PDA

View Full Version : And .... another Virtomundo



upandgone
2008-08-18, 18:57
Hello chaps

Thank you in advance for your efforts.
Looking through the other posts i attached the combo fix log (done first) along with the hijack log (done second).

Thank you

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:56, on 18/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Vista Drive Icon\DrvIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windguru.com/int/index.php?sc=58
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [DrvIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Norton Save and Restore] "C:\Program Files\Norton Save and Restore\Agent\NSRTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [VistaDriveIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1219062456156
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.instantaction.com/download/iaplayer.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

--
End of file - 11550 bytes





COMBO FIX LOG

ComboFix 08-08-17.03 - Patric 2008-08-18 9:24:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1391 [GMT -4:00]
Running from: C:\Documents and Settings\Patric\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\All Users\Application Data\Starware386
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\1154_button_1b_def.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\1154_button_1b_over.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\Button_50.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\Button_60.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\Button_70.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\findithotxp.png
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\finditxp.png
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\logo.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\logoxp.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\Reference.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\ReferenceHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\referencehotxp.png
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\referencexp.png
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\Weather.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\WeatherHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\weatherhotxp.png
C:\Documents and Settings\All Users\Application Data\Starware386\buttons\weatherxp.png
C:\Documents and Settings\All Users\Application Data\Starware386\contexts\error.xml
C:\Documents and Settings\All Users\Application Data\Starware386\contexts\Related.xml
C:\Documents and Settings\All Users\Application Data\Starware386\contexts\Travel.xml
C:\Documents and Settings\All Users\Application Data\Starware386\images\walertXP.bmp
C:\Documents and Settings\All Users\Application Data\Starware386\SimpleUpdate\ProductMessagingConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware386\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware386\SimpleUpdate\SimpleUpdateConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware386\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware386\SimpleUpdate\TimerManagerConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware386\SimpleUpdate\TimerManagerConfig.xml.backup
C:\Documents and Settings\Patric\Application Data\Starware386
C:\Documents and Settings\Patric\Application Data\Starware386\Button_5\Button_5Options.xml
C:\Documents and Settings\Patric\Application Data\Starware386\Button_5\Button_5Options.xml.backup
C:\Documents and Settings\Patric\Application Data\Starware386\Button_6\Button_6Options.xml
C:\Documents and Settings\Patric\Application Data\Starware386\Button_6\Button_6Options.xml.backup
C:\Documents and Settings\Patric\Application Data\Starware386\Button_7\Button_7Options.xml
C:\Documents and Settings\Patric\Application Data\Starware386\Button_7\Button_7Options.xml.backup
C:\Documents and Settings\Patric\Application Data\Starware386\Screensavers\ScreensaversOptions.xml
C:\Documents and Settings\Patric\Application Data\Starware386\Screensavers\ScreensaversOptions.xml.backup
C:\Documents and Settings\Patric\Cookies\patric@cleanuptool[1].txt
C:\Documents and Settings\Patric\Cookies\patric@komtrack[2].txt
C:\Documents and Settings\Patric\Cookies\patric@safepctool[2].txt
C:\Documents and Settings\Patric\Cookies\patric@tour.twistys[1].txt
C:\Documents and Settings\Patric\My Documents\My Documents.url
C:\Documents and Settings\Patric\My Documents\My Music\My Music.url
C:\Documents and Settings\Patric\My Documents\My Pictures\My Pictures.url
C:\Documents and Settings\Patric\My Documents\My Videos\My Video.url
C:\Program Files\PlayMP3z
C:\Program Files\PlayMP3z\PlayMP3.exe
C:\Program Files\PlayMP3z\uninstall.exe
C:\WINDOWS\BM1327020e.txt
C:\WINDOWS\BM1327020e.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\afppdidh.ini
C:\WINDOWS\system32\ahjikjqi.ini
C:\WINDOWS\system32\apwktcsy.dll
C:\WINDOWS\system32\arbnnabv.ini
C:\WINDOWS\system32\axeyxafh.dll
C:\WINDOWS\system32\bwnddqnu.dll
C:\WINDOWS\system32\cgttjvvp.dll
C:\WINDOWS\system32\cxoonyxh.dll
C:\WINDOWS\system32\ddcBQhEu.dll
C:\WINDOWS\system32\dipsooth.dll
C:\WINDOWS\system32\ditgemwe.dll
C:\WINDOWS\system32\dncxudgg.dll
C:\WINDOWS\system32\elscjdog.ini
C:\WINDOWS\system32\ewmegtid.ini
C:\WINDOWS\system32\fafdndce.exe
C:\WINDOWS\system32\fravcdra.exe
C:\WINDOWS\system32\ftdhyang.ini
C:\WINDOWS\system32\ggduxcnd.ini
C:\WINDOWS\system32\giebsldj.exe
C:\WINDOWS\system32\giSuDcdd.ini
C:\WINDOWS\system32\giSuDcdd.ini2
C:\WINDOWS\system32\gkdefmll.dll
C:\WINDOWS\system32\godjcsle.dll
C:\WINDOWS\system32\hbdjhmuq.dll
C:\WINDOWS\system32\hfaxyexa.ini
C:\WINDOWS\system32\huroxquh.ini
C:\WINDOWS\system32\hvbshtlk.dll
C:\WINDOWS\system32\hxynooxc.ini
C:\WINDOWS\system32\hyyvuaqy.exe
C:\WINDOWS\system32\iaoymaig.ini
C:\WINDOWS\system32\igytqmpr.ini
C:\WINDOWS\system32\iifmvput.exe
C:\WINDOWS\system32\inbocbyc.dll
C:\WINDOWS\system32\iqxtxpji.ini
C:\WINDOWS\system32\iwkfwbao.dll
C:\WINDOWS\system32\jtqabeax.exe
C:\WINDOWS\system32\jtwglqdl.dll
C:\WINDOWS\system32\jyulllwm.ini
C:\WINDOWS\system32\kauvbowe.ini
C:\WINDOWS\system32\klthsbvh.ini
C:\WINDOWS\system32\lbcrncni.dll
C:\WINDOWS\system32\leatiobj.dll
C:\WINDOWS\system32\lqiclhqn.ini
C:\WINDOWS\system32\mauhbaon.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mddlsfcr.ini
C:\WINDOWS\system32\mrtuphii.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\noabhuam.ini
C:\WINDOWS\system32\npraofsr.ini
C:\WINDOWS\system32\nqhlciql.dll
C:\WINDOWS\system32\oashdkoe.ini
C:\WINDOWS\system32\ofxxhrar.ini
C:\WINDOWS\system32\okxkndav.exe
C:\WINDOWS\system32\opfuecun.dll
C:\WINDOWS\system32\oqrejmvd.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pbctlukj.dll
C:\WINDOWS\system32\pbreqoaf.ini
C:\WINDOWS\system32\piioxpxv.ini
C:\WINDOWS\system32\ppgfwxsb.ini
C:\WINDOWS\system32\psbgeisl.dll
C:\WINDOWS\system32\pvvjttgc.ini
C:\WINDOWS\system32\pxgumnxx.dll
C:\WINDOWS\system32\qbagxefu.ini
C:\WINDOWS\system32\qbtsyoeg.ini
C:\WINDOWS\system32\qcndencp.exe
C:\WINDOWS\system32\qushgtxu.ini
C:\WINDOWS\system32\recloxod.dll
C:\WINDOWS\system32\ripcjvvw.dll
C:\WINDOWS\system32\rkaunkmw.exe
C:\WINDOWS\system32\sonysevq.dll
C:\WINDOWS\system32\sosvetsq.dll
C:\WINDOWS\system32\srqbopkb.ini
C:\WINDOWS\system32\suylayyj.exe
C:\WINDOWS\system32\svqqomsi.exe
C:\WINDOWS\system32\tafxdvfs.ini
C:\WINDOWS\system32\tiqxlmmt.ini
C:\WINDOWS\system32\uEhQBcdd.ini
C:\WINDOWS\system32\uEhQBcdd.ini2
C:\WINDOWS\system32\urteddrb.exe
C:\WINDOWS\system32\uwktllrv.dll
C:\WINDOWS\system32\uwslnrkf.ini
C:\WINDOWS\system32\vxvdsgdv.ini
C:\WINDOWS\system32\wcecyfhu.exe
C:\WINDOWS\system32\wypyscoa.ini
C:\WINDOWS\system32\xdasplsl.ini
C:\WINDOWS\system32\xrmermdq.ini
C:\WINDOWS\system32\xsahegdd.dll
C:\WINDOWS\system32\xwhswksc.ini
C:\WINDOWS\system32\xyfytuap.ini
C:\WINDOWS\system32\ynxxsxio.exe
C:\WINDOWS\system32\yoadtolk.dll
C:\WINDOWS\system32\yoirgaju.exe
C:\WINDOWS\system32\ysctkwpa.ini
F:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-07-18 to 2008-08-18 )))))))))))))))))))))))))))))))
.

