<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: HJT Log - fake alerts in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r21059839</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 07:32:16 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 07:32:16 EDT</lastBuildDate>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21078026</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : Looks like we have a mean clean machine here !!! Thank you so very much. It took a few days but I learned a lot.<br><br>Unfortunately, right at this moment I do not have the laptop at home. It needed to stay at the office and I will not have access to it until Wednesday if you need me to post anything further.<br><br>Before I left I was able to follow your instructions in your last post and then run several programs - mainly MS Office products and not one issue popped up.<br><br>Thank you Bill. :) You're my hero.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21078026</guid>
<pubDate>Mon, 08 Sep 2008 18:55:19 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21076653</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I am a happy with your last results. Thank you, you did a very nice job.  Lets wrap this up.<br><br>Please download to your Desktop <b>OT_MOVEIT2</b>:<br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>Please double-click OTMoveIt2.exe to run the utility.<br><br>Copy the file paths below to the clipboard by using your mouse and highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):<br><br><textarea name="code" class="text" cols=50 rows=10>C:\WINDOWS\system32\gbuvidsp.exe&#012;C:\WINDOWS\system32\bak&#012; &#012;</textarea><!--end code block--><br>Return to OTMoveIt2, right click in the <b>"Paste List Of Files/Patterns To Search For and Move"</b> window.<br><b><i> IMPORTANT -- </i></b> Paste only into the <u>left</u> input panel.<br>Right-click and choose <b>Paste</b>.<br><br>Click the red <b>Moveit</b> button.<br>When it has finished, use your mouse and do a Copy/Paste of the large right-hand panel that shows Results.<br>Save your Clipboard contents in a new Notepad file, as we will want to review these results later.<br>Close OTMoveIt2 when it has finished.<br><br>Note:  If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose <b>Yes.</b><br><br>Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 9</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br>Update your Version of Java.  The current version is 1.6.07:   go to &raquo;<A HREF="http://www.java.com/en/download/manual.jsp" >www.java.com/en/download/manual.jsp</A> and download and install the newest Java JRE release.<br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Please double-click OTMoveIt.exe to run it again.<br>&#8226; Click on the green <b>CleanUp!</b> button. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. <br>&#8226; After the list has been download you'll be asked if you want to Begin cleanup process? Select "Yes".<br>&#8226; This step removes the files, folders, and shortcuts created by the tools I had you download and run.<br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226;  <b>Suggestion:  Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Suggestion:  Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21076653</guid>
<pubDate>Mon, 08 Sep 2008 14:17:31 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21075533</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : Hurray! I left the laptop on battery with the box open that asked for the XP CDs, plugged her in and was able to "borrow" the original Windows CD from the exact same laptop another employee was using.<br><br>Popped it in and the scan continued without a hitch.<br><br>Per this post I will run HJT and post the log here.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 10:43:59 AM, on 9/8/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16705)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\WLTRYSVC.EXE<br>C:\WINDOWS\System32\bcmwltry.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>c:\WINDOWS\system32\ZuneBusEnum.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\stsystra.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe<br>C:\WINDOWS\explorer.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.giants.com/index2.html" >www.giants.com/index2.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.dell.com/" >www.dell.com/</A><br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe<br>O4 - Global Startup: Bluetooth Manager.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br>O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br>O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - &raquo;<small>https</small>://<A HREF="https://70.90.17.225/Remote/msrdp.cab">70.90.17.225/Remote/msrdp.cab</A><br>O16 - DPF: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} (NPRemvuPluginControl) - &raquo;<A HREF="http://24.46.98.45:8888/common/NPRemvu.cab" >24.46.98.45:8888/common/NPRemvu.cab</A><br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br><br>--<br>End of file - 5429 bytes<br><br>Once you give me the all clear I need to reinstall Symantec client. Please tell me that will not be a problem - useless but not a problem. Ocassionally the bosses do a walk by and may notice the icon missing from the systray plus I do not want to leave this machine completely vulnerable.<br><br> C:\WINDOWS\system32\gbuvidsp.exe<br><br>ia still showing on the machine.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21075533</guid>
<pubDate>Mon, 08 Sep 2008 10:43:07 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21075139</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : I will hopefully have the full CDs within the hour once I am at the office and maybe the computer will like them and all will be well. I will wait until I have them, finish the scan and post back before I try to delete that file.<br><br>If you are referring to this post in regard to the HJT edit &raquo;<A HREF="/forum/r21071850-">Re: HJT Log - fake alerts</A> I absolutely did that.<br><br>And I did post the CFScript.txt file - <br>ComboFix 08-09-05.04 - STravis 2008-09-07 21:42:34.5 - NTFSx86<br>Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.549 [GMT -4:00]<br>Running from: C:\Documents and Settings\STravis\Desktop\ComboFix.exe<br>* Created a new restore point<br><br>[color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]<br>.<br><br>((((((((((((((((((((((((( Files Created from 2008-08-08 to 2008-09-08 )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-07 19:12 . 2008-09-07 19:12 d-------- C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-07 19:12 . 2008-09-02 00:16 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-07 19:12 . 2008-09-02 00:16 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-05 00:04 . 2008-09-06 10:30 d-------- C:\Program Files\Symantec<br>2008-09-04 23:53 . 2008-09-04 23:53 90,112 --a------ C:\WINDOWS\system32\gbuvidsp.exe<br>2008-09-04 09:51 . 2008-09-04 09:51 d-------- C:\Program Files\Windows Defender<br>2008-09-04 08:55 . 2008-09-04 08:55 d-------- C:\Program Files\Trend Micro<br>2008-09-03 20:21 . 2008-09-03 20:21 d-------- C:\Documents and Settings\STravis\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-03 20:21 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-03 19:52 . 2008-09-04 16:18 d-------- C:\Program Files\EsetOnlineScanner<br>2008-09-03 11:44 . 2008-09-03 15:05 127 --a------ C:\WINDOWS\wininit.ini<br>2008-09-02 23:20 . 2008-09-02 23:20 d-------- C:\Program Files\Common Files\Wise Installation Wizard<br>2008-08-18 16:25 . 2008-08-18 16:25 d-------- C:\WINDOWS\system32\scripting<br>2008-08-18 16:25 . 2008-08-18 16:25 d-------- C:\WINDOWS\system32\en<br>2008-08-18 16:25 . 2008-08-18 21:18 d-------- C:\WINDOWS\system32\bits<br>2008-08-18 16:25 . 2008-08-18 16:25 d-------- C:\WINDOWS\l2schemas<br>2008-08-18 16:17 . 2007-08-10 20:46 33,656 --a------ C:\WINDOWS\system32\sprecovr.exe<br>2008-08-18 16:12 . 2007-02-28 05:53 2,137,600 --a------ C:\WINDOWS\system32\ntoskrnl.exe<br>2008-08-18 15:54 . 2008-04-13 20:12 7,680 --a------ C:\WINDOWS\system32\spdwnwxp.exe<br>2008-08-18 15:52 . 2006-12-28 15:01 19,569 --a------ C:\WINDOWS\[u]0[/u]02942_.tmp<br>2008-08-17 23:17 . 2008-08-19 21:27 d-------- C:\WINDOWS\system32\CatRoot_bak<br>2008-08-14 22:10 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll<br><br>.<br>(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-07 22:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-09-07 14:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater<br>2008-09-07 14:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared<br>2008-09-06 14:30 --------- d-----w C:\Program Files\Symantec AntiVirus<br>2008-09-06 14:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-09-05 03:23 57,344 ----a-w C:\WINDOWS\system32\userinit.exe<br>2008-09-03 16:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy<br>2008-09-03 03:20 --------- d-----w C:\Program Files\Lavasoft<br>2008-09-03 03:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-08-11 19:36 --------- d-----w C:\Documents and Settings\STravis\Application Data\Audacity<br>2008-08-01 11:46 --------- d-----w C:\Program Files\Google<br>2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll<br>2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll<br>2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe<br>2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe<br>2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll<br>2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll<br>2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll<br>2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll<br>2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll<br>2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll<br>2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll<br>2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll<br>2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll<br>2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll<br>2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll<br>2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll<br>2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll<br>2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll<br>2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\dllcache\mscms.dll<br>2008-06-24 14:57 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll<br>2008-06-23 09:20 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe<br>2008-06-23 09:20 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe<br>2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe<br>2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll<br>2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll<br>2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll<br>2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll<br>2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys<br>2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys<br>2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys<br>2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\dllcache\bthport.sys<br>2007-03-05 14:02 24,192 ----a-w C:\Documents and Settings\STravis\usbsermptxp.sys<br>2007-03-05 14:02 22,768 ----a-w C:\Documents and Settings\STravis\usbsermpt.sys<br>.<br><br>------- Sigcheck -------<br><br>2008-04-13 20:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe<br>2008-09-04 23:23 57344 b5bfcf3c4dfe120d2bb0f9736a17c065 C:\WINDOWS\system32\userinit.exe<br>.<br>((((((((((((((((((((((((((((( snapshot_2008-09-04_23.47.30.65 )))))))))))))))))))))))))))))))))))))))))<br>.<br>- 2008-09-04 22:07:58 40,960 ----a-r C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2008-09-05 04:05:37 40,960 ----a-r C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2006-11-02 09:46:05 363,520 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPCDMCLH.DLL<br>+ 2006-11-02 09:46:11 251,904 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFIME50.DLL<br>+ 2006-11-02 09:46:05 19,968 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFRES50.DLL<br>+ 2006-11-02 09:46:11 1,515,520 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZ3ALHN.DLL<br>+ 2006-11-02 09:46:05 1,253,888 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZ3RLHN.DLL<br>+ 2006-11-02 09:46:11 365,568 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZEVLHN.DLL<br>+ 2006-09-18 21:44:24 562,176 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZSSLHN.DLL<br>+ 2006-09-18 21:44:24 3,447,808 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZSTLHN.DLL<br>+ 2006-11-02 09:46:11 2,725,376 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZUILHN.DLL<br>- 2004-08-04 05:56:48 264,704 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrv.dll<br>+ 2006-11-02 09:46:13 372,736 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRV.DLL<br>- 2004-08-04 05:56:48 197,120 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll<br>+ 2006-11-02 09:46:11 740,864 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRVUI.DLL<br>- 2004-08-04 05:56:36 619,520 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll<br>+ 2006-11-02 09:41:12 761,344 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIRES.DLL<br>.<br>((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>----a-r 176,128 2005-10-07 04:13:38 C:\Program Files\Apoint\bak\Apoint.exe<br><br>----a-w 153,136 2007-03-09 22:53:56 C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe<br><br>----a-w 153,136 2007-03-12 17:49:26 C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe<br><br>----a-w 52,896 2006-07-20 00:26:04 C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe<br><br>----a-w 49,152 2005-12-10 01:29:52 C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe<br><br>----a-w 389,120 2006-07-17 02:29:54 C:\Program Files\Dell Support\bak\DSAgnt.exe<br><br>----a-w 132,496 2007-09-25 05:11:35 C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe<br><br>----a-w 1,694,208 2004-10-13 16:24:37 C:\Program Files\Messenger\bak\msmsgs.exe<br><br>----a-w 8,720,384 2007-12-19 01:47:24 C:\Program Files\MySpace\IM\bak\MySpaceIM.exe<br><br>----a-w 282,624 2006-09-01 19:57:48 C:\Program Files\QuickTime\bak\qttask.exe<br><br>----a-w 125,168 2006-09-28 01:33:44 C:\Program Files\Symantec AntiVirus\bak\VPTray.exe<br><br>----a-w 166,304 2007-11-07 00:09:54 C:\Program Files\Zune\bak\ZuneLauncher.exe<br>----a-w 158,624 2008-04-29 23:56:20 C:\Program Files\Zune\ZuneLauncher.exe<br><br>----a-w 15,360 2004-08-04 10:00:00 C:\WINDOWS\system32\bak\ctfmon.exe<br>----a-w 15,360 2004-08-04 10:00:00 C:\WINDOWS\system32\ctfmon.exe<br><br>----a-w 77,824 2005-12-13 07:41:08 C:\WINDOWS\system32\bak\hkcmd.exe<br><br>----a-w 118,784 2005-12-13 07:45:00 C:\WINDOWS\system32\bak\igfxpers.exe<br><br>----a-w 98,304 2005-12-13 07:44:18 C:\WINDOWS\system32\bak\igfxtray.exe<br><br>----a-w 1,347,584 2005-12-19 13:08:42 C:\WINDOWS\system32\bak\WLTRAY.exe<br><br>.<br>((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown<br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 C:\WINDOWS\stsystra.exe]<br><br>C:\Documents and Settings\STravis\Start Menu\Programs\Startup\<br>MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-01-29 951640]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-06-16 49152]<br>Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-10-06 24576]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]<br>@="Driver"<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=<br><br>R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]<br>R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]<br>S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9e35fbb-fdda-11dc-934f-0016cf72068b}]<br>\Shell\AutoRun\command - E:\LaunchU3.exe -a<br>.<br>Contents of the 'Scheduled Tasks' folder<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>R0 -: HKCU-Main,Start Page = hxxp://www.giants.com/index2.html<br>R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.dell.com/<br><br>O16 -: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} - hxxp://24.46.98.45:8888/common/NPRemvu.cab<br>C:\WINDOWS\Downloaded Program Files\NPRemvu.inf<br>C:\WINDOWS\NPRemvu.ocx<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;www.gmer.net<br>Rootkit scan 2008-09-07 21:44:26<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ...<br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ...<br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>Completion time: 2008-09-07 21:46:16<br>ComboFix-quarantined-files.txt 2008-09-08 01:45:52<br>ComboFix2.txt 2008-09-07 23:08:34<br>ComboFix3.txt 2008-09-06 14:49:19<br>ComboFix4.txt 2008-09-05 03:48:56<br>ComboFix5.txt 2008-09-08 01:42:05<br><br>Pre-Run: 40,253,759,488 bytes free<br>Post-Run: 40,240,181,248 bytes free<br><br>182 --- E O F --- 2008-09-06 13:16:35]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21075139</guid>
<pubDate>Mon, 08 Sep 2008 09:22:10 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21074277</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : If you:<br><br>1. Did the HijackThis edit I requested earlier.<br>2. Since you did not create the CFScript.txt file for Combofix, just use Explorer and try to delete this file:<br><br><b>\C:\WINDOWS\system32\gbuvidsp.exe</b><br><br>3. Please see my link about what to do if you do not have an XP "Full" CD to make SFC /Scannow happy.  You likely have everything you need to make it happy.  Let me know only if you cannot make it happy.  We can use your second PC to resolve the issue.<br><br>Bill<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074277</guid>
<pubDate>Mon, 08 Sep 2008 00:47:36 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21074216</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : It asked for the CD so I popped it in - the one with the file I copied from another computer but   .... "The CD you provided is the wrong CD. Please insert the Windows XP Pro CD ROM ...."<br><br>C:\WINDOWS\system32\gbuvidsp.exe is still there.<br><br>EDIT: That's it for me for tonight. I will leave the laptop on with the scan box open.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074216</guid>
<pubDate>Mon, 08 Sep 2008 00:24:40 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21074158</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : Scanning now.<br><br>While it does I have a quick question: is there a way to determine when or how this infection happened? It is important that I know what employee caused this if I can?<br>Apparently the paltry AV app we were provided with at the office, Symantec client, did not prevent this.<br><br>I was able to install several spyware apps but that was as much as I was allowed.<br><br>Still scanning.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074158</guid>
<pubDate>Mon, 08 Sep 2008 00:06:25 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21074110</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : OTMOVEIT2 can seem to stop responding.  Do not worry about this at the moment.<br><br>I want only that his file is gone:<br><br><b>C:\WINDOWS\system32\gbuvidsp.exe</b><br><br>It likely did that no matter what.<br><br>Now, see if you can do the SFC /Scannow.<br><br>Bill<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074110</guid>
<pubDate>Sun, 07 Sep 2008 23:55:01 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21074067</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : MoveIt freezes up after I paste the list of files. Not responding. I have no other programs running.<br><br>EDIT: same happens with a fresh copy]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074067</guid>
<pubDate>Sun, 07 Sep 2008 23:44:26 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073972</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : C:\windows\system32\userinit.exe  has just been copied to a CD. I was taken from a laptop with the exact same level OS as the infected laptop.<br><br>Before I start the procedure I would just like to clarify where or when I will be using this CD?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073972</guid>
<pubDate>Sun, 07 Sep 2008 23:24:19 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073914</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : I have 5 computers here at home - all running various flavors of Vista.<br><br>The infected machine is XP Pro SP2 - a co workers laptop.<br><br>My husbands laptop is XP Pro SP2. Can I simply copy that file to a CD? Is that what you are saying? The link you provided, while very informative, was a bit confusing to me.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073914</guid>
<pubDate>Sun, 07 Sep 2008 23:08:35 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073858</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : No, you cannot use the old CDs of XP.<br><br>But, look carefully at the article I linked.  You likely have everything you need already in place.  If not, you likely have everything you need with a very easy registry change.<br><br>I am fairly, not 100%, but fairly convinced that a core file for XP has been replaced with a malware version.  Since this computer is at Service Pack 2 level, if you have another machine with XP SP2, I can, if the original advice above cannot resolve matters, use a copy of:<br><br>C:\windows\system32\userinit.exe<br><br>from a known "clean" XP computer, and let use conclude this malware removal session.<br><br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073858</guid>
<pubDate>Sun, 07 Sep 2008 22:57:18 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073781</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : I do not have the CDs for this particular laptop - they are at the office and actually might not be available to me.<br><br>I do have a very old version of XP Professional here at home. <br>It is not installed on any computers. Can I use that CD if it comes down to it?<br><br>If this machine goes down it will be bad, very bad so I am very worried. As it is right now it is infected but functional. The wrong CD thing scares me. <br><br>How possible is it that the laptop becomes a paperweight?<br><br>EDIT: This laptop has SP2 but looking into the old CD I have I see no reference to SP2]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073781</guid>
<pubDate>Sun, 07 Sep 2008 22:39:51 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073617</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : We are almost done.  This one is a little tricky, as if I screw up here your compute may not be able to restart normally.  I do not want that to happen.<br><br>We used HijackThis to remove the startup entry for this file, but it is still around. <br><br><b>2008-09-04 23:53 . 2008-09-04 23:53 90,112 --a------ C:\WINDOWS\system32\gbuvidsp.exe</b><br><br>We need to sort this issue, and the concern I have with userinit.exe<br><br>Please download  to your Desktop <b>OT_MOVEIT</b>:<br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe&#012;</textarea><!--end code block--><br>Please double-click OTMoveIt2.exe to run the utility.<br><br>Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):<br><br><textarea name="code" class="text" cols=50 rows=10>&#91;Kill Explorer&#93;&#012;C:\WINDOWS\system32\gbuvidsp.exe&#012;&#91;EmptyTemps&#93;&#012;&#91;Start Explorer&#93;&#012;</textarea><!--end code block--><br>Return to OTMoveIt2, right click in the <b>"Paste List Of Files/Patterns To Search For and Move"</b> window.<br><b><i> IMPORTANT -- </i></b> Paste only into the <u>left</u> input panel.<br>Right-click and choose <b>Paste</b>.<br><br>Click the red <b>Moveit</b> button.<br>When it has finished, use your mouse and do a Copy/Paste of the large right-hand panel that shows Results.<br>Save your Clipboard contents in a new Notepad file, as we will want to review these results later.<br>Close OTMoveIt2 when it has finished.<br><br>Note:  If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose <b>Yes.</b><br><br>Whether you had to reboot or not, when back at the Desktop, click Start, Click Run, and enter into the Command Line that opens:<br><br><b>SFC /Scannow</b><br><br>This may well prompt for your XP CD.  Please insert the CD when prompted.  If there are issues, or you cannot find the CD, please visit this site for instructions:  &raquo;<A HREF="http://www.pcug.org.au/boesen/SFC/SFC.htm" >www.pcug.org.au/boesen/SFC/SFC.htm</A><br><br>Finally, run HijackThis one last time and post the log file.  I think we should be finished.<br><br>Best,<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073617</guid>
<pubDate>Sun, 07 Sep 2008 22:10:33 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073498</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : I forgot to disconnect from the Internet - did I screw it all up?<br><br>ComboFix 08-09-05.04 - STravis 2008-09-07 21:42:34.5 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.549 [GMT -4:00]<br>Running from: C:\Documents and Settings\STravis\Desktop\ComboFix.exe<br> * Created a new restore point<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((   Files Created from 2008-08-08 to 2008-09-08  )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-07 19:12 . 2008-09-07 19:12&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-07 19:12 . 2008-09-02 00:16&#9;38,528&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-07 19:12 . 2008-09-02 00:16&#9;17,200&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-05 00:04 . 2008-09-06 10:30&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-09-04 23:53 . 2008-09-04 23:53&#9;90,112&#9;--a------&#9;C:\WINDOWS\system32\gbuvidsp.exe<br>2008-09-04 09:51 . 2008-09-04 09:51&#9;&#9;d--------&#9;C:\Program Files\Windows Defender<br>2008-09-04 08:55 . 2008-09-04 08:55&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\STravis\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-03 19:52 . 2008-09-04 16:18&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-09-03 11:44 . 2008-09-03 15:05&#9;127&#9;--a------&#9;C:\WINDOWS\wininit.ini<br>2008-09-02 23:20 . 2008-09-02 23:20&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\scripting<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\en<br>2008-08-18 16:25 . 2008-08-18 21:18&#9;&#9;d--------&#9;C:\WINDOWS\system32\bits<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\l2schemas<br>2008-08-18 16:17 . 2007-08-10 20:46&#9;33,656&#9;--a------&#9;C:\WINDOWS\system32\sprecovr.exe<br>2008-08-18 16:12 . 2007-02-28 05:53&#9;2,137,600&#9;--a------&#9;C:\WINDOWS\system32\ntoskrnl.exe<br>2008-08-18 15:54 . 2008-04-13 20:12&#9;7,680&#9;--a------&#9;C:\WINDOWS\system32\spdwnwxp.exe<br>2008-08-18 15:52 . 2006-12-28 15:01&#9;19,569&#9;--a------&#9;C:\WINDOWS\[u]0[/u]02942_.tmp<br>2008-08-17 23:17 . 2008-08-19 21:27&#9;&#9;d--------&#9;C:\WINDOWS\system32\CatRoot_bak<br>2008-08-14 22:10 . 2008-05-01 10:30&#9;331,776&#9;---------&#9;C:\WINDOWS\system32\dllcache\msadce.dll<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-07 22:55&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-09-07 14:13&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Google Updater<br>2008-09-07 14:01&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-09-06 14:30&#9;---------&#9;d-----w&#9;C:\Program Files\Symantec AntiVirus<br>2008-09-06 14:30&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-09-05 03:23&#9;57,344&#9;----a-w&#9;C:\WINDOWS\system32\userinit.exe<br>2008-09-03 16:15&#9;---------&#9;d-----w&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-09-03 03:20&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-09-03 03:19&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-08-11 19:36&#9;---------&#9;d-----w&#9;C:\Documents and Settings\STravis\Application Data\Audacity<br>2008-08-01 11:46&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2008-07-19 02:10&#9;94,920&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\cdm.dll<br>2008-07-19 02:10&#9;94,920&#9;----a-w&#9;C:\WINDOWS\system32\cdm.dll<br>2008-07-19 02:10&#9;53,448&#9;----a-w&#9;C:\WINDOWS\system32\wuauclt.exe<br>2008-07-19 02:10&#9;53,448&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuauclt.exe<br>2008-07-19 02:10&#9;45,768&#9;----a-w&#9;C:\WINDOWS\system32\wups2.dll<br>2008-07-19 02:10&#9;36,552&#9;----a-w&#9;C:\WINDOWS\system32\wups.dll<br>2008-07-19 02:10&#9;36,552&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wups.dll<br>2008-07-19 02:09&#9;563,912&#9;----a-w&#9;C:\WINDOWS\system32\wuapi.dll<br>2008-07-19 02:09&#9;563,912&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuapi.dll<br>2008-07-19 02:09&#9;325,832&#9;----a-w&#9;C:\WINDOWS\system32\wucltui.dll<br>2008-07-19 02:09&#9;325,832&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wucltui.dll<br>2008-07-19 02:09&#9;205,000&#9;----a-w&#9;C:\WINDOWS\system32\wuweb.dll<br>2008-07-19 02:09&#9;205,000&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuweb.dll<br>2008-07-19 02:09&#9;1,811,656&#9;----a-w&#9;C:\WINDOWS\system32\wuaueng.dll<br>2008-07-19 02:09&#9;1,811,656&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuaueng.dll<br>2008-07-07 20:32&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\es.dll<br>2008-07-07 20:32&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\es.dll<br>2008-06-24 16:23&#9;74,240&#9;----a-w&#9;C:\WINDOWS\system32\mscms.dll<br>2008-06-24 16:23&#9;74,240&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mscms.dll<br>2008-06-24 14:57&#9;3,592,192&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mshtml.dll<br>2008-06-23 09:20&#9;70,656&#9;------w&#9;C:\WINDOWS\system32\dllcache\ie4uinit.exe<br>2008-06-23 09:20&#9;625,664&#9;------w&#9;C:\WINDOWS\system32\dllcache\iexplore.exe<br>2008-06-23 09:20&#9;13,824&#9;------w&#9;C:\WINDOWS\system32\dllcache\ieudinit.exe<br>2008-06-21 05:23&#9;161,792&#9;------w&#9;C:\WINDOWS\system32\dllcache\ieakui.dll<br>2008-06-20 17:41&#9;245,248&#9;----a-w&#9;C:\WINDOWS\system32\mswsock.dll<br>2008-06-20 17:41&#9;245,248&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mswsock.dll<br>2008-06-20 17:41&#9;148,992&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\dnsapi.dll<br>2008-06-20 10:45&#9;360,320&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\tcpip.sys<br>2008-06-20 10:44&#9;138,368&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\afd.sys<br>2008-06-20 09:52&#9;225,920&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\tcpip6.sys<br>2008-06-13 13:10&#9;272,128&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\bthport.sys<br>2007-03-05 14:02&#9;24,192&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermptxp.sys<br>2007-03-05 14:02&#9;22,768&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermpt.sys<br>.<br><br>------- Sigcheck -------<br><br>2008-04-13 20:12  26112  a93aee1928a9d7ce3e16d24ec7380f89&#9;C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe<br>2008-09-04 23:23  57344  b5bfcf3c4dfe120d2bb0f9736a17c065&#9;C:\WINDOWS\system32\userinit.exe<br>.<br>(((((((((((((((((((((((((((((   snapshot_2008-09-04_23.47.30.65   )))))))))))))))))))))))))))))))))))))))))<br>.<br>- 2008-09-04 22:07:58&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2008-09-05 04:05:37&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2006-11-02 09:46:05&#9;363,520&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPCDMCLH.DLL<br>+ 2006-11-02 09:46:11&#9;251,904&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFIME50.DLL<br>+ 2006-11-02 09:46:05&#9;19,968&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFRES50.DLL<br>+ 2006-11-02 09:46:11&#9;1,515,520&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZ3ALHN.DLL<br>+ 2006-11-02 09:46:05&#9;1,253,888&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZ3RLHN.DLL<br>+ 2006-11-02 09:46:11&#9;365,568&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZEVLHN.DLL<br>+ 2006-09-18 21:44:24&#9;562,176&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZSSLHN.DLL<br>+ 2006-09-18 21:44:24&#9;3,447,808&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZSTLHN.DLL<br>+ 2006-11-02 09:46:11&#9;2,725,376&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZUILHN.DLL<br>- 2004-08-04 05:56:48&#9;264,704&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrv.dll<br>+ 2006-11-02 09:46:13&#9;372,736&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRV.DLL<br>- 2004-08-04 05:56:48&#9;197,120&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll<br>+ 2006-11-02 09:46:11&#9;740,864&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRVUI.DLL<br>- 2004-08-04 05:56:36&#9;619,520&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll<br>+ 2006-11-02 09:41:12&#9;761,344&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIRES.DLL<br>.<br>(((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>----a-r           176,128 2005-10-07 04:13:38  C:\Program Files\Apoint\bak\Apoint.exe<br><br>----a-w           153,136 2007-03-09 22:53:56  C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe<br><br>----a-w           153,136 2007-03-12 17:49:26  C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe<br><br>----a-w            52,896 2006-07-20 00:26:04  C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe<br><br>----a-w            49,152 2005-12-10 01:29:52  C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe<br><br>----a-w           389,120 2006-07-17 02:29:54  C:\Program Files\Dell Support\bak\DSAgnt.exe<br><br>----a-w           132,496 2007-09-25 05:11:35  C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe<br><br>----a-w         1,694,208 2004-10-13 16:24:37  C:\Program Files\Messenger\bak\msmsgs.exe<br><br>----a-w         8,720,384 2007-12-19 01:47:24  C:\Program Files\MySpace\IM\bak\MySpaceIM.exe<br><br>----a-w           282,624 2006-09-01 19:57:48  C:\Program Files\QuickTime\bak\qttask.exe<br><br>----a-w           125,168 2006-09-28 01:33:44  C:\Program Files\Symantec AntiVirus\bak\VPTray.exe<br><br>----a-w           166,304 2007-11-07 00:09:54  C:\Program Files\Zune\bak\ZuneLauncher.exe<br>----a-w           158,624 2008-04-29 23:56:20  C:\Program Files\Zune\ZuneLauncher.exe<br><br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\bak\ctfmon.exe<br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\ctfmon.exe<br><br>----a-w            77,824 2005-12-13 07:41:08  C:\WINDOWS\system32\bak\hkcmd.exe<br><br>----a-w           118,784 2005-12-13 07:45:00  C:\WINDOWS\system32\bak\igfxpers.exe<br><br>----a-w            98,304 2005-12-13 07:44:18  C:\WINDOWS\system32\bak\igfxtray.exe<br><br>----a-w         1,347,584 2005-12-19 13:08:42  C:\WINDOWS\system32\bak\WLTRAY.exe<br><br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 C:\WINDOWS\stsystra.exe]<br><br>C:\Documents and Settings\STravis\Start Menu\Programs\Startup\<br>MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-01-29 951640]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-06-16 49152]<br>Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-10-06 24576]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]<br>@="Driver"<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=<br><br>R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]<br>R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]<br>S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9e35fbb-fdda-11dc-934f-0016cf72068b}]<br>\Shell\AutoRun\command - E:\LaunchU3.exe -a<br>.<br>Contents of the 'Scheduled Tasks' folder<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>R0 -: HKCU-Main,Start Page = hxxp://www.giants.com/index2.html<br>R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.dell.com/<br><br>O16 -: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} - hxxp://24.46.98.45:8888/common/NPRemvu.cab<br>C:\WINDOWS\Downloaded Program Files\NPRemvu.inf<br>C:\WINDOWS\NPRemvu.ocx<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-09-07 21:44:26<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>Completion time: 2008-09-07 21:46:16<br>ComboFix-quarantined-files.txt  2008-09-08 01:45:52<br>ComboFix2.txt  2008-09-07 23:08:34<br>ComboFix3.txt  2008-09-06 14:49:19<br>ComboFix4.txt  2008-09-05 03:48:56<br>ComboFix5.txt  2008-09-08 01:42:05<br><br>Pre-Run: 40,253,759,488 bytes free<br>Post-Run: 40,240,181,248 bytes free<br><br>182&#9;--- E O F ---&#9;2008-09-06 13:16:35]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073498</guid>
<pubDate>Sun, 07 Sep 2008 21:49:03 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073427</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I was afraid that might be the result.  Userinit.exe is, and where it is being referenced from the Registry, a core file.<br><br>The one in place has been compromised.<br><br>sUBs, the Author of Combofix, has a detection routine for this replacement I would like to use to make sure things are as they should (or must) be.<br><br>1. Delete Combofix.exe from your Desktop.  I need the newest version.<br><br>2. Download and Run  -- <b>ComboFix&copy; </b> <br>Download this file <b><u>-- to your Desktop --</u></b> from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable  your Antivirus  software -- this includes any Script Blocking Feature it may have.<br><br><b>Important:  Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.</b><br>&#8226; A window will open with a warning.  Accept any disclaimers to start the fix. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>Post back the results of C:\Combofix.txt  If there are suitable replacements that Combofix can find, we are nearly done.<br><br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073427</guid>
<pubDate>Sun, 07 Sep 2008 21:35:52 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073249</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : File userinit.exe received on 09.08.2008 03:01:29 (CET)Antivirus Version Last Update Result <br>AhnLab-V3 2008.9.6.0 2008.09.07 - <br>AntiVir 7.8.1.28 2008.09.07 PHISH/FraudTool.Agent.BW <br>Authentium 5.1.0.4 2008.09.07 W32/FakeAV2008.BW <br>Avast 4.8.1195.0 2008.09.07 - <br>AVG 8.0.0.161 2008.09.07 Win32/Heur <br>BitDefender 7.2 2008.09.08 - <br>CAT-QuickHeal 9.50 2008.09.06 (Suspicious) - DNAScan <br>ClamAV 0.93.1 2008.09.07 - <br>DrWeb 4.44.0.09170 2008.09.07 - <br>eSafe 7.0.17.0 2008.09.07 - <br>eTrust-Vet 31.6.6072 2008.09.05 - <br>Ewido 4.0 2008.09.07 - <br>F-Prot 4.4.4.56 2008.09.07 W32/FakeAV2008.BW <br>F-Secure 8.0.14332.0 2008.09.07 FraudTool.Win32.Agent.bw <br>Fortinet 3.112.0.0 2008.09.07 W32/Tibs.WA!tr.dldr <br>GData 19 2008.09.08 - <br>Ikarus T3.1.1.34.0 2008.09.08 Win32.SuspectCrc <br>K7AntiVirus 7.10.443 2008.09.05 - <br>Kaspersky 7.0.0.125 2008.09.08 not-a-virus:FraudTool.Win32.Agent.bw <br>McAfee 5378 2008.09.05 - <br>Microsoft 1.3903 2008.09.08 - <br>NOD32v2 3424 2008.09.07 - <br>Norman 5.80.02 2008.09.05 - <br>Panda 9.0.0.4 2008.09.07 - <br>PCTools 4.4.2.0 2008.09.07 - <br>Prevx1 V2 2008.09.08 Malicious Software <br>Rising 20.60.62.00 2008.09.07 - <br>Sophos 4.33.0 2008.09.07 Mal/EncPk-CO <br>Sunbelt 3.1.1616.1 2008.09.07 - <br>Symantec 10 2008.09.08 - <br>TheHacker 6.3.0.8.075 2008.09.06 - <br>TrendMicro 8.700.0.1004 2008.09.05 - <br>VBA32 3.12.8.5 2008.09.07 suspected of Malware-Cryptor.Win32.General.2 <br>ViRobot 2008.9.5.1365 2008.09.06 - <br>VirusBuster 4.5.11.0 2008.09.07 - <br>Webwasher-Gateway 6.6.2 2008.09.07 - <br> <br>Additional information <br>File size: 57344 bytes <br>MD5...: b5bfcf3c4dfe120d2bb0f9736a17c065 <br>SHA1..: b51211e9a221c066674a21a33546b8776f09c4a2 <br>SHA256: fade41dd65341422f062aa046b58b7c5d3e3c49a24b0daa2eb6f8a8eea8cd7ee <br>SHA512: 932efdfa2e62f37d30b8c09bc9192c9c67f2b7c2cb0ad62c7eb0445012f54941<br>f24e5e57f2997a16006dae399791c8e9d02e92b29479b54cd8f9aaf192e20b75 <br>PEiD..: - <br>TrID..: File type identification<br>Generic Win/DOS Executable (49.9%)<br>DOS Executable Generic (49.8%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) <br>PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x4019b0<br>timedatestamp.....: 0x46cfb54a (Sat Aug 25 04:51:22 2007)<br>machinetype.......: 0x14c (I386)<br><br>( 4 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x1000 0x1000 4.76 cd14a3572e7c34722c0f663d7b14a38f<br>.rdata 0x2000 0x1000 0x1000 2.69 0d83fb166d20fbaadfbf7ac107d94153<br>.data 0x3000 0xa000 0x9000 6.22 28f26301a650cb6b9006659579cb407a<br>.rsrc 0xd000 0x2000 0x2000 2.50 b3205ebb5f7eeb261eee2f87120c0243<br><br>( 1 imports ) <br>&gt; kernel32.dll: GetLastError<br><br>( 0 exports ) <br> <br>Prevx info: &raquo;<A HREF="http://info.prevx.com/aboutprogramtext.asp?PX5=246B703A005013C2E0E600E3FB9BFB00B873B577" >info.prevx.com/aboutprogramtext.&middot;&middot;&middot;B873B577</A> <br><br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073249</guid>
<pubDate>Sun, 07 Sep 2008 21:07:58 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21073202</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : Service load:  0%        100%  <br> <br>File:  userinit.exe  <br>Status:  INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)  <br>MD5:  b5bfcf3c4dfe120d2bb0f9736a17c065  <br>Packers detected:  - <br> <br>Scanner results  <br>Scan taken on 08 Sep 2008 00:20:25 (GMT)  <br>A-Squared  Found Win32.SuspectCrc  <br>AntiVir  Found PHISH/FraudTool.Agent.BW  <br>ArcaVir  Found nothing <br>Avast  Found nothing <br>AVG Antivirus  Found nothing <br>BitDefender  Found nothing <br>ClamAV  Found nothing <br>CPsecure  Found nothing <br>Dr.Web  Found nothing <br>F-Prot Antivirus  Found W32/FakeAV2008.BW  <br>F-Secure Anti-Virus  Found not-a-virus:FraudTool.Win32.Agent.bw (6, 2, 616)  <br>Ikarus  Found Win32.SuspectCrc  <br>Kaspersky Anti-Virus  Found not-a-virus:FraudTool.Win32.Agent.bw  <br>NOD32  Found nothing <br>Norman Virus Control  Found nothing <br>Panda Antivirus  Found nothing <br>Sophos Antivirus  Found Mal/EncPk-CO  <br>VirusBuster  Found nothing <br>VBA32  Found Malware-Cryptor.Win32.General.2 (probable variant)  <br>   <br>Statistics  <br>Last file scanned at least one scanner reported something about: Website_Ripper_Copier_3.2.zip (MD5: 6d56ab0c38aa016c924051a44246ba80, size: 2717787 bytes), detected by:<br><br>Scanner  Malware name  <br>A-Squared  X  <br>AntiVir  X  <br>ArcaVir  X  <br>Avast  X  <br>AVG Antivirus  Win32/Themida  <br>BitDefender  X  <br>ClamAV  X  <br>CPsecure  X  <br>Dr.Web  X  <br>F-Prot Antivirus  X  <br>F-Secure Anti-Virus  Trojan-Downloader.Win32.Bagle.aaw  <br>Ikarus  X  <br>Kaspersky Anti-Virus  Trojan-Downloader.Win32.Bagle.aaw  <br>NOD32  X  <br>Norman Virus Control  X  <br>Panda Antivirus  X  <br>Sophos Antivirus  X  <br>VirusBuster  X  <br>VBA32  X  <br><br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073202</guid>
<pubDate>Sun, 07 Sep 2008 21:00:06 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21072999</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : <b>(1)</b> MBAM Log results:<br>Malwarebytes' Anti-Malware 1.26<br>Database version: 1103<br>Windows 5.1.2600 Service Pack 2<br><br>9/7/2008 8:12:06 PM<br>mbam-log-2008-09-07 (20-12-06).txt<br><br>Scan type: Full Scan (C:\|)<br>Objects scanned: 92797<br>Time elapsed: 41 minute(s), 4 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 0<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>(No malicious items detected)<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br><b>2.</b> Contents of Combofix.txt<br>ComboFix 08-09-04.08 - STravis 2008-09-07 19:00:39.4 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.606 [GMT -4:00]<br>Running from: C:\Documents and Settings\STravis\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\STravis\Desktop\CFScript.txt<br> * Created a new restore point<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((   Files Created from 2008-08-07 to 2008-09-07  )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-06 22:53 . 2008-09-06 22:53&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-06 22:53 . 2008-09-02 00:26&#9;38,528&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-06 22:53 . 2008-09-02 00:25&#9;17,200&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-05 00:04 . 2008-09-06 10:30&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-09-04 23:53 . 2008-09-04 23:53&#9;90,112&#9;--a------&#9;C:\WINDOWS\system32\gbuvidsp.exe<br>2008-09-04 09:51 . 2008-09-04 09:51&#9;&#9;d--------&#9;C:\Program Files\Windows Defender<br>2008-09-04 08:55 . 2008-09-04 08:55&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\STravis\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-03 19:52 . 2008-09-04 16:18&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-09-03 11:44 . 2008-09-03 15:05&#9;127&#9;--a------&#9;C:\WINDOWS\wininit.ini<br>2008-09-02 23:20 . 2008-09-02 23:20&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\scripting<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\en<br>2008-08-18 16:25 . 2008-08-18 21:18&#9;&#9;d--------&#9;C:\WINDOWS\system32\bits<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\l2schemas<br>2008-08-18 16:17 . 2007-08-10 20:46&#9;33,656&#9;--a------&#9;C:\WINDOWS\system32\sprecovr.exe<br>2008-08-18 16:12 . 2007-02-28 05:53&#9;2,137,600&#9;--a------&#9;C:\WINDOWS\system32\ntoskrnl.exe<br>2008-08-18 15:54 . 2008-04-13 20:12&#9;7,680&#9;--a------&#9;C:\WINDOWS\system32\spdwnwxp.exe<br>2008-08-18 15:52 . 2006-12-28 15:01&#9;19,569&#9;--a------&#9;C:\WINDOWS\[u]0[/u]02942_.tmp<br>2008-08-17 23:17 . 2008-08-19 21:27&#9;&#9;d--------&#9;C:\WINDOWS\system32\CatRoot_bak<br>2008-08-14 22:10 . 2008-05-01 10:30&#9;331,776&#9;---------&#9;C:\WINDOWS\system32\dllcache\msadce.dll<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-07 22:55&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-09-07 14:13&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Google Updater<br>2008-09-07 14:01&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-09-06 14:30&#9;---------&#9;d-----w&#9;C:\Program Files\Symantec AntiVirus<br>2008-09-06 14:30&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-09-05 03:23&#9;57,344&#9;----a-w&#9;C:\WINDOWS\system32\userinit.exe<br>2008-09-03 16:15&#9;---------&#9;d-----w&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-09-03 03:20&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-09-03 03:19&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-08-11 19:36&#9;---------&#9;d-----w&#9;C:\Documents and Settings\STravis\Application Data\Audacity<br>2008-08-01 11:46&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2008-07-19 02:10&#9;94,920&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\cdm.dll<br>2008-07-19 02:10&#9;94,920&#9;----a-w&#9;C:\WINDOWS\system32\cdm.dll<br>2008-07-19 02:10&#9;53,448&#9;----a-w&#9;C:\WINDOWS\system32\wuauclt.exe<br>2008-07-19 02:10&#9;53,448&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuauclt.exe<br>2008-07-19 02:10&#9;45,768&#9;----a-w&#9;C:\WINDOWS\system32\wups2.dll<br>2008-07-19 02:10&#9;36,552&#9;----a-w&#9;C:\WINDOWS\system32\wups.dll<br>2008-07-19 02:10&#9;36,552&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wups.dll<br>2008-07-19 02:09&#9;563,912&#9;----a-w&#9;C:\WINDOWS\system32\wuapi.dll<br>2008-07-19 02:09&#9;563,912&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuapi.dll<br>2008-07-19 02:09&#9;325,832&#9;----a-w&#9;C:\WINDOWS\system32\wucltui.dll<br>2008-07-19 02:09&#9;325,832&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wucltui.dll<br>2008-07-19 02:09&#9;205,000&#9;----a-w&#9;C:\WINDOWS\system32\wuweb.dll<br>2008-07-19 02:09&#9;205,000&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuweb.dll<br>2008-07-19 02:09&#9;1,811,656&#9;----a-w&#9;C:\WINDOWS\system32\wuaueng.dll<br>2008-07-19 02:09&#9;1,811,656&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuaueng.dll<br>2008-07-07 20:32&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\es.dll<br>2008-07-07 20:32&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\es.dll<br>2008-06-24 16:23&#9;74,240&#9;----a-w&#9;C:\WINDOWS\system32\mscms.dll<br>2008-06-24 16:23&#9;74,240&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mscms.dll<br>2008-06-24 14:57&#9;3,592,192&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mshtml.dll<br>2008-06-23 09:20&#9;70,656&#9;------w&#9;C:\WINDOWS\system32\dllcache\ie4uinit.exe<br>2008-06-23 09:20&#9;625,664&#9;------w&#9;C:\WINDOWS\system32\dllcache\iexplore.exe<br>2008-06-23 09:20&#9;13,824&#9;------w&#9;C:\WINDOWS\system32\dllcache\ieudinit.exe<br>2008-06-21 05:23&#9;161,792&#9;------w&#9;C:\WINDOWS\system32\dllcache\ieakui.dll<br>2008-06-20 17:41&#9;245,248&#9;----a-w&#9;C:\WINDOWS\system32\mswsock.dll<br>2008-06-20 17:41&#9;245,248&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mswsock.dll<br>2008-06-20 17:41&#9;148,992&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\dnsapi.dll<br>2008-06-20 10:45&#9;360,320&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\tcpip.sys<br>2008-06-20 10:44&#9;138,368&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\afd.sys<br>2008-06-20 09:52&#9;225,920&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\tcpip6.sys<br>2008-06-13 13:10&#9;272,128&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\bthport.sys<br>2007-03-05 14:02&#9;24,192&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermptxp.sys<br>2007-03-05 14:02&#9;22,768&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermpt.sys<br>.<br><br>------- Sigcheck -------<br><br>2008-04-13 20:12  26112  a93aee1928a9d7ce3e16d24ec7380f89&#9;C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe<br>2008-09-04 23:23  57344  b5bfcf3c4dfe120d2bb0f9736a17c065&#9;C:\WINDOWS\system32\userinit.exe<br>.<br>(((((((((((((((((((((((((((((   snapshot_2008-09-04_23.47.30.65   )))))))))))))))))))))))))))))))))))))))))<br>.<br>- 2008-09-04 22:07:58&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2008-09-05 04:05:37&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2006-11-02 09:46:05&#9;363,520&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPCDMCLH.DLL<br>+ 2006-11-02 09:46:11&#9;251,904&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFIME50.DLL<br>+ 2006-11-02 09:46:05&#9;19,968&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPFRES50.DLL<br>+ 2006-11-02 09:46:11&#9;1,515,520&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZ3ALHN.DLL<br>+ 2006-11-02 09:46:05&#9;1,253,888&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZ3RLHN.DLL<br>+ 2006-11-02 09:46:11&#9;365,568&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZEVLHN.DLL<br>+ 2006-09-18 21:44:24&#9;562,176&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZSSLHN.DLL<br>+ 2006-09-18 21:44:24&#9;3,447,808&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZSTLHN.DLL<br>+ 2006-11-02 09:46:11&#9;2,725,376&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZUILHN.DLL<br>- 2004-08-04 05:56:48&#9;264,704&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrv.dll<br>+ 2006-11-02 09:46:13&#9;372,736&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRV.DLL<br>- 2004-08-04 05:56:48&#9;197,120&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll<br>+ 2006-11-02 09:46:11&#9;740,864&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRVUI.DLL<br>- 2004-08-04 05:56:36&#9;619,520&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll<br>+ 2006-11-02 09:41:12&#9;761,344&#9;----a-w&#9;C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIRES.DLL<br>.<br>(((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>----a-r           176,128 2005-10-07 04:13:38  C:\Program Files\Apoint\bak\Apoint.exe<br><br>----a-w           153,136 2007-03-09 22:53:56  C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe<br><br>----a-w           153,136 2007-03-12 17:49:26  C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe<br><br>----a-w            52,896 2006-07-20 00:26:04  C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe<br><br>----a-w            49,152 2005-12-10 01:29:52  C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe<br><br>----a-w           389,120 2006-07-17 02:29:54  C:\Program Files\Dell Support\bak\DSAgnt.exe<br><br>----a-w           132,496 2007-09-25 05:11:35  C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe<br><br>----a-w         1,694,208 2004-10-13 16:24:37  C:\Program Files\Messenger\bak\msmsgs.exe<br><br>----a-w         8,720,384 2007-12-19 01:47:24  C:\Program Files\MySpace\IM\bak\MySpaceIM.exe<br><br>----a-w           282,624 2006-09-01 19:57:48  C:\Program Files\QuickTime\bak\qttask.exe<br><br>----a-w           125,168 2006-09-28 01:33:44  C:\Program Files\Symantec AntiVirus\bak\VPTray.exe<br><br>----a-w           166,304 2007-11-07 00:09:54  C:\Program Files\Zune\bak\ZuneLauncher.exe<br>----a-w           158,624 2008-04-29 23:56:20  C:\Program Files\Zune\ZuneLauncher.exe<br><br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\bak\ctfmon.exe<br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\ctfmon.exe<br><br>----a-w            77,824 2005-12-13 07:41:08  C:\WINDOWS\system32\bak\hkcmd.exe<br><br>----a-w           118,784 2005-12-13 07:45:00  C:\WINDOWS\system32\bak\igfxpers.exe<br><br>----a-w            98,304 2005-12-13 07:44:18  C:\WINDOWS\system32\bak\igfxtray.exe<br><br>----a-w         1,347,584 2005-12-19 13:08:42  C:\WINDOWS\system32\bak\WLTRAY.exe<br><br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 C:\WINDOWS\stsystra.exe]<br><br>C:\Documents and Settings\STravis\Start Menu\Programs\Startup\<br>MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-01-29 951640]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-06-16 49152]<br>Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-10-06 24576]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]<br>@="Driver"<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=<br><br>R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]<br>R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]<br>S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9e35fbb-fdda-11dc-934f-0016cf72068b}]<br>\Shell\AutoRun\command - E:\LaunchU3.exe -a<br>.<br>Contents of the 'Scheduled Tasks' folder<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-09-07 19:03:25<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>**************************************************************************<br>.<br>Completion time: 2008-09-07 19:08:33<br>ComboFix-quarantined-files.txt  2008-09-07 23:07:30<br>ComboFix2.txt  2008-09-06 14:49:19<br>ComboFix3.txt  2008-09-05 03:48:56<br>ComboFix4.txt  2008-09-04 03:30:40<br><br>Pre-Run: 40,295,854,080 bytes free<br>Post-Run: 40,281,223,168 bytes free<br><br>171&#9;--- E O F ---&#9;2008-09-06 13:16:35<br><br><b>3.</b>new HijackThis log<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:12:51 PM, on 9/7/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16705)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\WLTRYSVC.EXE<br>C:\WINDOWS\System32\bcmwltry.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>c:\WINDOWS\system32\ZuneBusEnum.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\stsystra.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe<br>C:\WINDOWS\explorer.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.giants.com/index2.html" >www.giants.com/index2.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.dell.com/" >www.dell.com/</A><br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe<br>O4 - Global Startup: Bluetooth Manager.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br>O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br>O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - &raquo;<small>https</small>://<A HREF="https://70.90.17.225/Remote/msrdp.cab">70.90.17.225/Remote/msrdp.cab</A><br>O16 - DPF: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} (NPRemvuPluginControl) - &raquo;<A HREF="http://24.46.98.45:8888/common/NPRemvu.cab" >24.46.98.45:8888/common/NPRemvu.cab</A><br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br><br>--<br>End of file - 5379 bytes<br><br>Will submit the previously mentioned file right now and post back on that.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21072999</guid>
<pubDate>Sun, 07 Sep 2008 20:18:27 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21071850</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : If MBAM or Combofix request or force a reboot, allow them to do so.  Some malware infectors can only be removed during the reboot process, as they are then in an inactive state.<br><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O4 - HKCU\..\Run: [AdmApiCmd] C:\WINDOWS\system32\gbuvidsp.exe</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. We need to run Combofix again.<br><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>" or as above use your Mouse to do a Copy/Paste:<br><textarea name="code" class="text" cols=50 rows=10>File::&#012;C:\WINDOWS\system32\gbuvidsp.exe&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3. Run <b>MBAM</b> again, just as instructed earlier above.  It should report a clean result.<br><br>4. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; You new <b>MBAM</b> log result;<br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The new HijackThis log.<br><br>Now, a favor.  I want you to submit for anlysis this file:<br><br><b>c:\windows\system32\userinit.exe </b><br><br>I regularly submit (on-line) files to be scanned for malware.  These two sites are my favorites, and use multiple AV programs for their scans -- up to 32 different major AV products are used to scan the file:<br><br>&#8226; <b>Jotti's Virus Scan</b><br>&raquo;<A HREF="http://virusscan.jotti.org/" >virusscan.jotti.org/</A><br><br>&#8226; <b>VirusTotal</b><br>&raquo;<A HREF="http://www.virustotal.com/" >www.virustotal.com/</A><br><br>These servers can be busy, but the whole process is surprisingly fast for such extensive AV testing.  There is the added "Good Citizenship" factor -- if the file is found suspicious it automatically alerts the antivirus vendors of a new malware to include in their definition files.<br><br>Submit to both, and report the results back to the Forum.  I appreciate this extra step on your part.<br><br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21071850</guid>
<pubDate>Sun, 07 Sep 2008 16:23:15 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21069135</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : (1)<br>MBAM log results after uninstall old and reinstall new:<br>Malwarebytes' Anti-Malware 1.26<br>Database version: 1120<br>Windows 5.1.2600 Service Pack 2<br><br>9/6/2008 11:42:01 PM<br>mbam-log-2008-09-06 (23-42-01).txt<br><br>Scan type: Full Scan (C:\|)<br>Objects scanned: 92965<br>Time elapsed: 41 minute(s), 51 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 0<br>Registry Values Infected: 0<br>Registry Data Items Infected: 2<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>(No malicious items detected)<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br>(2)<br>Combofix.txt:<br>ComboFix 08-09-04.08 - STravis 2008-09-06 10:40:41.3 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.476 [GMT -4:00]<br>Running from: C:\Documents and Settings\STravis\Desktop\ComboFix.exe<br>Command switches used :: C:\Documents and Settings\STravis\Desktop\CFscript.txt<br> * Created a new restore point<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>C:\Documents and Settings\All Users\Application Data\zehchwhk<br>C:\Documents and Settings\All Users\Application Data\zehchwhk\lyhshubi.exe<br>C:\WINDOWS\system32\fozixwjc.exe<br>C:\WINDOWS\system32\ujyhuhgd.exe<br>C:\WINDOWS\system32\xcxebazm.exe<br>C:\WINDOWS\system32\ynejmroz.exe<br><br>.<br>(((((((((((((((((((((((((   Files Created from 2008-08-06 to 2008-09-06  )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-05 00:04 . 2008-09-06 10:30&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-09-04 23:53 . 2008-09-04 23:53&#9;90,112&#9;--a------&#9;C:\WINDOWS\system32\gbuvidsp.exe<br>2008-09-04 09:51 . 2008-09-04 09:51&#9;&#9;d--------&#9;C:\Program Files\Windows Defender<br>2008-09-04 08:55 . 2008-09-04 08:55&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\STravis\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-02 00:16&#9;38,528&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-03 20:21 . 2008-09-02 00:16&#9;17,200&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-03 19:52 . 2008-09-04 16:18&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-09-03 11:44 . 2008-09-03 15:05&#9;127&#9;--a------&#9;C:\WINDOWS\wininit.ini<br>2008-09-02 23:20 . 2008-09-02 23:20&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\scripting<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\en<br>2008-08-18 16:25 . 2008-08-18 21:18&#9;&#9;d--------&#9;C:\WINDOWS\system32\bits<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\l2schemas<br>2008-08-18 16:17 . 2007-08-10 20:46&#9;33,656&#9;--a------&#9;C:\WINDOWS\system32\sprecovr.exe<br>2008-08-18 16:12 . 2007-02-28 05:53&#9;2,137,600&#9;--a------&#9;C:\WINDOWS\system32\ntoskrnl.exe<br>2008-08-18 15:54 . 2008-04-13 20:12&#9;7,680&#9;--a------&#9;C:\WINDOWS\system32\spdwnwxp.exe<br>2008-08-18 15:52 . 2006-12-28 15:01&#9;19,569&#9;--a------&#9;C:\WINDOWS\[u]0[/u]02942_.tmp<br>2008-08-17 23:17 . 2008-08-19 21:27&#9;&#9;d--------&#9;C:\WINDOWS\system32\CatRoot_bak<br>2008-08-14 22:10 . 2008-05-01 10:30&#9;331,776&#9;---------&#9;C:\WINDOWS\system32\dllcache\msadce.dll<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-06 14:30&#9;---------&#9;d-----w&#9;C:\Program Files\Symantec AntiVirus<br>2008-09-06 14:30&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-09-06 14:30&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-09-06 14:02&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-09-06 13:13&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Google Updater<br>2008-09-05 03:23&#9;57,344&#9;----a-w&#9;C:\WINDOWS\system32\userinit.exe<br>2008-09-03 16:15&#9;---------&#9;d-----w&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-09-03 03:20&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-09-03 03:19&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-08-11 19:36&#9;---------&#9;d-----w&#9;C:\Documents and Settings\STravis\Application Data\Audacity<br>2008-08-01 11:46&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2008-07-19 02:10&#9;94,920&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\cdm.dll<br>2008-07-19 02:10&#9;94,920&#9;----a-w&#9;C:\WINDOWS\system32\cdm.dll<br>2008-07-19 02:10&#9;53,448&#9;----a-w&#9;C:\WINDOWS\system32\wuauclt.exe<br>2008-07-19 02:10&#9;53,448&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuauclt.exe<br>2008-07-19 02:10&#9;45,768&#9;----a-w&#9;C:\WINDOWS\system32\wups2.dll<br>2008-07-19 02:10&#9;36,552&#9;----a-w&#9;C:\WINDOWS\system32\wups.dll<br>2008-07-19 02:10&#9;36,552&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wups.dll<br>2008-07-19 02:09&#9;563,912&#9;----a-w&#9;C:\WINDOWS\system32\wuapi.dll<br>2008-07-19 02:09&#9;563,912&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuapi.dll<br>2008-07-19 02:09&#9;325,832&#9;----a-w&#9;C:\WINDOWS\system32\wucltui.dll<br>2008-07-19 02:09&#9;325,832&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wucltui.dll<br>2008-07-19 02:09&#9;205,000&#9;----a-w&#9;C:\WINDOWS\system32\wuweb.dll<br>2008-07-19 02:09&#9;205,000&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuweb.dll<br>2008-07-19 02:09&#9;1,811,656&#9;----a-w&#9;C:\WINDOWS\system32\wuaueng.dll<br>2008-07-19 02:09&#9;1,811,656&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuaueng.dll<br>2008-07-07 20:32&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\es.dll<br>2008-07-07 20:32&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\es.dll<br>2008-06-24 16:23&#9;74,240&#9;----a-w&#9;C:\WINDOWS\system32\mscms.dll<br>2008-06-24 16:23&#9;74,240&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mscms.dll<br>2008-06-24 14:57&#9;3,592,192&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mshtml.dll<br>2008-06-23 09:20&#9;70,656&#9;------w&#9;C:\WINDOWS\system32\dllcache\ie4uinit.exe<br>2008-06-23 09:20&#9;625,664&#9;------w&#9;C:\WINDOWS\system32\dllcache\iexplore.exe<br>2008-06-23 09:20&#9;13,824&#9;------w&#9;C:\WINDOWS\system32\dllcache\ieudinit.exe<br>2008-06-21 05:23&#9;161,792&#9;------w&#9;C:\WINDOWS\system32\dllcache\ieakui.dll<br>2008-06-20 17:41&#9;245,248&#9;----a-w&#9;C:\WINDOWS\system32\mswsock.dll<br>2008-06-20 17:41&#9;245,248&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mswsock.dll<br>2008-06-20 17:41&#9;148,992&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\dnsapi.dll<br>2008-06-20 10:45&#9;360,320&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\tcpip.sys<br>2008-06-20 10:44&#9;138,368&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\afd.sys<br>2008-06-20 09:52&#9;225,920&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\tcpip6.sys<br>2008-06-13 13:10&#9;272,128&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\bthport.sys<br>2007-03-05 14:02&#9;24,192&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermptxp.sys<br>2007-03-05 14:02&#9;22,768&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermpt.sys<br>.<br><br>------- Sigcheck -------<br><br>2008-04-13 20:12  26112  a93aee1928a9d7ce3e16d24ec7380f89&#9;C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe<br>2008-09-04 23:23  57344  b5bfcf3c4dfe120d2bb0f9736a17c065&#9;C:\WINDOWS\system32\userinit.exe<br>.<br>(((((((((((((((((((((((((((((   snapshot_2008-09-04_23.47.30.65   )))))))))))))))))))))))))))))))))))))))))<br>.<br>- 2008-09-04 22:07:58&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2008-09-05 04:05:37&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>.<br>(((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>----a-r           176,128 2005-10-07 04:13:38  C:\Program Files\Apoint\bak\Apoint.exe<br><br>----a-w           153,136 2007-03-09 22:53:56  C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe<br><br>----a-w           153,136 2007-03-12 17:49:26  C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe<br><br>----a-w            52,896 2006-07-20 00:26:04  C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe<br><br>----a-w            49,152 2005-12-10 01:29:52  C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe<br><br>----a-w           389,120 2006-07-17 02:29:54  C:\Program Files\Dell Support\bak\DSAgnt.exe<br><br>----a-w           132,496 2007-09-25 05:11:35  C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe<br><br>----a-w         1,694,208 2004-10-13 16:24:37  C:\Program Files\Messenger\bak\msmsgs.exe<br><br>----a-w         8,720,384 2007-12-19 01:47:24  C:\Program Files\MySpace\IM\bak\MySpaceIM.exe<br><br>----a-w           282,624 2006-09-01 19:57:48  C:\Program Files\QuickTime\bak\qttask.exe<br><br>----a-w           125,168 2006-09-28 01:33:44  C:\Program Files\Symantec AntiVirus\bak\VPTray.exe<br><br>----a-w           166,304 2007-11-07 00:09:54  C:\Program Files\Zune\bak\ZuneLauncher.exe<br>----a-w           158,624 2008-04-29 23:56:20  C:\Program Files\Zune\ZuneLauncher.exe<br><br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\bak\ctfmon.exe<br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\ctfmon.exe<br><br>----a-w            77,824 2005-12-13 07:41:08  C:\WINDOWS\system32\bak\hkcmd.exe<br><br>----a-w           118,784 2005-12-13 07:45:00  C:\WINDOWS\system32\bak\igfxpers.exe<br><br>----a-w            98,304 2005-12-13 07:44:18  C:\WINDOWS\system32\bak\igfxtray.exe<br><br>----a-w         1,347,584 2005-12-19 13:08:42  C:\WINDOWS\system32\bak\WLTRAY.exe<br><br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br>"AdmApiCmd"="C:\WINDOWS\system32\gbuvidsp.exe" [2008-09-04 90112]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 C:\WINDOWS\stsystra.exe]<br><br>C:\Documents and Settings\STravis\Start Menu\Programs\Startup\<br>MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-01-29 951640]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-06-16 49152]<br>Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-10-06 24576]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]<br>@="Driver"<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=<br><br>R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]<br>R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]<br>S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9e35fbb-fdda-11dc-934f-0016cf72068b}]<br>\Shell\AutoRun\command - E:\LaunchU3.exe -a<br><br>*Newly Created Service* - ERASERUTILDRV10822<br>*Newly Created Service* - NAVENG<br>*Newly Created Service* - NAVEX15<br>*Newly Created Service* - SAVRT<br>*Newly Created Service* - SAVRTPEL<br>*Newly Created Service* - SPBBCDRV<br>*Newly Created Service* - SYMEVENT<br>*Newly Created Service* - SYMREDRV<br>.<br>Contents of the 'Scheduled Tasks' folder<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>Notify-NavLogon - (no file)<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-09-06 10:43:31<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>PROCESS: C:\WINDOWS\system32\winlogon.exe<br>-> C:\WINDOWS\system32\NavLogon.dll<br>.<br>Completion time: 2008-09-06 10:49:18<br>ComboFix-quarantined-files.txt  2008-09-06 14:48:15<br>ComboFix2.txt  2008-09-05 03:48:56<br>ComboFix3.txt  2008-09-04 03:30:40<br><br>Pre-Run: 40,361,709,568 bytes free<br>Post-Run: 40,347,242,496 bytes free<br><br>179&#9;--- E O F ---&#9;2008-09-06 13:16:35<br><br>(3)<br>New HijackThis log:<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 11:43:26 PM, on 9/6/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16705)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\WLTRYSVC.EXE<br>C:\WINDOWS\System32\bcmwltry.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>c:\WINDOWS\system32\ZuneBusEnum.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\system32\userinit.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\stsystra.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\WINDOWS\system32\gbuvidsp.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.giants.com/index2.html" >www.giants.com/index2.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.dell.com/" >www.dell.com/</A><br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [AdmApiCmd] C:\WINDOWS\system32\gbuvidsp.exe<br>O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe<br>O4 - Global Startup: Bluetooth Manager.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br>O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br>O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - &raquo;<small>https</small>://<A HREF="https://70.90.17.225/Remote/msrdp.cab">70.90.17.225/Remote/msrdp.cab</A><br>O16 - DPF: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} (NPRemvuPluginControl) - &raquo;<A HREF="http://24.46.98.45:8888/common/NPRemvu.cab" >24.46.98.45:8888/common/NPRemvu.cab</A><br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br><br>--<br>End of file - 5575 bytes<br><br>FYI: as I clicked spell check before hitting post now the security alert graphic popped up like in my first post. Oy!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21069135</guid>
<pubDate>Sat, 06 Sep 2008 23:54:20 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21068174</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : I found the combofix.txt file so I am OK on that but am still concerned on the reboot. Have stopped at that part. Did not reboor or download a fresh copy of malwarebytes yet.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21068174</guid>
<pubDate>Sat, 06 Sep 2008 13:12:35 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21067663</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : ISSUE!<br><br>Procedure went fine up to this point:<br><br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br><b>&#149;!&#149; A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.</b><br><br>!! When the CF scan completed I did File and Exit but did NOT get a the "save changes" question. The log simply blinked away. There is a log.txt file in My Documents but it is dated 9/4/08 and I can only assume it is from the pre-cleanup procedures.<br><br>Might that log.txt be somewhere else? I will look but I am not going to perform any more scans until I hear back.<br><br>EDIT: no current log.txt and Malwarebytes asks for a reboot to finish the uninstall of current installation. Will a reboot be OK?<br><br>Also, since the AV is managed by the main corporate office there is no disable feature so I simply uninstalled it and will reinstall once the machine is clean. It found no issues when this all began so I am less than thrilled with it to begin with. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21067663</guid>
<pubDate>Sat, 06 Sep 2008 11:02:44 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21062367</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : #1. We should be able to clean this completely without major trauma (or surgery).<br><br>#2. This malware infection does not spread through network shares.  Your home network machines will be fine.<br><br>Best regards,<br>Bill Castner<br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21062367</guid>
<pubDate>Fri, 05 Sep 2008 12:37:17 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21061924</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : Thank you so much for responding. I have printed out your instructions and will follow them exactly as written.<br><br>1. I have to do this tonight since we are at work now and prying eyes won't allow this to happen just yet.<br><br>2. This is a vital office laptop - what are the chances, even if I follow the steps explicitly - that it will die a sorry death. A format will effect both my co workers and my job status. As it is, the employee who caused this to happen ( used the computer and stopped all virus/malware protection) will be fired. Before that happens I need to ascertain a date if possible.<br><br>3. Once I bring this laptop home I need to allow it access to my wireless network. Should I be worried about my home machines which have virus protection as well as several malware protection apps in real time.<br><br>FYI - our work computers came with the Symantec client which we are not allowed to uninstall. I prefer AVG but that is not going to happen. We all run SpyBot on a daily schedule as well as AdAware on a daily basis. I insist on it or I will not clean the computers. I will now be running ESET also as recommended by lilhurricane. CCleaner is run before shutdown each night.<br><br>I will post back once I have completed your instructions.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21061924</guid>
<pubDate>Fri, 05 Sep 2008 11:16:32 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21061477</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : <b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>Please download<b>  <i>ATF Cleaner</i></b> <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><br><b>First Step:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows XP to show hidden files:</b><br><i>To enable the viewing of Hidden files follow these steps: </i><br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Double-click on the My Computer icon. <br>&#8226; Select the Tools menu and click Folder Options. <br>&#8226; After the new window appears select the View tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <br><br>TeaTimer is an excellent tool for the prevention of spyware but it can sometimes prevent HijackThis from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.<br>&#8226; Open Spybot Search & Destroy.<br>&#8226; In the Mode menu click "Advanced mode" if not already selected.<br>&#8226; Choose Yes at the Warning prompt.<br>&#8226; Expand the Tools menu.<br>&#8226; Click Resident.<br>&#8226; <b>Uncheck</b> the Resident "TeaTimer" (Protection of overall system settings) active. box.<br>&#8226; In the File menu click Exit to exit Spybot Search & Destroy.<br>&#8226; Download and Unzip to your Desktop:  &raquo;<A HREF="http://www.techsupportforum.com/sectools/ResetTeaTimer.zip" >www.techsupportforum.com/sectool&middot;&middot;&middot;imer.zip</A><br>&#8226; Double click <b>ResetTeaTimer.bat</b> to remove all entries set by TeaTimer.<br><br><b><u>Malware Removal Steps</u></b><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O4 - HKCU\..\Run: [ApiSrv] C:\WINDOWS\system32\fozixwjc.exe<br>O4 - HKCU\..\Run: [cmdinfo] C:\WINDOWS\system32\ujyhuhgd.exe<br>O4 - HKCU\..\Run: [setsh] C:\WINDOWS\system32\xcxebazm.exe<br>O4 - HKLM\..\Policies\Explorer\Run: [iQkkP4fm85] C:\Documents and Settings\All Users\Application Data\zehchwhk\lyhshubi.exe</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download -- but <i>do not</i> yet run  -- <b>ComboFix&copy; </b> <br><br>Download this file <b><u>-- to your Desktop --</u></b>  from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>" or use your Mouse to do a Copy/Paste:<br><textarea name="code" class="text" cols=50 rows=10>Registry::&#012;&#91;HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run&#93;&#012;"iQkkP4fm85"=-&#012; &#012;Folder::&#012;C:\Documents and Settings\All Users\Application Data\zehchwhk&#012; &#012;File::&#012;C:\WINDOWS\system32\ynejmroz.exe&#012;C:\WINDOWS\system32\xcxebazm.exe&#012;C:\WINDOWS\system32\ujyhuhgd.exe&#012;C:\WINDOWS\system32\fozixwjc.exe&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Be sure your Notepad document now matches what you see in the Code Box.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:  </b> Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3. Use Add or Remove Programs and <b>Uninstall</b> your current installation of Malwarebyte's Anti-malware.  Then please download MalwareBytes Anti-malware (MBAM) again  from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is <b>Un-</b>selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>4. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The <b>MBAM</b> log results;<br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21061477</guid>
<pubDate>Fri, 05 Sep 2008 09:42:34 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21060277</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : Fresh combofix log ran in Safe Mode:<br><br>ComboFix 08-09-04.08 - STravis 2008-09-04 23:38:46.2 - NTFSx86 MINIMAL<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.784 [GMT -4:00]<br>Running from: C:\Documents and Settings\STravis\Desktop\ComboFix.exe<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((   Files Created from 2008-08-05 to 2008-09-05  )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-04 18:07 . 2006-09-18 17:55&#9;109,744&#9;--a------&#9;C:\WINDOWS\system32\drivers\SYMEVENT.SYS<br>2008-09-04 18:07 . 2006-09-18 17:55&#9;48,816&#9;--a------&#9;C:\WINDOWS\system32\S32EVNT1.DLL<br>2008-09-04 18:06 . 2008-09-04 18:07&#9;&#9;d--------&#9;C:\Program Files\Symantec<br>2008-09-04 18:04 . 2008-09-04 18:04&#9;94,208&#9;--a------&#9;C:\WINDOWS\system32\ynejmroz.exe<br>2008-09-04 10:12 . 2008-09-04 10:12&#9;94,208&#9;--a------&#9;C:\WINDOWS\system32\xcxebazm.exe<br>2008-09-04 09:51 . 2008-09-04 09:51&#9;&#9;d--------&#9;C:\Program Files\Windows Defender<br>2008-09-04 08:55 . 2008-09-04 08:55&#9;&#9;d--------&#9;C:\Program Files\Trend Micro<br>2008-09-03 21:44 . 2008-09-03 21:44&#9;86,016&#9;--a------&#9;C:\WINDOWS\system32\ujyhuhgd.exe<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\STravis\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-02 00:16&#9;38,528&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-03 20:21 . 2008-09-02 00:16&#9;17,200&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-03 19:52 . 2008-09-04 16:18&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-09-03 11:44 . 2008-09-03 15:05&#9;127&#9;--a------&#9;C:\WINDOWS\wininit.ini<br>2008-09-02 23:20 . 2008-09-02 23:20&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-09-02 23:06 . 2008-09-02 23:06&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\zehchwhk<br>2008-09-02 23:06 . 2008-09-02 23:06&#9;81,920&#9;--a------&#9;C:\WINDOWS\system32\fozixwjc.exe<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\scripting<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\en<br>2008-08-18 16:25 . 2008-08-18 21:18&#9;&#9;d--------&#9;C:\WINDOWS\system32\bits<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\l2schemas<br>2008-08-18 16:17 . 2007-08-10 20:46&#9;33,656&#9;--a------&#9;C:\WINDOWS\system32\sprecovr.exe<br>2008-08-18 16:12 . 2007-02-28 05:53&#9;2,137,600&#9;--a------&#9;C:\WINDOWS\system32\ntoskrnl.exe<br>2008-08-18 15:54 . 2008-04-13 20:12&#9;7,680&#9;--a------&#9;C:\WINDOWS\system32\spdwnwxp.exe<br>2008-08-18 15:52 . 2006-12-28 15:01&#9;19,569&#9;--a------&#9;C:\WINDOWS\[u]0[/u]02942_.tmp<br>2008-08-17 23:17 . 2008-08-19 21:27&#9;&#9;d--------&#9;C:\WINDOWS\system32\CatRoot_bak<br>2008-08-14 22:10 . 2008-05-01 10:30&#9;331,776&#9;---------&#9;C:\WINDOWS\system32\dllcache\msadce.dll<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-05 03:34&#9;---------&#9;d-----w&#9;C:\Program Files\Symantec AntiVirus<br>2008-09-05 03:28&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Google Updater<br>2008-09-05 03:23&#9;57,344&#9;----a-w&#9;C:\WINDOWS\system32\userinit.exe<br>2008-09-05 02:54&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-09-04 22:08&#9;---------&#9;d-----w&#9;C:\Program Files\Common Files\Symantec Shared<br>2008-09-04 22:06&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Symantec<br>2008-09-03 16:15&#9;---------&#9;d-----w&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-09-03 03:20&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-09-03 03:19&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-08-11 19:36&#9;---------&#9;d-----w&#9;C:\Documents and Settings\STravis\Application Data\Audacity<br>2008-08-01 11:46&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2008-07-19 02:10&#9;94,920&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\cdm.dll<br>2008-07-19 02:10&#9;94,920&#9;----a-w&#9;C:\WINDOWS\system32\cdm.dll<br>2008-07-19 02:10&#9;53,448&#9;----a-w&#9;C:\WINDOWS\system32\wuauclt.exe<br>2008-07-19 02:10&#9;53,448&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuauclt.exe<br>2008-07-19 02:10&#9;45,768&#9;----a-w&#9;C:\WINDOWS\system32\wups2.dll<br>2008-07-19 02:10&#9;36,552&#9;----a-w&#9;C:\WINDOWS\system32\wups.dll<br>2008-07-19 02:10&#9;36,552&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wups.dll<br>2008-07-19 02:09&#9;563,912&#9;----a-w&#9;C:\WINDOWS\system32\wuapi.dll<br>2008-07-19 02:09&#9;563,912&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuapi.dll<br>2008-07-19 02:09&#9;325,832&#9;----a-w&#9;C:\WINDOWS\system32\wucltui.dll<br>2008-07-19 02:09&#9;325,832&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wucltui.dll<br>2008-07-19 02:09&#9;205,000&#9;----a-w&#9;C:\WINDOWS\system32\wuweb.dll<br>2008-07-19 02:09&#9;205,000&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuweb.dll<br>2008-07-19 02:09&#9;1,811,656&#9;----a-w&#9;C:\WINDOWS\system32\wuaueng.dll<br>2008-07-19 02:09&#9;1,811,656&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\wuaueng.dll<br>2008-07-07 20:32&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\es.dll<br>2008-07-07 20:32&#9;253,952&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\es.dll<br>2008-06-24 16:23&#9;74,240&#9;----a-w&#9;C:\WINDOWS\system32\mscms.dll<br>2008-06-24 16:23&#9;74,240&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mscms.dll<br>2008-06-24 14:57&#9;3,592,192&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mshtml.dll<br>2008-06-23 09:20&#9;70,656&#9;------w&#9;C:\WINDOWS\system32\dllcache\ie4uinit.exe<br>2008-06-23 09:20&#9;625,664&#9;------w&#9;C:\WINDOWS\system32\dllcache\iexplore.exe<br>2008-06-23 09:20&#9;13,824&#9;------w&#9;C:\WINDOWS\system32\dllcache\ieudinit.exe<br>2008-06-21 05:23&#9;161,792&#9;------w&#9;C:\WINDOWS\system32\dllcache\ieakui.dll<br>2008-06-20 17:41&#9;245,248&#9;----a-w&#9;C:\WINDOWS\system32\mswsock.dll<br>2008-06-20 17:41&#9;245,248&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\mswsock.dll<br>2008-06-20 17:41&#9;148,992&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\dnsapi.dll<br>2008-06-20 10:45&#9;360,320&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\tcpip.sys<br>2008-06-20 10:44&#9;138,368&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\afd.sys<br>2008-06-20 09:52&#9;225,920&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\tcpip6.sys<br>2008-06-13 13:10&#9;272,128&#9;----a-w&#9;C:\WINDOWS\system32\dllcache\bthport.sys<br>2007-03-05 14:02&#9;24,192&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermptxp.sys<br>2007-03-05 14:02&#9;22,768&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermpt.sys<br>.<br><br>------- Sigcheck -------<br><br>2008-04-13 20:12  26112  a93aee1928a9d7ce3e16d24ec7380f89&#9;C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe<br>2008-09-04 23:23  57344  b5bfcf3c4dfe120d2bb0f9736a17c065&#9;C:\WINDOWS\system32\userinit.exe<br>.<br>(((((((((((((((((((((((((((((   snapshot@2008-09-03_23.29.04.62   )))))))))))))))))))))))))))))))))))))))))<br>.<br>- 2008-03-04 21:11:41&#9;25,214&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\ARPPRODUCTICON.exe<br>+ 2008-09-04 22:07:58&#9;25,214&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\ARPPRODUCTICON.exe<br>- 2008-03-04 21:11:39&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2008-09-04 22:07:58&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>- 2008-03-04 21:11:40&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\NewShortcut1.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>+ 2008-09-04 22:07:58&#9;40,960&#9;----a-r&#9;C:\WINDOWS\Installer\{33CFCF98-F8D6-4549-B469-6F4295676D83}\NewShortcut1.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exe<br>- 2006-09-28 01:35:04&#9;34,600&#9;----a-w&#9;C:\WINDOWS\system32\cba.dll<br>+ 2006-09-28 00:35:04&#9;34,600&#9;----a-w&#9;C:\WINDOWS\system32\cba.dll<br>- 2006-08-07 21:01:56&#9;12,992&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symdns.sys<br>+ 2006-08-07 20:01:56&#9;12,992&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symdns.sys<br>- 2006-08-07 21:02:02&#9;110,784&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symfw.sys<br>+ 2006-08-07 20:02:02&#9;110,784&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symfw.sys<br>- 2006-08-07 21:02:18&#9;31,936&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symids.sys<br>+ 2006-08-07 20:02:18&#9;31,936&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symids.sys<br>- 2006-08-07 21:02:14&#9;28,352&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symndis.sys<br>+ 2006-08-07 20:02:14&#9;28,352&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symndis.sys<br>- 2006-08-07 21:02:22&#9;24,768&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symredrv.sys<br>+ 2006-08-07 20:02:22&#9;24,768&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symredrv.sys<br>- 2006-08-07 21:02:26&#9;195,776&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symtdi.sys<br>+ 2006-08-07 20:02:26&#9;195,776&#9;----a-w&#9;C:\WINDOWS\system32\drivers\symtdi.sys<br>+ 2004-08-04 10:00:00&#9;24,576&#9;----a-w&#9;C:\WINDOWS\system32\init32.exe<br>- 2007-03-15 22:19:28&#9;1,476,992&#9;------w&#9;C:\WINDOWS\system32\LegitCheckControl.dll<br>+ 2008-03-20 22:06:36&#9;1,480,232&#9;----a-w&#9;C:\WINDOWS\system32\LegitCheckControl.DLL<br>- 2006-09-28 01:35:04&#9;83,696&#9;----a-w&#9;C:\WINDOWS\system32\loc32vc0.dll<br>+ 2006-09-28 00:35:04&#9;83,696&#9;----a-w&#9;C:\WINDOWS\system32\loc32vc0.dll<br>- 2003-03-19 03:12:12&#9;1,047,552&#9;----a-w&#9;C:\WINDOWS\system32\mfc71u.dll<br>+ 2003-03-19 02:12:12&#9;1,047,552&#9;----a-w&#9;C:\WINDOWS\system32\mfc71u.dll<br>- 2008-08-05 18:11:01&#9;15,888,504&#9;----a-w&#9;C:\WINDOWS\system32\MRT.exe<br>+ 2008-08-05 15:11:02&#9;15,888,504&#9;----a-w&#9;C:\WINDOWS\system32\MRT.exe<br>- 2006-09-28 01:35:06&#9;46,896&#9;----a-w&#9;C:\WINDOWS\system32\msgsys.dll<br>+ 2006-09-28 00:35:06&#9;46,896&#9;----a-w&#9;C:\WINDOWS\system32\msgsys.dll<br>- 2006-09-28 01:33:54&#9;43,760&#9;----a-w&#9;C:\WINDOWS\system32\NavLogon.dll<br>+ 2006-09-28 00:33:54&#9;43,760&#9;----a-w&#9;C:\WINDOWS\system32\NavLogon.dll<br>- 2006-09-28 01:35:06&#9;83,752&#9;----a-w&#9;C:\WINDOWS\system32\nts.dll<br>+ 2006-09-28 00:35:06&#9;83,752&#9;----a-w&#9;C:\WINDOWS\system32\nts.dll<br>- 2006-09-28 01:35:08&#9;83,752&#9;----a-w&#9;C:\WINDOWS\system32\pds.dll<br>+ 2006-09-28 00:35:08&#9;83,752&#9;----a-w&#9;C:\WINDOWS\system32\pds.dll<br>- 2006-08-07 21:02:32&#9;534,208&#9;----a-w&#9;C:\WINDOWS\system32\SymNeti.dll<br>+ 2006-08-07 20:02:32&#9;534,208&#9;----a-w&#9;C:\WINDOWS\system32\SymNeti.dll<br>- 2006-08-07 21:02:30&#9;161,472&#9;----a-w&#9;C:\WINDOWS\system32\SymRedir.dll<br>+ 2006-08-07 20:02:30&#9;161,472&#9;----a-w&#9;C:\WINDOWS\system32\SymRedir.dll<br>.<br>-- Snapshot reset to current date --<br>.<br>(((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>----a-r           176,128 2005-10-07 04:13:38  C:\Program Files\Apoint\bak\Apoint.exe<br><br>----a-w           153,136 2007-03-09 22:53:56  C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe<br><br>----a-w           153,136 2007-03-12 17:49:26  C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe<br><br>----a-w            52,896 2006-07-20 00:26:04  C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe<br>----a-w            52,896 2006-07-19 23:26:04  C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br><br>----a-w            49,152 2005-12-10 01:29:52  C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe<br><br>----a-w           389,120 2006-07-17 02:29:54  C:\Program Files\Dell Support\bak\DSAgnt.exe<br><br>----a-w           132,496 2007-09-25 05:11:35  C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe<br><br>----a-w         1,694,208 2004-10-13 16:24:37  C:\Program Files\Messenger\bak\msmsgs.exe<br><br>----a-w         8,720,384 2007-12-19 01:47:24  C:\Program Files\MySpace\IM\bak\MySpaceIM.exe<br><br>----a-w           282,624 2006-09-01 19:57:48  C:\Program Files\QuickTime\bak\qttask.exe<br><br>----a-w           125,168 2006-09-28 01:33:44  C:\Program Files\Symantec AntiVirus\bak\VPTray.exe<br>----a-w           125,168 2006-09-28 00:33:44  C:\Program Files\Symantec AntiVirus\VPTray.exe<br><br>----a-w           166,304 2007-11-07 00:09:54  C:\Program Files\Zune\bak\ZuneLauncher.exe<br>----a-w           158,624 2008-04-29 23:56:20  C:\Program Files\Zune\ZuneLauncher.exe<br><br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\bak\ctfmon.exe<br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\ctfmon.exe<br><br>----a-w            77,824 2005-12-13 07:41:08  C:\WINDOWS\system32\bak\hkcmd.exe<br><br>----a-w           118,784 2005-12-13 07:45:00  C:\WINDOWS\system32\bak\igfxpers.exe<br><br>----a-w            98,304 2005-12-13 07:44:18  C:\WINDOWS\system32\bak\igfxtray.exe<br><br>----a-w         1,347,584 2005-12-19 13:08:42  C:\WINDOWS\system32\bak\WLTRAY.exe<br><br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br>"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]<br>"ApiSrv"="C:\WINDOWS\system32\fozixwjc.exe" [2008-09-02 81920]<br>"cmdinfo"="C:\WINDOWS\system32\ujyhuhgd.exe" [2008-09-03 86016]<br>"setsh"="C:\WINDOWS\system32\xcxebazm.exe" [2008-09-04 94208]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]<br>"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]<br>"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 C:\WINDOWS\stsystra.exe]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]<br>"iQkkP4fm85"="C:\Documents and Settings\All Users\Application Data\zehchwhk\lyhshubi.exe" [2008-09-02 65536]<br><br>C:\Documents and Settings\STravis\Start Menu\Programs\Startup\<br>MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-01-29 951640]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-06-16 49152]<br>Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-10-06 24576]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]<br>@="Driver"<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=<br><br>R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]<br>S2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]<br>S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9e35fbb-fdda-11dc-934f-0016cf72068b}]<br>\Shell\AutoRun\command - E:\LaunchU3.exe -a<br><br>*Newly Created Service* - MDMXSDK<br>.<br>Contents of the 'Scheduled Tasks' folder<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>R0 -: HKCU-Main,Start Page = hxxp://www.dell.com<br>R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.dell.com/<br><br>O16 -: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} - hxxp://24.46.98.45:8888/common/NPRemvu.cab<br>C:\WINDOWS\Downloaded Program Files\NPRemvu.inf<br>C:\WINDOWS\NPRemvu.ocx<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-09-04 23:42:37<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>**************************************************************************<br>.<br>Completion time: 2008-09-04 23:48:55<br>ComboFix-quarantined-files.txt  2008-09-05 03:47:52<br>ComboFix2.txt  2008-09-04 03:30:40<br><br>Pre-Run: 37,492,264,960 bytes free<br>Post-Run: 37,495,316,480 bytes free<br><br>219&#9;--- E O F ---&#9;2008-09-03 19:06:11]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21060277</guid>
<pubDate>Thu, 04 Sep 2008 23:59:04 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21059839</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : Combofix log:<br><br>ComboFix 08-09-03.02 - STravis 2008-09-03 22:58:17.1 - NTFSx86 MINIMAL<br>Running from: C:\Documents and Settings\STravis\My Documents\ComboFix.exe<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((   Files Created from 2008-08-04 to 2008-09-04  )))))))))))))))))))))))))))))))<br>.<br><br>2008-09-03 21:44 . 2008-09-03 21:44&#9;86,016&#9;--a------&#9;C:\WINDOWS\system32\ujyhuhgd.exe<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Program Files\Malwarebytes' Anti-Malware<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\STravis\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-03 20:21&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-09-03 20:21 . 2008-09-02 00:16&#9;38,528&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbamswissarmy.sys<br>2008-09-03 20:21 . 2008-09-02 00:16&#9;17,200&#9;--a------&#9;C:\WINDOWS\system32\drivers\mbam.sys<br>2008-09-03 19:52 . 2008-09-03 19:54&#9;&#9;d--------&#9;C:\Program Files\EsetOnlineScanner<br>2008-09-03 11:44 . 2008-09-03 15:05&#9;127&#9;--a------&#9;C:\WINDOWS\wininit.ini<br>2008-09-02 23:20 . 2008-09-02 23:20&#9;&#9;d--------&#9;C:\Program Files\Common Files\Wise Installation Wizard<br>2008-09-02 23:06 . 2008-09-02 23:06&#9;&#9;d--------&#9;C:\Documents and Settings\All Users\Application Data\zehchwhk<br>2008-09-02 23:06 . 2008-09-02 23:06&#9;81,920&#9;--a------&#9;C:\WINDOWS\system32\fozixwjc.exe<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\scripting<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\system32\en<br>2008-08-18 16:25 . 2008-08-18 21:18&#9;&#9;d--------&#9;C:\WINDOWS\system32\bits<br>2008-08-18 16:25 . 2008-08-18 16:25&#9;&#9;d--------&#9;C:\WINDOWS\l2schemas<br>2008-08-18 16:17 . 2007-08-10 20:46&#9;33,656&#9;--a------&#9;C:\WINDOWS\system32\sprecovr.exe<br>2008-08-18 16:12 . 2007-02-28 05:53&#9;2,137,600&#9;--a------&#9;C:\WINDOWS\system32\ntoskrnl.exe<br>2008-08-18 15:54 . 2008-04-13 20:12&#9;7,680&#9;--a------&#9;C:\WINDOWS\system32\spdwnwxp.exe<br>2008-08-18 15:52 . 2006-12-28 15:01&#9;19,569&#9;--a------&#9;C:\WINDOWS\[u]0[/u]02942_.tmp<br>2008-08-17 23:17 . 2008-08-19 21:27&#9;&#9;d--------&#9;C:\WINDOWS\system32\CatRoot_bak<br>2008-08-14 22:10 . 2008-05-01 10:30&#9;331,776&#9;---------&#9;C:\WINDOWS\system32\dllcache\msadce.dll<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-09-04 02:53&#9;---------&#9;d-----w&#9;C:\Program Files\Symantec AntiVirus<br>2008-09-04 02:28&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Google Updater<br>2008-09-03 23:14&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-09-03 16:15&#9;---------&#9;d-----w&#9;C:\Program Files\Spybot - Search & Destroy<br>2008-09-03 03:20&#9;---------&#9;d-----w&#9;C:\Program Files\Lavasoft<br>2008-09-03 03:19&#9;---------&#9;d-----w&#9;C:\Documents and Settings\All Users\Application Data\Lavasoft<br>2008-08-11 19:36&#9;---------&#9;d-----w&#9;C:\Documents and Settings\STravis\Application Data\Audacity<br>2008-08-01 11:46&#9;---------&#9;d-----w&#9;C:\Program Files\Google<br>2007-03-05 14:02&#9;24,192&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermptxp.sys<br>2007-03-05 14:02&#9;22,768&#9;----a-w&#9;C:\Documents and Settings\STravis\usbsermpt.sys<br>.<br><br>(((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>----a-r           176,128 2005-10-07 04:13:38  C:\Program Files\Apoint\bak\Apoint.exe<br><br>----a-w           153,136 2007-03-09 22:53:56  C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe<br><br>----a-w           153,136 2007-03-12 17:49:26  C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe<br><br>----a-w            52,896 2006-07-20 00:26:04  C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe<br>----a-w            52,896 2006-07-20 00:26:04  C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br><br>----a-w            49,152 2005-12-10 01:29:52  C:\Program Files\CyberLink\PowerDVD\bak\DVDLauncher.exe<br><br>----a-w           389,120 2006-07-17 02:29:54  C:\Program Files\Dell Support\bak\DSAgnt.exe<br><br>----a-w           132,496 2007-09-25 05:11:35  C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe<br><br>----a-w         1,694,208 2004-10-13 16:24:37  C:\Program Files\Messenger\bak\msmsgs.exe<br><br>----a-w         8,720,384 2007-12-19 01:47:24  C:\Program Files\MySpace\IM\bak\MySpaceIM.exe<br><br>----a-w           282,624 2006-09-01 19:57:48  C:\Program Files\QuickTime\bak\qttask.exe<br><br>----a-w           125,168 2006-09-28 01:33:44  C:\Program Files\Symantec AntiVirus\bak\VPTray.exe<br>----a-w           125,168 2006-09-28 01:33:44  C:\Program Files\Symantec AntiVirus\VPTray.exe<br><br>----a-w           166,304 2007-11-07 00:09:54  C:\Program Files\Zune\bak\ZuneLauncher.exe<br>----a-w           158,624 2008-04-29 23:56:20  C:\Program Files\Zune\ZuneLauncher.exe<br><br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\bak\ctfmon.exe<br>----a-w            15,360 2004-08-04 10:00:00  C:\WINDOWS\system32\ctfmon.exe<br><br>----a-w            77,824 2005-12-13 07:41:08  C:\WINDOWS\system32\bak\hkcmd.exe<br><br>----a-w           118,784 2005-12-13 07:45:00  C:\WINDOWS\system32\bak\igfxpers.exe<br><br>----a-w            98,304 2005-12-13 07:44:18  C:\WINDOWS\system32\bak\igfxtray.exe<br><br>----a-w         1,347,584 2005-12-19 13:08:42  C:\WINDOWS\system32\bak\WLTRAY.exe<br><br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]<br>"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]<br>"ApiSrv"="C:\WINDOWS\system32\fozixwjc.exe" [2008-09-02 81920]<br>"cmdinfo"="C:\WINDOWS\system32\ujyhuhgd.exe" [2008-09-03 86016]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]<br>"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]<br>"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 C:\WINDOWS\stsystra.exe]<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]<br>"iQkkP4fm85"="C:\Documents and Settings\All Users\Application Data\zehchwhk\lyhshubi.exe" [2008-09-02 65536]<br><br>C:\Documents and Settings\STravis\Start Menu\Programs\Startup\<br>MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-01-29 951640]<br><br>C:\Documents and Settings\All Users\Start Menu\Programs\Startup\<br>Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-06-16 49152]<br>Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-10-06 24576]<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]<br>@="Driver"<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=<br>"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=<br><br>R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]<br>R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]<br>S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9e35fbb-fdda-11dc-934f-0016cf72068b}]<br>\Shell\AutoRun\command - E:\LaunchU3.exe -a<br>.<br>Contents of the 'Scheduled Tasks' folder<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>Notify-dimsntfy - (no file)<br><br>.<br>------- Supplementary Scan -------<br>.<br>R0 -: HKCU-Main,Start Page = hxxp://www.dell.com<br>R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.dell.com/<br>O8 -: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html<br>O8 -: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html<br>O8 -: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html<br>O8 -: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html<br>O8 -: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html<br>O8 -: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html<br><br>O16 -: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} - hxxp://24.46.98.45:8888/common/NPRemvu.cab<br>C:\WINDOWS\Downloaded Program Files\NPRemvu.inf<br>C:\WINDOWS\NPRemvu.ocx<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-09-03 23:21:17<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>**************************************************************************<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>C:\WINDOWS\system32\WLTRYSVC.EXE<br>C:\WINDOWS\system32\BCMWLTRY.EXE<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>C:\Program Files\Dell\QuickSet\NicConfigSvc.exe<br>C:\Program Files\Zune\ZuneNss.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe<br>C:\WINDOWS\system32\dwwin.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2008-09-03 23:30:39 - machine was rebooted [STravis]<br>ComboFix-quarantined-files.txt  2008-09-04 03:29:35<br><br>Pre-Run: 37,850,038,272 bytes free<br>Post-Run: 37,776,023,552 bytes free<br><br>152&#9;--- E O F ---&#9;2008-09-03 19:06:11]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21059839</guid>
<pubDate>Thu, 04 Sep 2008 22:35:37 EDT</pubDate>
</item>

<item>
<title>HJT Log - fake alerts</title>
<link>http://www.dslreports.com/forum/remark,21058811</link>
<description><![CDATA[<A HREF="/useremail/u/238858"><b>Annmarie</b></A> : I have very little time to clean this up so excuse me for being abrupt. Co workers laptop, Windows XP running Symantec client suddenly began getting nasty pop ups and what appeared to be Windows security alerts. Someone used his laptop while he was out of the office.<br>Between he and I we followed the FAQ procedure to the T. His words "found and cleaned tons of stuff but that one keeps showing up". That "one" is the .jpg I posted - it pops up with different trojan names. <br>I snuck (sneaked?) the laptop out of the office so I could clean it at home. I have to get it back tonight before the security cameras go back on.<br>Here is the HJT log:<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 6:58:51 PM, on 9/4/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v7.00 (7.00.6000.16705)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\WLTRYSVC.EXE<br>C:\WINDOWS\System32\bcmwltry.exe<br>C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>c:\WINDOWS\system32\ZuneBusEnum.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Documents and Settings\All Users\Application Data\zehchwhk\lyhshubi.exe<br>C:\WINDOWS\stsystra.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>C:\WINDOWS\system32\fozixwjc.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe<br>C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe<br>C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe<br>C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\Symantec AntiVirus\vptray.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\WINDOWS\system32\fozixwjc.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell.com" >www.dell.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.dell.com/" >www.dell.com/</A><br>R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll<br>O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKCU\..\Run: [ApiSrv] C:\WINDOWS\system32\fozixwjc.exe<br>O4 - HKCU\..\Run: [cmdinfo] C:\WINDOWS\system32\ujyhuhgd.exe<br>O4 - HKCU\..\Run: [setsh] C:\WINDOWS\system32\xcxebazm.exe<br>O4 - HKLM\..\Policies\Explorer\Run: [iQkkP4fm85] C:\Documents and Settings\All Users\Application Data\zehchwhk\lyhshubi.exe<br>O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe<br>O4 - Global Startup: Bluetooth Manager.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)<br>O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll<br>O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - &raquo;<A HREF="http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab" >www.symantec.com/techsupp/asa/ss&middot;&middot;&middot;tlsr.cab</A><br>O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - &raquo;<A HREF="http://www.eset.eu/buxus/docs/OnlineScanner.cab" >www.eset.eu/buxus/docs/OnlineScanner.cab</A><br>O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - &raquo;<small>https</small>://<A HREF="https://70.90.17.225/Remote/msrdp.cab">70.90.17.225/Remote/msrdp.cab</A><br>O16 - DPF: {CF38E898-0A6B-11D6-83C6-0080AD7D6076} (NPRemvuPluginControl) - &raquo;<A HREF="http://24.46.98.45:8888/common/NPRemvu.cab" >24.46.98.45:8888/common/NPRemvu.cab</A><br>O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE<br>O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE<br><br>--<br>End of file - 7563 bytes<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21058811?c=1346523&ret=L2ZvcnVtL3IyMTA1OTgzOS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="49962 bytes" WIDTH=600 HEIGHT=367 SRC="/r0/download/1346523.thumb600~52901ef2317f414342394c7bfebd47dc/trojan alert.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21058811</guid>
<pubDate>Thu, 04 Sep 2008 19:36:03 EDT</pubDate>
</item>

</channel>
</rss>
