Hi.
So I ran combofix.exe and it needed to reboot so i figured i'd let it reboot into Normal Mode. Once entering Normal Mode, there were 4-5 red/white circle X's in my lower right tray along with yellow exclamation points telling me of impending attacks and detections and yadda yadda. about 15-20 minutes later, the combofix log popped out. Also, SDFix.exe was finishing up it's reboot-log so i decided to not mess with it and let that finish. So i have that log for you too. And HiJackThis i also ran in Normal Mode.
I can still recognize some uglies but i'll let you be the judge of that.
COMBOFIX
ComboFix 08-09-25.06 - NICHOLAS MENDILLO 2008-09-26 11:05:42.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.300 [GMT -4:00]
Running from: C:\Documents and Settings\NICHOLAS MENDILLO\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\WINDOWS\eqxk.exe
C:\WINDOWS\rwlfsdmk.dll
C:\WINDOWS\system32\fugudipi.dll
C:\WINDOWS\system32\hbysokrf.ini
C:\WINDOWS\system32\nnnNhGAq.dll
C:\WINDOWS\system32\QYxHPXyb.ini
C:\WINDOWS\system32\toxwvjxo.ini
C:\WINDOWS\Tasks\moyhxksx.job
C:\x
.
((((((((((((((((((((((((( Files Created from 2008-08-26 to 2008-09-26 )))))))))))))))))))))))))))))))
.
2008-09-26 11:21 . 2008-09-24 02:13 25,088 --a--c--- C:\x
2008-09-26 11:21 . 2008-09-24 02:13 25,088 --a------ C:\WINDOWS\system32\YURD.exe
2008-09-26 01:07 . 2008-09-26 01:07 <DIR> d----c--- C:\_OTMoveIt
2008-09-26 00:28 . 2008-09-24 02:13 25,088 --a------ C:\WINDOWS\system32\YUR11.exe
2008-09-25 21:16 . 2008-09-08 23:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-09-25 21:16 . 2008-09-19 12:26 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-09-25 21:16 . 2008-09-19 12:26 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-09-25 21:16 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-09-25 16:32 . 2008-09-26 01:22 <DIR> d----c--- C:\rsit
2008-09-25 13:33 . 2008-09-25 13:33 136,320 --a------ C:\WINDOWS\system32\xgyinccj.dll
2008-09-24 19:38 . 2008-09-24 19:38 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-24 19:23 . 2008-09-25 02:35 <DIR> d----c--- C:\SDFix
2008-09-24 17:42 . 2008-09-24 02:13 24,064 --a------ C:\WINDOWS\system32\YUR13.exe
2008-09-24 17:41 . 2008-09-24 02:13 25,088 --a------ C:\WINDOWS\system32\YUR12.exe
2008-09-24 15:52 . 2008-09-24 15:52 <DIR> d-------- C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Lexmark Productivity Studio
2008-09-24 13:28 . 2008-09-24 13:28 137,344 --a------ C:\WINDOWS\system32\lwughfvg.dll
2008-09-24 13:28 . 2008-09-24 13:28 137,344 --a------ C:\WINDOWS\system32\leyxxn.dll
2008-09-24 13:28 . 2008-09-24 13:28 103,552 --a------ C:\WINDOWS\system32\frkosybh.dll
2008-09-24 13:24 . 2008-09-26 11:06 840,182 --ahs---- C:\WINDOWS\system32\QYxHPXyb.ini2
2008-09-24 13:24 . 2008-09-24 13:24 326,656 --a------ C:\WINDOWS\system32\byXPHxYQ.dll
2008-09-24 13:18 . 2008-09-24 13:18 53,248 --ahs---- C:\WINDOWS\system32\nnnmlMeE.dll
2008-09-24 13:14 . 2008-09-24 02:13 25,088 --a------ C:\WINDOWS\system32\YUR77.exe
2008-09-24 13:14 . 2008-09-24 02:13 25,088 --a------ C:\WINDOWS\system32\YUR76.exe
2008-09-24 13:14 . 2008-09-24 02:13 24,064 --a------ C:\WINDOWS\system32\YUR7A.exe
2008-09-24 13:14 . 2008-09-24 02:13 24,064 --a------ C:\WINDOWS\system32\YUR78.exe
2008-09-24 13:11 . 2008-09-24 13:11 <DIR> dr-hsc--- C:\resycled
2008-09-23 23:59 . 2008-09-23 23:59 <DIR> d-------- C:\Program Files\Lexmark Toolbar
2008-09-23 23:57 . 2008-09-24 15:56 <DIR> d-------- C:\Documents and Settings\All Users\Lx_cats
