i know, utorrent can be a nasty program i have deleted that program several times as it may have caused problems in the past. needless to say i havent used that program in a couple of years. i have removed the program again.
combofix has been run and heres its report. a new dds will be posted shortly.
ComboFix 09-10-03.01 - Spiderman 10/04/2009 9:27.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.159 [GMT -4:00]
Running from: c:\documents and settings\Spiderman\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Spiderman\Application Data\wiaserva.log
c:\documents and settings\Spiderman\Start Menu\Programs\Startup\ikowin32.exe
c:\program files\Common\_helper.dll
c:\program files\Common\helper.dll
c:\program files\Common\helper.sig
c:\program files\Shared\lib.dll
c:\program files\Shared\lib.sig
c:\temp\abW9
c:\temp\abW9\tPho.log
c:\windows\abahakucadic.dll
c:\windows\aborerew.dll
c:\windows\abozemiz.dll
c:\windows\acaderotegixiv.dll
c:\windows\acavakadevi.dll
c:\windows\acerimuquj.dll
c:\windows\adafegizutaz.dll
c:\windows\adexipab.dll
c:\windows\adowegumesawe.dll
c:\windows\aduyamuk.dll
c:\windows\agaqatuza.dll
c:\windows\ajakigat.dll
c:\windows\ajayelovawubixax.dll
c:\windows\ajibatidedug.dll
c:\windows\ajocetuw.dll
c:\windows\alewanulamolimar.dll
c:\windows\alotakob.dll
c:\windows\amezawuf.dll
c:\windows\amifepohebafi.dll
c:\windows\amikulej.dll
c:\windows\amukupugebudax.dll
c:\windows\anelizodowurafox.dll
c:\windows\anurituci.dll
c:\windows\apegupiditemekok.dll
c:\windows\aqugojudoyatupek.dll
c:\windows\arihexop.dll
c:\windows\arubawutilesol.dll
c:\windows\asicolal.dll
c:\windows\atezosowuwu.dll
c:\windows\atomanap.dll
c:\windows\avanepoza.dll
c:\windows\avezaxifivufep.dll
c:\windows\avukejubetovapuz.dll
c:\windows\awaworucato.dll
c:\windows\awayofik.dll
c:\windows\aweqasoqege.dll
c:\windows\awequmofut.dll
c:\windows\awiritadumo.dll
c:\windows\axinirumecahalev.dll
c:\windows\ayimapiq.dll
c:\windows\download
c:\windows\ebajurij.dll
c:\windows\ebimizih.dll
c:\windows\ebocoroj.dll
c:\windows\ecefotoc.dll
c:\windows\edilaref.dll
c:\windows\edojolij.dll
c:\windows\eduhovoj.dll
c:\windows\efemirux.dll
c:\windows\egayiyoh.dll
c:\windows\eheriwesozo.dll
c:\windows\ehigozux.dll
c:\windows\ejerivehamiro.dll
c:\windows\ejeruzifuloru.dll
c:\windows\ejidiwoxewofes.dll
c:\windows\ejodafaw.dll
c:\windows\ejotilarej.dll
c:\windows\ekesuyeg.dll
c:\windows\ekoboneravasam.dll
c:\windows\eleharuculihi.dll
c:\windows\eleqafarip.dll
c:\windows\elujewuj.dll
c:\windows\enebebaguwimu.dll
c:\windows\enuxusum.dll
c:\windows\epulifipuluk.dll
c:\windows\eqamoyes.dll
c:\windows\eqavafidelujolij.dll
c:\windows\evayasomizih.dll
c:\windows\ewedigojeruqa.dll
c:\windows\ewihedil.dll
c:\windows\ewizotuqo.dll
c:\windows\ewolorom.dll
c:\windows\ewovuzitoha.dll
c:\windows\exapejid.dll
c:\windows\exelowunikazubi.dll
c:\windows\eximifora.dll
c:\windows\exovevukov.dll
c:\windows\eyogudorayeher.dll
c:\windows\eyudobuvo.dll
c:\windows\gcdx.dll
c:\windows\ibimapiqiyonox.dll
c:\windows\ibotuwef.dll
c:\windows\ibuwunoz.dll
c:\windows\icopevubeqo.dll
c:\windows\idogezorijegozu.dll
c:\windows\idujizuqu.dll
c:\windows\ifereweha.dll
c:\windows\ifidevac.dll
c:\windows\ifiyuruwokuqisal.dll
c:\windows\ifocoxicakihev.dll
c:\windows\ifogafek.dll
c:\windows\ijuxorigeg.dll
c:\windows\ikenalepetiyo.dll
c:\windows\imawiloji.dll
c:\windows\imujoxuc.dll
c:\windows\imunesey.dll
c:\windows\Installer\11195550.msp
c:\windows\Installer\3970c5.msp
c:\windows\Installer\73330d.msp
c:\windows\Installer\9dbd7d7.msp
c:\windows\Installer\f876ad4.msi
c:\windows\Installer\f876adc.msi
c:\windows\Installer\f876ae4.msi
c:\windows\Installer\f876af1.msi
c:\windows\Installer\f876af9.msi
c:\windows\Installer\f876b01.msi
c:\windows\inutezezuquj.dll
c:\windows\ipopuficuzuhi.dll
c:\windows\iqafovah.dll
c:\windows\iqejinur.dll
c:\windows\iqokilomi.dll
c:\windows\irakarat.dll
c:\windows\irenufuq.dll
c:\windows\isitibuxer.dll
c:\windows\itecigitulob.dll
c:\windows\itedowubucu.dll
c:\windows\iwewogij.dll
c:\windows\iwisefubemob.dll
c:\windows\ixikerevafidel.dll
c:\windows\ixitikapawogep.dll
c:\windows\ixiyetasoyu.dll
c:\windows\ixuqeduk.dll
c:\windows\iyatahixowetohe.dll
c:\windows\msstd.dll
c:\windows\msto.dll
c:\windows\obawulevefi.dll
c:\windows\obe.dll
c:\windows\obiwiyel.dll
c:\windows\odajezoweqoh.dll
c:\windows\odehusucam.dll
c:\windows\ofazowem.dll
c:\windows\ofeholuh.dll
c:\windows\oferesox.dll
c:\windows\ofofafawi.dll
c:\windows\ofoqusiwoj.dll
c:\windows\ofuvozeraz.dll
c:\windows\ogakupujaxakuqe.dll
c:\windows\ogipucovotuket.dll
c:\windows\oheqazejo.dll
c:\windows\ojipevubeqovuzi.dll
c:\windows\ojuqafar.dll
c:\windows\okecuvuhoxuquxoj.dll
c:\windows\okehazuyosegefim.dll
c:\windows\okucuzuhifuci.dll
c:\windows\olemopajeboy.dll
c:\windows\olenelanavecazu.dll
c:\windows\oliyonidopumam.dll
c:\windows\olumodet.dll
c:\windows\omelolac.dll
c:\windows\omiyeviw.dll
c:\windows\onehebaf.dll
c:\windows\opohugil.dll
c:\windows\opunevif.dll
c:\windows\oqegovagifobaw.dll
c:\windows\oraluwen.dll
c:\windows\orehifuc.dll
c:\windows\orejulowu.dll
c:\windows\osutiles.dll
c:\windows\oteqesuhelehizu.dll
c:\windows\ovadurayapeva.dll
c:\windows\oviloqetuguzele.dll
c:\windows\owebalikoqatu.dll
c:\windows\oxenozum.dll
c:\windows\oxumopuduy.dll
c:\windows\oyolaloc.dll
c:\windows\system32\aston.mt
c:\windows\system32\comrepl.exe
c:\windows\system32\drivers\3e3b0e9.sys
c:\windows\system32\mcrh.tmp
c:\windows\ubejefiq.dll
c:\windows\ubelerih.dll
c:\windows\ucagosixaxeteted.dll
c:\windows\ucelesolas.dll
c:\windows\ucezitoha.dll
c:\windows\ucijumuqobo.dll
c:\windows\ucikiwikisoxe.dll
c:\windows\ucoyenev.dll
c:\windows\udexusumo.dll
c:\windows\udociluvunebur.dll
c:\windows\ufihilofej.dll
c:\windows\ufirubohojafabi.dll
c:\windows\ufiyosegef.dll
c:\windows\ugifiwuz.dll
c:\windows\ugiholur.dll
c:\windows\uhikorilowadil.dll
c:\windows\uhinufeworitulus.dll
c:\windows\uhodesuvaruk.dll
c:\windows\uhoyiger.dll
c:\windows\ukayewecig.dll
c:\windows\ukicagayusaqitih.dll
c:\windows\ukifefeqacolal.dll
c:\windows\ukonirumecah.dll
c:\windows\ukoyuzubizeb.dll
c:\windows\unuhovehula.dll
c:\windows\unuwevev.dll
c:\windows\upotepin.dll
c:\windows\upuyosamavab.dll
c:\windows\uracusezejoher.dll
c:\windows\urewixanimi.dll
c:\windows\uribiyov.dll
c:\windows\urocawaj.dll
c:\windows\urucozis.dll
c:\windows\urufixej.dll
c:\windows\usoniwulaqo.dll
c:\windows\usotolix.dll
c:\windows\usoxivaz.dll
c:\windows\utodiqatarive.dll
c:\windows\utogofor.dll
c:\windows\uvajivanoq.dll
c:\windows\uvamibah.dll
c:\windows\uvikuwafonut.dll
c:\windows\uwapalir.dll
c:\windows\uwemavab.dll
c:\windows\uwodewiy.dll
c:\windows\uxatigokidonot.dll
c:\windows\uxeturet.dll
c:\windows\uxosuloromazizu.dll
c:\windows\uxucubalepi.dll
c:\windows\uyazoquqisefac.dll
c:\windows\uyezizaz.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_3e3b0e9
((((((((((((((((((((((((( Files Created from 2009-09-04 to 2009-10-04 )))))))))))))))))))))))))))))))
.
2009-10-04 14:11 . 2009-10-04 14:11 11554 ----a-w- c:\windows\egoxowalif.dll
2009-09-12 19:11 . 2009-09-12 19:11 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-04 17:15 . 2009-09-12 19:11 -------- d-----w- c:\documents and settings\Bobo\Local Settings\Application Data\{7774A5C0-4F5A-4A25-A039-29FB6B2E855C}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-04 13:44 . 2009-06-23 12:15 -------- d-----w- c:\program files\Shared
2009-10-04 13:44 . 2009-03-31 21:56 -------- d-----w- c:\program files\Common
2009-10-04 13:21 . 2002-08-29 10:00 182656 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-10-04 12:15 . 2009-08-28 01:45 120 ----a-w- c:\windows\Ulujoqafarip.dat
2009-09-30 00:02 . 2005-12-30 00:37 -------- d-----w- c:\program files\Common Files\KnifeEdge
2009-09-14 21:38 . 2005-07-13 03:08 -------- d-----w- c:\program files\Program Files
2009-09-12 19:10 . 2009-03-15 00:26 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-03 03:58 . 2004-07-09 22:13 118440 ----a-w- c:\documents and settings\Spiderman\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-25 21:35 . 2009-08-25 16:29 -------- d-----w- c:\documents and settings\All Users\Application Data\10983904
2009-08-06 21:57 . 2009-08-06 21:57 -------- d-----w- c:\program files\MSBuild
2009-08-06 21:56 . 2009-08-06 21:56 -------- d-----w- c:\program files\Reference Assemblies
2009-07-17 19:01 . 2002-08-29 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 19:01 . 2002-08-29 10:00 58880 ----a-w- c:\windows\system32\atl(3)(3).dll
2009-07-14 03:43 . 2004-08-11 05:45 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2006-11-25 07:57 . 2006-11-25 07:57 482 ----a-w- c:\program files\Del.js
2005-08-21 16:42 . 2005-06-27 23:17 905 -c--a-w- c:\program files\uninstal.log
2006-01-11 06:41 . 2004-08-29 00:07 56 --sh--r- c:\windows\SYSTEM32\6BBF71BA10.sys
2006-09-24 00:47 . 2004-08-29 00:07 10856 --sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-05-12 6729728]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-02-08 295856]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\SYSTEM32\nvmctray.dll [2005-05-12 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\SYSTEM32\narrator.exe [2008-04-14 53760]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli carcpc.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk.disabled
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
backup=c:\windows\pss\Exif Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=c:\windows\pss\PowerReg Scheduler.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Spiderman^Start Menu^Programs^Startup^clippy.exe]
path=c:\documents and settings\Spiderman\Start Menu\Programs\Startup\clippy.exe
backup=c:\windows\pss\clippy.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Spiderman^Start Menu^Programs^Startup^Magnifier.lnk]
path=c:\documents and settings\Spiderman\Start Menu\Programs\Startup\Magnifier.lnk
backup=c:\windows\pss\Magnifier.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Spiderman^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
path=c:\documents and settings\Spiderman\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
backup=c:\windows\pss\Stardock ObjectDock.lnkStartup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Insider"=c:\program files\Insider\Insider.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"runner1"=c:\windows\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
"QuickTime Task"="c:\program files\QuickTime\bak\qttask.exe" -atboottime
"nwiz"=nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\SYSTEM32\\lxczcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\FRegister.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\BCGUpdate.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\Summitsoft Products.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\BCGFonts.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\Splash_LDS.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\Splash Series 1_Oct132008.exe"=
S3 brfilt;Brother MFC Filter Driver;c:\windows\SYSTEM32\DRIVERS\BrFilt.sys [8/13/2006 9:48 AM 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\SYSTEM32\DRIVERS\BrParImg.sys [8/13/2006 9:48 AM 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\SYSTEM32\DRIVERS\BrParwdm.sys [8/13/2006 9:48 AM 39552]
S3 BrSerWDM;Brother Serial driver;c:\windows\SYSTEM32\DRIVERS\BrSerWdm.sys [8/13/2006 9:48 AM 60416]
S3 DMSKSSRh;DMSKSSRh;\??\c:\docume~1\SPIDER~1\LOCALS~1\Temp\DMSKSSRh.sys --> c:\docume~1\SPIDER~1\LOCALS~1\Temp\DMSKSSRh.sys [?]
S3 SaiNtSub;SaiNtSub;c:\windows\SYSTEM32\DRIVERS\SaiNtSub.sys [2/4/2005 10:28 PM 19200]
S3 samhid;samhid;c:\windows\system32\drivers\samhid.sys --> c:\windows\system32\drivers\samhid.sys [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.98rock.com/cc-common/babes/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: &Search
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} - hxxp://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
DPF: {D9EA64B2-B966-E177-332C-78B69886526D} - hxxp://download.newaol.com/bkpromo/download/PerformerSetup.cab
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKLM-Run-Ksebuhey - c:\windows\urufixej.dll
AddRemove-Viewpoint Manager - c:\program files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-04 10:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1665667976-894762885-3311537992-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(552)
c:\windows\system32\NTMARTA.DLL
- - - - - - - > 'lsass.exe'(608)
c:\windows\carcpc.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3540)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\carcpc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\windows\SYSTEM32\lxczcoms.exe
c:\windows\SYSTEM32\nvsvc32.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\windows\SYSTEM32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-10-04 10:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-04 14:17
ComboFix2.txt 2007-11-30 03:16
Pre-Run: 4,740,100,096 bytes free
Post-Run: 4,988,645,376 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
406 --- E O F --- 2009-08-27 21:59