please help me. i have read the other threads concerning this virus but am not sure what to do first. I have windows xp and yesterday my windows live messenger 8.1 starting sending rude messages and files to the friends on my contact list. Also MSN continuosly freezes and that is when i think the messages are sent. luckily none of my friends opened the files sent. i do not know how i got this as i have not opened any files myself.
i have run the combofix o7 as you said but don't know what to do now. i saved it in word as i dont know how to save it to desktop.
please help me as i use msn for work as well.
thank you in advance
debbie
attached below is the combofix log
ComboFix 07-09-21.2 - "debbie" 2007-09-25 21:25:32.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.335 [GMT 1:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\cursorcafe.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\cursorcafeA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\games.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\gamesA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\screensaver.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\buttons\screensaverA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\contexts\error.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\contexts\related.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\contexts\travel.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\contexts\Travel.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\ProductMessagingConfig .xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\ProductMessagingConfig .xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\SimpleUpdateConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\SimpleUpdateConfig.xml .backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\TimerManagerConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware\SimpleUpdate\TimerManagerConfig.xml .backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\cursorcafe.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\cursorcafeA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\games.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\gamesA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\screensaver.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\buttons\screensaverA.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\contexts\error.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\contexts\related.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\contexts\travel.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\contexts\Travel.xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\ProductMessagingConfig. xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\ProductMessagingConfig. xml.backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\SimpleUpdateConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\SimpleUpdateConfig.xml. backup
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\TimerManagerConfig.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware\SimpleUpdate\TimerManagerConfig.xml. backup
C:\DOCUME~1\CHARLO~1\APPLIC~1\FunWebProducts
C:\DOCUME~1\CHARLO~1\APPLIC~1\FunWebProducts\Data\charlotte\avatar.dat
C:\DOCUME~1\CHARLO~1\APPLIC~1\FunWebProducts\Data\charlotte\register.dat
C:\DOCUME~1\debbie\APPLIC~1\macromedia\Flash Player\#SharedObjects\JNU6XF5R\iforex.com
C:\DOCUME~1\debbie\APPLIC~1\macromedia\Flash Player\#SharedObjects\JNU6XF5R\iforex.com\Emerp\Events\flash_object.swf\use r_data.sol
C:\DOCUME~1\debbie\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\DOCUME~1\debbie\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\00BF6EFD.urr
C:\Program Files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MySignatureInsertBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\iMeshBar
C:\Program Files\iMeshBar\bar\Cache\0001C685
C:\Program Files\iMeshBar\bar\Cache\0015BBA0.bin
C:\Program Files\iMeshBar\bar\Cache\0015BE67.bmp
C:\Program Files\iMeshBar\bar\Cache\0015BEB7.bmp
C:\Program Files\iMeshBar\bar\Cache\files.ini
C:\Program Files\iMeshBar\bar\History\search
C:\Program Files\iMeshBar\bar\Settings\prevcfg.htm
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\2.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\3.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\3.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\3.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\3.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\3.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\3.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\3.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\3.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\3.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\3.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\3.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\3.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\3.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\3.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\3.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\3.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\3.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\avatar.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\bgfadel.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\bgfader.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\close.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\common-x.css
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\common.css
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\cornerbl.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\cornerbr.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\htmlctrl.js
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\include.js
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\index.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\loading.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\login.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\logo.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\max.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\min.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\noflash.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\spacer.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\spacer.swf
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\unmax.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\wardrobe.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\window.ico
C:\Program Files\MyWebSearch\bar\Cache\00015166.bin
C:\Program Files\MyWebSearch\bar\Cache\000153BF.bin
C:\Program Files\MyWebSearch\bar\Cache\000155F9.bin
C:\Program Files\MyWebSearch\bar\Cache\000157A8.bin
C:\Program Files\MyWebSearch\bar\Cache\0001592F.bin
C:\Program Files\MyWebSearch\bar\Cache\00029222.bin
C:\Program Files\MyWebSearch\bar\Cache\00040F26
C:\Program Files\MyWebSearch\bar\Cache\0006FBBA
C:\Program Files\MyWebSearch\bar\Cache\0009E6F9
C:\Program Files\MyWebSearch\bar\Cache\00112411
C:\Program Files\MyWebSearch\bar\Cache\0011F3AB
C:\Program Files\MyWebSearch\bar\Cache\00139204
C:\Program Files\MyWebSearch\bar\Cache\002681BA
C:\Program Files\MyWebSearch\bar\Cache\002686EE.bin
C:\Program Files\MyWebSearch\bar\Cache\002687A2.bin
C:\Program Files\MyWebSearch\bar\Cache\002687F3.bin
C:\Program Files\MyWebSearch\bar\Cache\00268825.bin
C:\Program Files\MyWebSearch\bar\Cache\0026BB31.bin
C:\Program Files\MyWebSearch\bar\Cache\0026BCC2.bin
C:\Program Files\MyWebSearch\bar\Cache\0026BD3A.bin
C:\Program Files\MyWebSearch\bar\Cache\0026BDF8.bin
C:\Program Files\MyWebSearch\bar\Cache\0026BE67.bin
C:\Program Files\MyWebSearch\bar\Cache\003E3855
C:\Program Files\MyWebSearch\bar\Cache\004A5289
C:\Program Files\MyWebSearch\bar\Cache\0073A576.bin
C:\Program Files\MyWebSearch\bar\Cache\0073A652.bin
C:\Program Files\MyWebSearch\bar\Cache\0073A68E.bin
C:\Program Files\MyWebSearch\bar\Cache\007720C8
C:\Program Files\MyWebSearch\bar\Cache\007726BA.bin
C:\Program Files\MyWebSearch\bar\Cache\0077275A
C:\Program Files\MyWebSearch\bar\Cache\009B3B68
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Search\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\bar\Settings\settings.dat.bak
C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
C:\Program Files\screensavers.com
C:\Program Files\screensavers.com\Installer\bin\iebyterange.xml
C:\Program Files\screensavers.com\Installer\bin\iebyterange.xml.backup
C:\Program Files\screensavers.com\Installer\bin\ScreensaversInst.dll
C:\Program Files\screensavers.com\Installer\bin\siuninst.exe
C:\Program Files\screensavers.com\Wallpaper\Shrek 2 - Puss in Boots.jpg
C:\Program Files\screensavers.com\Wallpaper\swpstart.exe
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\f3PSSavr.scr
.
((((((((((((((((((((((((( Files Created from 2007-08-25 to 2007-09-25 )))))))))))))))))))))))))))))))
.
2007-09-25 21:23 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-25 20:52 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-09-25 20:52 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-09-25 20:52 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-09-25 20:52 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-09-25 20:52 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-09-25 20:52 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-09-25 20:52 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-09-25 20:52 <DIR> d-------- C:\DOCUME~1\debbie\APPLIC~1\PC Tools
2007-09-24 08:04 51,712 -r-hs---- C:\WINDOWS\system32\mdn.exe
2007-09-20 19:21 290,816 --a------ C:\WINDOWS\Pumpkin Madness.scr
2007-09-20 19:21 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Softdisk LLC
2007-09-14 17:23 <DIR> d-------- C:\Program Files\Common Files\xing shared
2007-09-12 23:38 <DIR> d-------- C:\DOCUME~1\debbie\APPLIC~1\Roxio
2007-09-02 12:26 <DIR> d-------- C:\DOCUME~1\MIKE~1.DOW\APPLIC~1\Real
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-25 19:40 --------- d-------- C:\Program Files\MSN Messenger
2007-09-25 18:58 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-09-25 18:49 --------- d-------- C:\Program Files\Common Files\AOL
2007-09-25 18:49 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-09-25 09:56 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
2007-09-24 21:49 --------- d-------- C:\Program Files\Napster
2007-09-24 19:08 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\burn spam ping upload
2007-09-22 21:35 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
2007-09-21 22:02 --------- d-------- C:\DOCUME~1\AARON~1.DOW\APPLIC~1\IMVU
2007-09-19 17:53 --------- d-------- C:\DOCUME~1\debbie\APPLIC~1\Real
2007-09-15 09:10 --------- d-------- C:\DOCUME~1\AARON~1.DOW\APPLIC~1\WINDOWLICENSEBITS
2007-09-14 17:23 --------- d-------- C:\Program Files\Common Files\Real
2007-09-13 23:13 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Program dead road burn
2007-09-11 17:10 --------- d-------- C:\DOCUME~1\AARON~1.DOW\APPLIC~1\Real
2007-09-02 12:52 --------- d-------- C:\DOCUME~1\MIKE~1.DOW\APPLIC~1\MSN6
2007-08-20 17:42 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Napster
2007-08-20 17:41 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-20 17:41 --------- d-------- C:\Program Files\Common Files\Napster Shared
2007-08-20 16:30 --------- d-------- C:\DOCUME~1\CHARLO~1\APPLIC~1\Real
2007-08-19 22:58 --------- d-------- C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Real
2007-08-19 22:01 --------- d-------- C:\DOCUME~1\debbie\APPLIC~1\Google
2007-08-19 21:57 --------- d-------- C:\Program Files\Google
2007-08-19 14:14 --------- d-------- C:\Program Files\AOL 9.0a
2007-08-16 07:41 --------- d-------- C:\Program Files\AOL Companion
2007-08-15 20:48 --------- d-------- C:\Program Files\Common Files\aolshare
2007-08-15 20:48 --------- d-------- C:\Program Files\AOL Toolbar
2007-08-15 10:06 --------- d-------- C:\DOCUME~1\CHARLO~1\APPLIC~1\MSN6
2007-08-15 09:40 --------- d-------- C:\Program Files\MSXML 4.0
2007-08-12 09:48 --------- d-------- C:\Program Files\IMVU
2007-08-08 15:45 --------- d-------- C:\DOCUME~1\CHARLO~1\APPLIC~1\WINDOWLICENSEBITS
2007-08-08 15:40 --------- d-------- C:\DOCUME~1\CHARLO~1\APPLIC~1\Screenshot Sender
2007-08-05 21:30 --------- d-------- C:\Program Files\NaturalMotion
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-06-29 15:41 98304 --a--c--- C:\WINDOWS\system32\CmdLineExt.dll
2007-06-26 07:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2004-07-22 11:51 3432656 --a--c--- C:\Program Files\ManagedDX.CAB
2004-07-19 23:58 1156363 --a--c--- C:\Program Files\BDANT.cab
2004-07-19 23:53 976020 --a--c--- C:\Program Files\BDAXP.cab
2004-07-09 15:17 13265040 --a--c--- C:\Program Files\dxnt.cab
2004-07-09 10:13 703080 --a--c--- C:\Program Files\BDA.cab
2004-07-09 10:13 15493481 --a--c--- C:\Program Files\DirectX.cab
2004-07-09 05:08 472576 --a--c--- C:\Program Files\dxsetup.exe
2004-07-09 05:08 2242560 --a--c--- C:\Program Files\dsetup32.dll
2004-07-09 04:03 62976 --a--c--- C:\Program Files\DSETUP.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5345A7A1-805A-4923-B505-86B2FEBA3FE0}]
C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]
2006-07-06 20:54 352256 --------- C:\Program Files\GamesBar\oberontb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"HostManager"="C:\Program Files\Common Files\AOL\1181588533\ee\AOLSoftware.exe" [2006-11-17 14:21]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [2004-03-26 22:58]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2007-01-12 19:36]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-14 17:23]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-09-20 15:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Actiontec 802.11g USB Wireless LAN.lnk - C:\Program Files\Actiontec 802.11g USB Wireless LAN\PRISMCFG.EXE [2007-06-20 18:02:50]
AOL 9.0 Tray Icon.lnk - C:\Program Files\AOL 9.0a\aoltray.exe [2007-08-15 20:47:27]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-08-19 21:56:19]
C:\DOCUME~1\AARON~1.DOW\STARTM~1\Programs\Startup\
IMVU.lnk - C:\Program Files\IMVU\IMVUClient.exe [2007-08-08 05:13:02]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxs ervice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcore service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Actiontec 802.11g USB Wireless LAN.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Actiontec 802.11g USB Wireless LAN.lnk
backup=C:\WINDOWS\pss\Actiontec 802.11g USB Wireless LAN.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\AOL 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ViaMixer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ViaMixer.lnk
backup=C:\WINDOWS\pss\ViaMixer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^charlotte^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\charlotte\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkStartup
?
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Burn drive third file]
C:\Documents and Settings\All Users\Application Data\ExtraLoveBurnDrive\facemore.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamWizard]
C:\Program Files\Common Files\Logitech\QCDRV\BIN\CamWizrd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3600 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1181588533\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImInstaller_IncrediMail]
C:\DOCUME~1\MIKE~1.DOW\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_in stall[1].exe -startup -product IncrediMail
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
C:\Program Files\IncrediMail\bin\IncMail.exe /c
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
"C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
C:\WINDOWS\System32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
"C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ms1src]
c:\program files\common files\system\ms1src.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar Search Scope Monitor]
"C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=0
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntl Netguard]
"C:\Program Files\ntl\ntl Netguard\RPS.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OemReset]
%systemroot%\OPTIONS\OEMRESET.EXE /AUDIT
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSS]
C:\windows\system32\rlvknlg.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRISMSVR.EXE]
"C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
S3 gbalink;GBA Link Driver (gbalink.sys);C:\WINDOWS\system32\Drivers\gbalink.sys
S3 ldiskl;ldiskl;\??\C:\DOCUME~1\debbie\LOCALS~1\Temp\ldiskl.sys
S3 ss_bus;Samsung Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys
S3 Vsp;Vsp;\??\C:\WINDOWS\System32\drivers\Vsp.sys
S4 spcstb;spcstb;C:\WINDOWS\system32\DRIVERS\spcstb.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-09-25 20:00:00 C:\WINDOWS\Tasks\A0FF1687918493D3.job"
"2007-09-25 20:00:00 C:\WINDOWS\Tasks\ABF5D28D91A64B59.job"
"2007-09-25 19:39:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-09-25 21:51:07
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-25 21:55:59 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-25 21:55
.
--- E O F ---