Hey I'm worried too, however, I don't think its anything out of the ordinary that can't be fixed. I think you misunderstood something though. I have been resourceful enough on my own to rid myself of the majority of the previous infections up till this point, which would include me practicing safe surfing as you say. So its not like I've come to this forum asking for help 3 times previously and am still infected.
I do not know how or if this is really why I was initially infected yesterday, but I can only make the connection through this correlation.. The infection probably happened because I had my windows firewall off, my live-scanners off, and my popup blocker off while being idle online. However, doing all of that was necessary for reasons I won't bother you with the details of. The initial infection happened while I was merely afk, with two trusted websites opened on my browser, because when I came back I saw half a dozen new popup windows opened, including a installation window for a rogue antispyware program (which may have finished automatically installing, without my consent or knowledge, unfortunately). And I can't be sure if I ever got it off 100% the previous 3 times even though I followed many self-help steps.
But my point is that I could, if you want, provide even further information about the current and previous infections if it will be helpful in the diagnosis. After all, I would like to be able to do what I can on my own so I can know what to do for future cases and have countermeasures readily available. Before I posted my first message the last thing I did was actually do a combofix scan (I've had it installed for awhile now), and have the log from yesterday, if you want to see it.
However, after I came back this evening from classes, the infection grew worse even though I had all of my protection on, logged off windows, and presumably quarantined most of the problem from last night. As a result, my MBAM log obviously looks quite a bit different now, as well as my HJT and Combofix log.------------------------------------------------------------------------------------------------------------------------------------
Here are the new results of the most recent quick MBAM scan after re-infectionMalwarebytes' Anti-Malware 1.34
Database version: 1778
Windows 5.1.2600 Service Pack 2
2/18/2009 7:13:12 PM
mbam-log-2009-02-18 (19-13-12).txt
Scan type: Quick Scan
Objects scanned: 67554
Time elapsed: 2 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xlmocmxc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vxvwopod.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\Charles\reader_s.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\reader_s.exe (Trojan.FakeAlert.H) -> Delete on reboot.
C:\WINDOWS\xlmocmxc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\vxvwopod.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\jzbrbmbq.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\3.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\5.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\6.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\8.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\9.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
------------------------------------------------------------------------------------------------------------------------------------
New HJTlog after MBAM scanLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:20:51 PM, on 2/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\RocketDock\ObjectDock\Docklets\KkMenu\KkTrayServer.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.4chan.orgR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [mspy2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] "C:\WINDOWS\KHALMNPR.EXE"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [1A:KkTrayServer] "C:\Program Files\RocketDock\ObjectDock\Docklets\KkMenu\KkTrayServer.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Rainlendar2] "C:\Program Files\Rainlendar2\Rainlendar2.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [igndlm.exe] "C:\Program Files\Download Manager\DLM.exe" /windowsstart /startifwork
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Charles\reader_s.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [reader_s] C:\Documents and Settings\Charles\reader_s.exe (User 'Default user')
O4 - S-1-5-18 Startup: DsktpListView.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: UltraMon.exe.lnk = C:\Program Files\UltraMon\UltraMon.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: DsktpListView.exe (User 'Default user')
O4 - .DEFAULT Startup: UltraMon.exe.lnk = C:\Program Files\UltraMon\UltraMon.exe (User 'Default user')
O4 - Startup: DsktpListView.exe
O4 - Startup: UltraMon.exe.lnk = C:\Program Files\UltraMon\UltraMon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cabO16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) -
http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cabO16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) -
http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 7731 bytes
------------------------------------------------------------------------------------------------------------------------------------
New Combofix log after MBAM scanComboFix 09-02-17.02 - Charles 2009-02-18 19:23:53.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2814.2339 [GMT -6:00]
Running from: c:\documents and settings\Charles\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\config\systemprofile\reader_s.exe
c:\windows\system32\d3d8caps.dat
c:\windows\system32\drivers\ntndis.sys
c:\windows\system32\userinit.exe . . . is infected!! c:\windows\system32\spoolsv.exe . . . is infected!! c:\windows\explorer.exe . . . is infected!!.
((((((((((((((((((((((((( Files Created from 2009-01-19 to 2009-02-19 )))))))))))))))))))))))))))))))
.
2009-02-18 19:00 . 2009-02-18 19:00 0 --a------ c:\windows\system32\12.tmp
2009-02-18 19:00 . 2009-02-18 19:00 0 --a------ c:\windows\system32\11.tmp
2009-02-18 18:59 . 2009-02-18 18:59 0 --a------ c:\windows\system32\10.tmp
2009-02-18 16:04 . 2006-02-14 18:22 142,464 --a------ c:\windows\system32\drivers\aec.sys.bak
2009-02-18 12:12 . 2009-02-18 12:14 163,748 --a------ c:\windows\system32\19.tmp
2009-02-18 12:11 . 2009-02-18 12:12 24,577 --a------ c:\windows\system32\17.tmp
2009-02-18 12:11 . 2009-02-18 12:11 128 --a------ c:\windows\system32\16.tmp
2009-02-17 22:21 . 2009-02-17 22:27 <DIR> d-------- c:\program files\Enigma Software Group
2009-02-17 17:58 . 2009-02-17 17:58 <DIR> d-------- C:\VundoFix Backups
2009-02-17 15:59 . 2007-05-02 03:01 49,265 --a------ c:\windows\system32\jpicpl32.cpl
2009-02-17 15:24 . 2009-02-17 15:24 <DIR> d-------- c:\program files\Trend Micro
2009-02-16 18:00 . 2002-02-15 14:02 676,352 --a------ c:\windows\system32\rtl60.bpl
2009-02-16 17:59 . 2009-02-16 18:28 <DIR> d-------- c:\windows\system32\inf
2009-02-14 20:52 . 2009-02-14 20:52 <DIR> d--hs---- C:\found.000
2009-02-10 18:50 . 2009-02-10 18:50 <DIR> d-------- c:\program files\Rainlendar2
2009-02-10 18:50 . 2009-02-18 19:35 <DIR> d-------- c:\documents and settings\Charles\.rainlendar2
2009-02-08 22:11 . 2009-02-08 22:11 <DIR> d-------- c:\program files\Steinberg
2009-02-08 13:56 . 2009-02-08 22:15 <DIR> d-------- c:\program files\VOCALOID2
2009-02-08 13:08 . 2009-02-08 13:08 <DIR> d----c--- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-07 12:04 . 2009-02-13 18:04 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-07 12:04 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-07 12:04 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-05 21:19 . 2008-07-10 18:28 79,896 --a------ c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.0.1600.22.dll
2009-02-05 21:19 . 2008-07-10 18:28 50,200 --a------ c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.0.1600.22.dll
2009-02-05 21:18 . 2009-02-05 21:18 <DIR> d-------- c:\windows\system32\RsFx
2009-02-05 20:06 . 2009-02-05 21:18 <DIR> d-------- c:\program files\Microsoft SQL Server
2009-02-05 20:04 . 2009-02-05 21:17 <DIR> d-------- c:\program files\Microsoft.NET
2009-02-05 20:04 . 2009-02-05 20:05 <DIR> d-------- c:\program files\Microsoft Visual Studio 9.0
2009-02-05 20:04 . 2009-02-05 20:04 <DIR> d-------- c:\program files\Common Files\Merge Modules
2009-02-05 20:04 . 2009-02-05 20:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-05 20:03 . 2009-02-05 20:03 <DIR> d-------- c:\program files\Microsoft SDKs
2009-02-04 19:54 . 2009-02-04 19:54 <DIR> d-------- C:\Dell
2009-02-03 17:23 . 2009-02-06 20:04 <DIR> d-------- c:\documents and settings\Charles\Application Data\foobar2000
2009-02-03 17:22 . 2009-02-03 17:22 <DIR> d-------- c:\program files\foobar2000
2009-02-02 08:50 . 2009-02-02 08:50 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-29 22:47 . 2009-01-29 22:47 <DIR> d-------- c:\program files\Adobe Media Player
2009-01-29 22:43 . 2009-01-29 22:43 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-01-26 08:01 . 2009-01-26 08:07 <DIR> d-------- c:\program files\ComboFix
2009-01-25 20:28 . 2009-01-25 20:28 <DIR> d-------- c:\program files\Alwil Software
2009-01-25 20:27 . 2009-01-25 20:27 <DIR> d-------- c:\program files\Tools
2009-01-25 20:27 . 2009-02-04 19:37 <DIR> d-------- c:\program files\Setup
2009-01-20 21:21 . 2009-01-20 22:36 136 --a------ c:\windows\TrayServerData.ini
2009-01-19 23:33 . 2009-01-19 23:33 <DIR> d-------- c:\documents and settings\Charles\Application Data\DonationCoder
2009-01-19 23:33 . 2009-01-19 23:33 46 --a------ c:\windows\system32\DonationCoder_desktopcoral_InstallInfo.dat
2009-01-19 15:38 . 2009-01-19 15:41 27 --a------ c:\windows\SDAddressBox16827d0561119.ini
2009-01-19 15:37 . 2009-01-19 15:37 7,852 --a------ c:\windows\system32\mcdmsg7.dll
2009-01-19 14:18 . 2009-01-19 14:18 7,840 --a------ c:\windows\system32\mcdmsg5.dll
2009-01-19 11:24 . 2009-01-19 11:30 <DIR> d-------- c:\documents and settings\Charles\Application Data\Stardock
2009-01-19 11:24 . 2009-01-19 11:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Stardock
2009-01-19 11:24 . 2009-01-19 11:24 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{CC8D4389-E989-40EE-AF09-2330B1EE8BF7}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-19 01:35 --------- d-----w c:\program files\DNA
2009-02-19 01:35 --------- d-----w c:\documents and settings\Charles\Application Data\DNA
2009-02-18 18:21 --------- d-----w c:\program files\SUPERAntiSpyware
2009-02-18 18:13 182,912 ----a-w c:\windows\system32\drivers\ndis.sys
2009-02-18 02:42 --------- d-----w c:\documents and settings\Charles\Application Data\Hamachi
2009-02-17 21:59 --------- d-----w c:\program files\Java
2009-02-16 21:12 --------- d-----w c:\documents and settings\Charles\Application Data\BitTorrent
2009-02-09 04:14 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-07 17:58 --------- d-----w c:\program files\Common Files\Adobe
2009-02-07 17:52 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-07 17:52 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-06 23:20 --------- d-----w c:\program files\RocketDock
2009-02-06 02:16 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2009-02-05 01:37 --------- d-----w c:\program files\polytrans
2009-02-05 01:37 --------- d-----w c:\program files\pebuilder3110a
2009-02-05 01:37 --------- d-----w c:\program files\Metaseq
2009-02-05 01:37 --------- d-----w c:\program files\DivX
2009-02-02 06:05 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-30 13:24 --------- d-----w c:\program files\NCH Swift Sound
2009-01-26 02:28 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-25 20:45 --------- d-----w c:\program files\TEATIME
2009-01-23 04:54 --------- d-----w c:\documents and settings\Charles\Application Data\Winamp
2009-01-22 04:52 --------- d-----w c:\program files\AutoCAD 2008
2009-01-21 04:38 --------- d-----w c:\program files\Common Files\Stardock
2009-01-19 18:25 --------- d-----w c:\program files\Rainmeter
2009-01-19 17:29 --------- d-----w c:\program files\Stardock
2009-01-18 02:04 --------- d-----w c:\program files\Vstplugins
2009-01-17 21:22 --------- d-----w c:\program files\Autodesk
2009-01-16 17:20 6,216,032 ----a-w C:\windowsupdateagent30-x86.exe
2009-01-16 17:20 3,038 ----a-w C:\fix_svchost.bat
2009-01-16 17:20 1,266,056 ----a-w C:\WindowsXP-KB927891.exe
2009-01-16 05:41 --------- d-----w c:\program files\CCleaner
2009-01-15 02:42 90,112 ----a-w c:\windows\ST6UNST.EXE
2009-01-15 02:42 270,336 ------w c:\windows\Setup1.exe
2009-01-14 22:58 --------- d-----w c:\documents and settings\Charles\Application Data\360desktop
2009-01-14 20:43 --------- d-----w c:\documents and settings\Charles\Application Data\OtakuSoftware
2009-01-14 06:03 --------- d-----w c:\program files\UltraMon
2009-01-14 05:41 34,760 ----a-w c:\windows\system32\drivers\Partizan.sys
2009-01-14 02:12 --------- d-----w c:\documents and settings\Charles\Application Data\SUPERAntiSpyware.com
2009-01-14 02:12 --------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-09 03:55 --------- d-----w c:\program files\Common Files\Nero
2009-01-09 03:53 --------- d-----w c:\program files\Common Files\Ahead
2009-01-09 03:53 --------- d-----w c:\program files\Ahead
2009-01-07 14:55 --------- d-----w c:\program files\Western Digital Technologies
2009-01-07 14:55 --------- d-----w c:\program files\Western Digital
2009-01-06 03:52 --------- d-----w c:\program files\Unlocker
2009-01-04 18:24 --------- d-----w c:\program files\Combined Community Codec Pack
2009-01-04 15:07 --------- d-----w c:\documents and settings\Charles\Application Data\cucusoft
2009-01-03 20:17 --------- d-----w c:\documents and settings\Charles\Application Data\Uniblue
2009-01-01 15:27 --------- d-----w c:\program files\Logitech
2009-01-01 15:27 --------- d-----w c:\documents and settings\All Users\Application Data\Logitech
2008-12-31 03:53 --------- d-----w c:\program files\Samurize
2008-12-30 23:39 1,266,056 ----a-w c:\program files\WindowsXP-KB927891.exe
2008-12-30 23:28 --------- d-----w c:\program files\Windows Media Connect 2
2008-12-29 15:13 --------- d-----w c:\program files\7-Zip
2008-12-29 01:28 78,240 ----a-w c:\windows\system32\drivers\FILEM701.SYS
2008-12-27 22:47 --------- d-----w c:\program files\Common Files\BitDefender
2008-12-27 01:32 --------- d-----w c:\documents and settings\Charles\Application Data\Styler
2008-12-26 02:06 --------- d-----w c:\program files\Tunatic
2008-12-26 02:03 --------- d-----w c:\program files\Sony
2008-12-26 02:03 --------- d-----w c:\program files\Fraps
2008-12-26 02:00 --------- d-----w c:\program files\Ventrilo
2008-12-26 01:58 --------- d-----w c:\program files\Winamp
2008-04-13 05:54 22,328 ----a-r c:\documents and settings\Charles\Application Data\PnkBstrK.sys
2008-02-18 20:07 16,825 ----a-w c:\program files\Readme.txt
.
------- Sigcheck -------
2008-04-13 13:20 182656 558635d3af1c7546d26067d5d9b6959e c:\windows\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\ndis.sys
2008-04-13 13:20 182656 558635d3af1c7546d26067d5d9b6959e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ndis.sys
2009-02-18 12:13 213376 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\dllcache\ndis.sys
2009-02-18 12:13 213376 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2007-06-13 04:23 1050112 75e9b5067c2158f85f42c379412520c7 c:\windows\explorer.exe
2007-06-13 05:26 1050624 3d10ddc9dd0cbf7a881d0a7aa1c93a33 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2008-04-13 18:12 1050624 6ed9cba80bbebeb3854e0b85cfc0bb98 c:\windows\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\explorer.exe
2008-04-13 18:12 1050624 0424d1da981f357aa946de2a17e80839 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2007-06-13 04:23 1050112 c28d240b09a6394cb068037d68fdd877 c:\windows\system32\dllcache\explorer.exe
2008-04-13 18:12 32256 e1031847a9066a97a5c99596d5f5b71b c:\windows\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\ctfmon.exe
2008-04-13 18:12 32256 477199118b01885b775324b188ccdeb2 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2004-08-04 06:00 32256 9794af585920b47a0051a23fd1975fce c:\windows\system32\ctfmon.exe
2004-08-04 06:00 32768 876f114181d174cc6e07888100b678e5 c:\windows\system32\dllcache\ctfmon.exe
2005-06-10 18:17 74752 1a22d3d48a37889f260e56373a4e7826 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2008-04-13 18:12 74752 d4f57c08fd0b6b5071f6a8d375f4092a c:\windows\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\spoolsv.exe
2008-04-13 18:12 74752 d71ec8adf5f8a924f0e53bab3ac3d237 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
2005-06-10 17:53 74752 c75b8721a32b78ef59291f6239898c9e c:\windows\system32\spoolsv.exe
2005-06-10 17:53 75264 399e8717d8ba18041a108cd5be8c22c7 c:\windows\system32\dllcache\spoolsv.exe
2008-04-13 18:12 43008 f193cd3ad0d2f1dc0f97125dd7f23b98 c:\windows\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\userinit.exe
2008-04-13 18:12 43008 0ffadb5813f953038aab6e432c58aa78 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
2004-08-04 06:00 41472 a8c080c9bdaed994bf56f63920789921 c:\windows\system32\userinit.exe
2004-08-04 06:00 41984 869877499acf1b4a3d4bc6ea533364e2 c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-02-17_18.32.46.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-21 02:02:28 184,320 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 02:02:28 183,808 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2000-08-31 14:00:00 97,308 ----a-w c:\windows\grep.exe
+ 2000-08-31 14:00:00 97,820 ----a-w c:\windows\grep.exe
- 2000-08-31 14:00:00 116,224 ----a-w c:\windows\sed.exe
+ 2000-08-31 14:00:00 115,712 ----a-w c:\windows\sed.exe
+ 2001-07-14 23:32:24 69,632 ----a-w c:\windows\setupupd\temp\wsdueng.dll
- 2000-08-31 14:00:00 179,200 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 14:00:00 179,712 ----a-w c:\windows\SWREG.exe
- 2000-08-31 14:00:00 155,136 ----a-w c:\windows\SWSC.exe
+ 2000-08-31 14:00:00 154,624 ----a-w c:\windows\SWSC.exe
- 2000-08-31 14:00:00 229,888 ----a-w c:\windows\SWXCACLS.exe
+ 2000-08-31 14:00:00 229,376 ----a-w c:\windows\SWXCACLS.exe
- 2009-02-18 00:28:10 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-19 01:34:02 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-18 18:13:14 16,384 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
- 2009-02-18 00:28:10 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-19 01:34:02 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-18 22:01:22 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009021820090219\index.dat
- 2009-02-18 00:28:10 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-19 01:34:02 180,224 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2000-08-31 14:00:00 73,284 ----a-w c:\windows\VFIND.exe
+ 2000-08-31 14:00:00 72,548 ----a-w c:\windows\VFIND.exe
- 2000-08-31 14:00:00 84,992 ----a-w c:\windows\zip.exe
+ 2000-08-31 14:00:00 85,504 ----a-w c:\windows\zip.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 516096]
"1A:KkTrayServer"="c:\program files\RocketDock\ObjectDock\Docklets\KkMenu\KkTrayServer.exe" [2006-03-28 125440]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 32256]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 221184]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2008-08-24 4087808]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1711616]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2008-08-01 1103216]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 507336]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-01-02 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-12-13 2095640]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-12-13 2051096]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-05-16 1650688]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_12\bin\jusched.exe" [2007-05-02 75520]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 472064]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 472064]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 176128]
"mspy2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 84408]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 229432]
"Kernel and Hardware Abstraction Layer"="c:\windows\KHALMNPR.EXE" [2008-02-29 76304]
c:\documents and settings\Charles\Start Menu\Programs\Startup\
DsktpListView.exe [2001-04-23 33792]
UltraMon.exe.lnk - c:\program files\UltraMon\UltraMon.exe [2008-09-29 749056]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-29 805392]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
"UIHost"="c:\windows\system32\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-13 23:04 356352 c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\a.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\matrix31290.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpa.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpb.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpc.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0Partizan
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\SINS_Launcher.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\NVIDIA Corporation\\nTune\\nTuneService.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-04 55024]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-02-07 179856]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2008-09-14 10496]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-02-07 15504]
S3 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2009-01-13 34760]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2008-07-10 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-07-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688]
.
Contents of the 'Scheduled Tasks' folder
2009-02-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
2009-02-19 c:\windows\Tasks\iklmlnts.job
- c:\windows\system32\jkkIYpoP.dll []
2009-02-18 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Charles.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-02-11 10:19]
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-reader_s - c:\documents and settings\Charles\reader_s.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.4chan.org
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Winamp Search
DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab
FF - ProfilePath - c:\documents and settings\Charles\Application Data\Mozilla\Firefox\Profiles\
0qrhfdmb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.4chan.org/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-18 19:35:06
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-682003330-839522115-725345543-1003\Software\KISS-MA\K0Y0_0€0&W0Y0_0A0 *-*J0Œ0a0“0n0D0D0j0Š0-*]
"InstallPath"="c:\\Program Files\\KISS-MA\\????????\\"
"DskSht"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1104)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\vssvc.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
c:\program files\UltraMon\UltraMonTaskbar.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2009-02-18 19:38:59 - machine was rebooted [Charles]
ComboFix-quarantined-files.txt 2009-02-19 01:38:52
ComboFix2.txt 2009-02-18 03:52:21
ComboFix3.txt 2009-02-18 00:33:43
ComboFix4.txt 2009-01-26 14:07:24
ComboFix5.txt 2009-02-19 01:18:30
Pre-Run: 55,330,648,064 bytes free
Post-Run: 55,321,743,360 bytes free
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
387
-------------------------------------------------------------------------------------------------------------------------------------
PSI am without SP3 still because of the bad feedback it got after initial release, and because someone close to me had his computer's performance greatly reduced since the service pack failed to fully install. If you say updating to SP3 for security updates will be crucial to the removal and future safety however, I will update. Also, the new infection was so bad, that just by being connected to the router, everyone in the household would lose connection. Not just that, but I had to re-install Combofix to the desktop because it could not find all the necessary files to load.