2008-09-23 23:48 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-09-23 23:48 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\dllcache\usbprint.sys
2008-09-23 23:46 . 2008-09-23 23:46 <DIR> d----c--- C:\logs
2008-09-23 23:45 . 2006-08-01 01:53 40,960 --a------ C:\WINDOWS\system32\lxdivs.dll
2008-09-23 23:44 . 2007-03-30 10:13 344,064 --a------ C:\WINDOWS\system32\lxdicoin.dll
2008-09-23 23:43 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-23 23:43 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-23 23:42 . 2001-08-17 22:36 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll
2008-09-23 23:42 . 2001-08-17 22:36 87,040 --a------ C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2008-09-23 23:41 . 2007-03-23 15:44 692,224 --a------ C:\WINDOWS\system32\lxdidrs.dll
2008-09-23 23:41 . 2007-02-09 14:07 69,632 --a------ C:\WINDOWS\system32\lxdicnv4.dll
2008-09-23 23:41 . 2007-01-23 19:40 65,536 --a------ C:\WINDOWS\system32\lxdicaps.dll
2008-09-23 23:20 . 2008-09-23 23:42 <DIR> d-------- C:\Program Files\Lexmark 3500-4500 Series
2008-09-22 23:13 . 2008-09-23 01:34 <DIR> d-------- C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\ImgBurn
2008-09-22 02:35 . 2008-09-22 02:35 <DIR> d-------- C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\dvdcss
2008-09-17 00:46 . 2008-09-24 12:50 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-15 13:59 . 2008-09-24 16:13 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-15 13:59 . 2008-09-15 13:59 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-06 15:54 . 2008-09-06 15:55 117,527 --a--c--- C:\Route 2 on Independence Day.mp3
2008-09-06 15:52 . 2008-09-06 15:52 894,504 --a------ C:\Program Files\WGAPluginInstall.exe
2008-08-30 00:15 . 2008-08-30 00:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-08-30 00:13 . 2008-08-30 00:14 <DIR> d-------- C:\Program Files\Dell Support Center
2008-08-30 00:13 . 2008-08-30 00:13 <DIR> d-------- C:\Program Files\Common Files\supportsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-26 15:20 --------- d-----w C:\Program Files\Logs
2008-09-26 15:20 --------- d-----w C:\Program Files\Config
2008-09-26 01:38 4,150 ----a-w C:\WINDOWS\system32\tmp.reg
2008-09-24 05:11 --------- d-----w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\uTorrent
2008-09-24 03:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-23 02:41 --------- d-----w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Vso
2008-09-10 03:21 267,056 ----a-w C:\Program Files\uTorrent.exe
2008-09-03 17:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-09-01 06:24 --------- d-----w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Registry Booster
2008-08-31 20:07 --------- d-----w C:\Program Files\TabIt
2008-08-30 04:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-08-25 04:31 --------- d-----w C:\Program Files\Reports
2008-08-25 04:26 --------- d-----w C:\Program Files\wxp
2008-08-25 04:26 --------- d-----w C:\Program Files\w2k
2008-08-25 04:26 --------- d-----w C:\Program Files\Trans
2008-08-25 04:26 --------- d-----w C:\Program Files\License
2008-08-25 04:26 --------- d-----w C:\Program Files\DbgHelp
2008-08-25 04:24 5,991,904 ----a-w C:\Program Files\Sunbelt-Personal-Firewall.exe
2008-08-24 22:18 86,733,638 -c--a-w C:\registrybackup.reg
2008-08-24 17:34 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-08-24 17:34 --------- d-----w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Malwarebytes
