jwied
2007-07-11, 22:13
After scanning many of the other threads and trying several times with a variety of removal tools and scanners, I just can't seem to get rid of VirtueMonde and ErrorSafe. Using AVG, Spy-Bot, McAfee, and Ad-Aware I have come across the following malware:
Those that keep returning are: Virtuemonde and ErrorSafe. Those that have come and been eradicated are: MediaPlex, Trojan.Small, and Adware.Zango.
The malware is causing internet explorer to launch to (usually) one of these pages: llehs.com, jack9.com, and cams.com.
Any help is most appreciated. Here's ComboFix and Hijackthis (ran after combofix) logs:
0----------
"Jeremy" - 2007-07-11 11:55:33 - ComboFix 07-07-10.1 - Service Pack 2
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\axdrgbji.dll
C:\WINDOWS\system32\fydauuoe.dll
C:\WINDOWS\system32\qcnlgfls.dll
C:\WINDOWS\system32\ijbgrdxa.ini
C:\WINDOWS\system32\vyadd.bak1
C:\WINDOWS\system32\vyadd.bak2
C:\WINDOWS\system32\vyadd.ini
C:\WINDOWS\system32\eouuadyf.ini
C:\WINDOWS\system32\pqstv.bak1
C:\WINDOWS\system32\pqstv.bak2
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\ddayv.dll
C:\WINDOWS\system32\xxyaxvw.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((( Files Created from 2007-06-11 to 2007-07-11 )))))))))))))))))))))))))))))))
2007-07-11 11:57 66,624 --a------ C:\WINDOWS\system32\labxdimg.dll
2007-07-11 11:54 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-10 07:00 <DIR> d-------- C:\DOCUME~1\Jeremy\APPLIC~1\gtk-2.0
2007-07-10 07:00 <DIR> d-------- C:\DOCUME~1\Jeremy\.thumbnails
2007-07-10 06:59 <DIR> d-------- C:\DOCUME~1\Jeremy\.gimp-2.2
2007-07-09 21:52 <DIR> d-------- C:\WINDOWS\pss
2007-07-09 21:39 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-07-09 21:39 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-07-09 21:39 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-07-09 14:27 <DIR> d-------- C:\DOCUME~1\Jeremy\.housecall6.6
2007-07-08 09:31 88,524 --a------ C:\smitfrau.reg
2007-07-08 09:31 3,451 --a------ C:\delfiles.cmd
2007-07-08 09:31 16,824 --a------ C:\replace.cmd
2007-07-08 09:31 1,458 --a------ C:\smitfra.reg
2007-07-07 18:28 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-07-07 18:28 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-07-07 18:09 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-07-07 18:09 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-07 16:53 <DIR> d-------- C:\DOCUME~1\Jeremy\APPLIC~1\PC Tools
2007-07-07 16:52 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-07-07 16:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
2007-07-07 16:31 <DIR> d-------- C:\WINDOWS\RegisteredPackages
2007-07-07 16:30 19,456 --a------ C:\WINDOWS\system32\winbug32.dll
2007-07-07 01:08 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-07-07 01:08 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-07-06 18:09 66,048 --a------ C:\WINDOWS\ieResetIcons.exe
2007-07-06 16:17 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-05 17:05 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-06-30 11:36 <DIR> d-------- C:\DOCUME~1\Jeremy\APPLIC~1\FastStone
2007-06-26 18:16 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-06-26 18:16 <DIR> d-------- C:\WINDOWS\nview
2007-06-26 18:14 446,464 --a------ C:\WINDOWS\system32\CapabilityTable.exe
2007-06-26 18:14 356,352 --a------ C:\WINDOWS\system32\nvuide.exe
2007-06-26 18:14 208,896 --a------ C:\WINDOWS\system32\nvusmb.exe
2007-06-26 18:14 208,896 --a------ C:\WINDOWS\system32\nvunrm.exe
2007-06-26 18:14 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-06-26 18:14 110,080 --a------ C:\WINDOWS\system32\drivers\nvtcp.sys
2007-06-26 18:04 69,632 --a------ C:\WINDOWS\Alcmtr.exe
2007-06-26 18:04 315,392 --a------ C:\WINDOWS\HideWin.exe
2007-06-26 18:04 1,822,720 --a------ C:\WINDOWS\SkyTel.exe
2007-06-24 22:08 81,920 --a------ C:\WINDOWS\system32\nvwddi.dll
2007-06-24 22:08 81,920 --a------ C:\WINDOWS\system32\nvmctray.dll
2007-06-24 22:08 8,466,432 --a------ C:\WINDOWS\system32\nvcpl.dll
2007-06-24 22:08 6,729,728 --a------ C:\WINDOWS\system32\nvoglnt.dll
2007-06-24 22:08 6,234,112 --a------ C:\WINDOWS\system32\nvdisps.dll
