Hi Corrine
Here is the
ComboFix LogComboFix 08-11-16.01 - Owner 2008-11-16 17:04:45.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.234 [GMT -5:00]
Command switches used :: c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Desktop\CFScript.txt
FILE ::
c:\windows\system32\_003711_.tmp.dll
c:\windows\system32\_003742_.tmp.dll
c:\windows\system32\_003767_.tmp.dll
c:\windows\system32\_006940_.tmp.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\AntiXPVSTFix.exe
c:\windows\system32\drivers\TDSSserv.sys
c:\windows\system32\IEDFix.C.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\BrowserSearch\BrowserSearch.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\BrowserSearch\BrowserSearch.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Configurator\Configurator.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Configurator\Configurator.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Dating\DatingOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Dating\DatingOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Free_Credit_Score\Free_Credit_ScoreOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Free_Credit_Score\Free_Credit_ScoreOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Games\GamesOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Games\GamesOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Games\images\active\Games0.bmp
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Layouts\ToolbarLayout.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Layouts\ToolbarLayout.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Manager\ManagerOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Manager\ManagerOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Movies\images\active\Movies0.bmp
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Movies\MoviesOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Movies\MoviesOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Recipe_RSS\Recipe_RSSOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Recipe_RSS\Recipe_RSSOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Recipes\RecipesOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Recipes\RecipesOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Reference\ReferenceOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Reference\ReferenceOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Ringtones\RingtonesOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Ringtones\RingtonesOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Search_Recipes\Search_RecipesOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Search_Recipes\Search_RecipesOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Toolbar\TBProductsOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Toolbar\TBProductsOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Weather\AlertArchive.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Weather\WeatherOptions.xml
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Starware337\Weather\WeatherOptions.xml.backup
c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Favorites\Online Security Test.url
c:\windows\system32\_003697_.tmp.dll
c:\windows\system32\_003698_.tmp.dll
c:\windows\system32\_003699_.tmp.dll
c:\windows\system32\_003700_.tmp.dll
c:\windows\system32\_003707_.tmp.dll
c:\windows\system32\_003708_.tmp.dll
c:\windows\system32\_003709_.tmp.dll
c:\windows\system32\_003710_.tmp.dll
c:\windows\system32\_003711_.tmp.dll
c:\windows\system32\_003712_.tmp.dll
c:\windows\system32\_003713_.tmp.dll
c:\windows\system32\_003714_.tmp.dll
c:\windows\system32\_003715_.tmp.dll
c:\windows\system32\_003716_.tmp.dll
c:\windows\system32\_003717_.tmp.dll
c:\windows\system32\_003718_.tmp.dll
c:\windows\system32\_003719_.tmp.dll
c:\windows\system32\_003720_.tmp.dll
c:\windows\system32\_003722_.tmp.dll
c:\windows\system32\_003723_.tmp.dll
c:\windows\system32\_003724_.tmp.dll
c:\windows\system32\_003725_.tmp.dll
c:\windows\system32\_003726_.tmp.dll
c:\windows\system32\_003727_.tmp.dll
c:\windows\system32\_003728_.tmp.dll
c:\windows\system32\_003730_.tmp.dll
c:\windows\system32\_003731_.tmp.dll
c:\windows\system32\_003732_.tmp.dll
c:\windows\system32\_003733_.tmp.dll
c:\windows\system32\_003734_.tmp.dll
c:\windows\system32\_003735_.tmp.dll
c:\windows\system32\_003736_.tmp.dll
c:\windows\system32\_003738_.tmp.dll
c:\windows\system32\_003739_.tmp.dll
c:\windows\system32\_003740_.tmp.dll
c:\windows\system32\_003741_.tmp.dll
c:\windows\system32\_003742_.tmp.dll
c:\windows\system32\_003743_.tmp.dll
c:\windows\system32\_003744_.tmp.dll
c:\windows\system32\_003745_.tmp.dll
c:\windows\system32\_003746_.tmp.dll
c:\windows\system32\_003747_.tmp.dll
c:\windows\system32\_003748_.tmp.dll
c:\windows\system32\_003751_.tmp.dll
c:\windows\system32\_003752_.tmp.dll
c:\windows\system32\_003753_.tmp.dll
c:\windows\system32\_003755_.tmp.dll
c:\windows\system32\_003756_.tmp.dll
c:\windows\system32\_003757_.tmp.dll
c:\windows\system32\_003758_.tmp.dll
c:\windows\system32\_003760_.tmp.dll
c:\windows\system32\_003761_.tmp.dll
c:\windows\system32\_003762_.tmp.dll
c:\windows\system32\_003763_.tmp.dll
c:\windows\system32\_003764_.tmp.dll
c:\windows\system32\_003765_.tmp.dll
c:\windows\system32\_003767_.tmp.dll
c:\windows\system32\_003768_.tmp.dll
c:\windows\system32\_003769_.tmp.dll
c:\windows\system32\_003770_.tmp.dll
c:\windows\system32\_003771_.tmp.dll
c:\windows\system32\_003774_.tmp.dll
c:\windows\system32\_003775_.tmp.dll
c:\windows\system32\_003776_.tmp.dll
c:\windows\system32\_003777_.tmp.dll
c:\windows\system32\_003778_.tmp.dll
c:\windows\system32\_003779_.tmp.dll
c:\windows\system32\_003780_.tmp.dll
c:\windows\system32\_003782_.tmp.dll
c:\windows\system32\_003783_.tmp.dll
c:\windows\system32\_003784_.tmp.dll
c:\windows\system32\_003785_.tmp.dll
c:\windows\system32\_003786_.tmp.dll
c:\windows\system32\_003787_.tmp.dll
c:\windows\system32\_003788_.tmp.dll
c:\windows\system32\_003789_.tmp.dll
c:\windows\system32\_003791_.tmp.dll
c:\windows\system32\_003792_.tmp.dll
c:\windows\system32\_003793_.tmp.dll
c:\windows\system32\_003794_.tmp.dll
c:\windows\system32\_003796_.tmp.dll
c:\windows\system32\_003797_.tmp.dll
c:\windows\system32\_003801_.tmp.dll
c:\windows\system32\_003802_.tmp.dll
c:\windows\system32\_003804_.tmp.dll
c:\windows\system32\_003807_.tmp.dll
c:\windows\system32\_003809_.tmp.dll
c:\windows\system32\_003810_.tmp.dll
c:\windows\system32\_003811_.tmp.dll
c:\windows\system32\_003812_.tmp.dll
c:\windows\system32\_003815_.tmp.dll
c:\windows\system32\_003816_.tmp.dll
c:\windows\system32\_003817_.tmp.dll
c:\windows\system32\_003818_.tmp.dll
c:\windows\system32\_003819_.tmp.dll
c:\windows\system32\_003824_.tmp.dll
c:\windows\system32\_003826_.tmp.dll
c:\windows\system32\_005828_.tmp.dll
c:\windows\system32\_005829_.tmp.dll
c:\windows\system32\_005830_.tmp.dll
c:\windows\system32\_005831_.tmp.dll
c:\windows\system32\_005838_.tmp.dll
c:\windows\system32\_005839_.tmp.dll
c:\windows\system32\_005840_.tmp.dll
c:\windows\system32\_005841_.tmp.dll
c:\windows\system32\_005843_.tmp.dll
c:\windows\system32\_005844_.tmp.dll
c:\windows\system32\_005847_.tmp.dll
c:\windows\system32\_005848_.tmp.dll
c:\windows\system32\_005850_.tmp.dll
c:\windows\system32\_005851_.tmp.dll
c:\windows\system32\_005852_.tmp.dll
c:\windows\system32\_005854_.tmp.dll
c:\windows\system32\_005857_.tmp.dll
c:\windows\system32\_005858_.tmp.dll
c:\windows\system32\_005862_.tmp.dll
c:\windows\system32\_005863_.tmp.dll
c:\windows\system32\_005865_.tmp.dll
c:\windows\system32\_005868_.tmp.dll
c:\windows\system32\_005870_.tmp.dll
c:\windows\system32\_005871_.tmp.dll
c:\windows\system32\_005872_.tmp.dll
c:\windows\system32\_005873_.tmp.dll
c:\windows\system32\_005874_.tmp.dll
c:\windows\system32\_005877_.tmp.dll
c:\windows\system32\_005878_.tmp.dll
c:\windows\system32\_005879_.tmp.dll
c:\windows\system32\_005880_.tmp.dll
c:\windows\system32\_005881_.tmp.dll
c:\windows\system32\_005886_.tmp.dll
c:\windows\system32\_005888_.tmp.dll
c:\windows\system32\_005889_.tmp.dll
c:\windows\system32\_006926_.tmp.dll
c:\windows\system32\_006927_.tmp.dll
c:\windows\system32\_006928_.tmp.dll
c:\windows\system32\_006929_.tmp.dll
c:\windows\system32\_006936_.tmp.dll
c:\windows\system32\_006937_.tmp.dll
c:\windows\system32\_006938_.tmp.dll
c:\windows\system32\_006940_.tmp.dll
c:\windows\system32\_006941_.tmp.dll
c:\windows\system32\_006944_.tmp.dll
c:\windows\system32\_006945_.tmp.dll
c:\windows\system32\_006947_.tmp.dll
c:\windows\system32\_006948_.tmp.dll
c:\windows\system32\_006949_.tmp.dll
c:\windows\system32\_006951_.tmp.dll
c:\windows\system32\_006954_.tmp.dll
c:\windows\system32\_006955_.tmp.dll
c:\windows\system32\_006959_.tmp.dll
c:\windows\system32\_006960_.tmp.dll
c:\windows\system32\_006962_.tmp.dll
c:\windows\system32\_006965_.tmp.dll
c:\windows\system32\_006967_.tmp.dll
c:\windows\system32\_006968_.tmp.dll
c:\windows\system32\_006969_.tmp.dll
c:\windows\system32\_006970_.tmp.dll
c:\windows\system32\_006973_.tmp.dll
c:\windows\system32\_006974_.tmp.dll
c:\windows\system32\_006975_.tmp.dll
c:\windows\system32\_006976_.tmp.dll
c:\windows\system32\_006977_.tmp.dll
c:\windows\system32\_006982_.tmp.dll
c:\windows\system32\_006984_.tmp.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\AntiXPVSTFix.exe
c:\windows\system32\drivers\TDSSserv.sys
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\TDSSadw.dll
c:\windows\system32\TDSSerrors.log
c:\windows\system32\tdssinit.dll
c:\windows\system32\tdssl.dll
c:\windows\system32\tdsslog.dll
c:\windows\system32\TDSSmain.dll
c:\windows\system32\tdssserf.dll
c:\windows\system32\tdssserf1.dll
c:\windows\system32\TDSSservers.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV
-------\Legacy_TDSSSERV
((((((((((((((((((((((((( Files Created from 2008-10-16 to 2008-11-16 )))))))))))))))))))))))))))))))
.
2008-11-12 17:47 . 2008-11-12 17:47 <DIR> d-------- C:\rsit
2008-11-12 17:47 . 2008-11-13 19:06 <DIR> d-------- c:\program files\trend micro
2008-11-12 04:43 . 2008-11-12 04:43 <DIR> d---s---- c:\windows\system32\config\systemprofile\UserData
2008-11-11 19:25 . 2005-11-09 00:26 38,400 --a------ c:\windows\system32\moveex.exe
2008-11-10 21:31 . 2008-11-10 21:31 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-10 21:31 . 2008-11-10 21:31 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-11-10 21:31 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-10 21:31 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-10-26 17:13 . 2008-10-26 17:13 <DIR> d-------- c:\windows\system32\Adobe
2008-10-26 09:20 . 2008-10-26 09:21 <DIR> d-------- c:\program files\iTunes
2008-10-26 09:20 . 2008-10-26 09:20 <DIR> d-------- c:\program files\iPod
2008-10-26 09:20 . 2008-10-26 09:21 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-26 09:19 . 2008-10-26 09:19 <DIR> d-------- c:\program files\Bonjour
2008-10-26 09:18 . 2008-10-26 09:19 <DIR> d-------- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-16 21:53 --------- d-----w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\skypePM
2008-11-16 21:53 --------- d-----w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Skype
2008-11-12 00:41 --------- d-----w c:\program files\Java
2008-11-09 21:29 90,112 ----a-w c:\windows\DUMP2376.tmp
2008-10-26 14:19 --------- d-----w c:\program files\Common Files\Apple
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-08 15:34 --------- d-----w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Bell
2008-10-01 17:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-09-27 21:00 --------- d-----w c:\documents and settings\Administrator\Application Data\Bell
2008-09-27 00:59 --------- d-----w c:\program files\Apple Software Update
2008-09-25 11:32 --------- d-----w c:\documents and settings\Anita\Application Data\AVGTOOLBAR
2008-09-24 23:36 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-09-24 23:36 --------- d-----w c:\program files\Adobe Media Player
2008-09-24 07:00 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2008-09-23 08:54 --------- d-----w c:\documents and settings\Anita\Application Data\Bell
2008-09-23 01:33 --------- d-----w c:\program files\Bell
2008-09-23 00:48 --------- d-----w c:\program files\Common Files\Scanner
2008-09-23 00:47 --------- d--h--w c:\program files\InstallShield Installation Information
2008-09-23 00:47 --------- d-----w c:\program files\Common Files\Authentium
2008-09-23 00:47 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Bell
2008-09-22 01:10 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-09-22 01:10 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys
2008-09-22 01:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2008-09-22 00:40 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-09-21 23:27 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-09-21 23:19 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2008-09-21 23:18 --------- d-----w c:\program files\Lavasoft
2008-09-17 16:48 --------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-09-17 15:05 --------- d-----w c:\program files\Common Files\Teleca Shared
2008-09-16 03:18 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\MSN6
2008-09-16 03:18 --------- d-----w c:\documents and settings\Administrator\Application Data\MSN6
2008-02-29 20:46 0 -c--a-w c:\program files\temp01
2008-02-25 22:26 32 ----a-w c:\documents and settings\All Users.WINDOWS\Application Data\ezsid.dat
2007-03-12 00:10 28,952 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\GDIPFONTCACHEV1.DAT
2007-01-30 15:16 28,952 ----a-w c:\documents and settings\Anita\Application Data\GDIPFONTCACHEV1.DAT
2006-12-02 20:26 92,064 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\mqdmmdm.sys
2006-12-02 20:26 9,232 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\mqdmmdfl.sys
2006-12-02 20:26 79,328 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\mqdmserd.sys
2006-12-02 20:26 66,656 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\mqdmbus.sys
2006-12-02 20:26 6,208 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\mqdmcmnt.sys
2006-12-02 20:26 5,936 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\mqdmwhnt.sys
2006-12-02 20:26 4,048 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\mqdmcr.sys
2006-12-02 20:26 25,600 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\usbsermptxp.sys
2006-12-02 20:26 22,768 ----a-w c:\documents and settings\Owner.BELLOTTI-VVVH8Z\usbsermpt.sys
2006-04-12 09:26 774,144 ----a-w c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-03-10 35328]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-05-06 185784]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-11 1234712]
"SSA.exe"="c:\program files\Bell\Sympatico Security Advisor\SSA.exe" [2007-03-27 2061816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\Anita\Start Menu\Programs\Startup\
iWin Desktop Alerts.lnk - c:\documents and settings\All Users.WINDOWS\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe [2007-12-09 107520]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-02-24 344064]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-09-21 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-09-21 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-09-21 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-09-21 76040]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2008-11-10 38496]
S3 Radialpoint Security Services;Radialpoint Security Services;c:\windows\system32\dllhost.exe /Processid:{80098F68-1220-4F43-80A8-15C7395B8874} [2003-07-16 5120]
.
Contents of the 'Scheduled Tasks' folder
2008-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-16 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe []
2006-04-10 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-13 17:38]
.
- - - - ORPHANS REMOVED - - - -
Notify-dimsntfy - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Owner.BELLOTTI-VVVH8Z\Application Data\Mozilla\Firefox\Profiles\yduk8ddy.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.foodtv.ca/
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-16 17:17:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Authentium\AntiVirus\dvpapi.exe
c:\windows\system32\HPZipm12.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-11-16 17:23:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-16 22:23:42
ComboFix2.txt 2008-11-12 01:12:53
Pre-Run: 53,209,153,536 bytes free
Post-Run: 56,223,055,872 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
404 --- E O F --- 2008-11-12 23:03:46
Here is the
Eset Online Scanner Log# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3615 (20081115)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=c5da79b0b1e8834484e07b74b8f8f4ef
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-11-16 11:41:09
# local_time=2008-11-16 06:41:09 (-0500, Eastern Standard Time)
# country="Canada"
# osver=5.1.2600 NT Service Pack 2
# scanned=316288
# found=7
# scan_time=4340
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssadw.dll.vir Win32/Agent.ODG trojan F464FE1A3CDE6B1D24EAA3A7C948088D
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssl.dll.vir Win32/Agent.ODG trojan 7CB122B25F9206A73A99BD2BDD9E25CD
C:\QooBox\Quarantine\C\WINDOWS\system32\tdsslog.dll.vir Win32/Agent.OBU trojan AE7C5EDD787BCDD8ED5966BDF02F1B46
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssmain.dll.vir Win32/Agent.OGC trojan 335915A73568AE9BF532C41DF91A3B31
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssserf.dll.vir Win32/Agent.ODG trojan 67E17F3C7F3C0134CAC7374FD013D9F4
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssserf1.dll.vir Win32/Agent.ODG trojan 69D78C4A5D8CC85A00344C37157B87A2
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\TDSSserv.sys.vir Win32/Agent.ODG trojan C9B36AE929D020240A91FF5200E8FE80
Here is a new
Hijackthis LogLogfile of HijackThis v1.99.1
Scan saved at 6:45:09 PM, on 16/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Mystery Stories - Island of Hope\Images\stg_drm.ocx
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://spaces.msn.com//PhotoUpload/MsnPUpld.cabO16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/buxus/docs/OnlineScanner.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader3.cabO16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1144285784203O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cabO16 - DPF: {B12213CD-4189-415D-A054-7999528459F7} (pixelStormLauncher Class) -
http://aolsvc.aol.com/onlinegames/tryrumblecube/pixelstormlauncher.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://aolsvc.aol.com/onlinegames/tryaces/zylomgamesplayer.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabO16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) -
http://sympatico.zone.msn.com/bingame/jobo/default/AstoundLauncher.cab#version=1,0,0,10O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Rainbow Web 2\Images\armhelper.ocx
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) -
http://sympatico.zone.msn.com/bingame/hsol/default/SCEWebLauncher.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Radialpoint Unicorn Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Scan and Clean utility\rpsupdaterR.exe
Thanks again for your help.