2008-08-24 17:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-24 17:33 2,085,280 ----a-w C:\Program Files\mbam-setup.exe
2008-08-22 16:38 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-20 17:31 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-17 19:01 38,472 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-17 19:01 17,144 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-08-07 05:53 --------- d-----w C:\Program Files\Google
2008-07-31 00:59 32,768 ----a-w C:\Program Files\bcd_installed.exe
2008-07-30 14:36 95,528 ----a-w C:\Program Files\SbPFLnch.exe
2008-07-30 14:36 95,528 ----a-w C:\Program Files\SbFw.dll
2008-07-30 14:36 91,432 ----a-w C:\Program Files\SbFwIm.dll
2008-07-30 14:36 79,144 ----a-w C:\Program Files\SbPFWsc.dll
2008-07-30 14:36 62,760 ----a-w C:\Program Files\SDK_Inst.exe
2008-07-30 14:36 275,752 ----a-w C:\Program Files\SbFwe.dll
2008-07-30 14:36 111,912 ----a-w C:\Program Files\SbErrRpt.exe
2008-07-30 14:36 1,705,256 ----a-w C:\Program Files\SbPFCl.exe
2008-07-30 14:36 1,361,192 ----a-w C:\Program Files\SbPFSvc.exe
2008-07-30 13:58 3,293 ----a-w C:\Program Files\Readme.txt
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll
2008-06-12 23:24 1,495,112 ----a-w C:\Program Files\install_flash_player.exe
2008-03-21 15:40 122,879 -c--a-w C:\Program Files\4482-utorrent.8020.dmp
2008-03-19 08:37 144,665 -c--a-w C:\Program Files\4482-utorrent.d009.dmp
2008-03-14 21:38 1,454,656 ----a-w C:\Program Files\Silverlight.exe
2008-02-17 03:12 132,608 ----a-w C:\Program Files\VundoFix.exe
2008-02-15 22:29 50,688 ----a-w C:\Program Files\ATF-Cleaner.exe
2008-02-04 19:04 555,572 ----a-w C:\Program Files\spf4-en.chm
2008-01-29 21:47 125,164 -c--a-w C:\Program Files\4482-utorrent.5094.dmp
2008-01-26 18:36 158,275 -c--a-w C:\Program Files\4482-utorrent.b16a.dmp
2007-12-09 08:36 2,400,784 ----a-w C:\Program Files\WLinstaller.exe
2007-10-02 12:34 148,511 -c--a-w C:\Program Files\4482-utorrent.54f2.dmp
2007-08-10 03:11 1,436,096 ----a-w C:\Program Files\Silverlight.1.0.RC.exe
2007-08-09 11:32 270,336 ----a-w C:\Program Files\cfgconv.exe
2007-06-28 15:41 47,360 -c--a-w C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\pcouffin.sys
2007-05-18 00:40 1,066 -c--a-w C:\Program Files\SuperDAT.log
2007-05-18 00:36 736,180 ----a-w C:\Program Files\CSA.exe
2007-04-09 21:47 5,632 -csha-w C:\Program Files\Thumbs.db
2007-01-22 15:22 859,648 ----a-w C:\Program Files\PocoFoundation.dll
2007-01-22 15:22 470,016 ----a-w C:\Program Files\PocoXML.dll
2007-01-22 15:22 467,456 ----a-w C:\Program Files\PocoNet.dll
2007-01-22 15:22 211,456 ----a-w C:\Program Files\PocoUtil.dll
2007-01-22 15:22 18,432 ----a-w C:\Program Files\PocoExt.dll
2007-01-08 18:15 29,424 ----a-w C:\Program Files\1942.zip
2006-12-24 01:40 680,575 ----a-w C:\Program Files\TabIt-2.03-full.exe
2006-09-25 16:11 263,680 ----a-w C:\Program Files\FairUse4WM.exe
2006-07-19 20:52 466,944 ----a-w C:\Program Files\boost_regex-vc71-mt-1_33_1.dll
2006-03-09 15:59 36,465,208 ----a-w C:\Program Files\iTunesSetup.exe
2006-02-28 19:46 290,816 ----a-w C:\Program Files\curllib.dll
2006-02-14 19:36 97,280 ----a-w C:\Program Files\zlibwapi.dll
2006-02-14 19:36 155,648 ----a-w C:\Program Files\ssleay32.dll
2006-02-14 19:35 888,832 ----a-w C:\Program Files\kticonv.dll
2006-02-14 19:35 827,392 ----a-w C:\Program Files\libeay32.dll
2006-01-21 21:10 11,817,800 ----a-w C:\Program Files\GoogleEarth.exe
2006-01-17 23:28 8,715,352 ----a-w C:\Program Files\Install_AIM.exe
2005-12-05 23:00 74,448 -c----w C:\Program Files\DSETUP.dll
