My PC, the one I'm writing this from, doesn't see the other computers on the network. It's been a problem for a while, and I've so far been unable to fix it, so I just accept that I can't transfer data that way. And my laptop has no 3.5 floppy drive. Luckily however I was able to get my internet connection to work for a little while by opening Microsoft Update through the Control Panel, and I ran HiJackThis and sent both logs to myself via email.
ComboFix Log:
ComboFix 07-10-23.2 - ibm 2007-10-25 0:12:29.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.80 [GMT -4:00]
Running from: C:\Documents and Settings\ibm\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
.
---- Previous Run -------
.
C:\check_LSA7.txt
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\ibm\My Documents\MBOLS~1
C:\Documents and Settings\ibm\My Documents\MBOLS~1\??mbols\
C:\Documents and Settings\ibm\My Documents\MBOLS~1\mmc.exe
C:\Documents and Settings\ibm\Start Menu\Programs\Outerinfo
C:\Documents and Settings\ibm\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\ibm\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\LocalService\Local Settings\Application Data\n.ini
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\ComPlus Applications\hoqeric4444.dll
C:\Program Files\ComPlus Applications\hoqeric83122.dll
C:\Program Files\ecurit~1
C:\Program Files\ecurit~1\w?nlogon.exe
C:\Program Files\ISM
C:\Program Files\ISM\targets.gz
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\ISM2
C:\Program Files\ISM2\dictionary.gz
C:\Program Files\ISM2\ISMPack7.exe
C:\Program Files\ISM2\targets.gz
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\Temporary
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fCOe
C:\Temp\fCOe\tOasF.log
C:\WINDOWS\b122.exe
C:\WINDOWS\b143.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\_svchost.exe
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\
0_exception.nls
C:\WINDOWS\system32\ac1
C:\WINDOWS\system32\ac1\rwv12drv.exe
C:\WINDOWS\system32\afjfovui.exe
C:\WINDOWS\system32\bsxi.dll
C:\WINDOWS\system32\drivers\Anaq61.sys
C:\WINDOWS\system32\drivers\Bbst69.sys
C:\WINDOWS\system32\drivers\runtime2.sys
C:\WINDOWS\system32\drivers\secdrv.sys
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\geuyblhg.dll
C:\WINDOWS\system32\gillm.bak1
C:\WINDOWS\system32\gillm.bak2
C:\WINDOWS\system32\gillm.ini
C:\WINDOWS\system32\gillm.ini2
C:\WINDOWS\system32\gillm.tmp
C:\WINDOWS\system32\iifebcy.dll
C:\WINDOWS\system32\kdwnf.exe
C:\WINDOWS\system32\kjodhlri.exe
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\lanmandrv.sys
C:\WINDOWS\system32\lanmanwrk.exe
C:\WINDOWS\system32\mkjxrvgr.ini
C:\WINDOWS\system32\mllig.dll
C:\WINDOWS\system32\oTt08e
C:\WINDOWS\system32\oTt08e\oTt08e1099.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\poof
C:\WINDOWS\system32\qmopt.dll
C:\WINDOWS\system32\qsvpekja.exe
C:\WINDOWS\system32\rgvrxjkm.dll
C:\WINDOWS\system32\RunOnce3.t__
C:\WINDOWS\system32\RunOnce3.tmp
C:\WINDOWS\system32\update176.exe
C:\WINDOWS\system32\update177.exe
C:\WINDOWS\system32\update246.exe
C:\WINDOWS\system32\update285.exe
C:\WINDOWS\system32\update294.exe
C:\WINDOWS\system32\vp4
C:\WINDOWS\system32\vp4\dode83122.exe
C:\WINDOWS\system32\wnsintcc.exe
C:\WINDOWS\system32\zb2
C:\WINDOWS\Temp\436277.exe
C:\WINDOWS\Temp\440042.exe
C:\WINDOWS\tsitra1000106.exe
C:\WINDOWS\tsitra11.exe
C:\WINDOWS\tsitra77.exe
C:\WINDOWS\tsitra801.exe
C:\WINDOWS\TTC-4444.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\winshow.exe
C:\WINDOWS\wnsxs~1
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_ANAQ61
-------\LEGACY_CMDSERVICE
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_LANMANDRV
-------\LEGACY_MICROSOFT_INTERNET_EXPLORER
-------\LEGACY_NETWORK_MONITOR
-------\LEGACY_POOF
-------\LEGACY_SYMAVC32
-------\DomainService
-------\kprof
-------\lanmandrv
-------\Microsoft Internet Explorer
-------\poof
-------\Anaq61
((((((((((((((((((((((((( Files Created from 2007-09-25 to 2007-10-25 )))))))))))))))))))))))))))))))
.
2007-10-24 22:42 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-24 03:09 <DIR> d-------- C:\WINDOWS\All Users
2007-10-24 02:20 <DIR> d-------- C:\WINDOWS\provisioning
2007-10-24 02:20 <DIR> d-------- C:\WINDOWS\peernet
2007-10-24 01:13 1,082,368 --a------ C:\WINDOWS\system32\esent.dll
2007-10-24 00:43 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-10-24 00:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-10-23 22:54 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-10-23 22:54 <DIR> d-------- C:\WINDOWS\ehome
2007-10-23 22:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Viewpoint
2007-10-23 21:54 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-23 21:48 84,544 --a------ C:\WINDOWS\system32\gjxatywx.dll
2007-10-23 17:01 <DIR> d-------- C:\WINDOWS\sv3965
2007-10-23 17:01 16,024 --a------ C:\WINDOWS\system32\qmogemap.exe
2007-10-23 01:38 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-10-23 01:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2007-10-22 22:36 16,024 --a------ C:\WINDOWS\system32\qmipejlf.exe
2007-10-22 22:04 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-10-22 18:23 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2007-10-22 18:23 4,569 --------- C:\WINDOWS\system32\secupd.dat
2007-10-22 18:17 35,840 --a------ C:\WINDOWS\system32\ssl.dat
2007-10-22 18:17 35,840 --a------ C:\WINDOWS\system32\KernelDrv.exe
2007-10-22 18:17 23,685 --a------ C:\WINDOWS\system32\kcopt.dll
2007-10-22 18:17 18,967 --a------ C:\WINDOWS\system32\ksvcl.dll
2007-10-22 18:17 10,240 --a------ C:\WINDOWS\system32\Dll.dll
2007-10-22 18:07 16,024 --a------ C:\WINDOWS\system32\qmpdnbmf.exe
2007-10-22 17:38 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Avant Profiles
2007-10-22 17:37 44 --a------ C:\WINDOWS\system32\p2hhr.bat
2007-10-22 17:35 10,000 --a------ C:\WINDOWS\system32\S7dsf4g.dll
2007-10-22 17:35 10,000 --a------ C:\WINDOWS\system32\Dhgthfg.dll
2007-10-22 17:33 7,680 --a------ C:\WINDOWS\ie_update3r.exe
2007-10-22 03:23 <DIR> d-------- C:\Documents and Settings\ibm\Application Data\SpyGuardPro
2007-10-22 03:22 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-10-22 03:22 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-10-22 03:22 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-10-22 03:22 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2007-10-22 03:22 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-10-22 03:20 <DIR> d-------- C:\Temp
2007-10-21 18:34 <DIR> d-------- C:\Program Files\Lavasoft
2007-10-21 18:33 <DIR> d--hs---- C:\WINDOWS\aWJt
2007-10-21 18:32 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-21 18:31 19,755,376 --a------ C:\aaw2007.exe
2007-10-21 18:30 1,939,926 --a------ C:\absetup.exe
2007-10-21 03:14 77,824 --a------ C:\MicroSofts.pif
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-22 03:02 --------- d-----w C:\Program Files\Avant Browser
2007-09-15 04:39 --------- d-----w C:\Program Files\Simu
2007-08-31 08:40 --------- d-----w C:\Program Files\Common Files\Adobe
2007-08-26 05:19 --------- d-----w C:\Documents and Settings\ibm\Application Data\Viewpoint
2007-08-26 05:12 --------- d-----w C:\Documents and Settings\ibm\Application Data\acccore
2007-08-26 05:11 --------- d-----w C:\Program Files\Viewpoint
2007-08-26 05:11 --------- d-----w C:\Program Files\AIM6
2007-08-26 05:10 --------- d-----w C:\Program Files\Common Files\AOL
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-31 02:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 02:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 02:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 02:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 02:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 02:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 02:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 02:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-31 02:18 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
2004-10-01 23:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2005-07-29 20:24:26 472 --sha-r C:\WINDOWS\aWJt\uqLQ.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8ABA9A9C-8791-4d61-8D5B-BCC9448EA573}]
C:\Program Files\ISM\BndDrive7.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"="tp4mon.exe" [2004-08-04 03:56 C:\WINDOWS\system32\tp4mon.exe]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-03 00:24]
"KernelDrv.exe"="C:\WINDOWS\System32\KernelDrv.exe" [2007-10-22 18:17]
"fc606473"="C:\WINDOWS\System32\gjxatywx.dll" [2007-10-23 21:48]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"="" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-24 05:56]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]
"Pira"="C:\DOCUME~1\ibm\MYDOCU~1\MBOLS~1\mmc.exe" []
"ISMModule7"="C:\Program Files\ISM\ISMModule7.exe" []
"Mgrr"="C:\Program Files\?ecurity\w?nlogon.exe" []
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 12:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Ksmntix]
Ksmntix.dll 2001-08-18 08:00 62464 C:\WINDOWS\system32\Ksmntix.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Mnbdiev]
Mnbdiev.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Tetbvpe]
tetbvpe.dll
S3 WlanUIB;iodata 802.11b USB Driver;C:\WINDOWS\system32\DRIVERS\MA111nd5.sys
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-25 00:15:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ?:?w?????????????????4@?????????D????4@?d???D???????d????<?w0???B;?wl?@?t?@?@7a?l?@?????????????????????????????????????????????????v??w ??w????B;?wj=?w?????4@??????>?w????l?@????????w????t?@???a?????????l?@?l?@?????MB?w????t?@?????l?@?8?@?l?@????s???????????
scanning hidden files ...
C:\WINDOWS\system32\ntos.exe 262144 bytes executable
C:\WINDOWS\system32\wsnpoem
scan completed successfully
hidden files: 2
**************************************************************************
.
Completion time: 2007-10-25 0:16:58
.
--- E O F ---
HiJackThis Log:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 2:58:57 PM, on 10/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\tp4mon.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\System32\KernelDrv.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\AVANTB~1\avant.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\ibm\Desktop\HiJackThis_v2.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BndShell3 BHO Class - {8ABA9A9C-8791-4d61-8D5B-BCC9448EA573} - C:\Program Files\ISM\BndDrive7.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [KernelDrv.exe] C:\WINDOWS\System32\KernelDrv.exe
O4 - HKLM\..\Run: [fc606473] rundll32.exe "C:\WINDOWS\System32\gjxatywx.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Pira] "C:\DOCUME~1\ibm\MYDOCU~1\MBOLS~1\mmc.exe" -vt yazb
O4 - HKCU\..\Run: [ISMModule7] "C:\Program Files\ISM\ISMModule7.exe"
O4 - HKCU\..\Run: [Mgrr] "C:\Program Files\?ecurity\w?nlogon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5721FA68-5ABD-40A8-81F1-4136691194BF} (Launcher Class) -
https://www.play.net/components/activex/AXSAL.ocxO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/microsoftu...b?1189146894552O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu...b?1189146879240O17 - HKLM\System\CCS\Services\Tcpip\..\{0B8EC79A-D092-423A-9C8A-CEA3EF0B7C21}: NameServer = 85.255.113.134,85.255.112.140
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD44D9D0-2243-4DC6-9BB3-BC180D995C77}: NameServer = 85.255.113.134,85.255.112.140
O17 - HKLM\System\CCS\Services\Tcpip\..\{E0F3F161-F8DD-45F8-9CBD-900D718A2B16}: NameServer = 85.255.113.134,85.255.112.140
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.134 85.255.112.140
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B8EC79A-D092-423A-9C8A-CEA3EF0B7C21}: NameServer = 85.255.113.134,85.255.112.140
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.134 85.255.112.140
O17 - HKLM\System\CS2\Services\Tcpip\..\{0B8EC79A-D092-423A-9C8A-CEA3EF0B7C21}: NameServer = 85.255.113.134,85.255.112.140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.134 85.255.112.140
O20 - Winlogon Notify: Ksmntix - C:\WINDOWS\SYSTEM32\ksmntix.dll
O20 - Winlogon Notify: Mnbdiev - Mnbdiev.dll (file missing)
O20 - Winlogon Notify: Tetbvpe - tetbvpe.dll (file missing)
O21 - SSODL: AHnGixIyej - {FC6064DD-56CA-CE77-E65A-774AC7C63540} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
--
End of file - 5336 bytes