Thanks for any help you can give me. Below is a copy of the log from running the Combo Fix.
________________________________________________________________________________
______________________________________________
ComboFix 08-05-01.1 - Krystal 2008-05-01 22:12:03.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.550 [GMT -4:00]
Running from: C:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Krystal\Desktop\Error Cleaner.url
C:\Documents and Settings\Krystal\Desktop\Privacy Protector.url
C:\Documents and Settings\Krystal\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Krystal\Favorites\Error Cleaner.url
C:\Documents and Settings\Krystal\Favorites\Privacy Protector.url
C:\Documents and Settings\Krystal\Favorites\Spyware&Malware Protection.url
C:\Program Files\PC-Cleaner
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
.
((((((((((((((((((((((((( Files Created from 2008-04-02 to 2008-05-02 )))))))))))))))))))))))))))))))
.
2008-05-01 22:00 . 2008-05-01 22:00 98,304 --a------ C:\WINDOWS\system32\hatwvefo.exe
2008-04-30 23:24 . 2008-04-30 23:24 106,496 --a------ C:\WINDOWS\system32\xsvixcfw.exe
2008-04-30 23:03 . 2008-04-30 23:03 106,496 --a------ C:\WINDOWS\system32\zmtwpyfo.exe
2008-04-30 22:46 . 2008-05-01 22:10 1,781,008 --a------ C:\ComboFix.exe
2008-04-27 17:45 . 2008-04-27 17:45 <DIR> d-------- C:\Documents and Settings\Krystal\Application Data\Leadertech
2008-04-27 17:38 . 2008-04-27 17:38 <DIR> d-------- C:\Documents and Settings\Krystal\Application Data\TmpRecentIcons
2008-04-26 22:26 . 2008-05-01 22:01 <DIR> d-------- C:\Program Files\Save
2008-04-26 22:26 . 2008-04-26 22:26 <DIR> d-------- C:\Program Files\Mercora
2008-04-26 22:25 . 2008-04-26 22:25 <DIR> d-------- C:\Program Files\iTunes
2008-04-26 22:25 . 2008-04-26 22:25 <DIR> d-------- C:\Program Files\iPod
2008-04-26 22:25 . 2008-04-26 22:25 <DIR> d-------- C:\Program Files\Hanes T-ShirtMaker Lite
2008-04-26 22:24 . 2008-04-26 22:24 <DIR> d-------- C:\Program Files\Learn2.com
2008-04-26 22:24 . 2008-04-26 22:24 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-26 22:22 . 2008-04-26 22:22 <DIR> d-------- C:\WINDOWS\tiinst
2008-04-26 22:22 . 2008-04-26 22:22 <DIR> d-------- C:\Program Files\DVD-RAM
2008-04-26 22:22 . 2008-04-26 22:22 <DIR> d-------- C:\Program Files\ArcSoft
2008-04-26 22:22 . 2008-04-26 22:22 <DIR> d-------- C:\Program Files\Analog Devices
2008-04-26 22:08 . 2008-04-26 22:22 <DIR> d-------- C:\Program Files\SpywareBot
2008-04-26 22:08 . 2008-04-26 22:09 <DIR> d-------- C:\Documents and Settings\Selma.KRYSTAL\Application Data\SpywareBot
2008-04-26 22:01 . 2008-04-26 22:22 <DIR> d-------- C:\Documents and Settings\Selma.KRYSTAL\Application Data\GetRightToGo
2008-04-26 21:24 . 2008-04-26 21:24 4,096 --a------ C:\WINDOWS\system32\taack.dat
2008-04-26 21:24 . 2008-04-26 21:24 4,096 --a------ C:\WINDOWS\system32\hxiwlgpm.dat
2008-04-26 20:43 . 2008-04-26 20:43 <DIR> d-------- C:\Documents and Settings\Selma.KRYSTAL\Application Data\Apple Computer
2008-04-26 20:36 . 2008-04-26 20:36 <DIR> d-------- C:\Documents and Settings\Selma.KRYSTAL\Application Data\Leadertech
2008-04-26 10:16 . 2008-04-26 10:16 <DIR> d-------- C:\Documents and Settings\Selma.KRYSTAL\Application Data\Intel
2008-04-26 10:15 . 2005-07-28 17:08 <DIR> d-------- C:\Documents and Settings\Selma.KRYSTAL\Application Data\toshiba
2008-04-26 10:15 . 2008-04-26 22:25 <DIR> d---s---- C:\Documents and Settings\Selma.KRYSTAL
2008-04-26 10:15 . 2008-05-01 22:11 1,024 --ah----- C:\Documents and Settings\Selma.KRYSTAL\ntuser.dat.LOG
2008-04-26 00:21 . 2008-04-26 22:26 <DIR> d-------- C:\WINDOWS\privacy_danger(4)
2008-04-26 00:13 . 2008-04-26 22:26 <DIR> d-------- C:\WINDOWS\privacy_danger(3)
2008-04-26 00:03 . 2008-04-26 22:26 <DIR> d-------- C:\WINDOWS\privacy_danger(2)
