\Documents and Settings\Administrator\My Documents\pos1115.tmp
C:\Documents and Settings\Administrator\My Documents\pos1116.tmp
C:\Documents and Settings\Administrator\My Documents\pos1117.tmp
C:\Documents and Settings\Administrator\My Documents\pos1118.tmp
C:\Documents and Settings\Administrator\My Documents\pos1119.tmp
C:\Documents and Settings\Administrator\My Documents\pos111A.tmp
C:\Documents and Settings\Administrator\My Documents\pos111B.tmp
C:\Documents and Settings\Administrator\My Documents\pos111C.tmp
C:\Documents and Settings\Administrator\My Documents\pos111D.tmp
C:\Documents and Settings\Administrator\My Documents\pos111E.tmp
C:\Documents and Settings\Administrator\My Documents\pos111F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1120.tmp
C:\Documents and Settings\Administrator\My Documents\pos1121.tmp
C:\Documents and Settings\Administrator\My Documents\pos1122.tmp
C:\Documents and Settings\Administrator\My Documents\pos1123.tmp
C:\Documents and Settings\Administrator\My Documents\pos1124.tmp
C:\Documents and Settings\Administrator\My Documents\pos1125.tmp
C:\Documents and Settings\Administrator\My Documents\pos1126.tmp
C:\Documents and Settings\Administrator\My Documents\pos1127.tmp
C:\Documents and Settings\Administrator\My Documents\pos1128.tmp
C:\Documents and Settings\Administrator\My Documents\pos1129.tmp
C:\Documents and Settings\Administrator\My Documents\pos112A.tmp
C:\Documents and Settings\Administrator\My Documents\pos112B.tmp
C:\Documents and Settings\Administrator\My Documents\pos112C.tmp
C:\Documents and Settings\Administrator\My Documents\pos112D.tmp
C:\Documents and Settings\Administrator\My Documents\pos112E.tmp
C:\Documents and Settings\Administrator\My Documents\pos112F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1130.tmp
C:\Documents and Settings\Administrator\My Documents\pos1131.tmp
C:\Documents and Settings\Administrator\My Documents\pos1132.tmp
C:\Documents and Settings\Administrator\My Documents\pos1133.tmp
C:\Documents and Settings\Administrator\My Documents\pos1134.tmp
C:\Documents and Settings\Administrator\My Documents\pos1135.tmp
C:\Documents and Settings\Administrator\My Documents\pos1136.tmp
C:\Documents and Settings\Administrator\My Documents\pos1137.tmp
C:\Documents and Settings\Administrator\My Documents\pos1138.tmp
C:\Documents and Settings\Administrator\My Documents\pos1139.tmp
C:\Documents and Settings\Administrator\My Documents\pos113A.tmp
C:\Documents and Settings\Administrator\My Documents\pos113B.tmp
C:\Documents and Settings\Administrator\My Documents\pos113C.tmp
C:\Documents and Settings\Administrator\My Documents\pos113D.tmp
C:\Documents and Settings\Administrator\My Documents\pos113E.tmp
C:\Documents and Settings\Administrator\My Documents\pos113F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1140.tmp
C:\Documents and Settings\Administrator\My Documents\pos1141.tmp
C:\Documents and Settings\Administrator\My Documents\pos1142.tmp
C:\Documents and Settings\Administrator\My Documents\pos1143.tmp
C:\Documents and Settings\Administrator\My Documents\pos1144.tmp
C:\Documents and Settings\Administrator\My Documents\pos1145.tmp
C:\Documents and Settings\Administrator\My Documents\pos1146.tmp
C:\Documents and Settings\Administrator\My Documents\pos1147.tmp
C:\Documents and Settings\Administrator\My Documents\pos1148.tmp
C:\Documents and Settings\Administrator\My Documents\pos1149.tmp
C:\Documents and Settings\Administrator\My Documents\pos114A.tmp
C:\Documents and Settings\Administrator\My Documents\pos114B.tmp
C:\Documents and Settings\Administrator\My Documents\pos114C.tmp
C:\Documents and Settings\Administrator\My Documents\pos114D.tmp
C:\Documents and Settings\Administrator\My Documents\pos114E.tmp
C:\Documents and Settings\Administrator\My Documents\pos114F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1150.tmp
C:\Documents and Settings\Administrator\My Documents\pos1151.tmp
C:\Documents and Settings\Administrator\My Documents\pos1152.tmp
C:\Documents and Settings\Administrator\My Documents\pos1153.tmp
C:\Documents and Settings\Administrator\My Documents\pos1154.tmp
C:\Documents and Settings\Administrator\My Documents\pos1155.tmp
C:\Documents and Settings\Administrator\My Documents\pos1156.tmp
C:\Documents and Settings\Administrator\My Documents\pos1157.tmp
C:\Documents and Settings\Administrator\My Documents\pos1158.tmp
C:\Documents and Settings\Administrator\My Documents\pos1159.tmp
C:\Documents and Settings\Administrator\My Documents\pos115A.tmp
C:\Documents and Settings\Administrator\My Documents\pos115B.tmp
C:\Documents and Settings\Administrator\My Documents\pos115C.tmp
C:\Documents and Settings\Administrator\My Documents\pos115D.tmp
C:\Documents and Settings\Administrator\My Documents\pos115E.tmp
C:\Documents and Settings\Administrator\My Documents\pos115F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1160.tmp
C:\Documents and Settings\Administrator\My Documents\pos1161.tmp
C:\Documents and Settings\Administrator\My Documents\pos1162.tmp
C:\Documents and Settings\Administrator\My Documents\pos1163.tmp
C:\Documents and Settings\Administrator\My Documents\pos1164.tmp
C:\Documents and Settings\Administrator\My Documents\pos1165.tmp
C:\Documents and Settings\Administrator\My Documents\pos1166.tmp
C:\Documents and Settings\Administrator\My Documents\pos1167.tmp
C:\Documents and Settings\Administrator\My Documents\pos1168.tmp
C:\Documents and Settings\Administrator\My Documents\pos1169.tmp
C:\Documents and Settings\Administrator\My Documents\pos116A.tmp
