I recently got Time-Warner Roadrunner DSL and had assumed they were installing the free virus protection upon installation. They did not and in that first week the computer got this. I tried downloading AdAware and some other free spyware, but nothing was allowed to update. Same with CA Anti-Spyware, the virus protection program that RoadRunner finally sent to me. Problem not solved and now I can't connect to the internet at home (though perhaps that is a separate issue).
I have downloaded ComboFix on my work computer and transferred it to my laptop by jumpdrive and ran it. Below is the log file.
ComboFix 08-10-05.03 - Matt Gray 2008-10-05 18:11:14.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.710 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Matt Gray\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Matt Gray\Cookies\matt_gray@article.archive.nytimes[1].txt
C:\Documents and Settings\Matt Gray\Cookies\matt_gray@cityroom.blogs.nytimes[1].txt
C:\Documents and Settings\Matt Gray\Cookies\matt_gray@std.o.nytimes[2].txt
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\TDSSadw.dll
C:\WINDOWS\system32\TDSSerrors.log
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\TDSSlog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\TDSSserf1.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\system32\windows_update.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-05 to 2008-10-05 )))))))))))))))))))))))))))))))
.
2008-10-05 17:31 . 2007-08-20 13:38 879,784 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2008-10-05 17:31 . 2007-08-20 13:38 108,312 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2008-10-05 17:31 . 2007-08-20 13:37 99,592 --a------ C:\WINDOWS\system32\isafeif.dll
2008-10-05 17:31 . 2007-08-20 13:26 79,424 --a------ C:\WINDOWS\system32\vetredir.dll
2008-10-05 17:31 . 2007-08-20 13:37 75,016 --a------ C:\WINDOWS\system32\isafprod.dll
2008-10-05 17:31 . 2007-08-20 13:38 32,264 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2008-10-05 17:31 . 2007-08-20 13:38 26,376 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2008-10-05 17:31 . 2007-08-20 13:38 21,512 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2008-10-05 17:31 . 2007-08-20 13:38 21,128 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2008-10-05 17:30 . 2008-10-05 17:30 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-10-04 16:14 . 2000-03-23 12:50 446,464 -ra------ C:\WINDOWS\system32\hhactivex.dll
2008-10-04 16:14 . 1999-05-07 13:24 414,944 --a------ C:\WINDOWS\system32\COMCT332.OCX
2008-10-04 16:14 . 1998-11-10 10:46 328,480 --a------ C:\WINDOWS\system32\ssa3d30.ocx
2008-10-04 16:14 . 2002-01-08 17:00 176,128 --a------ C:\WINDOWS\system32\RcdScan.dll
2008-10-04 16:14 . 1998-09-24 12:03 171,967 --a------ C:\WINDOWS\system32\Odbcjet.hlp
2008-10-04 16:14 . 1998-09-24 12:03 7,348 --a------ C:\WINDOWS\system32\Odbcjet.cnt
2008-10-04 15:42 . 2008-10-04 15:42 32,154 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k0
2008-10-04 15:42 . 2008-10-04 15:42 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k7
2008-10-04 15:42 . 2008-10-04 15:42 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k6
2008-10-04 15:42 . 2008-10-04 15:42 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k5
2008-10-04 15:42 . 2008-10-04 15:42 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k4
2008-10-04 15:42 . 2008-10-04 15:42 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k3
2008-10-04 15:42 . 2008-10-04 15:42 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k2
2008-10-04 15:42 . 2008-10-04 15:42 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k1
2008-10-04 15:20 . 2008-10-04 15:20 <DIR> d-------- C:\Program Files\CA
2008-10-04 15:20 . 2008-10-05 17:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CA
2008-09-30 11:02 . 2008-10-05 17:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-29 23:58 . 2008-09-29 23:58 8,704 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-09-28 10:49 . 2008-09-28 10:49 <DIR> d-------- C:\Documents and Settings\Dina Rivera\Application Data\Snapfish
2008-09-25 10:15 . 2008-10-01 20:38 <DIR> d-------- C:\Documents and Settings\Dina Rivera\.blurb
2008-09-25 10:13 . 2008-09-25 10:14 <DIR> d-------- C:\Program Files\BookSmart
2008-09-12 15:52 . 2008-09-21 16:09 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-05 21:36 --------- d-----w C:\Program Files\Lavasoft
2008-10-05 21:36 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-10-05 21:34 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-05 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-05 21:33 --------- d-----w C:\Program Files\SpywareBlaster
2008-10-04 20:28 90,112 ----a-w C:\WINDOWS\DUMP277d.tmp
2008-10-04 20:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-04 19:24 --------- d-----w C:\Program Files\Symantec
2008-10-04 19:17 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-10-04 14:04 53,350 ----a-w C:\Documents and Settings\Dina Rivera\Application Data\wklnhst.dat
2008-10-04 14:04 --------- d-----w C:\Program Files\Dl_cats
2008-09-30 15:03 --------- d-----w C:\Documents and Settings\Matt Gray\Application Data\Lavasoft
2008-09-30 02:49 46,902 ----a-w C:\Documents and Settings\Matt Gray\Application Data\wklnhst.dat
2008-09-28 23:09 --------- d-----w C:\Documents and Settings\Matt Gray\Application Data\uTorrent
2008-09-21 16:25 --------- d-----w C:\Documents and Settings\Matt Gray\Application Data\Free Download Manager
2008-08-21 13:54 --------- d-----w C:\Program Files\TaxCut05
2008-08-21 13:53 --------- d-----w C:\Program Files\Sonic
2008-08-15 02:06 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2006-12-04 14:43 75,136 -c--a-w C:\Documents and Settings\Dina Rivera\Application Data\GDIPFONTCACHEV1.DAT
2006-08-07 01:24 75,136 -c--a-w C:\Documents and Settings\Matt Gray\Application Data\GDIPFONTCACHEV1.DAT
2005-10-13 18:24 34,511,160 -c--a-w C:\Program Files\iTunesSetup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 155648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 126976]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 606208]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 69632]
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-07-22 425984]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-16 177416]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-02-05 1193224]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-02-05 173320]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-02-05 259336]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2008-10-05 14088]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-08-20 230664]
C:\Documents and Settings\Dina Rivera\Start Menu\Programs\Startup\
wkcalrem.LNK - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-09-16 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-09-30 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-11-15 806912]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMultiIE"= 0 (0x0)
"LWA"= 0 (0x0)
"LWB"= 0 (0x0)
"LWC"= 0 (0x0)
"LWD"= 0 (0x0)
"LWE"= 0 (0x0)
"LWF"= 0 (0x0)
"LWG"= 0 (0x0)
"LWH"= 0 (0x0)
"LWI"= 0 (0x0)
"LWJ"= 0 (0x0)
"LWK"= 0 (0x0)
"LWL"= 0 (0x0)
"LWM"= 0 (0x0)
"LWN"= 0 (0x0)
"LWO"= 0 (0x0)
"LWP"= 0 (0x0)
"LWQ"= 0 (0x0)
"LWR"= 0 (0x0)
"LWS"= 0 (0x0)
"LWT"= 0 (0x0)
"LWU"= 0 (0x0)
"LWV"= 0 (0x0)
"LWW"= 0 (0x0)
"LWX"= 0 (0x0)
"LWY"= 0 (0x0)
"LWZ"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 13:30 79368 C:\WINDOWS\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\My Music\\utorrent.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Free Download Manager\\fdm.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys [2007-10-18 93712]
R1 vcdrom;Virtual CD-ROM Device Driver;C:\WINDOWS\system32\drivers\VCdRom.sys [2001-12-19 8576]
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys [2007-10-18 134672]
R3 Amps2prt;A4Tech PS/2 Port Mouse Filter Driver;C:\WINDOWS\system32\Drivers\Amps2prt.sys [2000-11-13 10195]
S3 ComFiltr;Panda Anti-Dialer;C:\WINDOWS\system32\DRIVERS\COMFiltr.sys [ ]
S3 PavSRK.sys;PavSRK.sys;C:\WINDOWS\system32\PavSRK.sys [ ]
S3 PPCtlPriv;PPCtlPriv;C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2007-08-16 189704]
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2004-05-07 79616]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-09-11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-10-05 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Matt Gray at 5 30 PM.job
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-16 21:10]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-ISUSPM Startup - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
HKLM-Run-WheelMouse - Amoumain.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Matt Gray\Application Data\Mozilla\Firefox\Profiles\c034huka.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.msn.com/
FF -: plugin - C:\Documents and Settings\Matt Gray\Application Data\Mozilla\Firefox\Profiles\c034huka.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPUploader.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npvirtools.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-05 18:17:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\TDSSserv]
"imagepath"="\systemroot\system32\drivers\TDSSserv.sys"
.
Completion time: 2008-10-05 18:20:09
ComboFix-quarantined-files.txt 2008-10-05 22:19:07
Pre-Run: 25,332,215,808 bytes free
Post-Run: 26,170,642,432 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
243 --- E O F --- 2008-09-21 19:49:03