2008-04-25 22:05 . 2008-04-26 22:26 <DIR> d-------- C:\Program Files\Save(2)
2008-04-25 20:58 . 2008-04-26 22:26 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-25 20:58 . 2008-04-26 22:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-15 11:22 . 2008-04-15 11:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ghgvizif
2008-04-15 11:22 . 2008-04-15 05:34 266,240 --a------ C:\WINDOWS\lgmxvpatxqs.dll
2008-04-15 11:22 . 2008-04-15 05:34 221,184 --a------ C:\WINDOWS\omlbpkaw.dll
2008-04-15 11:22 . 2008-04-15 05:34 188,416 --a------ C:\WINDOWS\pmsoarbf.dll
2008-04-15 11:22 . 2008-04-15 05:34 155,648 --a------ C:\WINDOWS\qtvglped.dll
2008-04-15 11:22 . 2008-04-15 11:22 102,400 --a------ C:\WINDOWS\system32\snmrmpqt.exe
2008-04-15 11:22 . 2008-04-15 05:34 94,208 --a------ C:\WINDOWS\npqtsrak.exe
2008-04-15 11:22 . 2008-04-15 05:34 81,920 --a------ C:\WINDOWS\rtqmekwg.exe
2008-04-15 11:22 . 2008-04-15 11:22 10,240 --a------ C:\WINDOWS\system32\wlcstp32.dll
2008-04-15 00:11 . 2008-04-15 00:11 <DIR> d-------- C:\Program Files\Virtual Earth 3D
2008-04-04 00:53 . 2008-04-04 00:53 0 --a------ C:\WINDOWS\TSMLite.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 21:49 --------- d-----w C:\Program Files\Yahoo!
2008-04-27 02:25 --------- d-----w C:\Program Files\DivX
2008-04-27 02:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-04-27 02:22 --------- d-----r C:\Program Files\TypingMaster
2008-04-27 01:48 --------- d-----w C:\Program Files\Norton Security Scan
2008-04-27 01:36 --------- d-----w C:\Program Files\TOSHIBA
2008-04-27 01:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-27 01:22 --------- d-----w C:\Program Files\Pure Networks
2008-04-27 00:42 --------- d-----w C:\Program Files\InterActual
2008-04-27 00:36 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-27 00:32 --------- d-----w C:\Program Files\InterVideo
2008-03-22 15:14 --------- d-----w C:\Program Files\Cosmi
2008-03-22 15:14 --------- d-----w C:\Program Files\Common Files\Cosmi
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 02:12 --------- d-----w C:\Documents and Settings\Krystal\Application Data\HP
2008-03-18 01:32 --------- d-----w C:\Program Files\HP
2008-03-18 01:32 --------- d-----w C:\Program Files\Common Files\HP
2008-03-18 01:30 --------- d-----w C:\Program Files\Hewlett-Packard
2008-03-18 01:29 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-01-24 04:03 668 ----a-w C:\Documents and Settings\Krystal\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-04-30_23.05.11.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-01 03:02:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-02 02:00:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7348D74C-731B-DECE-9F8A-A37D8214708E}]
2008-04-15 11:22 10240 --a------ C:\WINDOWS\system32\wlcstp32.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DEC7717A-5974-46F2-8698-2B490F0FCA08}]
2008-04-15 05:34 266240 --a------ C:\WINDOWS\lgmxvpatxqs.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{67D59DA3-7A57-42C3-BBC1-D348E3944F88}"= "C:\WINDOWS\qtvglped.dll" [2008-04-15 05:34 155648]
[HKEY_CLASSES_ROOT\clsid\{67d59da3-7a57-42c3-bbc1-d348e3944f88}]
[HKEY_CLASSES_ROOT\qtvglped.1]
[HKEY_CLASSES_ROOT\TypeLib\{7471CDC9-D492-4BDC-8B57-3799F3912A9F}]
[HKEY_CLASSES_ROOT\qtvglped]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 03:32 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
"WhenUSave"="C:\Program Files\Save\Save.exe" [2006-08-25 17:45 803184]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [2007-03-16 10:51 715888]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 10:59 224248]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 16:32 8699904]
"hltuopjf"="C:\WINDOWS\system32\snmrmpqt.exe" [2008-04-15 11:22 102400]
"trvcvzva"="C:\WINDOWS\system32\zmtwpyfo.exe" [2008-04-30 23:03 106496]
"spinsnee"="C:\WINDOWS\system32\xsvixcfw.exe" [2008-04-30 23:24 106496]
"nrimazgr"="C:\WINDOWS\system32\hatwvefo.exe" [2008-05-01 22:00 98304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-04-05 19:25 73728]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2005-08-10 14:23 356352]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-07 23:02 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-07 22:59 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-07 23:03 114688]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 19:17 88358 C:\WINDOWS\agrsmmsg.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 18:28 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 18:26 688218]
"TFncKy"="TFncKy.exe" []
"TPSMain"="TPSMain.exe" [2005-06-01 00:00 282624 C:\WINDOWS\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" []
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 17:03 1077301]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 19:13 122880]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 20:37 151552]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 08:33 122941]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 14:27 385024]
"2131743181"="D:\UReg\Pentax_Win_GM_10042005.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 22:58 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 13:36 256576]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" [ ]
"CFSServ.exe"="CFSServ.exe" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 10:59 224248]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 16:32 8699904]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Belkin F5D8053 N Wireless USB Adapter Utility.lnk - C:\Program Files\Belkin\F5D8053\Belkinwcui.exe [2007-07-02 20:45:04 1728512]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-07-28 16:56:17 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"ucgkg4wm1U"= C:\Documents and Settings\All Users\Application Data\ghgvizif\adwxkjwd.exe
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pmsoarbf"= {931400CA-0D4C-4A52-B22D-6C412ADDB8A6} - C:\WINDOWS\pmsoarbf.dll [2008-04-15 05:34 188416]
"omlbpkaw"= {554354C3-7D4E-4572-B080-48694CD09D71} - C:\WINDOWS\omlbpkaw.dll [2008-04-15 05:34 221184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 14:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= C:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\TOSHIBA\\ConfigFree\\CFXFER.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys [2005-01-11 13:05]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;C:\WINDOWS\system32\DRIVERS\rt2870.sys [2007-05-09 02:03]
S3 iscFlash;iscFlash;C:\DOCUME~1\Owner\LOCALS~1\Temp\isc16tmp\iscflash.sys []
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-05-30 21:28]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-03 01:58:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-11 20:08:58 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2008-04-27 02:16:27 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.ex
- C:\Program Files\SpywareBot
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-01 22:13:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-01 22:14:32
ComboFix-quarantined-files.txt 2008-05-02 02:14:17
ComboFix2.txt 2008-05-01 05:21:22
ComboFix3.txt 2008-05-01 03:05:26
Pre-Run: 84,761,923,584 bytes free
Post-Run: 84,755,275,776 bytes free
228 --- E O F --- 2008-04-09 04:19:37
________________________________________________________________________________
______________________________________________
Krystal
Selma - Email-adress removed, please do not post your email-adress here because you will receive a lot of spam.
Attached Files
Edited by Thunderbird1988, 02 May 2008 - 01:47 AM.