C:\Documents and Settings\Administrator\My Documents\pos116B.tmp
C:\Documents and Settings\Administrator\My Documents\pos116C.tmp
C:\Documents and Settings\Administrator\My Documents\pos116D.tmp
C:\Documents and Settings\Administrator\My Documents\pos116E.tmp
C:\Documents and Settings\Administrator\My Documents\pos116F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1170.tmp
C:\Documents and Settings\Administrator\My Documents\pos1171.tmp
C:\Documents and Settings\Administrator\My Documents\pos1172.tmp
C:\Documents and Settings\Administrator\My Documents\pos1173.tmp
C:\Documents and Settings\Administrator\My Documents\pos1174.tmp
C:\Documents and Settings\Administrator\My Documents\pos1175.tmp
C:\Documents and Settings\Administrator\My Documents\pos1176.tmp
C:\Documents and Settings\Administrator\My Documents\pos1177.tmp
C:\Documents and Settings\Administrator\My Documents\pos1178.tmp
C:\Documents and Settings\Administrator\My Documents\pos1179.tmp
C:\Documents and Settings\Administrator\My Documents\pos117A.tmp
C:\Documents and Settings\Administrator\My Documents\pos117B.tmp
C:\Documents and Settings\Administrator\My Documents\pos117C.tmp
C:\Documents and Settings\Administrator\My Documents\pos117D.tmp
C:\Documents and Settings\Administrator\My Documents\pos117E.tmp
C:\Documents and Settings\Administrator\My Documents\pos117F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1180.tmp
C:\Documents and Settings\Administrator\My Documents\pos1181.tmp
C:\Documents and Settings\Administrator\My Documents\pos1182.tmp
C:\Documents and Settings\Administrator\My Documents\pos1183.tmp
C:\Documents and Settings\Administrator\My Documents\pos1184.tmp
C:\Documents and Settings\Administrator\My Documents\pos1185.tmp
C:\Documents and Settings\Administrator\My Documents\pos1186.tmp
C:\Documents and Settings\Administrator\My Documents\pos1187.tmp
C:\Documents and Settings\Administrator\My Documents\pos1188.tmp
C:\Documents and Settings\Administrator\My Documents\pos1189.tmp
C:\Documents and Settings\Administrator\My Documents\pos118A.tmp
C:\Documents and Settings\Administrator\My Documents\pos118B.tmp
C:\Documents and Settings\Administrator\My Documents\pos118C.tmp
C:\Documents and Settings\Administrator\My Documents\pos118D.tmp
C:\Documents and Settings\Administrator\My Documents\pos118E.tmp
C:\Documents and Settings\Administrator\My Documents\pos118F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1190.tmp
C:\Documents and Settings\Administrator\My Documents\pos1191.tmp
C:\Documents and Settings\Administrator\My Documents\pos1192.tmp
C:\Documents and Settings\Administrator\My Documents\pos1193.tmp
C:\Documents and Settings\Administrator\My Documents\pos1194.tmp
C:\Documents and Settings\Administrator\My Documents\pos1195.tmp
C:\Documents and Settings\Administrator\My Documents\pos1196.tmp
C:\Documents and Settings\Administrator\My Documents\pos1197.tmp
C:\Documents and Settings\Administrator\My Documents\pos1198.tmp
C:\Documents and Settings\Administrator\My Documents\pos1199.tmp
C:\Documents and Settings\Administrator\My Documents\pos119A.tmp
C:\Documents and Settings\Administrator\My Documents\pos119B.tmp
C:\Documents and Settings\Administrator\My Documents\pos119C.tmp
C:\Documents and Settings\Administrator\My Documents\pos119D.tmp
C:\Documents and Settings\Administrator\My Documents\pos119E.tmp
C:\Documents and Settings\Administrator\My Documents\pos119F.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A0.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A1.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A2.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A3.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A4.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A5.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A6.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A7.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A8.tmp
C:\Documents and Settings\Administrator\My Documents\pos11A9.tmp
C:\Documents and Settings\Administrator\My Documents\pos11AA.tmp
C:\Documents and Settings\Administrator\My Documents\pos11AB.tmp
C:\Documents and Settings\Administrator\My Documents\pos11AC.tmp
C:\Documents and Settings\Administrator\My Documents\pos11AD.tmp
C:\Documents and Settings\Administrator\My Documents\pos11AE.tmp
C:\Documents and Settings\Administrator\My Documents\pos11AF.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B0.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B1.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B2.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B3.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B4.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B5.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B6.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B7.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B8.tmp
C:\Documents and Settings\Administrator\My Documents\pos11B9.tmp
C:\Documents and Settings\Administrator\My Documents\pos11BA.tmp
C:\Documents and Settings\Administrator\My Documents\pos11BB.tmp
C:\Documents and Settings\Administrator\My Documents\pos11BC.tmp
C:\Documents and Settings\Administrator\My Documents\pos11BD.tmp
C:\Documents and Settings\Administrator\My Documents\pos11BE.tmp
C:\Documents and Settings\Administrator\My Documents\pos11BF.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C0.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C1.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C2.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C3.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C4.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C5.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C6.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C7.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C8.tmp
C:\Documents and Settings\Administrator\My Documents\pos11C9.tmp
C:\Documents and Settings\Administrator\My Documents\pos11CA.tmp
C:\Documents and Settings\Administrator\My Documents\pos11CB.tmp
C:\Documents and Settings\Administrator\My Documents\pos11CC.tmp
C:\Documents and Settings\Administrator\My Documents\pos11CD.tmp
C:\Documents and Settings\Administrator\My Documents\pos11CE.tmp
C:\Documents and Settings\Administrator\My Documents\pos11CF.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D0.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D1.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D2.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D3.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D4.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D5.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D6.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D7.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D8.tmp
C:\Documents and Settings\Administrator\My Documents\pos11D9.tmp
C:\Documents and Settings\Administrator\My Documents\pos11DA.tmp
C:\Documents and Settings\Administrator\My Documents\pos11DB.tmp
C:\Documents and Settings\Administrator\My Documents\pos11DC.tmp
C:\Documents and Settings\Administrator\My Documents\pos11DD.tmp
C:\Documents and Settings\Administrator\My Documents\pos11DE.tmp
C:\Documents and Settings\Administrator\My Documents\pos11DF.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E0.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E1.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E2.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E3.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E4.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E5.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E6.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E7.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E8.tmp
C:\Documents and Settings\Administrator\My Documents\pos11E9.tmp
C:\Documents and Settings\Administrator\My Documents\pos11EA.tmp
C:\Documents and Settings\Administrator\My Documents\pos11EB.tmp
C:\Documents and Settings\Administrator\My Documents\pos11EC.tmp
C:\Documents and Settings\Administrator\My Documents\pos11ED.tmp
C:\Documents and Settings\Administrator\My Documents\pos11EE.tmp
C:\Documents and Settings\Administrator\My Documents\pos11EF.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F0.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F1.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F2.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F3.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F4.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F5.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F6.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F7.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F8.tmp
C:\Documents and Settings\Administrator\My Documents\pos11F9.tmp
C:\Documents and Settings\Administrator\My Documents\pos11FA.tmp
C:\Documents and Settings\Administrator\My Documents\pos11FB.tmp
C:\Documents and Settings\Administrator\My Documents\pos11FC.tmp
C:\Documents and Settings\Administrator\My Documents\pos11FD.tmp
C:\Documents and Settings\Administrator\My Documents\pos11FE.tmp
C:\Documents and Settings\Administrator\My Documents\pos11FF.tmp
C:\Documents and Settings\Administrator\My Documents\pos1200.tmp
C:\Documents and Settings\Administrator\My Documents\pos1201.tmp
C:\Documents and Settings\Administrator\My Documents\pos1202.tmp
C:\Documents and Settings\Administrator\My Documents\pos1203.tmp
C:\Documents and Settings\Administrator\My Documents\pos1204.tmp
C:\Documents and Settings\Administrator\My Documents\pos1205.tmp
C:\Documents and Settings\Administrator\My Documents\pos1206.tmp
C:\Documents and Settings\Administrator\My Documents\pos1207.tmp
C:\Documents and Settings\Administrator\My Documents\pos1208.tmp
C:\Documents and Settings\Administrator\My Documents\pos1209.tmp
C:\Documents and Settings\Administrator\My Documents\pos120A.tmp
C:\Documents and Settings\Administrator\My Documents\pos120B.tmp
C:\Documents and Settings\Administrator\My Documents\pos120C.tmp
C:\Documents and Settings\Administrator\My Documents\pos120D.tmp
C:\Documents and Settings\Administrator\My Documents\pos120E.tmp
C:\Documents and Settings\Administrator\My Documents\pos120F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1210.tmp
C:\Documents and Settings\Administrator\My Documents\pos1211.tmp
C:\Documents and Settings\Administrator\My Documents\pos1212.tmp
C:\Documents and Settings\Administrator\My Documents\pos1213.tmp
C:\Documents and Settings\Administrator\My Documents\pos1214.tmp
C:\Documents and Settings\Administrator\My Documents\pos1215.tmp
C:\Documents and Settings\Administrator\My Documents\pos1216.tmp
C:\Documents and Settings\Administrator\My Documents\pos1217.tmp
C:\Documents and Settings\Administrator\My Documents\pos1218.tmp
C:\Documents and Settings\Administrator\My Documents\pos1219.tmp
C:\Documents and Settings\Administrator\My Documents\pos121A.tmp
C:\Documents and Settings\Administrator\My Documents\pos121B.tmp
C:\Documents and Settings\Administrator\My Documents\pos121C.tmp
C:\Documents and Settings\Administrator\My Documents\pos121D.tmp
C:\Documents and Settings\Administrator\My Documents\pos121E.tmp
C:\Documents and Settings\Administrator\My Documents\pos121F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1220.tmp
C:\Documents and Settings\Administrator\My Documents\pos1221.tmp
C:\Documents and Settings\Administrator\My Documents\pos1222.tmp
C:\Documents and Settings\Administrator\My Documents\pos1223.tmp
C:\Documents and Settings\Administrator\My Documents\pos1224.tmp
C:\Documents and Settings\Administrator\My Documents\pos1225.tmp
C:\Documents and Settings\Administrator\My Documents\pos1226.tmp
C:\Documents and Settings\Administrator\My Documents\pos1227.tmp
C:\Documents and Settings\Administrator\My Documents\pos1228.tmp
C:\Documents and Settings\Administrator\My Documents\pos1229.tmp
C:\Documents and Settings\Administrator\My Documents\pos122A.tmp
C:\Documents and Settings\Administrator\My Documents\pos122B.tmp
C:\Documents and Settings\Administrator\My Documents\pos122C.tmp
C:\Documents and Settings\Administrator\My Documents\pos122D.tmp
C:\Documents and Settings\Administrator\My Documents\pos122E.tmp
C:\Documents and Settings\Administrator\My Documents\pos122F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1230.tmp
C:\Documents and Settings\Administrator\My Documents\pos1231.tmp
C:\Documents and Settings\Administrator\My Documents\pos1232.tmp
C:\Documents and Settings\Administrator\My Documents\pos1233.tmp
C:\Documents and Settings\Administrator\My Documents\pos1234.tmp
C:\Documents and Settings\Administrator\My Documents\pos1235.tmp
C:\Documents and Settings\Administrator\My Documents\pos1236.tmp
C:\Documents and Settings\Administrator\My Documents\pos1237.tmp
C:\Documents and Settings\Administrator\My Documents\pos1238.tmp
C:\Documents and Settings\Administrator\My Documents\pos1239.tmp
C:\Documents and Settings\Administrator\My Documents\pos123A.tmp
C:\Documents and Settings\Administrator\My Documents\pos123B.tmp
C:\Documents and Settings\Administrator\My Documents\pos123C.tmp
C:\Documents and Settings\Administrator\My Documents\pos123D.tmp
C:\Documents and Settings\Administrator\My Documents\pos123E.tmp
C:\Documents and Settings\Administrator\My Documents\pos123F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1240.tmp
C:\Documents and Settings\Administrator\My Documents\pos1241.tmp
C:\Documents and Settings\Administrator\My Documents\pos1242.tmp
C:\Documents and Settings\Administrator\My Documents\pos1243.tmp
C:\Documents and Settings\Administrator\My Documents\pos1244.tmp
C:\Documents and Settings\Administrator\My Documents\pos1245.tmp
C:\Documents and Settings\Administrator\My Documents\pos1246.tmp
C:\Documents and Settings\Administrator\My Documents\pos1247.tmp
C:\Documents and Settings\Administrator\My Documents\pos1248.tmp
C:\Documents and Settings\Administrator\My Documents\pos1249.tmp
C:\Documents and Settings\Administrator\My Documents\pos124A.tmp
C:\Documents and Settings\Administrator\My Documents\pos124B.tmp
C:\Documents and Settings\Administrator\My Documents\pos124C.tmp
C:\Documents and Settings\Administrator\My Documents\pos124D.tmp
C:\Documents and Settings\Administrator\My Documents\pos124E.tmp
C:\Documents and Settings\Administrator\My Documents\pos124F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1250.tmp
C:\Documents and Settings\Administrator\My Documents\pos1251.tmp
C:\Documents and Settings\Administrator\My Documents\pos1252.tmp
C:\Documents and Settings\Administrator\My Documents\pos1253.tmp
C:\Documents and Settings\Administrator\My Documents\pos1254.tmp
C:\Documents and Settings\Administrator\My Documents\pos1255.tmp
C:\Documents and Settings\Administrator\My Documents\pos1256.tmp
C:\Documents and Settings\Administrator\My Documents\pos1257.tmp
C:\Documents and Settings\Administrator\My Documents\pos1258.tmp
C:\Documents and Settings\Administrator\My Documents\pos1259.tmp
C:\Documents and Settings\Administrator\My Documents\pos125A.tmp
C:\Documents and Settings\Administrator\My Documents\pos125B.tmp
C:\Documents and Settings\Administrator\My Documents\pos125C.tmp
C:\Documents and Settings\Administrator\My Documents\pos125D.tmp
C:\Documents and Settings\Administrator\My Documents\pos125E.tmp
C:\Documents and Settings\Administrator\My Documents\pos125F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1260.tmp
C:\Documents and Settings\Administrator\My Documents\pos1261.tmp
C:\Documents and Settings\Administrator\My Documents\pos1262.tmp
C:\Documents and Settings\Administrator\My Documents\pos1263.tmp
C:\Documents and Settings\Administrator\My Documents\pos1264.tmp
C:\Documents and Settings\Administrator\My Documents\pos1265.tmp
C:\Documents and Settings\Administrator\My Documents\pos1266.tmp
C:\Documents and Settings\Administrator\My Documents\pos1267.tmp
C:\Documents and Settings\Administrator\My Documents\pos1268.tmp
C:\Documents and Settings\Administrator\My Documents\pos1269.tmp
C:\Documents and Settings\Administrator\My Documents\pos126A.tmp
C:\Documents and Settings\Administrator\My Documents\pos126B.tmp
C:\Documents and Settings\Administrator\My Documents\pos126C.tmp
C:\Documents and Settings\Administrator\My Documents\pos126D.tmp
C:\Documents and Settings\Administrator\My Documents\pos126E.tmp
C:\Documents and Settings\Administrator\My Documents\pos126F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1270.tmp
C:\Documents and Settings\Administrator\My Documents\pos1271.tmp
C:\Documents and Settings\Administrator\My Documents\pos1272.tmp
C:\Documents and Settings\Administrator\My Documents\pos1273.tmp
C:\Documents and Settings\Administrator\My Documents\pos1274.tmp