2007-06-24 22:08 466,944 --a------ C:\WINDOWS\system32\nvshell.dll
2007-06-24 22:08 45,056 --a------ C:\WINDOWS\system32\nvmccsrs.dll
2007-06-24 22:08 442,368 --a------ C:\WINDOWS\system32\nvappbar.exe
2007-06-24 22:08 425,984 --a------ C:\WINDOWS\system32\keystone.exe
2007-06-24 22:08 37,376 --a------ C:\WINDOWS\system32\nvcodins.dll
2007-06-24 22:08 37,376 --a------ C:\WINDOWS\system32\nvcod.dll
2007-06-24 22:08 360,448 --a------ C:\WINDOWS\system32\nvapi.dll
2007-06-24 22:08 3,518,464 --a------ C:\WINDOWS\system32\nvvitvs.dll
2007-06-24 22:08 3,321,856 --a------ C:\WINDOWS\system32\nvgames.dll
2007-06-24 22:08 286,720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll
2007-06-24 22:08 229,376 --a------ C:\WINDOWS\system32\nvmccs.dll
2007-06-24 22:08 2,326,528 --a------ C:\WINDOWS\system32\nvwss.dll
2007-06-24 22:08 188,416 --a------ C:\WINDOWS\system32\nvmccss.dll
2007-06-24 22:08 155,716 --a------ C:\WINDOWS\system32\nvsvc32.exe
2007-06-24 22:08 147,456 --a------ C:\WINDOWS\system32\nvcolor.exe
2007-06-24 22:08 1,703,936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2007-06-24 22:08 1,626,112 --a------ C:\WINDOWS\system32\nwiz.exe
2007-06-24 22:08 1,474,560 --a------ C:\WINDOWS\system32\nview.dll
2007-06-24 22:08 1,339,392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2007-06-24 22:08 1,142,784 --a------ C:\WINDOWS\system32\nvmobls.dll
2007-06-24 22:08 1,019,904 --a------ C:\WINDOWS\system32\nvwimg.dll
2007-06-17 13:49 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-06-17 12:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\LightScribe
2007-06-17 09:27 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-06-17 09:27 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-06-17 09:12 <DIR> d-------- C:\DOCUME~1\Jeremy\APPLIC~1\Ahead
2007-06-17 09:10 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-06-17 09:10 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-06-16 23:57 36,734 --a------ C:\WINDOWS\system32\OggDSuninst.exe
2007-06-15 19:01 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-06-15 16:40 719,872 --a------ C:\WINDOWS\system32\devil.dll
2007-06-15 16:40 308,224 --a------ C:\WINDOWS\system32\avisynth.dll
2007-06-15 16:39 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2007-06-15 12:22 745,472 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-06-15 12:22 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-06-13 09:46 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2007-06-13 09:46 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2007-06-13 09:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ALM
2007-06-12 23:16 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-06-12 18:50 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2007-06-12 18:50 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-11 16:19:22 -------- dc----w D:\Program Files\Mozilla Thunderbird
2007-07-10 04:43:36 -------- dc----w D:\Program Files\RogueRemover
2007-07-08 17:43:39 -------- dc----w D:\Program Files\Safer Networking
2007-07-08 16:50:36 1,604 ----a-w C:\WINDOWS\system32\tmp.reg
2007-07-08 01:30:00 -------- dc----w D:\Program Files\GIMP-2.0
2007-07-07 08:08:02 -------- dc----w D:\Program Files\Stardock
2007-07-07 01:18:05 -------- dc-h--w D:\Program Files\InstallShield Installation Information
2007-07-06 23:17:23 -------- dc----w D:\Program Files\QuickTime Alternative
2007-06-30 16:48:20 -------- dc----w D:\Program Files\Minefield
2007-06-27 01:15:22 -------- dc----w D:\Program Files\NVIDIA Corporation
2007-06-27 01:13:00 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2007-06-27 01:04:40 -------- dc----w D:\Program Files\Realtek
2007-06-27 00:52:59 -------- dc----w D:\Program Files\Fox LiveUpdate
2007-06-27 00:32:59 4,821 ----a-w C:\WINDOWS\mozver.dat
2007-06-25 05:08:00 6,806,720 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-06-25 05:08:00 5,686,528 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-06-25 05:08:00 1,018,772 ----a-w C:\WINDOWS\system32\nvucode.bin
2007-06-18 00:55:06 -------- dc----w D:\Program Files\THQ
2007-06-17 16:28:43 -------- dc----w D:\Program Files\DVDlabPro2
2007-06-17 16:10:33 -------- dc----w D:\Program Files\Nero
2007-06-17 16:03:50 -------- dc----w D:\Program Files\GUI for dvdauthor
2007-06-17 01:22:08 -------- dc----w D:\Program Files\DIKO
2007-06-16 16:30:29 -------- dc----w D:\Program Files\WISE-FTP
2007-06-15 19:22:07 -------- dc----w D:\Program Files\Xvid
2007-06-13 16:33:59 -------- dc----w D:\Program Files\QuickTime
2007-06-13 15:57:13 -------- dc----w D:\Program Files\Windows Installer Clean Up
2007-06-13 15:43:46 -------- dc----w D:\Program Files\Metapad
2007-06-10 17:06:25 -------- dc----w D:\Program Files\Safarp
2007-06-10 17:04:20 -------- dc----w D:\Program Files\Easy Uninstaller
2007-06-10 15:42:41 -------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-06-10 08:56:09 -------- dc----w D:\Program Files\Sony
2007-06-05 21:55:20 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Ventrilo
2007-06-05 19:16:39 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-05 19:15:48 -------- dc----w D:\Program Files\7-Zip
2007-06-02 16:04:43 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Uniblue
2007-06-02 02:05:40 -------- dc----w D:\Program Files\MagicISO
2007-06-02 00:31:09 -------- dc----w D:\Program Files\BitLord
2007-06-01 03:09:48 -------- dc----w D:\Program Files\Microsoft Works
2007-06-01 03:08:50 -------- dc----w D:\Program Files\Microsoft.NET
2007-06-01 03:07:23 -------- dc----w D:\Program Files\Microsoft Visual Studio 8
2007-05-28 15:02:38 -------- dc----w D:\Program Files\SpeedFan
2007-05-27 16:39:06 -------- dc----w D:\Program Files\AMD
2007-05-27 06:16:05 -------- dc----w D:\Program Files\CFF Explorer
2007-05-27 01:37:56 1,100 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2007-05-24 19:16:37 -------- dc----w D:\Program Files\Cacheman
2007-05-22 04:49:20 -------- dc----w D:\Program Files\ATITool
2007-05-21 14:10:02 -------- dc----w D:\Program Files\CPU-z
2007-05-21 13:59:03 -------- d-----w C:\Program Files\Common Files\ActivCard
2007-05-21 13:58:57 -------- dc----w D:\Program Files\ActivCard
2007-05-21 13:53:07 -------- dc----w D:\Program Files\SCM Microsystems
2007-05-21 03:08:33 -------- dc-h--w D:\Program Files\WindowsUpdate
2007-05-20 11:21:31 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-05-20 11:20:30 -------- dc----w D:\Program Files\Futuremark
2007-05-20 07:19:55 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Logitech
2007-05-20 07:19:04 -------- d-----w C:\Program Files\Common Files\Logitech
2007-05-20 07:18:53 -------- dc----w D:\Program Files\Logitech
2007-05-20 02:56:10 -------- dc----w D:\Program Files\One Guy Coding
2007-05-20 02:44:56 -------- dc----w D:\Program Files\windows nt
2007-05-20 02:44:56 -------- dc----w D:\Program Files\movie maker
2007-05-20 02:44:55 -------- dc----w D:\Program Files\msn gaming zone
2007-05-20 02:44:55 -------- dc----w D:\Program Files\microsoft frontpage
2007-05-19 22:11:31 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Turbine
2007-05-19 21:57:34 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Thunderbird
2007-05-19 21:51:10 -------- dc----w D:\Program Files\FastStone Image Viewer
2007-05-19 21:43:59 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Talkback
2007-05-19 21:43:56 0 -c--a-w C:\WINDOWS\nsreg.dat
2007-05-19 21:38:48 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Leadertech
2007-05-19 21:35:05 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-05-19 21:30:10 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Lavasoft
2007-05-19 21:30:02 -------- dc----w D:\Program Files\Lavasoft
2007-05-19 21:27:10 -------- dc----w D:\Program Files\Fraps
2007-05-19 21:24:02 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Realtime Soft
2007-05-19 21:16:00 8 ----a-w C:\WINDOWS\system32\nvModes.dat
2007-05-19 21:13:07 -------- dc----w D:\Program Files\Creative
2007-05-19 21:12:45 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-05-19 21:12:44 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Creative
2007-05-19 20:32:13 0 --sha-r C:\MSDOS.SYS
2007-05-19 20:32:13 0 --sha-r C:\IO.SYS
2007-05-19 20:32:13 0 ----a-w C:\CONFIG.SYS
2007-05-19 20:32:13 0 ----a-w C:\AUTOEXEC.BAT
2007-05-19 20:30:50 -------- d-----w C:\Program Files\Common Files\MSSoap
2007-05-19 20:30:13 21,640 ----a-w C:\WINDOWS\system32\emptyregdb.dat
2007-05-19 14:12:08 -------- d-----w C:\Program Files\Common Files\ODBC
2007-05-19 14:12:06 -------- d-----w C:\Program Files\Common Files\SpeechEngines
2007-05-18 00:27:23 -------- dc----w D:\Program Files\Samsung
2007-04-27 15:55:00 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-04-27 15:55:00 5,431,296 ----a-w C:\WINDOWS\system32\nvdispsr.dll
2007-04-27 15:55:00 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll
2007-04-27 15:55:00 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-04-27 15:55:00 3,637,248 ----a-w C:\WINDOWS\system32\nvvitvsr.dll
2007-04-27 15:55:00 3,231,744 ----a-w C:\WINDOWS\system32\nvgamesr.dll
2007-04-27 15:55:00 2,854,912 ----a-w C:\WINDOWS\system32\nvmoblsr.dll
2007-04-27 15:55:00 2,412,544 ----a-w C:\WINDOWS\system32\nvwssr.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
2007-03-16 15:13 118784 --a--c--- D:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A83767F-EDDD-44B8-9737-34F5A413F3D2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
2006-10-27 00:48 2210608 --a--c--- D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a--c--- D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{938A8A03-A938-4019-B764-03FF8D167D79}]
2007-07-11 11:57 66624 --a------ C:\WINDOWS\system32\labxdimg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1D812B3-8F22-4BD2-BAB7-BF41B3F41BCB}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
2007-03-29 22:11 321120 --a--c--- D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7E3F0B7-9682-4D55-957D-C6DF0662A9EC}]
C:\WINDOWS\system32\vtsqp.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D7B1A975-F2C2-4F83-B086-26E34108DE3a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="D:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2006-03-13 17:14]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 C:\WINDOWS\CTHELPER.EXE]
"AVG7_CC"="d:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-05-20 08:10]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 17:33 C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 18:43 C:\WINDOWS\Alcmtr.exe]
"nwiz"="nwiz.exe" [2007-06-24 22:08 C:\WINDOWS\system32\nwiz.exe]
"CtxfiReg"="CTXFIREG.exe" [2006-08-11 14:53 C:\WINDOWS\system32\CTXFIREG.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 C:\WINDOWS\system32\CTXFIHLP.EXE]
"UltraMon"="D:\Program Files\UltraMon\UltraMon.exe" []
"!AVG Anti-Spyware"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-24 22:08]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AWMON"="D:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 12:12]
"AVG7_Run"="d:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-05-20 08:10]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [2006-10-27 00:48]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 05:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acAuth]
acauth.dll 2002-12-17 10:11 65536 C:\WINDOWS\system32\acauth.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CtxfiReg]
CTXFIREG.exe /FAIL1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UltraMon]
"D:\Program Files\UltraMon\UltraMon.exe" /auto
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UPS"=3 (0x3)
"NMIndexingService"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28b45920-1b6f-11dc-8d99-0015584562d0}]
AutoRun\command- H:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
Contents of the 'Scheduled Tasks' folder
2007-07-02 16:03:00 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-06-02 16:03:10 C:\WINDOWS\tasks\Uniblue SpyEraser.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-11 11:59:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NVR0Dev]
"ImagePath"="\??\C:\WINDOWS\nvoclock.sys"
Completion time: 2007-07-11 12:01:55 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-11 12:01
--- E O F ---
0------------
Those that keep returning are: Virtuemonde and ErrorSafe. Those that have come and been eradicated are: MediaPlex, Trojan.Small, and Adware.Zango.
The malware is causing internet explorer to launch to (usually) one of these pages: llehs.com, jack9.com, and cams.com.
Any help is most appreciated. Here's ComboFix and Hijackthis (ran after combofix) logs:
0----------
"Jeremy" - 2007-07-11 11:55:33 - ComboFix 07-07-10.1 - Service Pack 2
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\axdrgbji.dll
C:\WINDOWS\system32\fydauuoe.dll
C:\WINDOWS\system32\qcnlgfls.dll
C:\WINDOWS\system32\ijbgrdxa.ini
C:\WINDOWS\system32\vyadd.bak1
C:\WINDOWS\system32\vyadd.bak2
C:\WINDOWS\system32\vyadd.ini
C:\WINDOWS\system32\eouuadyf.ini
C:\WINDOWS\system32\pqstv.bak1
C:\WINDOWS\system32\pqstv.bak2
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\ddayv.dll
C:\WINDOWS\system32\xxyaxvw.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((( Files Created from 2007-06-11 to 2007-07-11 )))))))))))))))))))))))))))))))
2007-07-11 11:57 66,624 --a------ C:\WINDOWS\system32\labxdimg.dll
2007-07-11 11:54 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-10 07:00 <DIR> d-------- C:\DOCUME~1\Jeremy\APPLIC~1\gtk-2.0
2007-07-10 07:00 <DIR> d-------- C:\DOCUME~1\Jeremy\.thumbnails
2007-07-10 06:59 <DIR> d-------- C:\DOCUME~1\Jeremy\.gimp-2.2
2007-07-09 21:52 <DIR> d-------- C:\WINDOWS\pss
2007-07-09 21:39 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-07-09 21:39 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-07-09 21:39 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-07-09 14:27 <DIR> d-------- C:\DOCUME~1\Jeremy\.housecall6.6
2007-07-08 09:31 88,524 --a------ C:\smitfrau.reg
2007-07-08 09:31 3,451 --a------ C:\delfiles.cmd
2007-07-08 09:31 16,824 --a------ C:\replace.cmd
2007-07-08 09:31 1,458 --a------ C:\smitfra.reg
2007-07-07 18:28 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-07-07 18:28 <DIR> d-------- C:\Program Files\Common Files\GTK
2007-07-07 18:09 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-07-07 18:09 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-07 16:53 <DIR> d-------- C:\DOCUME~1\Jeremy\APPLIC~1\PC Tools
2007-07-07 16:52 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-07-07 16:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
2007-07-07 16:31 <DIR> d-------- C:\WINDOWS\RegisteredPackages
2007-07-07 16:30 19,456 --a------ C:\WINDOWS\system32\winbug32.dll
2007-07-07 01:08 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-07-07 01:08 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-07-06 18:09 66,048 --a------ C:\WINDOWS\ieResetIcons.exe
2007-07-06 16:17 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-05 17:05 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-06-30 11:36 <DIR> d-------- C:\DOCUME~1\Jeremy\APPLIC~1\FastStone
2007-06-26 18:16 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-06-26 18:16 <DIR> d-------- C:\WINDOWS\nview
2007-06-26 18:14 446,464 --a------ C:\WINDOWS\system32\CapabilityTable.exe
2007-06-26 18:14 356,352 --a------ C:\WINDOWS\system32\nvuide.exe
2007-06-26 18:14 208,896 --a------ C:\WINDOWS\system32\nvusmb.exe
2007-06-26 18:14 208,896 --a------ C:\WINDOWS\system32\nvunrm.exe
2007-06-26 18:14 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-06-26 18:14 110,080 --a------ C:\WINDOWS\system32\drivers\nvtcp.sys
2007-06-26 18:04 69,632 --a------ C:\WINDOWS\Alcmtr.exe
2007-06-26 18:04 315,392 --a------ C:\WINDOWS\HideWin.exe
2007-06-26 18:04 1,822,720 --a------ C:\WINDOWS\SkyTel.exe
2007-06-24 22:08 81,920 --a------ C:\WINDOWS\system32\nvwddi.dll
2007-06-24 22:08 81,920 --a------ C:\WINDOWS\system32\nvmctray.dll
2007-06-24 22:08 8,466,432 --a------ C:\WINDOWS\system32\nvcpl.dll
2007-06-24 22:08 6,729,728 --a------ C:\WINDOWS\system32\nvoglnt.dll
2007-06-24 22:08 6,234,112 --a------ C:\WINDOWS\system32\nvdisps.dll
2007-06-24 22:08 466,944 --a------ C:\WINDOWS\system32\nvshell.dll
2007-06-24 22:08 45,056 --a------ C:\WINDOWS\system32\nvmccsrs.dll
2007-06-24 22:08 442,368 --a------ C:\WINDOWS\system32\nvappbar.exe
2007-06-24 22:08 425,984 --a------ C:\WINDOWS\system32\keystone.exe
2007-06-24 22:08 37,376 --a------ C:\WINDOWS\system32\nvcodins.dll
2007-06-24 22:08 37,376 --a------ C:\WINDOWS\system32\nvcod.dll
2007-06-24 22:08 360,448 --a------ C:\WINDOWS\system32\nvapi.dll
2007-06-24 22:08 3,518,464 --a------ C:\WINDOWS\system32\nvvitvs.dll
2007-06-24 22:08 3,321,856 --a------ C:\WINDOWS\system32\nvgames.dll
2007-06-24 22:08 286,720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll
2007-06-24 22:08 229,376 --a------ C:\WINDOWS\system32\nvmccs.dll
2007-06-24 22:08 2,326,528 --a------ C:\WINDOWS\system32\nvwss.dll
2007-06-24 22:08 188,416 --a------ C:\WINDOWS\system32\nvmccss.dll
2007-06-24 22:08 155,716 --a------ C:\WINDOWS\system32\nvsvc32.exe
2007-06-24 22:08 147,456 --a------ C:\WINDOWS\system32\nvcolor.exe
2007-06-24 22:08 1,703,936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2007-06-24 22:08 1,626,112 --a------ C:\WINDOWS\system32\nwiz.exe
2007-06-24 22:08 1,474,560 --a------ C:\WINDOWS\system32\nview.dll
2007-06-24 22:08 1,339,392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2007-06-24 22:08 1,142,784 --a------ C:\WINDOWS\system32\nvmobls.dll
2007-06-24 22:08 1,019,904 --a------ C:\WINDOWS\system32\nvwimg.dll
2007-06-17 13:49 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-06-17 12:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\LightScribe
2007-06-17 09:27 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-06-17 09:27 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-06-17 09:12 <DIR> d-------- C:\DOCUME~1\Jeremy\APPLIC~1\Ahead
2007-06-17 09:10 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-06-17 09:10 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-06-16 23:57 36,734 --a------ C:\WINDOWS\system32\OggDSuninst.exe
2007-06-15 19:01 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-06-15 16:40 719,872 --a------ C:\WINDOWS\system32\devil.dll
2007-06-15 16:40 308,224 --a------ C:\WINDOWS\system32\avisynth.dll
2007-06-15 16:39 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2007-06-15 12:22 745,472 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-06-15 12:22 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-06-13 09:46 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2007-06-13 09:46 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2007-06-13 09:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ALM
2007-06-12 23:16 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-06-12 18:50 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2007-06-12 18:50 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-11 16:19:22 -------- dc----w D:\Program Files\Mozilla Thunderbird
2007-07-10 04:43:36 -------- dc----w D:\Program Files\RogueRemover
2007-07-08 17:43:39 -------- dc----w D:\Program Files\Safer Networking
2007-07-08 16:50:36 1,604 ----a-w C:\WINDOWS\system32\tmp.reg
2007-07-08 01:30:00 -------- dc----w D:\Program Files\GIMP-2.0
2007-07-07 08:08:02 -------- dc----w D:\Program Files\Stardock
2007-07-07 01:18:05 -------- dc-h--w D:\Program Files\InstallShield Installation Information
2007-07-06 23:17:23 -------- dc----w D:\Program Files\QuickTime Alternative
2007-06-30 16:48:20 -------- dc----w D:\Program Files\Minefield
2007-06-27 01:15:22 -------- dc----w D:\Program Files\NVIDIA Corporation
2007-06-27 01:13:00 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2007-06-27 01:04:40 -------- dc----w D:\Program Files\Realtek
2007-06-27 00:52:59 -------- dc----w D:\Program Files\Fox LiveUpdate
2007-06-27 00:32:59 4,821 ----a-w C:\WINDOWS\mozver.dat
2007-06-25 05:08:00 6,806,720 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-06-25 05:08:00 5,686,528 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-06-25 05:08:00 1,018,772 ----a-w C:\WINDOWS\system32\nvucode.bin
2007-06-18 00:55:06 -------- dc----w D:\Program Files\THQ
2007-06-17 16:28:43 -------- dc----w D:\Program Files\DVDlabPro2
2007-06-17 16:10:33 -------- dc----w D:\Program Files\Nero
2007-06-17 16:03:50 -------- dc----w D:\Program Files\GUI for dvdauthor
2007-06-17 01:22:08 -------- dc----w D:\Program Files\DIKO
2007-06-16 16:30:29 -------- dc----w D:\Program Files\WISE-FTP
2007-06-15 19:22:07 -------- dc----w D:\Program Files\Xvid
2007-06-13 16:33:59 -------- dc----w D:\Program Files\QuickTime
2007-06-13 15:57:13 -------- dc----w D:\Program Files\Windows Installer Clean Up
2007-06-13 15:43:46 -------- dc----w D:\Program Files\Metapad
2007-06-10 17:06:25 -------- dc----w D:\Program Files\Safarp
2007-06-10 17:04:20 -------- dc----w D:\Program Files\Easy Uninstaller
2007-06-10 15:42:41 -------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-06-10 08:56:09 -------- dc----w D:\Program Files\Sony
2007-06-05 21:55:20 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Ventrilo
2007-06-05 19:16:39 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-05 19:15:48 -------- dc----w D:\Program Files\7-Zip
2007-06-02 16:04:43 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Uniblue
2007-06-02 02:05:40 -------- dc----w D:\Program Files\MagicISO
2007-06-02 00:31:09 -------- dc----w D:\Program Files\BitLord
2007-06-01 03:09:48 -------- dc----w D:\Program Files\Microsoft Works
2007-06-01 03:08:50 -------- dc----w D:\Program Files\Microsoft.NET
2007-06-01 03:07:23 -------- dc----w D:\Program Files\Microsoft Visual Studio 8
2007-05-28 15:02:38 -------- dc----w D:\Program Files\SpeedFan
2007-05-27 16:39:06 -------- dc----w D:\Program Files\AMD
2007-05-27 06:16:05 -------- dc----w D:\Program Files\CFF Explorer
2007-05-27 01:37:56 1,100 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2007-05-24 19:16:37 -------- dc----w D:\Program Files\Cacheman
2007-05-22 04:49:20 -------- dc----w D:\Program Files\ATITool
2007-05-21 14:10:02 -------- dc----w D:\Program Files\CPU-z
2007-05-21 13:59:03 -------- d-----w C:\Program Files\Common Files\ActivCard
2007-05-21 13:58:57 -------- dc----w D:\Program Files\ActivCard
2007-05-21 13:53:07 -------- dc----w D:\Program Files\SCM Microsystems
2007-05-21 03:08:33 -------- dc-h--w D:\Program Files\WindowsUpdate
2007-05-20 11:21:31 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-05-20 11:20:30 -------- dc----w D:\Program Files\Futuremark
2007-05-20 07:19:55 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Logitech
2007-05-20 07:19:04 -------- d-----w C:\Program Files\Common Files\Logitech
2007-05-20 07:18:53 -------- dc----w D:\Program Files\Logitech
2007-05-20 02:56:10 -------- dc----w D:\Program Files\One Guy Coding
2007-05-20 02:44:56 -------- dc----w D:\Program Files\windows nt
2007-05-20 02:44:56 -------- dc----w D:\Program Files\movie maker
2007-05-20 02:44:55 -------- dc----w D:\Program Files\msn gaming zone
2007-05-20 02:44:55 -------- dc----w D:\Program Files\microsoft frontpage
2007-05-19 22:11:31 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Turbine
2007-05-19 21:57:34 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Thunderbird
2007-05-19 21:51:10 -------- dc----w D:\Program Files\FastStone Image Viewer
2007-05-19 21:43:59 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Talkback
2007-05-19 21:43:56 0 -c--a-w C:\WINDOWS\nsreg.dat
2007-05-19 21:38:48 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Leadertech
2007-05-19 21:35:05 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-05-19 21:30:10 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Lavasoft
2007-05-19 21:30:02 -------- dc----w D:\Program Files\Lavasoft
2007-05-19 21:27:10 -------- dc----w D:\Program Files\Fraps
2007-05-19 21:24:02 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Realtime Soft
2007-05-19 21:16:00 8 ----a-w C:\WINDOWS\system32\nvModes.dat
2007-05-19 21:13:07 -------- dc----w D:\Program Files\Creative
2007-05-19 21:12:45 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-05-19 21:12:44 -------- d-----w C:\DOCUME~1\Jeremy\APPLIC~1\Creative
2007-05-19 20:32:13 0 --sha-r C:\MSDOS.SYS
2007-05-19 20:32:13 0 --sha-r C:\IO.SYS
2007-05-19 20:32:13 0 ----a-w C:\CONFIG.SYS
2007-05-19 20:32:13 0 ----a-w C:\AUTOEXEC.BAT
2007-05-19 20:30:50 -------- d-----w C:\Program Files\Common Files\MSSoap
2007-05-19 20:30:13 21,640 ----a-w C:\WINDOWS\system32\emptyregdb.dat
2007-05-19 14:12:08 -------- d-----w C:\Program Files\Common Files\ODBC
2007-05-19 14:12:06 -------- d-----w C:\Program Files\Common Files\SpeechEngines
2007-05-18 00:27:23 -------- dc----w D:\Program Files\Samsung
2007-04-27 15:55:00 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-04-27 15:55:00 5,431,296 ----a-w C:\WINDOWS\system32\nvdispsr.dll
2007-04-27 15:55:00 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll
2007-04-27 15:55:00 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-04-27 15:55:00 3,637,248 ----a-w C:\WINDOWS\system32\nvvitvsr.dll
2007-04-27 15:55:00 3,231,744 ----a-w C:\WINDOWS\system32\nvgamesr.dll
2007-04-27 15:55:00 2,854,912 ----a-w C:\WINDOWS\system32\nvmoblsr.dll
2007-04-27 15:55:00 2,412,544 ----a-w C:\WINDOWS\system32\nvwssr.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
2007-03-16 15:13 118784 --a--c--- D:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A83767F-EDDD-44B8-9737-34F5A413F3D2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
2006-10-27 00:48 2210608 --a--c--- D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a--c--- D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{938A8A03-A938-4019-B764-03FF8D167D79}]
2007-07-11 11:57 66624 --a------ C:\WINDOWS\system32\labxdimg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1D812B3-8F22-4BD2-BAB7-BF41B3F41BCB}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
2007-03-29 22:11 321120 --a--c--- D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7E3F0B7-9682-4D55-957D-C6DF0662A9EC}]
C:\WINDOWS\system32\vtsqp.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D7B1A975-F2C2-4F83-B086-26E34108DE3a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="D:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2006-03-13 17:14]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 C:\WINDOWS\CTHELPER.EXE]
"AVG7_CC"="d:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-05-20 08:10]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 17:33 C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 18:43 C:\WINDOWS\Alcmtr.exe]
"nwiz"="nwiz.exe" [2007-06-24 22:08 C:\WINDOWS\system32\nwiz.exe]
"CtxfiReg"="CTXFIREG.exe" [2006-08-11 14:53 C:\WINDOWS\system32\CTXFIREG.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 C:\WINDOWS\system32\CTXFIHLP.EXE]
"UltraMon"="D:\Program Files\UltraMon\UltraMon.exe" []
"!AVG Anti-Spyware"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-24 22:08]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AWMON"="D:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 12:12]
"AVG7_Run"="d:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-05-20 08:10]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [2006-10-27 00:48]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 05:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acAuth]
acauth.dll 2002-12-17 10:11 65536 C:\WINDOWS\system32\acauth.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CtxfiReg]
CTXFIREG.exe /FAIL1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UltraMon]
"D:\Program Files\UltraMon\UltraMon.exe" /auto
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UPS"=3 (0x3)
"NMIndexingService"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28b45920-1b6f-11dc-8d99-0015584562d0}]
AutoRun\command- H:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
Contents of the 'Scheduled Tasks' folder
2007-07-02 16:03:00 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
2007-06-02 16:03:10 C:\WINDOWS\tasks\Uniblue SpyEraser.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-11 11:59:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NVR0Dev]
"ImagePath"="\??\C:\WINDOWS\nvoclock.sys"
Completion time: 2007-07-11 12:01:55 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-11 12:01
--- E O F ---
0------------