2005-12-05 23:00 484,560 ------w C:\Program Files\DXSETUP.exe
2005-12-05 23:00 2,247,888 -c----w C:\Program Files\dsetup32.dll
2004-11-09 14:21 29,619,712 ----a-w C:\Program Files\finaldraft7.exe
2003-08-20 11:05 41 -c--a-w C:\Program Files\Setup.Ini
2003-03-19 01:20 1,060,864 ----a-w C:\Program Files\mfc71.dll
2003-03-19 01:12 1,047,552 ----a-w C:\Program Files\mfc71u.dll
2003-03-19 00:14 499,712 ----a-w C:\Program Files\msvcp71.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{887F904C-85C2-4A71-9872-5D4B5C175CF1}]
2008-09-24 13:24 326656 --a------ C:\WINDOWS\system32\byXPHxYQ.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2005-06-02 67160]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"\YUR11.exe"="C:\Windows\system32\YUR11.exe" [2008-09-24 25088]
"\YURD.exe"="C:\Windows\system32\YURD.exe" [2008-09-24 25088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]
"vptray"="C:\Program Files\NavNT\vptray.exe" [2001-09-24 73728]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-24 729178]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 114688]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 77824]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" [2008-01-24 136512]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"lxdimon.exe"="C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 434864]
"lxdiamon"="C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 25264]
"\YUR11.exe"="C:\Windows\system32\YUR11.exe" [2008-09-24 25088]
"\YURD.exe"="C:\Windows\system32\YURD.exe" [2008-09-24 25088]
"SigmatelSysTrayApp"="stsystra.exe" [2005-09-09 C:\WINDOWS\stsystra.exe]
C:\Documents and Settings\NICHOLAS MENDILLO\Start Menu\Programs\Startup\
MEMonitor.lnk - E:\Programs\V CAST Music Manager\MEMonitor.exe [2008-05-23 951640]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-10-06 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
SafeConnect.lnk - C:\Program Files\SafeConnect\scClient.exe [2007-04-09 206368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\telelepu.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll schannel.dll digest.dll msnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2007-10-19 21:16 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"mW[íµˆÖ¾`=µú¾˜v%S8’ÿÙêé>grl>Ư\†Đ=ŸàÛ±̃"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\uTorrent.exe"=
"E:\\Programs\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"c:\\program files\\bcd_installed.exe"=
"C:\\WINDOWS\\system32\\lxdicoms.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"C:\\WINDOWS\\system32\\lxdicfg.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
"C:\\WINDOWS\\system32\\lxdiih.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 SbFw;SbFw;C:\WINDOWS\system32\drivers\SbFw.sys [2008-07-16 269736]
R1 sbhips;Sunbelt HIPS Driver;C:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 66600]
R2 lxdi_device;lxdi_device;C:\WINDOWS\system32\lxdicoms.exe [2007-06-11 517040]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe [2007-06-11 99248]
R2 SbPF.Launcher;SbPF.Launcher;C:\Program Files\SbPFLnch.exe [2008-07-30 95528]
R2 SCManager;SafeConnect Manager;C:\Program Files\SafeConnect\scManager.sys servicestart [ ]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\SbPFSvc.exe [2008-07-30 1361192]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{3BC2C1BE-7B91-4A8B-AEBE-B02E3DB8AC83} - C:\WINDOWS\dfmlxbpkwxo.dll
BHO-{9f0ad867-b3cb-4a3c-bb16-e7ed43c85b2a} - C:\WINDOWS\system32\mxcyzn.dll
BHO-{c7122979-4d01-47b3-a419-8e823e623d26} - C:\WINDOWS\system32\fugudipi.dll
BHO-{F77BBE3B-9C38-47F6-99D7-B79B453D0F50} - C:\WINDOWS\system32\nnnNhGAq.dll
HKCU-Run-\YUR10.exe - C:\Windows\system32\YUR10.exe
HKLM-Run-\YUR10.exe - C:\Windows\system32\YUR10.exe
HKLM-Run-larepemijo - C:\WINDOWS\system32\petolahu.dll
ShellExecuteHooks-{F77BBE3B-9C38-47F6-99D7-B79B453D0F50} - C:\WINDOWS\system32\nnnNhGAq.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Mozilla\Firefox\Profiles\a0f7pi4s.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1229.1533\npCIDetect11.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npmusicn.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-26 11:21:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Aim\pckfcikf\bartcache\1\CA4AA2292DCC4FD317955E2724514EA5 3262 bytes
C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Aim\pckfcikf\bartcache\1\87E4A9CB07FD8A0F604BC0B6B65270DA 1556 bytes
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
------------------------ Other Running Processes ------------------------
.
SystemRoot\System32\smss.exe [984]
??\C:\WINDOWS\system32\csrss.exe [1124]
??\C:\WINDOWS\system32\winlogon.exe [1148]
C:\WINDOWS\system32\services.exe [1200]
C:\WINDOWS\system32\lsass.exe [1220]
C:\WINDOWS\system32\svchost.exe [1384]
C:\WINDOWS\system32\svchost.exe [1452]
C:\WINDOWS\System32\svchost.exe [1488]
C:\WINDOWS\system32\svchost.exe [1528]
C:\WINDOWS\system32\svchost.exe [1700]
C:\WINDOWS\system32\svchost.exe [1804]
C:\WINDOWS\system32\spoolsv.exe [324]
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [448]
C:\Program Files\Bonjour\mDNSResponder.exe [472]
C:\Program Files\NavNT\defwatch.exe [488]
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [612]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe [872]
C:\WINDOWS\system32\lxdicoms.exe [1008]
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe [1404]
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe [1568]
C:\Program Files\SbPFLnch.exe [1932]
C:\Program Files\SafeConnect\scManager.sys [1960]
C:\Program Files\SbPFSvc.exe [2040]
C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe [600]
C:\Program Files\Dell Support Center\bin\sprtsvc.exe [844]
C:\WINDOWS\system32\svchost.exe [944]
C:\Program Files\SbPFCl.exe [2060]
C:\WINDOWS\system32\CF17519.exe [2708]
C:\WINDOWS\system32\wscntfy.exe [3936]
C:\WINDOWS\system32\wbem\wmiprvse.exe [4052]
C:\WINDOWS\System32\alg.exe [1076]
C:\Program Files\NavNT\vptray.exe [2308]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3200]
C:\WINDOWS\stsystra.exe [3228]
C:\WINDOWS\system32\igfxpers.exe [3464]
C:\WINDOWS\system32\igfxsrvc.exe [3508]
C:\WINDOWS\system32\hkcmd.exe [3592]
C:\WINDOWS\system32\WLTRAY.exe [596]
C:\WINDOWS\system32\dla\tfswctrl.exe [424]
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe [2192]
C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2484]
C:\Program Files\Network Associates\Common Framework\McTray.exe [2536]
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe [2732]
C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe [2928]
C:\WINDOWS\system32\cmd.exe [2808]
C:\Windows\system32\YUR11.exe [2136]
C:\Program Files\Messenger\msmsgs.exe [2344]
C:\Program Files\Digital Line Detect\DLG.exe [2856]
C:\Program Files\SafeConnect\scClient.exe [3248]
E:\Programs\V CAST Music Manager\MEMonitor.exe [3628]
C:\SDFix\apps\Cghtme.exe [3532]
C:\WINDOWS\explorer.exe [2692]
C:\WINDOWS\system32\imapi.exe [3676]
C:\ComboFix\catchme.cfexe [1616]
.
**************************************************************************
.
Completion time: 2008-09-26 11:38:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-26 15:36:55
ComboFix2.txt 2008-08-24 07:43:13
ComboFix3.txt 2008-02-19 00:43:58
Pre-Run: 22,530,408,448 bytes free
Post-Run: 22,512,586,752 bytes free
347 --- E O F --- 2008-09-10 07:06:54
SDFIX
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-26 11:33:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
IPC error: 2 The system cannot find the file specified.
C:\ComboFix\grep.cfexe [2300] 0xFE171710
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="E:\Programs\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:86,04,a9,7d,62,fd,c4,7b,fb,46,08,89,1f,9a,04,b4,36,84,28,35,38,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,39,2d,42,19,57,ef,69,26,11,89,a0,5b,c7,a0,b4,a9,0f,..
"khjeh"=hex:4b,b1,06,bb,c4,8a,5d,0b,0d,a7,73,99,0f,39,d4,ed,b0,91,b5,f9,c9,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:21,a0,84,75,ed,0c,fc,af,26,2b,06,0a,8d,a2,4a,39,c9,70,4a,18,bb,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="E:\Programs\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:86,04,a9,7d,62,fd,c4,7b,fb,46,08,89,1f,9a,04,b4,36,84,28,35,38,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,39,2d,42,19,57,ef,69,26,11,89,a0,5b,c7,a0,b4,a9,0f,..
"khjeh"=hex:4b,b1,06,bb,c4,8a,5d,0b,0d,a7,73,99,0f,39,d4,ed,b0,91,b5,f9,c9,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:21,a0,84,75,ed,0c,fc,af,26,2b,06,0a,8d,a2,4a,39,c9,70,4a,18,bb,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="E:\Programs\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:86,04,a9,7d,62,fd,c4,7b,fb,46,08,89,1f,9a,04,b4,36,84,28,35,38,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,39,2d,42,19,57,ef,69,26,11,89,a0,5b,c7,a0,b4,a9,0f,..
"khjeh"=hex:4b,b1,06,bb,c4,8a,5d,0b,0d,a7,73,99,0f,39,d4,ed,b0,91,b5,f9,c9,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:21,a0,84,75,ed,0c,fc,af,26,2b,06,0a,8d,a2,4a,39,c9,70,4a,18,bb,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000002c0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"AppInit_DLLs"="C:\WINDOWS\system32\telelepu.dll"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6273E193-D029-A27B-0287-31BA1142872B}]
"oafankhlgjgakegdlbjbhfdaiogang"=hex:64,61,6b,67,61,6b,6e,6c,00,e0
"oajfmhnekljkpmojpleijflchoiped"=hex:69,61,6a,67,70,6b,62,6d,6d,70,65,63,6e,70,61,6f,6e,6d,00,00
"nahgoheiookpdlcehndogpibdbdc"=hex:69,61,6a,67,70,6b,62,6d,6d,70,65,63,6e,70,61,6f,6e,6d,00,00
scanning hidden files ...
scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\uTorrent.exe"="C:\\Program Files\\uTorrent.exe:*:Enabled:uTorrent"
"E:\\Programs\\iTunes.exe"="E:\\Programs\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"="C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"c:\\program files\\bcd_installed.exe"="c:\\program files\\bcd_installed.exe:*:Enabled:Windows Application Service"
"C:\\WINDOWS\\system32\\lxdicoms.exe"="C:\\WINDOWS\\system32\\lxdicoms.exe:*:Enabled:Lexmark Communications System"
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"="C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe:*:Enabled:Lexmark Device Monitor"
"C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"="C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe:*:Enabled:Lexmark Imaging Studio"
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"="C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe:*:Enabled:Device Monitor"
"C:\\WINDOWS\\system32\\lxdicfg.exe"="C:\\WINDOWS\\system32\\lxdicfg.exe:*:Enabled:Printer Communication System"
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe:*:Enabled:Printer Status Window Interface"
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe:*:Enabled:Lexmark Connect Time Executable"
"C:\\WINDOWS\\system32\\lxdiih.exe"="C:\\WINDOWS\\system32\\lxdiih.exe:*:Enabled:Printer Communication System"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\\Program Files\\Lexmark 3500-4500 Series\\app4r.exe"="C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe:*:Enabled:Lexmark Imaging Studio"
Remaining Files :
Files with Hidden Attributes :
Fri 19 Sep 2008 19,968 ..SHR --- "C:\resycled\boot.com"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 18 Aug 2008 1,832,272 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 24 Sep 2008 53,248 A.SH. --- "C:\WINDOWS\system32\nnnmlMeE.dll"
Mon 13 Mar 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 10 Mar 2008 76,800 ...H. --- "C:\Documents and Settings\NICHOLAS MENDILLO\My Documents\~WRL0004.tmp"
Mon 10 Mar 2008 64,512 ...H. --- "C:\Documents and Settings\NICHOLAS MENDILLO\My Documents\~WRL1153.tmp"
Fri 23 May 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 24 Jun 2008 64,512 A.SH. --- "C:\_OTMoveIt\MovedFiles\09262008_010750\WINDOWS\system32\petolahu.dll"
Tue 24 Jun 2008 64,512 A.SH. --- "C:\_OTMoveIt\MovedFiles\09262008_010750\WINDOWS\system32\telelepu.dll"
Thu 9 Mar 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 19 Apr 2007 8 A..H. --- "C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Mon 3 Sep 2007 8 A..H. --- "C:\Documents and Settings\NICHOLAS MENDILLO\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u5\lock.tmp"
Finished!HIJACK THIS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:44:18, on 9/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe
C:\WINDOWS\system32\lxdicoms.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\SbPFLnch.exe
C:\Program Files\SafeConnect\scManager.sys
C:\Program Files\SbPFSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SbPFCl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
C:\WINDOWS\system32\cmd.exe
C:\Windows\system32\YUR11.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SafeConnect\scClient.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ntvdm.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
C:\SDFix\dnif.exe
E:\Programs\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.dell4me.com/mywayR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {E80593FD-9D97-4D1F-A1A7-51DFFE42CF1A} - C:\WINDOWS\system32\byXPHxYQ.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
O4 - HKLM\..\Run: [\YUR11.exe] C:\Windows\system32\YUR11.exe
O4 - HKLM\..\Run: [\YURD.exe] C:\Windows\system32\YURD.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [\YUR11.exe] C:\Windows\system32\YUR11.exe
O4 - HKCU\..\Run: [\YURD.exe] C:\Windows\system32\YURD.exe
O4 - HKUS\S-1-5-19\..\Run: [larepemijo] Rundll32.exe "C:\WINDOWS\system32\petolahu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [larepemijo] Rundll32.exe "C:\WINDOWS\system32\petolahu.dll",s (User 'NETWORK SERVICE')
O4 - Startup: MEMonitor.lnk = E:\Programs\V CAST Music Manager\MEMonitor.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SafeConnect.lnk = ?
O8 - Extra context menu item: Save with Download Manager... - file://C:\Program Files\J River\Media Center 11\DMDownload.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) -
https://support.micr...ActiveX/odc.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cabO16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) -
http://pictures05.ai...AIM.9.5.1.8.cabO20 - AppInit_DLLs: C:\WINDOWS\system32\telelepu.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\SbPFLnch.exe
O23 - Service: SafeConnect Manager (SCManager) - Unknown owner - C:\Program Files\SafeConnect\scManager.sys servicestart (file missing)
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\SbPFSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
--
End of file - 9844 bytes
Let's defeat this demon once and for all
-nick