C:\Documents and Settings\Administrator\My Documents\pos1275.tmp
C:\Documents and Settings\Administrator\My Documents\pos1276.tmp
C:\Documents and Settings\Administrator\My Documents\pos1277.tmp
C:\Documents and Settings\Administrator\My Documents\pos1278.tmp
C:\Documents and Settings\Administrator\My Documents\pos1279.tmp
C:\Documents and Settings\Administrator\My Documents\pos127A.tmp
C:\Documents and Settings\Administrator\My Documents\pos127B.tmp
C:\Documents and Settings\Administrator\My Documents\pos127C.tmp
C:\Documents and Settings\Administrator\My Documents\pos127D.tmp
C:\Documents and Settings\Administrator\My Documents\pos127E.tmp
C:\Documents and Settings\Administrator\My Documents\pos127F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1280.tmp
C:\Documents and Settings\Administrator\My Documents\pos1281.tmp
C:\Documents and Settings\Administrator\My Documents\pos1282.tmp
C:\Documents and Settings\Administrator\My Documents\pos1283.tmp
C:\Documents and Settings\Administrator\My Documents\pos1284.tmp
C:\Documents and Settings\Administrator\My Documents\pos1285.tmp
C:\Documents and Settings\Administrator\My Documents\pos1286.tmp
C:\Documents and Settings\Administrator\My Documents\pos1287.tmp
C:\Documents and Settings\Administrator\My Documents\pos1288.tmp
C:\Documents and Settings\Administrator\My Documents\pos1289.tmp
C:\Documents and Settings\Administrator\My Documents\pos128A.tmp
C:\Documents and Settings\Administrator\My Documents\pos128B.tmp
C:\Documents and Settings\Administrator\My Documents\pos128C.tmp
C:\Documents and Settings\Administrator\My Documents\pos128D.tmp
C:\Documents and Settings\Administrator\My Documents\pos128E.tmp
C:\Documents and Settings\Administrator\My Documents\pos128F.tmp
C:\Documents and Settings\Administrator\My Documents\pos1290.tmp
C:\Documents and Settings\Administrator\My Documents\pos1291.tmp
C:\Documents and Settings\Administrator\My Documents\pos1292.tmp
C:\Documents and Settings\Administrator\My Documents\pos1293.tmp
C:\Documents and Settings\Administrator\My Documents\pos1294.tmp
C:\Documents and Settings\Administrator\My Documents\pos1295.tmp
C:\Documents and Settings\Administrator\My Documents\pos1296.tmp
C:\Documents and Settings\Administrator\My Documents\pos1297.tmp
C:\Documents and Settings\Administrator\My Documents\pos1298.tmp
C:\Documents and Settings\Administrator\My Documents\pos1299.tmp
C:\Documents and Settings\Administrator\My Documents\pos129A.tmp
C:\Documents and Settings\Administrator\My Documents\pos129B.tmp
C:\Documents and Settings\Administrator\My Documents\pos129C.tmp
C:\Documents and Settings\Administrator\My Documents\pos129D.tmp
C:\Documents and Settings\Administrator\My Documents\pos129E.tmp
C:\Documents and Settings\Administrator\My Documents\pos129F.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A0.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A1.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A2.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A3.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A4.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A5.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A6.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A7.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A8.tmp
C:\Documents and Settings\Administrator\My Documents\pos12A9.tmp
C:\Documents and Settings\Administrator\My Documents\pos12AA.tmp
C:\Documents and Settings\Administrator\My Documents\pos12AB.tmp
C:\Documents and Settings\Administrator\My Documents\pos12AC.tmp
C:\Documents and Settings\Administrator\My Documents\pos12AD.tmp
C:\Documents and Settings\Administrator\My Documents\pos12AE.tmp
C:\Documents and Settings\Administrator\My Documents\pos12AF.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B0.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B1.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B2.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B3.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B4.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B5.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B6.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B7.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B8.tmp
C:\Documents and Settings\Administrator\My Documents\pos12B9.tmp
C:\Documents and Settings\Administrator\My Documents\pos12BA.tmp
C:\Documents and Settings\Administrator\My Documents\pos12BB.tmp
C:\Documents and Settings\Administrator\My Documents\pos12BC.tmp
C:\Documents and Settings\Administrator\My Documents\pos12BD.tmp
C:\Documents and Settings\Administrator\My Documents\pos12BE.tmp
C:\Documents and Settings\Administrator\My Documents\pos12BF.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C0.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C1.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C2.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C3.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C4.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C5.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C6.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C7.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C8.tmp
C:\Documents and Settings\Administrator\My Documents\pos12C9.tmp
C:\Documents and Settings\Administrator\My Documents\pos12CA.tmp
C:\Documents and Settings\Administrator\My Documents\pos12CB.tmp
C:\Documents and Settings\Administrator\My Documents\pos12CC.tmp
C:\Documents and Settings\Administrator\My Documents\pos12
  • 0

#6
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP

BTW, i'm not trying to argue with you i just wanted to clarify that i had done an AV scan. Is it common practice for people on this forum to try to insult new members? just because someone has 2 posts doesnt make them an idiot or mean they dont have knowledge of computers.

Excuse me? I was just trying to explain why an Antivirus installed is so important. Most people think that an Antivirus is mainly to remove malware . If that was true, then everyone should have enough with an online scan once in a while and no Antivirus installed. I know you probably did an AV scan previously, but you didn't have an Antivirus installed, so nothing would prevent future malware.
Not sure why you see this as an insult - or why you think that I see you as an idiot. I am just trying to explain things, this to make sure that you understand the importance of having an Antivirus installed.

The version of Combofix you are using is outdated.. that's why a new download is recommended to remove the latest malware.
So please download and run the latest version.
  • 0

#7
mmullins

mmullins

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
new log


ComboFix 08-02.02.5 - Administrator 2008-02-02 10:06:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.224 [GMT -6:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\tn3
C:\WINDOWS\ORUN32.EXE
C:\WINDOWS\system32\CMMGR32.EXE
C:\WINDOWS\system32\cyjolypa.ini
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
C:\WINDOWS\system32\jcatgwjl.ini
C:\WINDOWS\system32\klerwkli.ini
C:\WINDOWS\system32\mxgvhida.ini
C:\WINDOWS\system32\pemxauha.ini
C:\WINDOWS\system32\uycaedrh.ini
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.

2008-02-02 10:11 . 2008-02-02 10:11 <DIR> d-------- C:\Temp\tn3
2008-02-02 00:47 . 2008-02-02 00:47 <DIR> d-------- C:\Program Files\Avira
2008-02-02 00:47 . 2008-02-02 00:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-01 23:30 . 2008-02-01 23:32 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-01 23:30 . 2008-02-01 23:30 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-01 23:30 . 2008-02-01 23:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-01 23:30 . 2008-02-01 23:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-02-01 23:13 . 2008-02-01 23:13 <DIR> d-------- C:\Program Files\smitRem
2008-02-01 23:12 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-01 23:12 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-01 23:12 . 2008-02-02 00:55 83,456 --a------ C:\WINDOWS\system32\VACFix.exe
2008-02-01 23:12 . 2008-01-27 14:37 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-01 23:12 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-02-01 23:12 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-01 23:12 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-01 23:12 . 2008-02-01 23:12 2,688 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-01 22:03 . 2008-02-01 22:06 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-01 22:03 . 2008-02-01 22:06 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-29 21:58 . 2008-01-29 21:58 <DIR> d-------- C:\RkUnhooker
2008-01-29 21:25 . 2007-10-10 17:55 6,065,664 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-29 21:25 . 2007-06-30 21:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-29 21:25 . 2007-06-30 21:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-29 21:25 . 2007-10-10 17:55 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-29 21:25 . 2007-10-10 17:55 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-29 21:25 . 2007-10-10 17:55 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-29 21:25 . 2007-10-10 17:55 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-29 21:25 . 2007-10-10 17:55 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-29 21:25 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\dllcache\custsat.dll
2008-01-29 21:25 . 2007-10-10 04:59 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-27 23:17 . 2008-01-29 11:18 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-27 22:51 . 2008-01-27 22:51 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-27 22:25 . 2008-01-27 22:25 <DIR> d-------- C:\VundoFix Backups
2008-01-27 17:25 . 2007-07-09 07:09 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-27 17:17 . 2008-02-02 00:37 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-27 14:29 . 2008-01-27 14:29 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-27 14:23 . 2008-01-27 17:21 <DIR> d-------- C:\Program Files\SDFix
2008-01-27 14:11 . 2008-01-27 14:12 <DIR> d-------- C:\HJT
2008-01-26 09:55 . 2008-01-26 09:55 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-25 23:14 . 2008-01-25 23:14 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-24 22:28 . 2008-01-24 22:28 4,286 --a------ C:\WINDOWS\system32\everybodybets.32x32.4.ico
2008-01-24 22:26 . 2008-01-25 20:41 165 --a------ C:\WINDOWS\wininit.ini
2008-01-24 21:10 . 2008-01-24 21:10 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-01-24 21:10 . 2008-01-25 20:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-24 20:51 . 2008-01-29 10:39 <DIR> d-------- C:\WINDOWS\system32\wnzs6
2008-01-24 20:51 . 2008-01-29 10:39 <DIR> d-------- C:\WINDOWS\system32\ni4
2008-01-24 20:51 . 2008-02-02 01:48 <DIR> d-------- C:\WINDOWS\system32\nGpxx01
2008-01-24 20:51 . 2008-01-24 20:51 <DIR> d-------- C:\WINDOWS\system32\etz1
2008-01-24 20:51 . 2008-01-24 21:03 <DIR> d-------- C:\WINDOWS\system32\comg7
2008-01-24 20:51 . 2008-02-02 10:11 <DIR> d-------- C:\Temp
2008-01-24 20:51 . 2008-01-24 20:51 86,016 --a------ C:\WINDOWS\system32\drivers\parvdmm.sys
2008-01-24 18:30 . 2008-01-24 18:30 <DIR> d-------- C:\Program Files\Hamachi
2008-01-24 18:30 . 2008-02-02 01:11 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Hamachi
2008-01-24 18:30 . 2008-01-24 18:30 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 05:41 --------- d-----w C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor
2008-02-02 05:40 --------- d-----w C:\Program Files\NetWaiting
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{de9f9b1a-90eb-482f-99f1-4e28470171d5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 14:02 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 14:02 126976]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 16:48 32881]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-13 23:23 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 13:35 536576]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 13:59 385024]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 10:26 606208]
"WinVNC"="C:\Program Files\RealVNC\WinVNC\WinVNC.exe" [2003-03-05 13:49 335872]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-02 15:09 180269]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 17:26 217088]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-27 09:36 286720]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-02 01:06 249896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA8292"="command /c del C:\WINDOWS\system32\drivers\core.cache.dsk" [ ]
"SpybotDeletingC6275"="cmd /c del C:\WINDOWS\system32\drivers\core.cache.dsk" [ ]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2008-01-24 18:30:19 624416]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 12:42:22 45056]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-10-06 22:11:49 24576]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-841775164-1823166421-316617838-3476\Scripts\Logoff\0\0]
"Script"=cookies.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-841775164-1823166421-316617838-3476\Scripts\Logon\0\0]
"Script"=bginfo.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-841775164-1823166421-316617838-3476\Scripts\Logon\0\1]
"Script"=DST2007.vbs

R1 parvdmm;parvdmm;C:\WINDOWS\system32\drivers\parvdmm.sys [2008-01-24 20:51]
S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22b6397f-3f98-11dc-803d-0010c664a5e9}]
\Shell\AutoRun\command - D:\Setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-02 10:12:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
.
**************************************************************************
.
Completion time: 2008-02-02 10:16:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-02 16:16:18
ComboFix2.txt 2008-02-02 15:32:38
.
2008-01-31 09:01:29 --- E O F ---
  • 0

#8
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Ok,

* Open notepad - don't use any other texteditor than notepad or the script will fail.
Copy/paste the text in the quotebox below into notepad:

File::
C:\WINDOWS\system32\drivers\parvdmm.sys
C:\WINDOWS\system32\drivers\core.cache.dsk

Folder::
C:\WINDOWS\system32\wnzs6
C:\WINDOWS\system32\ni4
C:\Temp\tn3
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\etz1
C:\WINDOWS\system32\comg7
C:\VundoFix Backups

Driver::
MSControlService
parvdmm

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA8292"=-
"SpybotDeletingC6275"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{de9f9b1a-90eb-482f-99f1-4e28470171d5}]


Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.

Also, open C:\WINDOWS\wininit.ini and post the contents of it in your next reply.
  • 0

#9
mmullins

mmullins

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
ComboFix 08-02.02.5 - Administrator 2008-02-02 10:41:11.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.131 [GMT -6:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\parvdmm.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\parvdmm.sys
C:\temp\tn3
C:\VundoFix Backups
C:\WINDOWS\system32\comg7
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\parvdmm.sys
C:\WINDOWS\system32\etz1
C:\WINDOWS\system32\etz1\lovstadcom2.exe
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\ni4
C:\WINDOWS\system32\wnzs6

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_MSCONTROLSERVICE
-------\LEGACY_PARVDMM
-------\MSControlService
-------\parvdmm


((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.

2008-02-02 00:47 . 2008-02-02 00:47 <DIR> d-------- C:\Program Files\Avira
2008-02-02 00:47 . 2008-02-02 00:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-01 23:30 . 2008-02-01 23:32 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-01 23:30 . 2008-02-01 23:30 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-01 23:30 . 2008-02-01 23:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-01 23:30 . 2008-02-01 23:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-02-01 23:13 . 2008-02-01 23:13 <DIR> d-------- C:\Program Files\smitRem
2008-02-01 23:12 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-01 23:12 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-01 23:12 . 2008-02-02 00:55 83,456 --a------ C:\WINDOWS\system32\VACFix.exe
2008-02-01 23:12 . 2008-01-27 14:37 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-01 23:12 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-02-01 23:12 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-01 23:12 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-01 23:12 . 2008-02-01 23:12 2,688 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-01 22:03 . 2008-02-01 22:06 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-01 22:03 . 2008-02-01 22:06 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-29 21:58 . 2008-01-29 21:58 <DIR> d-------- C:\RkUnhooker
2008-01-29 21:25 . 2007-10-10 17:55 6,065,664 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-29 21:25 . 2007-06-30 21:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-29 21:25 . 2007-06-30 21:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-29 21:25 . 2007-10-10 17:55 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-29 21:25 . 2007-10-10 17:55 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-29 21:25 . 2007-10-10 17:55 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-29 21:25 . 2007-10-10 17:55 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-29 21:25 . 2007-10-10 17:55 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-29 21:25 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\dllcache\custsat.dll
2008-01-29 21:25 . 2007-10-10 04:59 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-27 23:17 . 2008-01-29 11:18 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-27 22:51 . 2008-01-27 22:51 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-27 17:25 . 2007-07-09 07:09 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-27 14:29 . 2008-01-27 14:29 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-27 14:23 . 2008-01-27 17:21 <DIR> d-------- C:\Program Files\SDFix
2008-01-27 14:11 . 2008-01-27 14:12 <DIR> d-------- C:\HJT
2008-01-26 09:55 . 2008-01-26 09:55 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-25 23:14 . 2008-01-25 23:14 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-24 22:28 . 2008-01-24 22:28 4,286 --a------ C:\WINDOWS\system32\everybodybets.32x32.4.ico
2008-01-24 22:26 . 2008-01-25 20:41 165 --a------ C:\WINDOWS\wininit.ini
2008-01-24 21:10 . 2008-01-24 21:10 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-01-24 21:10 . 2008-01-25 20:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-24 20:51 . 2008-02-02 10:41 <DIR> d-------- C:\Temp
2008-01-24 18:30 . 2008-01-24 18:30 <DIR> d-------- C:\Program Files\Hamachi
2008-01-24 18:30 . 2008-02-02 10:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Hamachi
2008-01-24 18:30 . 2008-01-24 18:30 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 05:41 --------- d-----w C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor
2008-02-02 05:40 --------- d-----w C:\Program Files\NetWaiting
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{de9f9b1a-90eb-482f-99f1-4e28470171d5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 14:02 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 14:02 126976]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 16:48 32881]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-13 23:23 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 13:35 536576]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 13:59 385024]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 10:26 606208]
"WinVNC"="C:\Program Files\RealVNC\WinVNC\WinVNC.exe" [2003-03-05 13:49 335872]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-02 15:09 180269]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 17:26 217088]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-27 09:36 286720]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-02 01:06 249896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA8292"="command /c del C:\WINDOWS\system32\drivers\core.cache.dsk" [ ]
"SpybotDeletingC6275"="cmd /c del C:\WINDOWS\system32\drivers\core.cache.dsk" [ ]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2008-01-24 18:30:19 624416]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 12:42:22 45056]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-10-06 22:11:49 24576]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-841775164-1823166421-316617838-3476\Scripts\Logoff\0\0]
"Script"=cookies.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-841775164-1823166421-316617838-3476\Scripts\Logon\0\0]
"Script"=bginfo.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-841775164-1823166421-316617838-3476\Scripts\Logon\0\1]
"Script"=DST2007.vbs


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22b6397f-3f98-11dc-803d-0010c664a5e9}]
\Shell\AutoRun\command - D:\Setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-02 10:47:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
.
**************************************************************************
.
Completion time: 2008-02-02 10:49:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-02 16:49:53
ComboFix2.txt 2008-02-02 16:16:24
ComboFix3.txt 2008-02-02 15:32:38
.
2008-01-31 09:01:29 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52:24 AM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\RealVNC\WinVNC\WinVNC.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Hamachi\hamachi.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [SpybotDeletingA8292] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6275] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O14 - IERESET.INF: START_PAGE_URL=http://www.thomashospital.com/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1005.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = admin
O17 - HKLM\Software\..\Telephony: DomainName = admin
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = admin
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = admin
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: VNC Server (winvnc) - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\WinVNC.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe

--
End of file - 6570 bytes


wininit.ini
[rename]
c:\tempjunk1917.tmp=C:\WINDOWS\system32\drivers\core.cache.dsk
nul=c:\tempjunk7533.tmp
c:\tempjunk7533.tmp=C:\WINDOWS\system32\drivers\core.cache.dsk
  • 0

#10
mmullins

mmullins

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
<< doublepost >>

Edited by miekiemoes, 02 February 2008 - 11:15 AM.

  • 0

Advertisements


#11
mmullins

mmullins

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
sorry for the double post. could mods please remove that?

that seems to have resolved the issue miekiemoes. thanks for your help. i'm impressed. what exactly did that text file do?
  • 0

#12
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi,

The textfile was a script I created for you to tell Combofix what exactly to delete..

However, I see your Spybot Teatimer interfered with some registry fixes here. But don't worry, we can fix them with HijackThis..
But you'll have to disable your Teatimer first, otherwise this won't work..
If teatimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.
How to disable TeaTimer <== click me for instructions.
After you disabled Teatimer, download ResetTeaTimer.bat to your desktop. (In case you use Firefox, rightclick the link and choose "save as").
Doubleclick ResetTeaTimer.bat and let it run.
This will only take a few seconds.

Then,
Check and fix next entries in HijackThis:

O4 - HKLM\..\RunOnce: [SpybotDeletingA8292] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6275] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"


They are leftover from a previous attempt to remove the files with Spybot, but Teatimer interfered there as well..

Then, delete the C:\WINDOWS\wininit.ini, because that one is not present by default on XP - and in your case it was added to install/replace malware.

Also,

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 4.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 4".
  • Click the "Download" button to the right.
  • For Platform, select "Windows"
  • For language, select your language
  • Read the License agreement and then Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement".
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    • Java 2 Runtime Environment, SE v1.4.2
    • J2SE Runtime Environment 5.0
    • J2SE Runtime Environment 5.0 Update 6
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.
Then, * Go to start > run and copy and paste next command in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Let me know in your next reply how things are now...
  • 0

#13
mmullins

mmullins

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
everything seems to be working great now. thanks again for the help! :)
  • 0

#14
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Glad I could help... and I hope you understand now that I wasn't insulting you or anything else. My main "goal" is to teach people how to make sure this won't happen again.
I think you know how you (or probably someone else who used this computer) got infected in the first place, so I'm sure that you (or the one responsible) won't make the same mistake again :)
And that's why I said why an Antivirus present and running is so important - it could have blocked/deleted the downloader/installer.

Please read my Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.
Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Happy Surfing again!
  • 0

#15
mmullins

mmullins

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
:) you know how tone can be misinterpreted in text, im sure. :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP