Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Removing a Trojan that is Write Protected
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > Removing a Trojan that is Write Protected  
Forum Quick Jump
 
New Topic Post reply to : Removing a Trojan that is Write Protected Printable version of : Removing a Trojan that is Write Protected
[ << Previous Thread | Next Thread >> ]

Becks287
New Member


Date Joined Jun 2008
Total Posts : 8
 
   Posted 6-29-2008 8:12 (GMT +2)    Quote: Removing a Trojan that is Write ProtectedAlert an admin about: Removing a Trojan that is Write Protected
My McAfee antivirus has detected a trojan but cannot remove it.
I have used various other devices, all of which can see it but they also cannot remove it.
 
The file is not hidden and is located as follows:
 
C:\windows\system32\avtapip.dll
 
I've also tried deleting from the safe mode and using the cmd.exe feature but neither have worked.
 
I'm assuming the problem is that its in a windows auto start up folder and is therefore protected.
Anyone know if this feature can be turned off long enough to allow me to delete it?
 
Thanks in advance
 
Back to Top
 

Becks287
New Member


Date Joined Jun 2008
Total Posts : 8
 
   Posted 6-29-2008 8:14 (GMT +2)    Quote: Removing a Trojan that is Write ProtectedAlert an admin about: Removing a Trojan that is Write Protected
Here's the log from combofix:
ComboFix 08-06-20.4 - Steve 2008-06-29 10:40:37.1 - NTFSx86
Running from: C:\Documents and Settings\Steve\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\hosts
C:\WINDOWS\Tasks.\At1.job
C:\WINDOWS\system32\avtapip.dll . . . . failed to delete
C:\WINDOWS\system32\vqzzxks.dll . . . . failed to delete
----- BITS: Possible infected sites -----
hxxp://www.hhdsoftware.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GTAHVETZ
-------\Service_gtahvetz


((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-29 )))))))))))))))))))))))))))))))
.
2008-06-28 23:35 . 2008-06-28 23:35 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-28 23:34 . 2008-06-28 23:34 <DIR> d----c--- C:\Program Files\SUPERAntiSpyware
2008-06-28 23:34 . 2008-06-28 23:34 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\SUPERAntiSpyware.com
2008-06-28 23:33 . 2008-06-28 23:33 <DIR> d----c--- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-28 23:25 . 2008-06-28 23:25 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Citrix
2008-06-28 23:20 . 2008-06-28 23:20 61,224 --a--c--- C:\Documents and Settings\Steve\GoToAssistDownloadHelper.exe
2008-06-28 20:59 . 2008-06-28 20:59 <DIR> d-------- C:\WINDOWS\Mozilla
2008-06-28 20:54 . 2008-06-29 00:21 <DIR> d----c--- C:\!KillBox
2008-06-28 20:10 . 2008-06-28 20:10 <DIR> d----c--- C:\Program Files\GiPo@Utilities
2008-06-28 20:10 . 2008-06-28 20:10 <DIR> d----c--- C:\Program Files\Common Files\Gibinsoft Shared
2008-06-28 17:10 . 2008-06-28 17:10 <DIR> d----c--- C:\Program Files\IDM Computer Solutions
2008-06-28 17:10 . 2008-06-28 17:10 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\IDMComp
2008-06-28 14:16 . 2008-06-28 14:16 <DIR> d----c--- C:\Documents and Settings\LocalService\Application Data\McAfee
2008-06-24 09:03 . 2008-06-29 10:58 6,072 --a------ C:\WINDOWS\system32\drivers\kgpfr2.cfg
2008-06-21 13:13 . 2008-06-29 10:58 12,544 --a------ C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-06-21 13:10 . 2008-06-29 09:59 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-06-21 13:08 . 2008-06-21 13:08 <DIR> d----c--- C:\Program Files\STOPzilla!
2008-06-21 13:08 . 2008-06-21 13:08 <DIR> d----c--- C:\Program Files\Common Files\iS3
2008-06-21 13:08 . 2008-06-29 11:00 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-06-21 11:14 . 2008-06-21 11:14 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Uniblue
2008-06-12 15:09 . 2008-06-12 15:09 258,048 -ra------ C:\WINDOWS\system32\SZBase5.dll
2008-06-12 15:08 . 2008-06-12 15:08 401,408 -ra------ C:\WINDOWS\system32\SZComp5.dll
2008-06-12 10:11 . 2008-06-12 10:11 364,544 -ra------ C:\WINDOWS\system32\IS3DBA5.dll
2008-06-12 10:11 . 2008-06-12 10:11 126,976 -ra------ C:\WINDOWS\system32\IS3HTUI5.dll
2008-06-12 10:10 . 2008-06-12 10:10 372,736 -ra------ C:\WINDOWS\system32\IS3UI5.dll
2008-06-12 10:10 . 2008-06-12 10:10 61,440 -ra------ C:\WINDOWS\system32\IS3Hks5.dll
2008-06-12 10:10 . 2008-06-12 10:10 23,040 -ra------ C:\WINDOWS\system32\IS3XDat5.dll
2008-06-12 10:09 . 2008-06-12 10:09 196,608 -ra------ C:\WINDOWS\system32\IS3Win325.dll
2008-06-12 10:08 . 2008-06-12 10:08 94,208 -ra------ C:\WINDOWS\system32\IS3Inet5.dll
2008-06-12 10:08 . 2008-06-12 10:08 90,112 -ra------ C:\WINDOWS\system32\IS3Svc5.dll
2008-06-12 10:05 . 2008-06-12 10:05 708,608 -ra------ C:\WINDOWS\system32\IS3Base5.dll
2008-06-10 19:18 . 2008-06-10 19:18 <DIR> d----c--- C:\Documents and Settings\NetworkService\Application Data\meidifwt
2008-06-10 18:23 . 2008-06-10 18:23 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\meidifwt
2008-06-10 11:15 . 2008-06-10 18:23 <DIR> d----c--- C:\Program Files\Common Files\Mozilla Shared
2008-06-10 11:04 . 2008-06-10 11:04 <DIR> d----c--- C:\Archive
2008-06-07 09:49 . 2002-11-06 11:02 128,000 --a--c--- C:\WINDOWS\system32\Cp5dll32i.dll
2008-06-07 09:49 . 2008-06-29 10:49 88,064 --a--c--- C:\WINDOWS\system32\avtapip.dll
2008-06-06 23:14 . 2008-06-06 23:14 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-06 23:14 . 2008-06-06 23:14 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Program Files\Common Files\Business Objects
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Inertia 3
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\regcrypt
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-06-04 15:47 . 2008-06-04 15:47 <DIR> d----c--- C:\Program Files\Microsoft.NET
2008-06-04 15:44 . 2008-06-04 15:44 <DIR> d----c--- C:\Program Files\MSXML 6.0
2008-06-03 15:19 . 2008-06-27 18:30 <DIR> d----c--- C:\Program Files\Legal & General
2008-06-03 15:19 . 2008-06-03 15:19 <DIR> d----c--- C:\Program Files\Common Files\F1
2008-05-29 11:20 . 2008-05-29 11:20 <DIR> d-------- C:\WINDOWS\Crystal
2008-05-29 11:20 . 2008-05-29 11:20 <DIR> d----c--- C:\Program Files\Seagate Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 22:05 --------- dc----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-28 22:00 --------- dc----w C:\Documents and Settings\Steve\Application Data\McAfee
2008-06-28 21:04 --------- dc----w C:\Program Files\MarkInfo
2008-06-28 13:08 --------- dc----w C:\Program Files\McAfee
2008-06-27 19:21 --------- dc----w C:\Program Files\mortgageLink Enterprise
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-09 18:43 --------- dc----w C:\Program Files\Google
2008-06-05 12:05 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-05-29 10:22 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2008-05-29 10:22 --------- dc----w C:\Program Files\Intermediary Mortgages
2008-05-15 12:25 --------- dc----w C:\Program Files\Coupon Printer
2008-05-13 09:03 34,432 ----a-r C:\WINDOWS\system32\drivers\SZKG.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-24 10:07 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-03-12 12:14 84,808 -c--a-w C:\Documents and Settings\Steve\Application Data\GDIPFONTCACHEV1.DAT
2005-11-23 14:55 62 -c-ha-w C:\Program Files\AppUpdate.log
2005-05-11 18:07 4,811 -c--a-w C:\Program Files\INSTALL.LOG
2001-09-28 16:00 164,864 -c--a-w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94CFA39F-389A-4D00-86C2-04F49C10A2D6}]
2003-03-31 13:00 84992 --a------ c:\windows\system32\vqzzxks.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F92C5901-4970-4121-9B82-C52AD1E53785}]
2008-06-29 10:49 88064 --a--c--- C:\WINDOWS\system32\avtapip.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"mount.exe"="C:\Program Files\GiPo@Utilities\FileUtilities.3\mount.exe" [2008-04-11 16:17 374272]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-09-19 14:35 114688]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe" [2003-03-26 19:19 45056]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 11:29 40960]
"VAIO Update 2"="C:\Program Files\sony\vaio update 2\VAIOUpdt.exe" [2003-11-18 14:55 135168]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"StartSQLManager"="C:\Program Files\Microsoft SQL Server\90\Tools\Binn\sqlmangr.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-01-28 14:49 77824]
"BHR"="C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe" [ ]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\videolib\sonydv.dll
"msacm.avis"= ff_acm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Customer Focus Alert.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Customer Focus Alert.lnk
backup=C:\WINDOWS\pss\Customer Focus Alert.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP LaserJet Director.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP LaserJet Director.lnk
backup=C:\WINDOWS\pss\HP LaserJet Director.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PowerPanel.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerPanel.lnk
backup=C:\WINDOWS\pss\PowerPanel.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a--c--- 2007-03-09 12:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a--c--- 2007-05-11 04:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEAutoRun]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fub2]
C:\WINDOWS\system32\fub2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HKSERV.EXE]
--a------ 2003-08-14 11:00 90112 C:\Program Files\Sony\HotKey Utility\HKserv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP AutoIndexer]
--a--c--- 2002-04-22 13:57 90112 C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP SchedIndexer]
--a--c--- 2002-04-22 13:56 94208 C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a--c--- 2005-02-17 00:11 49152 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a--c--- 2004-06-16 06:03 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon]
--a------ 2002-03-14 17:46 45056 C:\WINDOWS\system32\ico.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2004-01-28 14:49 77824 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StatusClient 2.6]
--a--c--- 2004-02-27 18:29 61440 C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup 2.5]
--a--c--- 2004-05-20 17:40 188416 C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
--a--c--- 2007-10-31 11:19 378784 C:\Program Files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\WINDOWS\\system32\\msiexec.exe"=
"C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\kdx\\KHost.exe"=
"C:\\Program Files\\KService\\KService.exe"=
"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"=
"C:\\Inertia 3\\System\\PSL.Development.MainApp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:iMp3Downloading
"6346:UDP"= 6346:UDP:iMp3Downloading
"5541:TCP"= 5541:TCP:@xpsp2res.dll,-22009
"80:TCP"= 80:TCP:@xpsp2res.dll,-22009
R0 mhksjmhy;mhksjmhy;C:\WINDOWS\system32\drivers\mhksjmhy.sys [2003-03-31 13:00]
R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 10:03]
R2 MSSQL$INERTIA3_SQL2005;SQL Server (INERTIA3_SQL2005);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINERTIA3_SQL2005 []
R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2003-08-26 17:27]
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys [2002-08-20 11:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\AUTOPLAY.EXE id=10000020000015000011 ver=1.0.0.0
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd5e0a3e-6b44-11db-959d-080046d2bc2e}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-15 09:04:56 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-03-01 01:00:28 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-29 10:55:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13131
 
   Posted 6-30-2008 6:48 (GMT +2)    Quote: Removing a Trojan that is Write ProtectedAlert an admin about: Removing a Trojan that is Write Protected
Hello cool
 
 
1. Get this version of Hijackthis from http://danborg.org/spy/hjt/alternativ.exe
 
2
Save it in a permanent folder of your choice, such as C:\HJT\. To create this specific folder on your hard drive: Double click the 'My Computer' icon on your desktop, then under the category hard disk drives: double click Local Disk:, then select file->New -> Folder and name it HJT
3 Run hijackthis.  (alternativ exe).

Choose the "Do a system scan and save a log file" option to perform your scan.
HijackThis will analyze your system, and automatically open a notepad textfile containing the HijackThis log when the scan is finished.
Open the text files containing the logs with a text editor and click Edit -> Select All, followed by Edit -> Copy.
From within the browser window and with the message body text box selected, click Edit -> Paste.
Post hijackthis log here


Do NOT post your problem in someone elses thread.

Back to Top
 

Becks287
New Member


Date Joined Jun 2008
Total Posts : 8
 
   Posted 7-1-2008 10:12 (GMT +2)    Quote: Removing a Trojan that is Write ProtectedAlert an admin about: Removing a Trojan that is Write Protected
Thanks for the reply.

This is the report from hijackthis



Logfile of HijackThis v1.99.1
Scan saved at 21:11:01, on 01/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Steve\Desktop\alternativ.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.bbc.co.uk/sport
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {94CFA39F-389A-4D00-86C2-04F49C10A2D6} - c:\windows\system32\vqzzxks.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: (no name) - {F92C5901-4970-4121-9B82-C52AD1E53785} - C:\WINDOWS\system32\avtapip.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [StartSQLManager] C:\Program Files\Microsoft SQL Server\90\Tools\Binn\sqlmangr.exe /n
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [GIology] "c:\Program Files\Legal & General\GIology\GIology.exe" /CheckUpdate
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{36A448F1-391E-48EC-A6E2-0C85391ABA29}: NameServer = 194.72.6.57,194.73.82.252,192.168.0.1
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SQL Server (INERTIA3_SQL2005) (MSSQL$INERTIA3_SQL2005) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINERTIA3_SQL2005 (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\sony\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\sony\photo server\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13131
 
   Posted 7-2-2008 9:24 (GMT +2)    Quote: Removing a Trojan that is Write ProtectedAlert an admin about: Removing a Trojan that is Write Protected
Run Hijackthis and place a check beside each of the following. Close all other browser windows except HJT.
Click fix checked:
O2 - BHO: (no name) - {94CFA39F-389A-4D00-86C2-04F49C10A2D6} - c:\windows\system32\vqzzxks.dll
O2 - BHO: (no name) - {F92C5901-4970-4121-9B82-C52AD1E53785} - C:\WINDOWS\system32\avtapip.dll
 
 
 
Please download Malwarebytes' Anti-Malware:
 
 
 
 to your desktop.
 
Double-click mbam-setup.exe and follow the prompts to install the program.
                     
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch

Malwarebytes' Anti-Malware, then click Finish.
                     
If an update is found, it will download and install the latest version.
                     
Once the program has loaded, select Perform full scan, then click Scan.
                     
When the scan is complete, click OK, then Show Results to view the results.
 
Be sure that everything is checked, and click Remove Selected.
 
When completed, a log will open in Notepad. Please save it to a convenient location.
 
 
 
Copy and Paste that log into your next reply, along with new combofix log.
 


Do NOT post your problem in someone elses thread.

Back to Top
 

Becks287
New Member


Date Joined Jun 2008
Total Posts : 8
 
   Posted 7-2-2008 5:33 (GMT +2)    Quote: Removing a Trojan that is Write ProtectedAlert an admin about: Removing a Trojan that is Write Protected
Hi.

Unfortunately HJT couldn't remove the 2 files specified.

Here's the log for Combofix

ComboFix 08-07-01.3 - Steve 2008-07-02 16:00:59.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.144 [GMT 1:00]
Running from: C:\Documents and Settings\Steve\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\SZComp5.dll
C:\WINDOWS\system32\avtapip.dll . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-06-02 to 2008-07-02 )))))))))))))))))))))))))))))))
.

2008-07-02 13:54 . 2008-07-02 13:54 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Malwarebytes
2008-07-02 13:54 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-02 13:53 . 2008-07-02 13:54 <DIR> d----c--- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-02 13:53 . 2008-07-02 13:53 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-02 13:53 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-01 16:30 . 2008-07-01 16:30 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Macrovision
2008-06-29 18:40 . 2008-06-29 18:40 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Talkback
2008-06-29 18:39 . 2008-06-29 18:39 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-28 23:35 . 2008-06-28 23:35 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-28 23:34 . 2008-06-28 23:34 <DIR> d----c--- C:\Program Files\SUPERAntiSpyware
2008-06-28 23:34 . 2008-06-28 23:34 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\SUPERAntiSpyware.com
2008-06-28 23:33 . 2008-06-28 23:33 <DIR> d----c--- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-28 23:25 . 2008-06-28 23:25 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Citrix
2008-06-28 23:20 . 2008-07-01 15:17 60,968 --a--c--- C:\Documents and Settings\Steve\GoToAssistDownloadHelper.exe
2008-06-28 20:59 . 2008-06-28 20:59 <DIR> d-------- C:\WINDOWS\Mozilla
2008-06-28 20:54 . 2008-07-02 14:14 <DIR> d----c--- C:\!KillBox
2008-06-28 20:10 . 2008-06-28 20:10 <DIR> d----c--- C:\Program Files\GiPo@Utilities
2008-06-28 20:10 . 2008-06-28 20:10 <DIR> d----c--- C:\Program Files\Common Files\Gibinsoft Shared
2008-06-28 17:10 . 2008-06-28 17:10 <DIR> d----c--- C:\Program Files\IDM Computer Solutions
2008-06-28 17:10 . 2008-06-28 17:10 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\IDMComp
2008-06-28 14:16 . 2008-06-28 14:16 <DIR> d----c--- C:\Documents and Settings\LocalService\Application Data\McAfee
2008-06-21 13:13 . 2008-07-01 17:38 15,928 --a------ C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-06-21 13:10 . 2008-07-01 15:06 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-06-21 13:08 . 2008-06-21 13:08 <DIR> d----c--- C:\Program Files\STOPzilla!
2008-06-21 13:08 . 2008-06-21 13:08 <DIR> d----c--- C:\Program Files\Common Files\iS3
2008-06-21 13:08 . 2008-07-02 16:09 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-06-21 11:14 . 2008-06-21 11:14 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Uniblue
2008-06-12 15:09 . 2008-06-12 15:09 258,048 -ra------ C:\WINDOWS\system32\SZBase5.dll
2008-06-12 10:11 . 2008-06-12 10:11 364,544 -ra------ C:\WINDOWS\system32\IS3DBA5.dll
2008-06-12 10:11 . 2008-06-12 10:11 126,976 -ra------ C:\WINDOWS\system32\IS3HTUI5.dll
2008-06-12 10:10 . 2008-06-12 10:10 372,736 -ra------ C:\WINDOWS\system32\IS3UI5.dll
2008-06-12 10:10 . 2008-06-12 10:10 61,440 -ra------ C:\WINDOWS\system32\IS3Hks5.dll
2008-06-12 10:10 . 2008-06-12 10:10 23,040 -ra------ C:\WINDOWS\system32\IS3XDat5.dll
2008-06-12 10:09 . 2008-06-12 10:09 196,608 -ra------ C:\WINDOWS\system32\IS3Win325.dll
2008-06-12 10:08 . 2008-06-12 10:08 94,208 -ra------ C:\WINDOWS\system32\IS3Inet5.dll
2008-06-12 10:08 . 2008-06-12 10:08 90,112 -ra------ C:\WINDOWS\system32\IS3Svc5.dll
2008-06-12 10:05 . 2008-06-12 10:05 708,608 -ra------ C:\WINDOWS\system32\IS3Base5.dll
2008-06-10 19:18 . 2008-06-10 19:18 <DIR> d----c--- C:\Documents and Settings\NetworkService\Application Data\meidifwt
2008-06-10 18:23 . 2008-06-10 18:23 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\meidifwt
2008-06-10 11:15 . 2008-06-10 18:23 <DIR> d----c--- C:\Program Files\Common Files\Mozilla Shared
2008-06-10 11:04 . 2008-06-10 11:04 <DIR> d----c--- C:\Archive
2008-06-07 09:49 . 2002-11-06 11:02 128,000 --a--c--- C:\WINDOWS\system32\Cp5dll32i.dll
2008-06-07 09:49 . 2008-06-29 10:49 88,064 --a--c--- C:\WINDOWS\system32\avtapip.dll
2008-06-06 23:14 . 2008-07-02 08:48 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-06 23:14 . 2008-06-06 23:14 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Program Files\Common Files\Business Objects
2008-06-05 13:12 . 2008-07-01 16:26 <DIR> d-------- C:\Inertia 3
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\regcrypt
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-06-04 15:47 . 2008-06-04 15:47 <DIR> d----c--- C:\Program Files\Microsoft.NET
2008-06-04 15:44 . 2008-06-04 15:44 <DIR> d----c--- C:\Program Files\MSXML 6.0
2008-06-03 15:19 . 2008-06-27 18:30 <DIR> d----c--- C:\Program Files\Legal & General
2008-06-03 15:19 . 2008-07-01 15:26 <DIR> d----c--- C:\Program Files\Common Files\F1

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 14:50 --------- dc----w C:\Program Files\McAfee
2008-07-02 10:03 --------- dc----w C:\Program Files\mortgageLink Enterprise
2008-07-01 20:51 --------- dc----w C:\Program Files\MarkInfo
2008-06-28 22:05 --------- dc----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-28 22:00 --------- dc----w C:\Documents and Settings\Steve\Application Data\McAfee
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-09 18:43 --------- dc----w C:\Program Files\Google
2008-06-05 12:05 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-05-29 10:22 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2008-05-29 10:22 --------- dc----w C:\Program Files\Intermediary Mortgages
2008-05-29 10:20 --------- dc----w C:\Program Files\Seagate Software
2008-05-15 12:25 --------- dc----w C:\Program Files\Coupon Printer
2008-05-13 09:03 34,432 ----a-r C:\WINDOWS\system32\drivers\SZKG.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-24 10:07 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-03-12 12:14 84,808 -c--a-w C:\Documents and Settings\Steve\Application Data\GDIPFONTCACHEV1.DAT
2005-11-23 14:55 62 -c-ha-w C:\Program Files\AppUpdate.log
2005-05-11 18:07 4,811 -c--a-w C:\Program Files\INSTALL.LOG
2001-09-28 16:00 164,864 -c--a-w C:\Program Files\UNWISE.EXE
2008-07-01 15:20 27,976 -c--a-w C:\Program Files\mozilla firefox\plugins\atgpcdec.dll
2008-07-01 15:20 125,848 -c--a-w C:\Program Files\mozilla firefox\plugins\atgpcext.dll
2008-07-01 15:21 98,712 -c--a-w C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
.

((((((((((((((((((((((((((((( snapshot@2008-06-29_11.07.13.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-29 09:53:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-02 15:09:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-16 12:29:22 45,056 -c--a-r C:\WINDOWS\Installer\$PatchCache$\Managed\87EE84B2FFF51C44EB277383C78A6A3B\3.29.0\bestbcrsa.dll
+ 2008-03-14 13:34:30 40,960 -c--a-r C:\WINDOWS\Installer\$PatchCache$\Managed\87EE84B2FFF51C44EB277383C78A6A3B\3.29.0\bestllbcrsa.dll
+ 2008-04-16 12:29:22 45,056 -c--a-r C:\WINDOWS\Installer\$PatchCache$\Managed\87EE84B2FFF51C44EB277383C78A6A3B\3.29.0\freefirstbcrsa.dll
+ 2007-08-15 10:12:40 36,864 -c--a-r C:\WINDOWS\Installer\$PatchCache$\Managed\87EE84B2FFF51C44EB277383C78A6A3B\3.29.0\llbc.dll
+ 2008-04-28 10:08:52 40,960 -c--a-r C:\WINDOWS\Installer\$PatchCache$\Managed\87EE84B2FFF51C44EB277383C78A6A3B\3.29.0\newmppi.dll
+ 2008-04-28 10:09:44 40,960 -c--a-r C:\WINDOWS\Installer\$PatchCache$\Managed\87EE84B2FFF51C44EB277383C78A6A3B\3.29.0\nuimortgageprotector.dll
+ 2008-04-03 11:37:04 61,440 -c--a-r C:\WINDOWS\Installer\$PatchCache$\Managed\87EE84B2FFF51C44EB277383C78A6A3B\3.29.0\psl.common.systemupdate.dll
+ 2008-04-23 13:00:52 442,368 -c--a-r C:\WINDOWS\Installer\$PatchCache$\Managed\87EE84B2FFF51C44EB277383C78A6A3B\3.29.0\psl.common.usercontrols.dll
- 2008-06-05 12:13:44 4,150 -c--a-r C:\WINDOWS\Installer\{2B48EE78-5FFF-44C1-BE72-37387CA8A6B3}\ARPPRODUCTICON.exe
+ 2008-07-01 15:34:50 4,150 -c--a-r C:\WINDOWS\Installer\{2B48EE78-5FFF-44C1-BE72-37387CA8A6B3}\ARPPRODUCTICON.exe
- 2008-06-05 12:13:44 45,056 -c--a-r C:\WINDOWS\Installer\{2B48EE78-5FFF-44C1-BE72-37387CA8A6B3}\NewShortcut1_28111ADBF25B4D2D8729086C68D09D06.exe
+ 2008-07-01 15:34:50 45,056 -c--a-r C:\WINDOWS\Installer\{2B48EE78-5FFF-44C1-BE72-37387CA8A6B3}\NewShortcut1_28111ADBF25B4D2D8729086C68D09D06.exe
- 2008-06-05 12:13:45 45,056 -c--a-r C:\WINDOWS\Installer\{2B48EE78-5FFF-44C1-BE72-37387CA8A6B3}\NewShortcut11_28111ADBF25B4D2D8729086C68D09D06.exe
+ 2008-07-01 15:34:51 45,056 -c--a-r C:\WINDOWS\Installer\{2B48EE78-5FFF-44C1-BE72-37387CA8A6B3}\NewShortcut11_28111ADBF25B4D2D8729086C68D09D06.exe
- 2008-06-29 08:52:20 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-07-02 11:28:49 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-06-29 08:52:20 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-02 11:28:49 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-06-29 08:52:20 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-02 11:28:49 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-25 03:21:18 2,889,088 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2008-03-25 03:21:20 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-06-29 21:35:08 70,264 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-07-02 15:10:35 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_150.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94CFA39F-389A-4D00-86C2-04F49C10A2D6}]
2003-03-31 13:00 84992 --a------ c:\windows\system32\vqzzxks.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F92C5901-4970-4121-9B82-C52AD1E53785}]
2008-06-29 10:49 88064 --a--c--- C:\WINDOWS\system32\avtapip.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-09-19 14:35 114688]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe" [2003-03-26 19:19 45056]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 11:29 40960]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 08:56 158208]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 06:03 81920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\videolib\sonydv.dll
"msacm.avis"= ff_acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Customer Focus Alert.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Customer Focus Alert.lnk
backup=C:\WINDOWS\pss\Customer Focus Alert.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP LaserJet Director.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP LaserJet Director.lnk
backup=C:\WINDOWS\pss\HP LaserJet Director.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PowerPanel.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerPanel.lnk
backup=C:\WINDOWS\pss\PowerPanel.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEAutoRun]
[X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a--c--- 2007-03-09 12:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a--c--- 2007-05-11 04:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GIology]
--a--c--- 2008-07-01 15:26 3262464 c:\Program Files\Legal & General\GIology\GIology.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HKSERV.EXE]
--a------ 2003-08-14 11:00 90112 C:\Program Files\sony\HotKey Utility\HKServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP AutoIndexer]
--a--c--- 2002-04-22 13:57 90112 C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP SchedIndexer]
--a--c--- 2002-04-22 13:56 94208 C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a--c--- 2005-02-17 00:11 49152 C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a--c--- 2004-06-16 06:03 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mount.exe]
--a--c--- 2008-04-11 16:17 374272 C:\Program Files\GiPo@Utilities\FileUtilities.3\mount.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2004-01-28 14:49 77824 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StatusClient 2.6]
--a--c--- 2004-02-27 18:29 61440 C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a--c--- 2008-05-28 10:33 1506544 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup 2.5]
--a--c--- 2004-05-20 17:40 188416 C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
--a--c--- 2007-10-31 11:19 378784 C:\Program Files\TomTom HOME 2\HOMERunner.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
--a------ 2003-11-18 14:55 135168 C:\Program Files\sony\vaio update 2\VAIOUpdt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon]
--a------ 2002-03-14 17:46 45056 C:\WINDOWS\system32\ico.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\WINDOWS\\system32\\msiexec.exe"=
"C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\kdx\\KHost.exe"=
"C:\\Program Files\\KService\\KService.exe"=
"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"=
"C:\\Inertia 3\\System\\PSL.Development.MainApp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:iMp3Downloading
"6346:UDP"= 6346:UDP:iMp3Downloading
"5541:TCP"= 5541:TCP:@xpsp2res.dll,-22009
"80:TCP"= 80:TCP:@xpsp2res.dll,-22009

R0 mhksjmhy;mhksjmhy;C:\WINDOWS\system32\drivers\mhksjmhy.sys [2003-03-31 13:00]
R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 10:03]
R2 MSSQL$INERTIA3_SQL2005;SQL Server (INERTIA3_SQL2005);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINERTIA3_SQL2005 []
R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2003-08-26 17:27]
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys [2002-08-20 11:59]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\AUTOPLAY.EXE id=10000020000015000011 ver=1.0.0.0

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd5e0a3e-6b44-11db-959d-080046d2bc2e}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-03-15 09:04:56 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-03-01 01:00:28 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
- - - - ORPHANS REMOVED - - - -

Toolbar-SITEguard - (no file)
HKLM-Run-StartSQLManager - C:\Program Files\Microsoft SQL Server\90\Tools\Binn\sqlmangr.exe
MSConfigStartUp-BHR - C:\Program Files\Zamaan's Software\Browser Hijack Retaliator 4.5\BHR.exe
MSConfigStartUp-fub2 - C:\WINDOWS\system32\fub2.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-02 16:11:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Apoint\ApntEx.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2008-07-02 16:19:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-02 15:19:27
ComboFix2.txt 2008-06-29 10:08:07

Pre-Run: 11,926,376,448 bytes free
Post-Run: 11,916,201,984 bytes free

290 --- E O F --- 2008-06-22 08:28:21






and here's the Malware one (which didn't find anything wrong):


Malwarebytes' Anti-Malware 1.19
Database version: 913
Windows 5.1.2600 Service Pack 2

15:41:00 02/07/2008
mbam-log-7-2-2008 (15-41-00).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 168627
Time elapsed: 1 hour(s), 43 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13131
 
   Posted 7-4-2008 9:02 (GMT +2)    Quote: Removing a Trojan that is Write ProtectedAlert an admin about: Removing a Trojan that is Write Protected
They seems to stubborn -
 
 
Open notepad and copy/paste the text in the quote box below into it:
Quote:
-----------------------------------------------------
KILLALL::
 
Snapshot::
 
File::
c:\windows\system32\vqzzxks.dll
C:\WINDOWS\system32\avtapip.dll
 
 
RootKit::
c:\windows\system32\vqzzxks.dll
C:\WINDOWS\system32\avtapip.dll
 
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94CFA39F-389A-4D00-86C2-04F49C10A2D6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F92C5901-4970-4121-9B82-C52AD1E53785}]
 
 

----------------------------------------------
 
Save this as CFScript.txt
 
 
At this point, You MUST EXIT ALL BROWSERS NOW before continuing!
Referring to the picture above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system.
It may reboot your system when it finishes. This is normal.
 
 
Post new hijackthis log along with fresh combofix log


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

Becks287
New Member


Date Joined Jun 2008
Total Posts : 8
 
   Posted 7-5-2008 1:52 (GMT +2)    Quote: Removing a Trojan that is Write ProtectedAlert an admin about: Removing a Trojan that is Write Protected
Unfortunately, that's not worked either shakehead

Here's the logs

ComboFix 08-07-01.3 - Steve 2008-07-05 12:23:41.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.273 [GMT 1:00]
Running from: C:\Documents and Settings\Steve\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Steve\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\avtapip.dll
c:\windows\system32\vqzzxks.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\avtapip.dll . . . . failed to delete
c:\windows\system32\vqzzxks.dll . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 )))))))))))))))))))))))))))))))
.

2008-07-02 13:54 . 2008-07-02 13:54 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Malwarebytes
2008-07-02 13:54 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-02 13:53 . 2008-07-02 13:54 <DIR> d----c--- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-02 13:53 . 2008-07-02 13:53 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-02 13:53 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-01 16:30 . 2008-07-01 16:30 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Macrovision
2008-06-29 18:40 . 2008-06-29 18:40 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Talkback
2008-06-29 18:39 . 2008-06-29 18:39 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-28 23:35 . 2008-06-28 23:35 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-28 23:34 . 2008-06-28 23:34 <DIR> d----c--- C:\Program Files\SUPERAntiSpyware
2008-06-28 23:34 . 2008-06-28 23:34 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\SUPERAntiSpyware.com
2008-06-28 23:33 . 2008-06-28 23:33 <DIR> d----c--- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-28 23:25 . 2008-06-28 23:25 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Citrix
2008-06-28 23:20 . 2008-07-01 15:17 60,968 --a--c--- C:\Documents and Settings\Steve\GoToAssistDownloadHelper.exe
2008-06-28 20:59 . 2008-06-28 20:59 <DIR> d-------- C:\WINDOWS\Mozilla
2008-06-28 20:54 . 2008-07-02 14:14 <DIR> d----c--- C:\!KillBox
2008-06-28 20:10 . 2008-06-28 20:10 <DIR> d----c--- C:\Program Files\GiPo@Utilities
2008-06-28 17:10 . 2008-06-28 17:10 <DIR> d----c--- C:\Program Files\IDM Computer Solutions
2008-06-28 17:10 . 2008-06-28 17:10 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\IDMComp
2008-06-28 14:16 . 2008-06-28 14:16 <DIR> d----c--- C:\Documents and Settings\LocalService\Application Data\McAfee
2008-06-21 13:13 . 2008-07-01 17:38 15,928 --a------ C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-06-21 13:10 . 2008-07-01 15:06 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-06-21 13:08 . 2008-06-21 13:08 <DIR> d----c--- C:\Program Files\STOPzilla!
2008-06-21 13:08 . 2008-06-21 13:08 <DIR> d----c--- C:\Program Files\Common Files\iS3
2008-06-21 13:08 . 2008-07-05 12:33 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-06-21 11:14 . 2008-06-21 11:14 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\Uniblue
2008-06-12 15:09 . 2008-06-12 15:09 258,048 -ra------ C:\WINDOWS\system32\SZBase5.dll
2008-06-12 10:11 . 2008-06-12 10:11 364,544 -ra------ C:\WINDOWS\system32\IS3DBA5.dll
2008-06-12 10:11 . 2008-06-12 10:11 126,976 -ra------ C:\WINDOWS\system32\IS3HTUI5.dll
2008-06-12 10:10 . 2008-06-12 10:10 372,736 -ra------ C:\WINDOWS\system32\IS3UI5.dll
2008-06-12 10:10 . 2008-06-12 10:10 61,440 -ra------ C:\WINDOWS\system32\IS3Hks5.dll
2008-06-12 10:10 . 2008-06-12 10:10 23,040 -ra------ C:\WINDOWS\system32\IS3XDat5.dll
2008-06-12 10:09 . 2008-06-12 10:09 196,608 -ra------ C:\WINDOWS\system32\IS3Win325.dll
2008-06-12 10:08 . 2008-06-12 10:08 94,208 -ra------ C:\WINDOWS\system32\IS3Inet5.dll
2008-06-12 10:08 . 2008-06-12 10:08 90,112 -ra------ C:\WINDOWS\system32\IS3Svc5.dll
2008-06-12 10:05 . 2008-06-12 10:05 708,608 -ra------ C:\WINDOWS\system32\IS3Base5.dll
2008-06-10 19:18 . 2008-06-10 19:18 <DIR> d----c--- C:\Documents and Settings\NetworkService\Application Data\meidifwt
2008-06-10 18:23 . 2008-06-10 18:23 <DIR> d----c--- C:\Documents and Settings\Steve\Application Data\meidifwt
2008-06-10 11:15 . 2008-06-10 18:23 <DIR> d----c--- C:\Program Files\Common Files\Mozilla Shared
2008-06-10 11:04 . 2008-06-10 11:04 <DIR> d----c--- C:\Archive
2008-06-07 09:49 . 2002-11-06 11:02 128,000 --a--c--- C:\WINDOWS\system32\Cp5dll32i.dll
2008-06-07 09:49 . 2008-06-29 10:49 88,064 --a--c--- C:\WINDOWS\system32\avtapip.dll
2008-06-06 23:14 . 2008-07-02 08:48 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-06 23:14 . 2008-06-06 23:14 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Program Files\Common Files\Business Objects
2008-06-05 13:12 . 2008-07-01 16:26 <DIR> d-------- C:\Inertia 3
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\regcrypt
2008-06-05 13:12 . 2008-06-05 13:12 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Macrovision

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-05 11:21 --------- dc----w C:\Program Files\mortgageLink Enterprise
2008-07-05 11:13 --------- dc----w C:\Program Files\MarkInfo
2008-07-05 10:24 --------- dc----w C:\Program Files\McAfee
2008-07-02 15:37 --------- dc----w C:\Program Files\Yahoo!
2008-07-01 14:26 --------- dc----w C:\Program Files\Common Files\F1
2008-06-28 22:05 --------- dc----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-28 22:00 --------- dc----w C:\Documents and Settings\Steve\Application Data\McAfee
2008-06-27 17:30 --------- dc----w C:\Program Files\Legal & General
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-09 18:43 --------- dc----w C:\Program Files\Google
2008-06-05 12:05 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-06-04 14:47 --------- dc----w C:\Program Files\Microsoft.NET
2008-06-04 14:44 --------- dc----w C:\Program Files\MSXML 6.0
2008-05-29 10:22 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2008-05-29 10:22 --------- dc----w C:\Program Files\Intermediary Mortgages
2008-05-29 10:20 --------- dc----w C:\Program Files\Seagate Software
2008-05-15 12:25 --------- dc----w C:\Program Files\Coupon Printer
2008-05-13 09:03 34,432 ----a-r C:\WINDOWS\system32\drivers\SZKG.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-24 10:07 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-03-12 12:14 84,808 -c--a-w C:\Documents and Settings\Steve\Application Data\GDIPFONTCACHEV1.DAT
2005-11-23 14:55 62 -c-ha-w C:\Program Files\AppUpdate.log
2005-05-11 18:07 4,811 -c--a-w C:\Program Files\INSTALL.LOG
2001-09-28 16:00 164,864 -c--a-w C:\Program Files\UNWISE.EXE
2008-07-01 15:20 27,976 -c--a-w C:\Program Files\mozilla firefox\plugins\atgpcdec.dll
2008-07-01 15:20 125,848 -c--a-w C:\Program Files\mozilla firefox\plugins\atgpcext.dll
2008-07-01 15:21 98,712 -c--a-w C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94CFA39F-389A-4D00-86C2-04F49C10A2D6}]
2008-07-05 12:30 84992 --a------ c:\windows\system32\vqzzxks.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F92C5901-4970-4121-9B82-C52AD1E53785}]
2008-06-29 10:49 88064 --a--c--- C:\WINDOWS\system32\avtapip.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-09-19 14:35 114688]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe" [2003-03-26 19:19 45056]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 11:29 40960]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 08:56 158208]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 06:03 81920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\videolib\sonydv.dll
"msacm.avis"= ff_acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Customer Focus Alert.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Customer Focus Alert.lnk
backup=C:\WINDOWS\pss\Customer Focus Alert.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP LaserJet Director.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP LaserJet Director.lnk
backup=C:\WINDOWS\pss\HP LaserJet Director.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PowerPanel.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PowerPanel.lnk
backup=C:\WINDOWS\pss\PowerPanel.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEAutoRun]
[X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a--c--- 2007-03-09 12:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a--c--- 2007-05-11 04:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GIology]
--a--c--- 2008-07-01 15:26 3262464 c:\Program Files\Legal & General\GIology\GIology.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HKSERV.EXE]
--a------ 2003-08-14 11:00 90112 C:\Program Files\sony\HotKey Utility\HKServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP AutoIndexer]
--a--c--- 2002-04-22 13:57 90112 C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP SchedIndexer]
--a--c--- 2002-04-22 13:56 94208 C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a--c--- 2005-02-17 00:11 49152 C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a--c--- 2004-06-16 06:03 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2004-01-28 14:49 77824 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StatusClient 2.6]
--a--c--- 2004-02-27 18:29 61440 C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a--c--- 2008-05-28 10:33 1506544 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup 2.5]
--a--c--- 2004-05-20 17:40 188416 C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
--a--c--- 2007-10-31 11:19 378784 C:\Program Files\TomTom HOME 2\HOMERunner.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
--a------ 2003-11-18 14:55 135168 C:\Program Files\sony\vaio update 2\VAIOUpdt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon]
--a------ 2002-03-14 17:46 45056 C:\WINDOWS\system32\ico.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\WINDOWS\\system32\\msiexec.exe"=
"C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\kdx\\KHost.exe"=
"C:\\Program Files\\KService\\KService.exe"=
"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"=
"C:\\Inertia 3\\System\\PSL.Development.MainApp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:iMp3Downloading
"6346:UDP"= 6346:UDP:iMp3Downloading
"5541:TCP"= 5541:TCP:@xpsp2res.dll,-22009
"80:TCP"= 80:TCP:@xpsp2res.dll,-22009

R0 mhksjmhy;mhksjmhy;C:\WINDOWS\system32\drivers\mhksjmhy.sys [2003-03-31 13:00]
R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 10:03]
R2 MSSQL$INERTIA3_SQL2005;SQL Server (INERTIA3_SQL2005);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINERTIA3_SQL2005 []
R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2003-08-26 17:27]
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys [2002-08-20 11:59]
S2 0069331215253508mcinstcleanup;McAfee Application Installer Cleanup (0069331215253508);C:\WINDOWS\TEMP\006933~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\AUTOPLAY.EXE id=10000020000015000011 ver=1.0.0.0

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd5e0a3e-6b44-11db-959d-080046d2bc2e}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe

*Newly Created Service* - 0069331215253508MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
"2008-03-15 09:04:56 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-03-01 01:00:28 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-mount - C:\Program Files\GiPo@Utilities\FileUtilities.3\mount.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-05 12:34:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe