Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Vundo trojan (log included)- help appreciated! [RESOLVED]


  • This topic is locked This topic is locked

#1
cocacola23

cocacola23

    Member

  • Member
  • PipPip
  • 15 posts
So any help would be greatly appreciated

It appears that the Vundo trojan has been on my computer for almost a month now. I've used SUPERAntiSpyware, VundoFix, and VirtumundoBegone.

All deleted many files, yet they came back once the computer rebooted

I tried Panda Activescan, but the computer crashed at the very end of it, so the scan couldn't be saved.

Please and thank-you to anyone who can help!

HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:10:58 PM, on 2/8/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\windows\System32\smss.exeC:\windows\system32\winlogon.exeC:\windows\system32\services.exeC:\windows\system32\lsass.exeC:\windows\system32\svchost.exeC:\windows\System32\svchost.exeC:\windows\system32\spoolsv.exeC:\windows\Explorer.exeC:\windows\zHotkey.exeC:\windows\RTHDCPL.EXEC:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exeC:\Program Files\Common Files\AOL\ACS\AOLAcsd.exeC:\windows\system32\RUNDLL32.EXEC:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exeC:\WINDOWS\arservice.exeC:\PROGRA~1\mcafee.com\agent\mcagent.exeC:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler .exeC:\WINDOWS\eHome\ehRecvr.exeC:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exeC:\WINDOWS\eHome\ehSched.exeC:\PROGRA~1\mcafee.com\agent\mcagent .exec:\program files\mcafee.com\agent\mcdetect.exec:\PROGRA~1\mcafee.com\vso\mcshield.exeC:\PROGRA~1\McAfee.com\PERSON~1\MpfTray .exeC:\Program Files\QuickTime\qttask                                    .exec:\progra~1\mcafee.com\vso\mcvsescn.exeC:\Program Files\iTunes\iTunesHelper.exec:\PROGRA~1\mcafee.com\agent\mctskshd.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXEC:\Program Files\Google\Gmail Notifier\gnotify.exeC:\Program Files\QuickTime\qttask                                     .exeC:\windows\system32\win32.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA .EXEC:\Program Files\iTunes\iTunesHelper .exeC:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exeC:\windows\system32\ctfmon.exeC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeC:\Program Files\Google\Gmail Notifier\gnotify .exeC:\Program Files\BigFix\bigfix.exeC:\windows\system32\ctfmon .exeC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exeC:\windows\system32\nvsvc32.exeC:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYSC:\windows\system32\svchost.exeC:\Program Files\RealVNC\VNC4\WinVNC4.exeC:\WINDOWS\system32\MsPMSPSv.exeC:\WINDOWS\system32\dllhost.exeC:\Program Files\iPod\bin\iPodService.exeC:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exeC:\windows\system32\rundll32.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\windows\system32\wuauclt.exeC:\windows\system32\wuauclt.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\Program Files\Internet Explorer\iexplore.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6540"]http://www.gateway.com/g/startpage.html?Ch...DTP&M=T6540[/url]R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6540"]http://www.gateway.com/g/startpage.html?Ch...DTP&M=T6540[/url]R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [url="http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6540"]http://www.gateway.com/g/startpage.html?Ch...DTP&M=T6540[/url]F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\drivers\ntndis.exeF3 - REG:win.ini: load=C:\windows\system32\awvvv.exeO3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dllO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dllO3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dllO4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exeO4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXEO4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exeO4 - HKLM\..\Run: [CHotkey] zHotkey.exeO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXEO4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1157372527\EE\AOLHostManager.exeO4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exeO4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktaskO4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exeO4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\MCUPDA~1.EXEO4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MS849B~1.EXEO4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startupO4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exeO4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exeO4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckRegO4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O5 "LPT1:" /M "Stylus CX3800"O4 - HKLM\..\Run: [Auto EPSON Stylus CX3800 Series on ACER-56FB35423D] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P50 "Auto EPSON Stylus CX3800 Series on ACER-56FB35423D" /O31 "\\ACER-56FB35423D\RinitaPrinter" /M "Stylus CX3800"O4 - HKLM\..\Run: [\\ACER-56FB35423D\EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P44 "\\ACER-56FB35423D\EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask                                     .exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P35 "EPSON Stylus CX3800 Series (Copy 1)" /O6 "USB001" /M "Stylus CX3800"O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exeO4 - HKLM\..\Run: [win32] win32.exeO4 - HKLM\..\Run: [44e7f7aa] rundll32.exe "C:\windows\system32\vihibrad.dll",bO4 - HKLM\..\RunServices: [win32] win32.exeO4 - HKCU\..\Run: [Power2GoExpress] NAO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHideO4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exeO4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeO4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXEO4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dllO9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dllO9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLLO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - [url="http://picasaweb.google.com/s/v/16.27/uploader2.cab"]http://picasaweb.google.com/s/v/16.27/uploader2.cab[/url]O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} (AXTNS Control) - [url="http://download.livemath.com/activex/AXTNS.ocx"]http://download.livemath.com/activex/AXTNS.ocx[/url]O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - [url="http://acs.pandasoftware.com/activescan/as5free/asinst.cab"]http://acs.pandasoftware.com/activescan/as5free/asinst.cab[/url]O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exeO23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exeO23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exeO23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exeO23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exeO23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exeO23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYSO23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe--End of file - 10635 bytes

VirtumundoBeGone log:

[02/07/2008, 16:58:40] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Rinita\My Documents\VirtumundoBeGone.exe" )[02/07/2008, 16:58:43] - Detected System Information:[02/07/2008, 16:58:43] -  Windows Version: 5.1.2600, Service Pack 2[02/07/2008, 16:58:43] -  Current Username: Rinita (Admin)[02/07/2008, 16:58:43] -  Windows is in NORMAL mode.[02/07/2008, 16:58:43] - Searching for Browser Helper Objects:[02/07/2008, 16:58:43] -  BHO 1: {0230112a-88e5-44bd-a4ab-b129b450c476} ()[02/07/2008, 16:58:43] - WARNING: BHO has no default name. Checking for Winlogon reference.[02/07/2008, 16:58:43] -  Checking for HKLM\...\Winlogon\Notify\vshndfiu[02/07/2008, 16:58:43] -  Key not found: HKLM\...\Winlogon\Notify\vshndfiu, continuing.[02/07/2008, 16:58:43] -  BHO 2: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)[02/07/2008, 16:58:43] -  BHO 3: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)[02/07/2008, 16:58:43] -  BHO 4: {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} (McAfee AntiPhishing Filter)[02/07/2008, 16:58:43] -  BHO 5: {5CC3F95E-EC38-4D53-9370-812A4257FFB3} ()[02/07/2008, 16:58:43] - WARNING: BHO has no default name. Checking for Winlogon reference.[02/07/2008, 16:58:43] -  Checking for HKLM\...\Winlogon\Notify\awvvv[02/07/2008, 16:58:43] -  Key not found: HKLM\...\Winlogon\Notify\awvvv, continuing.[02/07/2008, 16:58:43] -  BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)[02/07/2008, 16:58:43] -  BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)[02/07/2008, 16:58:43] -  BHO 8: {D7FD6C15-4927-4AAE-BF12-FBDABD287EB1} ()[02/07/2008, 16:58:43] - WARNING: BHO has no default name. Checking for Winlogon reference.[02/07/2008, 16:58:43] -  Checking for HKLM\...\Winlogon\Notify\hggdcaw[02/07/2008, 16:58:43] -  Key not found: HKLM\...\Winlogon\Notify\hggdcaw, continuing.[02/07/2008, 16:58:43] - Finished Searching Browser Helper Objects[02/07/2008, 16:58:43] - Finishing up...[02/07/2008, 16:58:43] - Nothing found! Exiting...

  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Please don't use quote boxes for the logs


Download ComboFix from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
  • 0

#3
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
The "read this" said to post a reply with the uninstall list

I can get the list open, but whenever i click the Save List button, HijackThis closes

I can send screenshots of the list if necessary.

Please and thank-you!
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Just continue with the ComboFix instructions above
  • 0

#5
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Wow. I didn't expect a reply so soon, but thanks

I just downloaded ComboFix. It was saved under MyDocuments, so i could see it while i ran the file.

My computer beeped, but not the sound as that is off, and closed ComboFix and the file that was in My Documents was instantly erased.

The ComboFix file is not in my Recycle Bin either.
  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Once you run ComboFix.exe the log should be in C:\ComboFix

Post that please
  • 0

#7
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Sorry, I closed the ComboFix continued box thinking it was another one of the vundo ads.

Does ComboFix ask you if you agree to the terms, and say that 1/100 machines do not make it through the disinfection process?
  • 0

#8
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Yes that is it

Please run ComboFix.exe and follow all the prompts

When it is done post the log
  • 0

#9
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
ComboFix log:

ComboFix 08-02.05.3 - Rinita 2008-02-08 15:45:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.338 [GMT -5:00]
Running from: C:\Documents and Settings\Rinita\My Documents\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\windows\system32\awvvv.dll
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\McAfee.com\Agent\MCUPDA~1 .EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe
C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee.com\Agent\MC1A3F~1.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
C:\Program Files\McAfee.com\Agent\MCUPDA~1.EXE
C:\Program Files\McAfee.com\Agent\MCUPDA~2.EXE
C:\Program Files\McAfee.com\Agent\MCUPDA~4 .EXE
C:\Program Files\McAfee.com\Agent\mcupdate .exe
C:\Program Files\McAfee.com\Agent\mcupdate.exe
C:\Program Files\McAfee.com\Personal Firewall\MpfTray.exe
C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee\SpamKiller\MS0516~1 .EXE
C:\Program Files\McAfee\SpamKiller\MS0516~1.EXE
C:\Program Files\McAfee\SpamKiller\MS0516~2 .EXE
C:\Program Files\McAfee\SpamKiller\MS0516~2.EXE
C:\Program Files\McAfee\SpamKiller\MS0516~3.EXE
C:\Program Files\McAfee\SpamKiller\MS1617~1 .EXE
C:\Program Files\McAfee\SpamKiller\MS1617~1.EXE
C:\Program Files\McAfee\SpamKiller\MS1617~2 .EXE
C:\Program Files\McAfee\SpamKiller\MS1617~2.EXE
C:\Program Files\McAfee\SpamKiller\MS1617~3 .EXE
C:\Program Files\McAfee\SpamKiller\MS1617~3.EXE
C:\Program Files\McAfee\SpamKiller\MS1617~4 .EXE
C:\Program Files\McAfee\SpamKiller\MS1617~4.EXE
C:\Program Files\McAfee\SpamKiller\MS162B~1.EXE
C:\Program Files\McAfee\SpamKiller\MS162B~2 .EXE
C:\Program Files\McAfee\SpamKiller\MS162B~3 .EXE
C:\Program Files\McAfee\SpamKiller\MS162B~3.EXE
C:\Program Files\McAfee\SpamKiller\MS162B~4 .EXE
C:\Program Files\McAfee\SpamKiller\MS162B~4.EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~1 .EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~1.EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~2.EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~3 .EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~4 .EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~4.EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~1 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~1.EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~2 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~2.EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~3 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~3.EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~4 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~4.EXE
C:\Program Files\McAfee\SpamKiller\MskAgent .exe
C:\Program Files\McAfee\SpamKiller\MskAgent.exe
C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\windows\system32\awvvv.dll
C:\windows\system32\awvvv.exe
C:\windows\system32\cqltmdhp.ini
C:\windows\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\darbihiv.ini
C:\windows\system32\drivers\ntndis.exe
C:\windows\system32\drivers\ntndis.sys . . . . failed to delete
C:\windows\system32\fvdmwqaq.ini
C:\windows\system32\hsnnkkbw.ini
C:\windows\system32\ittrakkn.dll
C:\windows\system32\mcrh.tmp
C:\WINDOWS\system32\nkkartti.ini
C:\windows\system32\qfoungnq.ini
C:\windows\system32\RCX33.tmp
C:\windows\system32\RCX36.tmp
C:\windows\system32\RCX63.tmp
C:\windows\system32\RCX6A.tmp
C:\windows\system32\RCX6E.tmp
C:\windows\system32\RCX6F.tmp
C:\windows\system32\RCX72.tmp
C:\windows\system32\RCX76.tmp
C:\windows\system32\RCX79.tmp
C:\windows\system32\RCX7F.tmp
C:\windows\system32\RCX86.tmp
C:\windows\system32\RCX89.tmp
C:\windows\system32\RCX8A.tmp
C:\windows\system32\RCX8B.tmp
C:\windows\system32\RCX8C.tmp
C:\windows\system32\RCX91.tmp
C:\windows\system32\RCX9E.tmp
C:\windows\system32\RCXA1.tmp
C:\windows\system32\RCXA2.tmp
C:\windows\system32\RCXA3.tmp
C:\windows\system32\RCXCA.tmp
C:\windows\system32\shyrbqij.dll
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
C:\windows\system32\sscvcerp.ini
C:\windows\system32\tmcrbrxo.dll
C:\windows\system32\uktsswfe.dll
C:\windows\system32\vihibrad.dll
C:\windows\system32\vshndfiu.dll
C:\windows\system32\vvvwa.ini
C:\WINDOWS\system32\vvvwa.ini2
C:\windows\system32\win32.exe
C:\windows\system32\xiufytxk.dll
C:\windows\system32\xlmdmblx.dll
C:\windows\system32\xoeqjxwi.dll
G:\Autorun.inf

<pre>
C:\Program Files\McAfee.com\Agent\MC1A3F~1 .EXE ---> C:\Program Files\McAfee.com\Agent\MCUPDA~4 .EXE
C:\Program Files\McAfee.com\Agent\MCUPDA~2 .EXE ---> C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_NTNDIS
-------\ntndis


((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.

2008-02-08 15:39 . 2004-08-10 14:00 388,608 --a------ C:\kmd.exe
2008-02-08 15:10 . 2008-02-08 15:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-07 20:15 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\RkPavProc.sys
2008-02-07 20:06 . 2008-02-07 20:16 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-07 20:06 . 2008-02-07 20:06 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-07 20:06 . 2008-02-07 20:06 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-07 20:06 . 2008-02-07 20:06 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-07 16:21 . 2008-02-07 20:41 <DIR> d-------- C:\VundoFix Backups
2008-02-07 15:59 . 2008-02-07 15:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 15:59 . 2008-02-07 15:59 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\SUPERAntiSpyware.com
2008-02-07 14:39 . 2008-02-07 20:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-07 14:39 . 2008-02-07 14:39 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-07 14:31 . 2008-02-08 15:50 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-06 07:29 . 2008-02-06 07:29 16,384 --a------ C:\WINDOWS\~DF1CD4.tmp
2008-02-06 07:13 . 2008-02-06 07:13 16,384 --a------ C:\WINDOWS\~DF35C7.tmp
2008-02-06 07:12 . 2008-02-06 07:12 16,384 --a------ C:\WINDOWS\~DFC01C.tmp
2008-02-06 07:12 . 2008-02-06 07:12 16,384 --a------ C:\WINDOWS\~DF7F09.tmp
2008-02-06 07:10 . 1994-11-30 00:00 51,797 --a------ C:\WINDOWS\CGMINIVW.HLP
2008-02-05 20:31 . 2008-02-05 20:31 90,688 --a------ C:\WINDOWS\system32\qaqwmdvf.dll
2008-02-05 20:25 . 2008-02-05 20:25 94,272 --a------ C:\WINDOWS\system32\rudkwtnr.dll
2008-02-04 20:34 . 2008-02-04 20:34 328,192 --a------ C:\WINDOWS\system32\RCX259.tmp
2008-01-28 20:00 . 2008-01-28 20:04 81 --a------ C:\WINDOWS\QTW.INI
2008-01-27 13:02 . 2008-02-07 15:42 366,080 --a------ C:\WINDOWS\mrofinu72.exe.tmp
2008-01-27 13:02 . 2008-01-27 13:02 270,698 --a------ C:\WINDOWS\system32\L24D7.tmp
2008-01-27 13:02 . 2008-01-27 13:02 181,965 --a------ C:\WINDOWS\system32\LF0B7.tmp
2008-01-26 09:02 . 2008-01-26 09:02 39,936 --a------ C:\WINDOWS\system32\byxvtqp.dll
2008-01-26 09:01 . 2008-01-26 09:02 270,698 --a------ C:\WINDOWS\system32\L7EE9.tmp
2008-01-26 09:01 . 2008-01-26 09:01 181,965 --a------ C:\WINDOWS\system32\L552A.tmp
2008-01-26 09:01 . 2008-01-26 09:01 9,292 --a------ C:\WINDOWS\system32\L7CE6.tmp
2008-01-19 17:38 . 2008-02-07 16:19 406,016 --a------ C:\WINDOWS\system32\PSDrvCheck .exe
2008-01-19 17:38 . 2008-02-07 16:19 155,648 --a------ C:\WINDOWS\system32\NeroCheck .exe
2008-01-19 17:38 . 2008-02-08 15:04 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2008-01-19 11:03 . 2008-02-08 15:04 4,864 --a------ C:\WINDOWS\system32\drivers\ntndis.sys
2008-01-17 18:31 . 2008-01-17 18:31 0 --a------ C:\WINDOWS\OpPrintServer.INI
2008-01-17 18:26 . 2008-01-17 18:26 <DIR> d-------- C:\WINDOWS\StartHtmico
2008-01-17 18:26 . 2008-01-17 18:26 <DIR> d-------- C:\WINDOWS\IP4000,3000
2008-01-17 18:26 . 2004-04-23 00:00 116,736 --a------ C:\WINDOWS\system32\CNMLM64.DLL
2008-01-17 18:26 . 2004-03-11 11:06 86,016 -ra------ C:\WINDOWS\system32\CNMCP64.exe
2008-01-17 18:26 . 2004-04-23 00:00 7,680 --a------ C:\WINDOWS\system32\CNMVS64.DLL
2008-01-17 16:02 . 2008-01-17 16:19 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-14 13:14 . 2005-11-21 00:48 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-01-14 13:14 . 2005-11-21 00:48 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-01-14 13:13 . 2008-01-14 13:17 <DIR> d-------- C:\Program Files\BitZipper
2008-01-14 13:13 . 2008-01-14 13:13 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\BitZipper
2008-01-14 12:45 . 2008-01-04 16:58 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-14 12:45 . 2008-01-04 16:58 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-01-14 12:45 . 2008-01-04 16:58 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-01-13 09:30 . 2008-01-13 09:30 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\Viewpoint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 20:50 --------- d-----w C:\Program Files\QuickTime
2008-02-08 20:49 --------- d-----w C:\Program Files\iTunes
2008-02-08 01:16 --------- d-----w C:\Program Files\Google
2008-02-07 20:14 --------- d-----w C:\Documents and Settings\Rinita\Application Data\Azureus
2008-02-06 12:29 16,384 ----a-w C:\windows\~DF1CD4.tmp
2008-02-06 12:13 16,384 ----a-w C:\windows\~DF35C7.tmp
2008-02-06 12:12 16,384 ----a-w C:\windows\~DFC01C.tmp
2008-02-06 12:12 16,384 ----a-w C:\windows\~DF7F09.tmp
2008-01-29 19:33 --------- d-----w C:\Program Files\Digital Media Reader
2008-01-17 23:32 --------- d-----w C:\Program Files\Canon
2008-01-14 18:05 --------- d-----w C:\Documents and Settings\Rinita\Application Data\LimeWire
2008-01-14 00:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-04 21:58 43,528 ------w C:\windows\system32\drivers\pxhelp20.sys
2007-12-31 16:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-29 16:37 --------- d-----w C:\Program Files\Quicken
2007-12-29 16:37 --------- d-----w C:\Program Files\Microsoft Works
2007-12-28 16:47 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-25 23:54 --------- d-----w C:\Program Files\InterActual
2007-12-25 15:54 --------- d-----w C:\Documents and Settings\Rinita\Application Data\CyberLink
2007-12-21 20:05 --------- d-----w C:\Program Files\Veoh Networks
2007-12-19 00:09 --------- d-----w C:\Program Files\LiveMath
2007-12-10 22:34 --------- d-----w C:\Documents and Settings\Rinita\Application Data\U3
2007-11-16 02:56 46 ----a-w C:\Documents and Settings\Rinita\Application Data\wklnhst.dat
2007-10-24 18:58 299,288 ----a-w C:\Program Files\GmailInstaller.exe
2007-10-02 18:59 1,164,456 ----a-w C:\Program Files\install_flash_player.exe
.
<pre>
----a-w		   125,528 2008-01-22 19:30:12  C:\Program Files\Common Files\AOL\1157372527\EE\AOLHostManager .exe
----a-w		   125,528 2008-01-22 19:31:03  C:\Program Files\Common Files\AOL\1157372527\EE\AOLHOS~1 .EXE
----a-w			79,448 2008-02-08 20:04:16  C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler .exe
----a-w		 2,052,189 2008-02-06 12:25:09  C:\Program Files\CyberLink\Power2Go\Power2GoExpress .exe
----a-w		   139,264 2008-01-29 19:33:37  C:\Program Files\Digital Media Reader\readericon45G .exe
----a-w		   479,232 2008-02-08 20:04:47  C:\Program Files\Google\Gmail Notifier\gnotify .exe
----a-w			68,856 2008-01-22 19:30:38  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w		   257,088 2008-02-08 20:04:40  C:\Program Files\iTunes\iTunesHelper .exe
----a-w		   469,504 2008-02-06 01:22:51  C:\Program Files\McAfee\SpamKiller\MS0516~3 .EXE
----a-w		   469,504 2008-02-06 12:24:54  C:\Program Files\McAfee\SpamKiller\MS0516~4 .EXE
----a-w		   469,504 2008-01-28 00:18:01  C:\Program Files\McAfee\SpamKiller\MS162B~1 .EXE
----a-w		   469,504 2008-01-26 16:49:13  C:\Program Files\McAfee\SpamKiller\MS18BE~2 .EXE
----a-w		 1,121,280 2008-02-08 01:45:19  C:\Program Files\McAfee\SpamKiller\MSKDetct .exe
----a-w		   303,104 2008-02-08 20:04:22  C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w		   564,224 2008-01-26 16:49:13  C:\Program Files\McAfee.com\Agent\mcupdate  .exe
----a-w		   212,992 2008-01-24 17:03:16  C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
----a-w		   212,992 2008-01-26 17:49:44  C:\Program Files\McAfee.com\Agent\MCUPDA~4 .EXE
----a-w		 1,005,096 2008-02-08 20:04:27  C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
----a-w		   151,552 2008-02-08 20:04:21  C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
----a-w		   163,840 2008-02-08 20:04:24  C:\Program Files\McAfee.com\VSO\mcvsshld .exe
----a-w			53,248 2008-01-31 19:43:06  C:\Program Files\McAfee.com\VSO\oasclnt .exe
----a-w		 1,694,208 2008-01-19 22:38:35  C:\Program Files\Messenger\msmsgs .exe
----a-w		   637,952 2008-02-06 12:02:47  C:\Program Files\QuickTime\qttask					   .exe
----a-w		   637,952 2008-02-06 01:22:53  C:\Program Files\QuickTime\qttask					  .exe
----a-w		   637,952 2008-01-26 16:49:13  C:\Program Files\QuickTime\qttask		  .exe
----a-w		 1,318,912 2008-02-08 20:04:56  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
----a-w		 1,287,696 2008-02-06 12:25:16  C:\Program Files\Uniblue\SpyEraser\SpyEraser .exe
----a-w		 3,477,504 2008-01-21 00:20:07  C:\Program Files\Veoh Networks\Veoh\VeohClient .exe
----a-w			64,512 2008-01-27 16:14:34  C:\WINDOWS\ehome\ehtray .exe
----a-w			15,360 2008-02-08 20:04:51  C:\WINDOWS\system32\ctfmon .exe
----a-w		   155,648 2008-02-07 21:19:59  C:\WINDOWS\system32\NeroCheck .exe
----a-w		   406,016 2008-02-07 21:19:54  C:\WINDOWS\system32\PSDrvCheck .exe
----a-w			98,304 2008-02-08 20:04:32  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIACA .EXE
</pre>


-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [ ]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [ ]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 77312 C:\WINDOWS\arpwrmsg.exe]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [ ]
"CHotkey"="zHotkey.exe" [2004-12-08 19:57 550912 C:\WINDOWS\zHotkey.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 15473664 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1157372527\EE\AOLHostManager.exe" [ ]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-30 09:02 7311360]
"nwiz"="nwiz.exe" [2005-11-30 09:02 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-30 09:02 86016]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [ ]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [ ]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [ ]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\MCUPDA~1.EXE" [2008-01-26 12:49 212992]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MS849B~1.EXE" [2008-02-06 07:24 469504]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [ ]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [ ]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [ ]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [ ]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [ ]
"Auto EPSON Stylus CX3800 Series on ACER-56FB35423D"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [ ]
"\\ACER-56FB35423D\EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"EPSON Stylus CX3800 Series (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [ ]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"win32"="win32.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"win32"="win32.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 20:17 443968]

C:\Documents and Settings\Rinita\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2006-09-04 07:20:23 2168360]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 BENDER;Pinnacle DV/AV Capture;C:\windows\system32\drivers\bender.sys [2006-11-21 13:34]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3b0979f5-3c0c-11db-9414-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 21:40:01 C:\windows\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-06 12:29:01 C:\windows\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2007-11-04 13:53:11 C:\windows\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

disk not found C:\

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

disk not found C:\

**************************************************************************

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\\\ACER-56FB35423D\\EPSON Stylus CX3800 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIACA.EXE /P44 \"\\\\ACER-56FB35423D\\EPSON Stylus CX3800 Series\" /O6 \"USB001\" /M \"Stylus CX3800\""
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\windows\system32\RUNDLL32.EXE
C:\windows\system32\NOTEPAD.EXE
.
**************************************************************************
.
Completion time: 2008-02-08 15:55:50 - machine was rebooted [Rinita]
ComboFix-quarantined-files.txt 2008-02-08 20:54:58
.
2008-01-08 22:46:15 --- E O F ---
  • 0

#10
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\~DF1CD4.tmp
C:\WINDOWS\~DF35C7.tmp
C:\WINDOWS\~DFC01C.tmp
C:\WINDOWS\~DF7F09.tmp
C:\WINDOWS\CGMINIVW.HLP
C:\WINDOWS\system32\qaqwmdvf.dll
C:\WINDOWS\system32\rudkwtnr.dll
C:\WINDOWS\system32\RCX259.tmp
C:\WINDOWS\mrofinu72.exe.tmp
C:\WINDOWS\system32\L24D7.tmp
C:\WINDOWS\system32\LF0B7.tmp
C:\WINDOWS\system32\byxvtqp.dll
C:\WINDOWS\system32\L7EE9.tmp
C:\WINDOWS\system32\L552A.tmp
C:\WINDOWS\system32\L7CE6.tmp
C:\windows\~DF1CD4.tmp
C:\windows\~DF35C7.tmp
C:\windows\~DFC01C.tmp
C:\windows\~DF7F09.tmp

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3b0979f5-3c0c-11db-9414-806d6172696f}]

RenV::
----a-w 125,528 2008-01-22 19:30:12 C:\Program Files\Common Files\AOL\1157372527\EE\AOLHostManager .exe
----a-w 125,528 2008-01-22 19:31:03 C:\Program Files\Common Files\AOL\1157372527\EE\AOLHOS~1 .EXE
----a-w 79,448 2008-02-08 20:04:16 C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler .exe
----a-w 2,052,189 2008-02-06 12:25:09 C:\Program Files\CyberLink\Power2Go\Power2GoExpress .exe
----a-w 139,264 2008-01-29 19:33:37 C:\Program Files\Digital Media Reader\readericon45G .exe
----a-w 479,232 2008-02-08 20:04:47 C:\Program Files\Google\Gmail Notifier\gnotify .exe
----a-w 68,856 2008-01-22 19:30:38 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w 257,088 2008-02-08 20:04:40 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 469,504 2008-02-06 01:22:51 C:\Program Files\McAfee\SpamKiller\MS0516~3 .EXE
----a-w 469,504 2008-02-06 12:24:54 C:\Program Files\McAfee\SpamKiller\MS0516~4 .EXE
----a-w 469,504 2008-01-28 00:18:01 C:\Program Files\McAfee\SpamKiller\MS162B~1 .EXE
----a-w 469,504 2008-01-26 16:49:13 C:\Program Files\McAfee\SpamKiller\MS18BE~2 .EXE
----a-w 1,121,280 2008-02-08 01:45:19 C:\Program Files\McAfee\SpamKiller\MSKDetct .exe
----a-w 303,104 2008-02-08 20:04:22 C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w 564,224 2008-01-26 16:49:13 C:\Program Files\McAfee.com\Agent\mcupdate .exe
----a-w 212,992 2008-01-24 17:03:16 C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
----a-w 212,992 2008-01-26 17:49:44 C:\Program Files\McAfee.com\Agent\MCUPDA~4 .EXE
----a-w 1,005,096 2008-02-08 20:04:27 C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
----a-w 151,552 2008-02-08 20:04:21 C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
----a-w 163,840 2008-02-08 20:04:24 C:\Program Files\McAfee.com\VSO\mcvsshld .exe
----a-w 53,248 2008-01-31 19:43:06 C:\Program Files\McAfee.com\VSO\oasclnt .exe
----a-w 1,694,208 2008-01-19 22:38:35 C:\Program Files\Messenger\msmsgs .exe
----a-w 637,952 2008-02-06 12:02:47 C:\Program Files\QuickTime\qttask .exe
----a-w 637,952 2008-02-06 01:22:53 C:\Program Files\QuickTime\qttask .exe
----a-w 637,952 2008-01-26 16:49:13 C:\Program Files\QuickTime\qttask .exe
----a-w 1,318,912 2008-02-08 20:04:56 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
----a-w 1,287,696 2008-02-06 12:25:16 C:\Program Files\Uniblue\SpyEraser\SpyEraser .exe
----a-w 3,477,504 2008-01-21 00:20:07 C:\Program Files\Veoh Networks\Veoh\VeohClient .exe
----a-w 64,512 2008-01-27 16:14:34 C:\WINDOWS\ehome\ehtray .exe
----a-w 15,360 2008-02-08 20:04:51 C:\WINDOWS\system32\ctfmon .exe
----a-w 155,648 2008-02-07 21:19:59 C:\WINDOWS\system32\NeroCheck .exe
----a-w 406,016 2008-02-07 21:19:54 C:\WINDOWS\system32\PSDrvCheck .exe
----a-w 98,304 2008-02-08 20:04:32 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIACA .EXE


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

  • 0

Advertisements


#11
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Problem solved!

I'm running SUPERAntiSpyware to make sure everything is gone, and it seems to be so far.

Thank you so very much for your time and effort!
  • 0

#12
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Post the logs so that we can be 100% sure
  • 0

#13
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
SUPERAntiSpyware came out clean

second log:

ComboFix 08-02.05.3 - Rinita 2008-02-08 20:23:13.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.533 [GMT -5:00]
Running from: C:\Documents and Settings\Rinita\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rinita\My Documents\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\windows\~DF1CD4.tmp
C:\WINDOWS\~DF1CD4.tmp
C:\windows\~DF35C7.tmp
C:\WINDOWS\~DF35C7.tmp
C:\WINDOWS\~DF7F09.tmp
C:\windows\~DF7F09.tmp
C:\WINDOWS\~DFC01C.tmp
C:\windows\~DFC01C.tmp
C:\WINDOWS\CGMINIVW.HLP
C:\WINDOWS\mrofinu72.exe.tmp
C:\WINDOWS\system32\byxvtqp.dll
C:\WINDOWS\system32\L24D7.tmp
C:\WINDOWS\system32\L552A.tmp
C:\WINDOWS\system32\L7CE6.tmp
C:\WINDOWS\system32\L7EE9.tmp
C:\WINDOWS\system32\LF0B7.tmp
C:\WINDOWS\system32\qaqwmdvf.dll
C:\WINDOWS\system32\RCX259.tmp
C:\WINDOWS\system32\rudkwtnr.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\qaqwmdvf.dll
C:\WINDOWS\system32\rudkwtnr.dll
C:\windows\~DF1CD4.tmp
C:\WINDOWS\~DF35C7.tmp
C:\windows\~DF7F09.tmp
C:\windows\~DFC01C.tmp
C:\WINDOWS\CGMINIVW.HLP
C:\WINDOWS\mrofinu72.exe.tmp
C:\WINDOWS\system32\byxvtqp.dll
C:\WINDOWS\system32\L24D7.tmp
C:\WINDOWS\system32\L552A.tmp
C:\WINDOWS\system32\L7CE6.tmp
C:\WINDOWS\system32\L7EE9.tmp
C:\WINDOWS\system32\LF0B7.tmp
C:\WINDOWS\system32\qaqwmdvf.dll
C:\WINDOWS\system32\RCX259.tmp
C:\WINDOWS\system32\rudkwtnr.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.

2008-02-08 17:13 . 2008-02-08 17:13 279 --a------ C:\Shortcut to Local Disk ©.lnk
2008-02-08 16:57 . 2004-08-10 14:00 388,608 --a------ C:\kmd.exe
2008-02-08 15:10 . 2008-02-08 15:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-07 20:15 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\RkPavProc.sys
2008-02-07 20:06 . 2008-02-07 20:16 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-07 20:06 . 2008-02-07 20:06 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-07 20:06 . 2008-02-07 20:06 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-07 20:06 . 2008-02-07 20:06 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-07 16:21 . 2008-02-07 20:41 <DIR> d-------- C:\VundoFix Backups
2008-02-07 15:59 . 2008-02-07 15:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 15:59 . 2008-02-07 15:59 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\SUPERAntiSpyware.com
2008-02-07 14:39 . 2008-02-07 20:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-07 14:39 . 2008-02-07 14:39 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-07 14:31 . 2008-02-08 20:23 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-28 20:00 . 2008-01-28 20:04 81 --a------ C:\WINDOWS\QTW.INI
2008-01-19 17:38 . 2008-02-07 16:19 406,016 --a------ C:\WINDOWS\system32\PSDrvCheck.exe
2008-01-19 17:38 . 2008-02-07 16:19 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-01-19 17:37 . 2008-01-27 11:14 64,512 --a--c--- C:\WINDOWS\system32\dllcache\ehtray.exe
2008-01-17 18:31 . 2008-01-17 18:31 0 --a------ C:\WINDOWS\OpPrintServer.INI
2008-01-17 18:26 . 2008-01-17 18:26 <DIR> d-------- C:\WINDOWS\StartHtmico
2008-01-17 18:26 . 2008-01-17 18:26 <DIR> d-------- C:\WINDOWS\IP4000,3000
2008-01-17 18:26 . 2004-04-23 00:00 116,736 --a------ C:\WINDOWS\system32\CNMLM64.DLL
2008-01-17 18:26 . 2004-03-11 11:06 86,016 -ra------ C:\WINDOWS\system32\CNMCP64.exe
2008-01-17 18:26 . 2004-04-23 00:00 7,680 --a------ C:\WINDOWS\system32\CNMVS64.DLL
2008-01-17 16:02 . 2008-01-17 16:19 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-14 13:14 . 2005-11-21 00:48 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-01-14 13:14 . 2005-11-21 00:48 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-01-14 13:13 . 2008-01-14 13:17 <DIR> d-------- C:\Program Files\BitZipper
2008-01-14 13:13 . 2008-01-14 13:13 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\BitZipper
2008-01-14 12:45 . 2008-01-04 16:58 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-14 12:45 . 2008-01-04 16:58 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-01-14 12:45 . 2008-01-04 16:58 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-01-13 09:30 . 2008-01-13 09:30 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\Viewpoint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 01:22 --------- d-----w C:\Program Files\iTunes
2008-02-09 01:22 --------- d-----w C:\Program Files\Digital Media Reader
2008-02-08 20:50 --------- d-----w C:\Program Files\QuickTime
2008-02-08 01:16 --------- d-----w C:\Program Files\Google
2008-02-07 20:14 --------- d-----w C:\Documents and Settings\Rinita\Application Data\Azureus
2008-01-17 23:32 --------- d-----w C:\Program Files\Canon
2008-01-14 18:05 --------- d-----w C:\Documents and Settings\Rinita\Application Data\LimeWire
2008-01-14 00:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-04 21:58 43,528 ------w C:\windows\system32\drivers\pxhelp20.sys
2007-12-31 16:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-29 16:37 --------- d-----w C:\Program Files\Quicken
2007-12-29 16:37 --------- d-----w C:\Program Files\Microsoft Works
2007-12-28 16:47 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-25 23:54 --------- d-----w C:\Program Files\InterActual
2007-12-25 15:54 --------- d-----w C:\Documents and Settings\Rinita\Application Data\CyberLink
2007-12-21 20:05 --------- d-----w C:\Program Files\Veoh Networks
2007-12-19 00:09 --------- d-----w C:\Program Files\LiveMath
2007-12-10 22:34 --------- d-----w C:\Documents and Settings\Rinita\Application Data\U3
2007-11-16 02:56 46 ----a-w C:\Documents and Settings\Rinita\Application Data\wklnhst.dat
2007-10-24 18:58 299,288 ----a-w C:\Program Files\GmailInstaller.exe
2007-10-02 18:59 1,164,456 ----a-w C:\Program Files\install_flash_player.exe
.
<pre>
----a-w		   469,504 2008-02-06 01:22:51  C:\Program Files\McAfee\SpamKiller\MS0516~3 .EXE
----a-w		   469,504 2008-02-06 12:24:54  C:\Program Files\McAfee\SpamKiller\MS0516~4 .EXE
----a-w		   469,504 2008-01-28 00:18:01  C:\Program Files\McAfee\SpamKiller\MS162B~1 .EXE
----a-w		   469,504 2008-01-26 16:49:13  C:\Program Files\McAfee\SpamKiller\MS18BE~2 .EXE
----a-w		   564,224 2008-01-26 16:49:13  C:\Program Files\McAfee.com\Agent\mcupdate  .exe
----a-w		   637,952 2008-02-06 12:02:47  C:\Program Files\QuickTime\qttask					   .exe
----a-w		   637,952 2008-02-06 01:22:53  C:\Program Files\QuickTime\qttask					  .exe
----a-w		   637,952 2008-01-26 16:49:13  C:\Program Files\QuickTime\qttask		  .exe
</pre>


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-19 17:38 1694208]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-22 14:30 68856]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-01-20 19:20 3477504]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-08 15:04 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2008-01-27 11:14 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 77312 C:\WINDOWS\arpwrmsg.exe]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2008-01-29 14:33 139264]
"CHotkey"="zHotkey.exe" [2004-12-08 19:57 550912 C:\WINDOWS\zHotkey.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 15473664 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1157372527\EE\AOLHostManager.exe" [2008-01-22 14:30 125528]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2008-02-08 15:04 79448]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-30 09:02 7311360]
"nwiz"="nwiz.exe" [2005-11-30 09:02 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-30 09:02 86016]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2008-02-08 15:04 151552]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2008-01-31 14:43 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2008-02-08 15:04 303104]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [ ]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MS849B~1.EXE" [2008-02-06 07:24 469504]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2008-02-07 20:45 1121280]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2008-02-08 15:04 163840]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2008-02-08 15:04 1005096]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2008-02-07 16:19 406016]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"Auto EPSON Stylus CX3800 Series on ACER-56FB35423D"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"\\ACER-56FB35423D\EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2008-02-07 16:19 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-08 15:04 257088]
"EPSON Stylus CX3800 Series (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2008-02-08 15:04 479232]
"win32"="win32.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"win32"="win32.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 20:17 443968]

C:\Documents and Settings\Rinita\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2006-09-04 07:20:23 2168360]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 BENDER;Pinnacle DV/AV Capture;C:\windows\system32\drivers\bender.sys [2006-11-21 13:34]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 21:40:01 C:\windows\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-06 12:29:01 C:\windows\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2007-11-04 13:53:11 C:\windows\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

disk not found C:\

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

disk not found C:\

**************************************************************************

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"\\\\ACER-56FB35423D\\EPSON Stylus CX3800 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIACA.EXE /P44 \"\\\\ACER-56FB35423D\\EPSON Stylus CX3800 Series\" /O6 \"USB001\" /M \"Stylus CX3800\""
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\windows\system32\RUNDLL32.EXE
C:\PROGRA~1\COMMON~1\AOL\115737~1\EE\AOLHOS~1.EXE
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\COMMON~1\AOL\115737~1\EE\AOLServiceHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
.
**************************************************************************
.
Completion time: 2008-02-08 20:31:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-09 01:30:22
ComboFix2.txt 2008-02-08 22:17:35
ComboFix3.txt 2008-02-08 20:55:51
.
2008-01-08 22:46:15 --- E O F ---
  • 0

#14
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Not done just yet

  • Download RenV.exe by sUBs to your desktop
  • Double click on it to run it
  • It will search your system drive looking for any modified .exe file and will produce a log for you.
  • Drag this log into RenV.exe and post the resulting log

  • 0

#15
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Ran on Sat 02/09/2008 - 16:59:07.92



----a-w		   469,504 2008-02-06 12:24:54  C:\Program Files\McAfee\SpamKiller\MS0516~4 .EXE

----a-w		   469,504 2008-01-28 00:18:01  C:\Program Files\McAfee\SpamKiller\MS162B~1 .EXE

----a-w		   469,504 2008-01-26 16:49:13  C:\Program Files\McAfee\SpamKiller\MS18BE~2 .EXE

----a-w		   564,224 2008-01-26 16:49:13  C:\Program Files\McAfee.com\Agent\mcupdate  .exe

----a-w		   637,952 2008-02-06 12:02:47  C:\Program Files\QuickTime\qttask					   .exe

----a-w		   637,952 2008-02-06 01:22:53  C:\Program Files\QuickTime\qttask					  .exe

----a-w		   637,952 2008-01-26 16:49:13  C:\Program Files\QuickTime\qttask		  .exe



 Entries:				7  (7)

 Directories:			0  Files:			 7

 Bytes:		  3,886,592  Blocks:		7,591

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP