Things are running a lot better! I haven't had a popup since restart yet. I did however get a DDL error:
Also... some simple stuff seems to be broke, such as my calculator and wordpad (notepad is fine).RUNDLL
C:\windows\system32\ptegdfcc.dll
The specified module could not be found.
Without further delay, here is my new ComboFix log:
ComboFix 07-11-19.4 - mmussleman 2007-11-27 15:05:32.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.341 [GMT -5:00]
Running from: C:\Documents and Settings\mmussleman\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\mmussleman\Desktop\CFScript.txt
FILE
C:\WINDOWS\17PHolmes572.exe
C:\WINDOWS\io43mvuiw4kj.exe
C:\WINDOWS\mrofinu572.exe.tmp
C:\WINDOWS\system32\atwnyndi.dll
C:\WINDOWS\system32\byxvwtt.dll
C:\WINDOWS\system32\byxwxww.dll
C:\WINDOWS\system32\ccbdewop.dll
C:\WINDOWS\system32\jhvdaers.dll
C:\WINDOWS\system32\mljjhij.dll
C:\WINDOWS\system32\mljjkij.dll
C:\WINDOWS\system32\nybgwjvd.dll
C:\WINDOWS\system32\ptegdfcc.dll
C:\WINDOWS\system32\qomjkjj.dll
C:\WINDOWS\system32\tuvvstu.dll
C:\WINDOWS\system32\tyvbvbjp.exe
C:\WINDOWS\system32\wvuvwwx.dll
C:\WINDOWS\system32\xcpqljxa.dll
C:\WINDOWS\TTC-4444.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\mmussleman\Desktop\Live Safety Center.lnk
C:\Documents and Settings\mmussleman\Desktop\Online Security Guide.lnk
C:\Documents and Settings\mmussleman\Favorites\Online Security Guide.lnk
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\WINDOWS\17PHolmes572.exe
C:\WINDOWS\io43mvuiw4kj.exe
C:\WINDOWS\mrofinu572.exe.tmp
C:\WINDOWS\system32\adeeg.ini
C:\WINDOWS\system32\adeeg.ini2
C:\WINDOWS\system32\atwnyndi.dll
C:\WINDOWS\system32\atwnyndi.dllbox
C:\WINDOWS\system32\byxvwtt.dll
C:\WINDOWS\system32\byxwxww.dll
C:\WINDOWS\system32\cc1
C:\WINDOWS\system32\ccbdewop.dll
C:\WINDOWS\system32\geeda.dll
C:\WINDOWS\system32\jhvdaers.dll
C:\WINDOWS\system32\mljjhij.dll
C:\WINDOWS\system32\mljjkij.dll
C:\WINDOWS\system32\nybgwjvd.dll
C:\WINDOWS\system32\ptegdfcc.dll
C:\WINDOWS\system32\qomjkjj.dll
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\system32\rMa02yy\rMa02yy1099.exe
C:\WINDOWS\system32\rMa06yy
C:\WINDOWS\system32\rMa06yy\rMa06yy1083.exe
C:\WINDOWS\system32\tuvvstu.dll
C:\WINDOWS\system32\tyvbvbjp.exe
C:\WINDOWS\system32\wvuvwwx.dll
C:\WINDOWS\system32\xcpqljxa.dll
.
((((((((((((((((((((((((( Files Created from 2007-10-27 to 2007-11-27 )))))))))))))))))))))))))))))))
.
2007-11-26 16:24 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Corel
2007-11-26 16:09 <DIR> d-------- C:\Documents and Settings\mmussleman\Application Data\Apple Computer
2007-11-26 16:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-26 14:02 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-11-26 14:02 <DIR> d-------- C:\Documents and Settings\mmussleman\Application Data\PC Tools
2007-11-26 14:02 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-11-26 08:51 780,579 ---hs---- C:\WINDOWS\system32\dvjwgbyn.ini
2007-11-21 16:29 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-11-21 15:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-21 15:04 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-11-21 11:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2007-11-09 16:31 <DIR> d-------- C:\Program Files\Dassault Systemes
2007-11-09 16:31 <DIR> d-------- C:\Documents and Settings\mmussleman\Application Data\DassaultSystemes
2007-11-09 16:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DassaultSystemes
2007-11-09 16:26 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-11-09 16:03 <DIR> d-------- C:\Program Files\Virtual Earth 3D
2007-11-07 08:55 <DIR> d-------- C:\FlexLM
2007-11-07 08:47 <DIR> d-------- C:\Program Files\GLOBEtrotter Software Inc
2007-11-07 08:47 18,432 --a------ C:\WINDOWS\system32\RNBOVDD.DLL
2007-11-07 08:47 9,949 --------- C:\WINDOWS\system32\SENTINEL.HLP
2007-11-07 08:47 6,656 --a------ C:\WINDOWS\system32\haspvdd.dll
2007-11-07 08:47 383 --a------ C:\WINDOWS\system32\haspdos.sys
2007-11-07 08:44 <DIR> d-------- C:\Program Files\Autodesk
2007-11-07 08:35 <DIR> d-------- C:\Program Files\Common Files\Alias Shared
2007-11-07 08:34 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-11-07 08:34 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-10-31 15:35 <DIR> d-------- C:\Program Files\Common Files\Avery
2007-10-31 15:35 <DIR> d-------- C:\Program Files\Avery Wizard 3.1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-27 20:25 --------- d-----w C:\Program Files\Symantec AntiVirus
2007-11-27 15:04 --------- d-----w C:\Documents and Settings\mmussleman\Application Data\AVG7
2007-11-26 20:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-21 16:10 --------- d-----w C:\Documents and Settings\mmussleman\Application Data\uTorrent
2007-11-07 13:47 47,616 ----a-w C:\WINDOWS\system32\drivers\Haspnt.sys
2007-11-07 13:35 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2007-10-18 05:16 79,688 ----a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-10-18 05:16 29,000 ----a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-10-18 05:15 62,280 ----a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-10-18 05:14 41,288 ----a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-10-12 20:46 --------- d-----w C:\Program Files\FileZilla Client
2007-10-10 14:13 --------- d-----w C:\Program Files\ZC2.10
2005-09-06 19:50 56 --sh--r C:\WINDOWS\system32\2D078FCBD5.sys
2007-04-10 20:44 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"4c1bf536"="C:\WINDOWS\system32\ptegdfcc.dll" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-06 09:19]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-04-30 12:48]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljjhij]
mljjhij.dll
C:\WINDOWS\system32\NavLogon.dll 2006-05-26 20:02 43760 C:\WINDOWS\system32\NavLogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\geeda.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 --a------ C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-03-29 21:05 339968 --a------ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2006-03-07 12:02 53408 --a------ C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2005-09-16 07:43 274432 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JobHisInit]
2001-11-16 20:23 135168 --a------ C:\Program Files\RMClient\JobHisInit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MplSetUp]
2000-11-04 20:09 40960 --a------ C:\Program Files\RMClient\MplSetUp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
2006-08-18 13:06 315392 --a------ C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
2006-08-25 11:25 3112960 --a------ C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 19:42 1404928 --a------ C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2003-11-19 17:48 32881 --a------ C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
2006-05-26 20:01 124656 --a------ C:\PROGRA~1\SYMANT~1\VPTray.exe
R2 NLCSAgent;NLCS Agent;C:\WINDOWS\system32\nlcspro\csagtprosvc.exe
*Newly Created Service* - ERASERUTILDRVI1
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-27 15:25:48
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-27 15:27:34 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-27 13:39
.
--- E O F ---