Hello AS,
Performed all steps. Logs follow. Things are running much better.
ComboFix 09-09-01.04 - 09/01/2009 22:20.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.543 [GMT -4:00]
Running from: c:\documents and settings\ios\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ios\Desktop\CFscript.txt
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
FILE ::
"c:\windows\system32\huzitala.dll"
"c:\windows\system32\logabopo.dll"
"c:\windows\system32\tovumevo.dll"
"c:\windows\system32\wesabipe.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\bepesata.dll
c:\windows\system32\huzitala.dll
c:\windows\system32\wesabipe.dll
----- BITS: Possible infected sites -----
hxxp://fh-dc1:8530
.
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.
2009-09-02 02:25 . 2009-09-02 02:25 53248 ----a-w- c:\temp\catchme.dll
2009-09-02 02:20 . 2009-09-02 02:20 -------- d-----w- c:\temp\WPDNSE
2009-09-02 01:11 . 2009-09-02 01:11 -------- d-----w- c:\program files\Trend Micro
2009-09-02 00:34 . 2009-09-02 01:00 -------- d-s---w- C:\Combo-Fix
2009-08-31 16:06 . 2008-04-14 00:12 169984 ----a-w- C:\msconfig.exe
2009-08-31 14:51 . 2009-09-02 00:52 440320 ----a-w- c:\windows\system32\desote.exe
2009-08-31 14:51 . 2009-08-31 14:51 163840 ----a-w- c:\windows\svchasts.exe
2009-08-31 14:50 . 2009-09-02 00:49 -------- d-----w- c:\program files\Windows Police Pro
2009-08-30 20:58 . 2009-02-03 14:32 3550592 ----a-w- C:\procexp.exe
2009-08-30 20:42 . 2009-09-02 00:50 -------- d-sh--w- c:\temp\Cookies
2009-08-30 20:42 . 2009-08-30 20:42 -------- d-sh--w- c:\temp\History
2009-08-30 20:42 . 2009-08-30 20:42 -------- d-sh--w- c:\temp\Temporary Internet Files
2009-08-30 16:14 . 2009-08-30 16:14 135680 ----a-w- C:\taskmgr.exe
2009-08-28 17:15 . 2009-08-28 17:53 -------- d--h--w- c:\windows\PIF
2009-08-28 16:28 . 2009-08-28 16:28 -------- d-----w- c:\program files\Spybot 1.6.2
2009-08-28 14:30 . 2009-08-28 14:30 111104 ----a-w- c:\documents and settings\ios\Application Data\cb.exe
2009-08-28 14:28 . 2009-08-28 14:28 34 ---ha-w- c:\windows\system32\VideoConverter_sysquict.dat
2009-08-28 14:08 . 2009-08-28 14:08 -------- d-----w- c:\program files\ESET
2009-08-28 03:54 . 2003-01-26 17:41 40960 ----a-w- c:\windows\system32\ssubtmr6.dll
2009-08-28 03:10 . 2009-08-28 03:10 -------- d-----w- c:\program files\Microsoft
2009-08-27 12:29 . 2009-08-27 12:29 -------- d-----w- c:\program files\Photo Story 3 for Windows
2009-08-25 20:49 . 2008-11-20 19:19 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-08-25 20:49 . 2008-11-20 19:19 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-08-25 20:49 . 2009-08-25 20:49 -------- d-----w- c:\documents and settings\ios\Local Settings\Application Data\Google
2009-08-25 20:49 . 2009-08-25 20:49 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-08-25 20:49 . 2009-08-25 20:49 -------- d-----w- c:\program files\Google
2009-08-06 20:46 . 2009-08-06 20:46 86287 ----a-w- c:\windows\system32\WinUpdateMan.exe
2009-08-06 17:48 . 2009-08-06 17:48 16384 ----a-w- c:\windows\system32\Msdirectx.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 01:13 . 2009-06-02 01:13 118272 --sha-w- c:\windows\system32\kovabova.dll
2009-09-02 00:39 . 2004-08-04 12:00 56320 ------w- c:\windows\system32\eventlog.dll
2009-08-31 15:28 . 2009-05-16 15:21 -------- d-----w- c:\program files\Autoruns
2009-08-31 14:35 . 2009-05-31 14:35 71680 --sha-w- c:\windows\system32\bihorugi.dll
2009-08-28 18:00 . 2007-02-26 14:13 188995 ----a-w- c:\windows\system32\nvModes.dat
2009-08-28 16:27 . 2008-10-25 19:31 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-28 16:25 . 2008-10-25 19:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-28 15:36 . 2009-05-28 15:36 82944 --sha-w- c:\windows\system32\bohumoye.dll
2009-08-28 15:36 . 2009-05-28 15:36 84992 --sha-w- c:\windows\system32\jarugimo.dll
2009-08-28 14:30 . 2009-08-28 14:30 0 ----a-w- c:\windows\system32\5C3.tmp
2009-08-28 03:55 . 2008-01-13 15:43 -------- d-----w- c:\documents and settings\ios\Application Data\DVD Flick
2009-08-28 03:54 . 2008-01-13 15:43 -------- d-----w- c:\program files\DVD Flick
2009-08-24 14:29 . 2008-08-03 12:55 -------- d-----w- c:\documents and settings\ios\Application Data\GrabIt
2009-08-14 21:47 . 2009-07-26 18:55 -------- d-----w- c:\documents and settings\ios\Application Data\gtk-2.0
2009-07-26 20:49 . 2009-07-26 20:49 -------- d-----w- c:\program files\MediaMonkey
2009-07-26 18:53 . 2009-07-26 18:47 -------- d-----w- c:\documents and settings\ios\Application Data\.easytag
2009-07-26 18:48 . 2009-07-26 17:46 -------- d-----w- c:\program files\EasyTAG
2009-07-26 18:46 . 2009-07-26 18:46 -------- d-----w- c:\program files\GTK2-Runtime
2009-07-26 17:52 . 2009-07-26 17:52 -------- d-----w- c:\program files\wingtk
2009-07-26 00:38 . 2009-07-25 23:41 -------- d-----w- c:\documents and settings\ios\Application Data\Mp3tag
2009-07-25 23:41 . 2009-07-25 23:41 -------- d-----w- c:\program files\Mp3tag
2009-07-25 02:01 . 2007-02-23 13:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-25 02:00 . 2009-07-25 02:00 -------- d-----w- c:\documents and settings\ios\Application Data\Apple Computer
2009-07-25 02:00 . 2009-07-25 01:59 -------- d-----w- c:\program files\QuickTime
2009-07-25 01:59 . 2009-07-25 01:59 -------- d-----w- c:\program files\iTunes
2009-07-25 01:59 . 2009-07-25 01:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-25 01:55 . 2009-07-25 01:55 -------- d-----w- c:\program files\iPod
2009-07-20 23:01 . 2009-07-20 23:01 -------- d-----w- c:\program files\Wisdom-soft ScreenHunter 5 Free
2009-07-16 01:07 . 2009-07-16 00:56 -------- d-----w- c:\program files\mp3DirectCut
2009-06-16 14:36 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-05-28 15:36 . 2009-05-28 15:36 82944 --sha-w- c:\windows\system32\lubiniyo.dll
2009-05-28 15:36 . 2009-05-28 15:36 82944 --sha-w- c:\windows\system32\wipekoka.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-02_00.56.35 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 12:00 . 2009-09-02 00:49 72882 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-09-02 00:58 72882 c:\windows\system32\perfc009.dat
+ 2009-09-02 01:13 . 2009-09-02 00:53 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-02-16 14:13 . 2009-09-02 00:53 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-02-16 14:13 . 2009-09-02 00:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-02-16 14:13 . 2009-09-02 00:53 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-02-16 14:13 . 2009-09-02 00:12 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2004-08-04 12:00 . 2009-09-02 00:58 446318 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2009-09-02 00:49 446318 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2e774fa8-46af-44d0-ab34-781296ef1b28}]
2009-05-28 15:36 82944 --sha-w- c:\windows\system32\lubiniyo.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-01 7561216]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-07-25 155648]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-02 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-02 696320]
"Client Access Service"="c:\program files\IBM\Client Access\cwbsvstr.exe" [2005-10-19 20531]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"Biomenu"="c:\program files\Protector Suite QL\menusw.exe" [2006-02-01 1632256]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"zunilovur"="c:\windows\system32\kovabova.dll" [2009-09-02 118272]
"NVHotkey"="nvHotkey.dll" - c:\windows\system32\nvhotkey.dll [2006-05-01 73728]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-01 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2005-05-12 4167376]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\ios\Start Menu\Programs\Startup\
PureText.lnk - c:\program files\PureText\PureText.exe [2008-11-11 28672]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2008-9-13 1459392]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{fa9bba13-339b-4972-ba03-bb12553c8a2b}"= "c:\windows\system32\kovabova.dll" [2009-09-02 118272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"susalezal"= {fa9bba13-339b-4972-ba03-bb12553c8a2b} - c:\windows\system32\kovabova.dll [2009-09-02 118272]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-02-01 17:56 39936 ----a-w- c:\windows\system32\fusstub.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\windows\system32\wipekoka.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office Communicator\\communicator.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\IBM\\Client Access\\cwbunnav.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\WinUpdateMan.exe"=
"c:\\WINDOWS\\system32\\BCMWLTRY.EXE"=
"c:\\WINDOWS\\system32\\lsass.exe"=
R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [2/1/2006 1:58 PM 13440]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [2/1/2006 1:58 PM 33024]
S2 C4ULoad2515;www.zanthic.com's CAN-4-USB/MCP2515 before Renumeration;c:\windows\system32\drivers\C4ULoad2.sys [4/27/2004 4:09 PM 19112]
S2 CAN4USB_MCP2515;www.zanthic.com's CAN-4-USB/MCP2510;c:\windows\system32\drivers\ezusb.sys [7/26/2000 2:22 PM 12307]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-lonilutive - c:\windows\system32\wesabipe.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://www.iilelearning.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://cnn-5.vo.llnwd.net/c1/static/cab_headless/GameTapWebUpdater.cab
FF - ProfilePath - c:\documents and settings\ios\Application Data\Mozilla\Firefox\Profiles\mpf69uud.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source=iglk
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-01 22:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\AutorunsDisabled]
"Appinit_Dlls"="c:\\WINDOWS\\system32\\tovumevo c:\\windows\\system32\\logabopo.dll,c:\\WINDOWS\\system32\\tovumevo.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1316)
c:\windows\system32\IWPDGINA.DLL
c:\program files\Intel\Wireless\Bin\SsoGnENU.dll
c:\windows\system32\PSLogon.dll
c:\program files\Protector Suite QL\vrlogon.dll
c:\program files\Protector Suite QL\ExtVapi.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus.dll
c:\windows\system32\fusstub.dll
c:\windows\system32\biologon.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\passport.dll
c:\program files\Protector Suite QL\config.dll
c:\program files\Protector Suite QL\BhTcAll.dll
c:\program files\Protector Suite QL\BhDevTfm.dll
c:\program files\Protector Suite QL\remote.dll
c:\program files\Protector Suite QL\crypto.dll
c:\program files\Protector Suite QL\mysafe.dll
- - - - - - - > 'lsass.exe'(1376)
c:\windows\system32\wipekoka.dll
c:\windows\system32\wininet.dll
- - - - - - - > 'Explorer.exe'(1024)
c:\windows\system32\WININET.dll
c:\windows\system32\kovabova.dll
c:\windows\system32\wipekoka.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Protector Suite QL\mysafe.dll
c:\program files\Protector Suite QL\infra.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\scardsvr.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\system32\CCM\clicomp\RemCtrl\Wuser32.exe
c:\windows\system32\CCM\CcmExec.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\rundll32.exe
c:\program files\McAfee\Common Framework\Mctray.exe
c:\windows\system32\rundll32.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Apoint\ApntEx.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-09-02 22:29 - machine was rebooted [ios]
ComboFix-quarantined-files.txt 2009-09-02 02:29
Pre-Run: 26,469,888,000 bytes free
Post-Run: 26,403,938,304 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
267
---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:56:05 AM, on 9/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Protector Suite QL\menusw.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\PureText\PureText.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Biomenu] "C:\Program Files\Protector Suite QL\menusw.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - S-1-5-18 Startup: PureText.lnk = C:\Program Files\PureText\PureText.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: PureText.lnk = C:\Program Files\PureText\PureText.exe (User 'Default user')
O4 - Startup: PureText.lnk = C:\Program Files\PureText\PureText.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell....iler/SysPro.CAB
O16 - DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} (CentraUpdaterAxCtl Class) -
http://www.iilelearning.com/SiteRoots/main...raUpdaterAx.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1243657873062
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} (GameTap Web Updater) -
http://cnn-5.vo.llnwd.net/c1/static/cab_he...pWebUpdater.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = NA.TakataCorp.com
O17 - HKLM\Software\..\Telephony: DomainName = NA.TakataCorp.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = NA.TakataCorp.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = NA.TakataCorp.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = NA.TakataCorp.com
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = NA.TakataCorp.com
O20 - AppInit_DLLs:
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Windows Defender (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 8538 bytes
---
Malwarebytes' Anti-Malware 1.40
Database version: 2729
Windows 5.1.2600 Service Pack 3
9/2/2009 5:38:50 AM
mbam-log-2009-09-02 (05-38-50).txt
Scan type: Quick Scan
Objects scanned: 130816
Time elapsed: 4 minute(s), 25 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 4
Registry Values Infected: 4
Registry Data Items Infected: 6
Folders Infected: 3
Files Infected: 40
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\wipekoka.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\lubiniyo.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\kovabova.dll (Trojan.Vundo.H) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2e774fa8-46af-44d0-ab34-781296ef1b28} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2e774fa8-46af-44d0-ab34-781296ef1b28} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2e774fa8-46af-44d0-ab34-781296ef1b28} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fa9bba13-339b-4972-ba03-bb12553c8a2b} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zunilovur (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lonilutive (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{fa9bba13-339b-4972-ba03-bb12553c8a2b} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\susalezal (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\wipekoka.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\wipekoka.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\wipekoka.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\kovabova.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\kovabova.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\Program Files\Windows Police Pro (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
Files Infected:
c:\WINDOWS\system32\kovabova.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\lubiniyo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\wipekoka.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\ios\Application Data\cb.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\desote.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bohumoye.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\ANTI_files.exe (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\msvcm80.dll (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\msvcp80.dll (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\msvcr80.dll (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\windows Police Pro.exe (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\dbsinit.exe (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\wispex.html (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\i1.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\i2.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\i3.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\j1.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\j2.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\j3.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\jj1.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\jj2.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\jj3.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\l1.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\l2.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\l3.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\pix.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\t1.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\t2.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\up1.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\up2.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\w1.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\w11.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\w2.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\w3.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\w3.jpg (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\wt1.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\wt2.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\Program Files\Windows Police Pro\tmp\images\wt3.gif (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully.
C:\msconfig.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wsaupdater.exe (Trojan.Agent) -> Quarantined and deleted successfully.
---
DDS (Ver_09-07-30.01) - NTFSx86
Run by ios at 5:48:52.96 on Wed 09/02/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.587 [GMT -4:00]
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Protector Suite QL\menusw.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\PureText\PureText.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ios\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [nwiz] nwiz.exe /installquiet
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [Client Access Service] "c:\program files\ibm\client access\cwbsvstr.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Biomenu] "c:\program files\protector suite ql\menusw.exe"
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
dRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\ios\startm~1\programs\startup\puretext.lnk - c:\program files\puretext\PureText.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ciscos~1.lnk - c:\program files\cisco systems\vpn client\vpngui.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://www.iilelearning.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243657873062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://cnn-5.vo.llnwd.net/c1/static/cab_headless/GameTapWebUpdater.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: psfus - fusstub.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\ios\applic~1\mozilla\firefox\profiles\mpf69uud.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source=iglk
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2006-11-30 31944]
R2 FdRedir;FdRedir;c:\program files\common files\protector suite ql\drivers\FdRedir.sys [2006-2-1 13440]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\common files\protector suite ql\drivers\filedisk.sys [2006-2-1 33024]
S2 C4ULoad2515;www.zanthic.com's CAN-4-USB/MCP2515 before Renumeration;c:\windows\system32\drivers\C4ULoad2.sys [2004-4-27 19112]
S2 CAN4USB_MCP2515;www.zanthic.com's CAN-4-USB/MCP2510;c:\windows\system32\drivers\ezusb.sys [2000-7-26 12307]
S2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2007-2-22 104000]
S2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2006-11-30 54872]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2006-11-30 144960]
S3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2007-2-22 72264]
S3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2007-2-22 34152]
S3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2007-2-22 168776]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
=============== Created Last 30 ================
2009-09-02 05:48 <DIR> --d----- c:\temp\RarSFX0
2009-09-02 05:42 <DIR> --d----- c:\temp\WPDNSE
2009-09-02 05:31 <DIR> --d----- c:\docume~1\ios\applic~1\Malwarebytes
2009-09-02 05:31 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-02 05:31 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-09-02 05:31 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-02 05:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-01 21:11 <DIR> --d----- c:\program files\Trend Micro
2009-09-01 20:58 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-09-01 20:37 <DIR> a-dshr-- C:\cmdcons
2009-09-01 20:34 229,376 a------- c:\windows\PEV.exe
2009-09-01 20:34 161,792 a------- c:\windows\SWREG.exe
2009-09-01 20:34 98,816 a------- c:\windows\sed.exe
2009-09-01 20:34 <DIR> --ds---- C:\Combo-Fix
2009-08-31 10:51 163,840 a------- c:\windows\svchasts.exe
2009-08-30 16:58 3,550,592 a------- C:\procexp.exe
2009-08-30 16:42 <DIR> --dsh--- c:\temp\History
2009-08-30 16:42 <DIR> --dsh--- c:\temp\Cookies
2009-08-30 16:42 <DIR> --dsh--- c:\temp\Temporary Internet Files
2009-08-30 12:14 135,680 a------- C:\taskmgr.exe
2009-08-28 13:15 <DIR> --d-h--- c:\windows\PIF
2009-08-28 12:28 <DIR> --d----- c:\program files\Spybot 1.6.2
2009-08-28 10:30 0 a------- c:\windows\system32\5C3.tmp
2009-08-28 10:28 34 a---h--- c:\windows\system32\VideoConverter_sysquict.dat
2009-08-28 10:08 <DIR> --d----- c:\program files\ESET
2009-08-27 23:54 40,960 a------- c:\windows\system32\ssubtmr6.dll
2009-08-27 23:54 609,824 a------- c:\windows\system32\comctl32.ocx
2009-08-27 23:54 164,144 a------- c:\windows\system32\comct232.ocx
2009-08-27 23:54 36,864 a------- c:\windows\system32\trayicon_handler.ocx
2009-08-27 23:54 28,672 a------- c:\windows\system32\mousewheel.ocx
2009-08-27 23:10 <DIR> --d----- c:\program files\Microsoft
2009-08-27 08:29 <DIR> --d----- c:\program files\Photo Story 3 for Windows
2009-08-25 16:49 9,200 -------- c:\windows\system32\drivers\cdralw2k.sys
2009-08-25 16:49 9,072 -------- c:\windows\system32\drivers\cdr4_xp.sys
2009-08-25 16:49 <DIR> --d----- c:\windows\system32\IOSUBSYS
2009-08-06 16:46 86,287 a------- c:\windows\system32\WinUpdateMan.exe
2009-08-06 13:48 16,384 a------- c:\windows\system32\Msdirectx.exe
==================== Find3M ====================
2009-09-01 20:39 56,320 -------- c:\windows\system32\eventlog.dll
2009-08-31 10:35 71,680 a--sh--- c:\windows\system32\bihorugi.dll
2009-08-28 14:00 188,995 a------- c:\windows\system32\nvModes.dat
2009-08-28 11:36 84,992 a--sh--- c:\windows\system32\jarugimo.dll
2009-06-16 10:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a------- c:\windows\system32\fontsub.dll
============= FINISH: 5:49:11.56 ===============