2008-08-15 22:38 . 2008-08-15 21:15 <DIR> d----c--- C:\SDFix
2008-08-15 22:08 . 2008-08-15 22:08 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-15 21:54 . 2008-08-15 22:41 <DIR> d-------- C:\Documents and Settings\Patric\.SunDownloadManager
2008-08-14 11:37 . 2008-08-18 07:49 <DIR> d-------- C:\Program Files\9Dragons
2008-08-06 21:00 . 2008-08-06 21:01 <DIR> d-------- C:\Program Files\iTunes
2008-07-30 20:21 . 2008-08-12 23:16 <DIR> d-------- C:\Program Files\Bonjour
2008-07-26 19:23 . 2008-07-26 19:23 0 --a------ C:\WINDOWS\system32\kauvbowe.tmp
2008-07-24 15:29 . 2008-07-24 15:29 <DIR> d-------- C:\Documents and Settings\Patric\Application Data\Symantec
2008-07-24 15:24 . 2008-07-24 15:24 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-07-24 15:21 . 2008-07-24 15:27 <DIR> d-------- C:\Program Files\Norton Internet Security
2008-07-24 15:18 . 2008-08-11 21:20 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-24 15:18 . 2008-08-11 21:20 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-24 15:18 . 2008-08-11 21:20 10,671 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-07-24 15:18 . 2008-08-11 21:20 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-07-24 10:04 . 2008-07-24 10:04 <DIR> d-------- C:\Documents and Settings\All Users\Symantec Temporary Files
2008-07-21 22:59 . 2008-07-21 23:28 <DIR> d-------- C:\Program Files\RegCure

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-18 13:34 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-18 03:41 --------- d-----w C:\Documents and Settings\Patric\Application Data\Skype
2008-08-17 23:30 --------- d-----w C:\Documents and Settings\Patric\Application Data\skypePM
2008-08-13 15:54 --------- d-----w C:\Program Files\Netcom3 Cleaner
2008-08-13 15:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-12 01:20 --------- d-----w C:\Program Files\Symantec
2008-08-09 11:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-07 01:05 --------- d-----w C:\Program Files\Apple Software Update
2008-08-07 01:00 --------- d-----w C:\Program Files\iPod
2008-08-05 04:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-02 21:21 682 -c--a-w C:\Documents and Settings\Patric\Application Data\wklnhst.dat
2008-07-31 00:19 --------- d-----w C:\Program Files\QuickTime
2008-07-30 21:42 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-07-30 21:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-07-30 21:28 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-07-27 16:43 --------- d-----w C:\Documents and Settings\Patric\Application Data\LimeWire
2008-07-13 18:03 --------- d-----w C:\Program Files\Yahoo!
2008-07-10 04:00 --------- d-----w C:\Documents and Settings\Patric\Application Data\DMCache
2008-07-09 23:33 --------- d-----w C:\Program Files\Safari
2008-07-08 15:15 --------- d-----w C:\Program Files\Java
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-03-15 00:32 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-08 04:22 0 -c-h--w C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
2008-02-13 13:07 20 -c-h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-12-27 02:08 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.

------- Sigcheck -------

2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\Resources\Energize\Backup\user32.dll
2007-03-08 11:36 577024 8925913f62eabc61b869f0fdf07b9cb4 C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 577024 8925913f62eabc61b869f0fdf07b9cb4 C:\WINDOWS\system32\dllcache\user32.dll

2008-01-12 03:13 1494016 945c0c989407d9ec3742b5c4fe7dae9c C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\Resources\Energize\Backup\explorer.exe
2008-01-12 03:13 1494016 945c0c989407d9ec3742b5c4fe7dae9c C:\WINDOWS\system32\dllcache\explorer.exe

2004-08-10 09:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\Resources\Energize\Backup\ctfmon.exe
2004-08-10 09:00 40448 fe77972fdb3eae3128b7abdb646e12a6 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 07:26 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 09:00 40448]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-15 18:00 68856]
"VistaDriveIcon"="C:\Program Files\Vista Drive Icon\DrvIcon.exe" [2007-11-05 14:00 45056]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-06 18:37 21898024]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 09:56 64512]
"DrvIcon"="C:\Program Files\Vista Drive Icon\DrvIcon.exe" [2007-11-05 14:00 45056]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47 289064]
"Norton Save and Restore"="C:\Program Files\Norton Save and Restore\Agent\NSRTray.exe" [2007-03-26 15:45 1582696]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-02-16 18:34 7557120]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 21:47 51048]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2005-12-29 14:21 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 09:00 40448]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 17:18 443968]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCPL"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoNetSetup"= 0 (0x0)
"NoNetSetupIDPage"= 0 (0x0)
"NoNetSetupSecurityPage"= 0 (0x0)
"NoWorkgroupContents"= 0 (0x0)
"NoEntireNetwork"= 0 (0x0)
"NoFileSharingControl"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"RestrictRun"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoRun"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoClose"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,77,69,6e,64,69,72,25,5c,52,65,73,6f,75,72,63,65,73,5c,4c,6f,\

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\9Dragons\\NDLAUNCHER.EXE"=
"C:\\Program Files\\VestGame\\WoKF\\PatcherKf.exe"=
"C:\\Program Files\\9Dragons\\NDLauncher2.exe"=
"C:\\Program Files\\9Dragons\\NINEDRAGONS.EXE"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-01-25 21:47]
R2 Norton Save and Restore;Norton Save and Restore;C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe [2007-03-26 15:45]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 21:38]
R3 BoiHwsetup;Access 32bits INT15 routine;C:\WINDOWS\system32\drivers\BoiHwSetup.sys [2005-06-11 00:42]
R3 cmo_bus;Data Modem @ CDMA Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\cmo_bus.sys [2005-08-17 13:59]
R3 cmo_mdfl;Data Modem @ CDMA Filter;C:\WINDOWS\system32\DRIVERS\cmo_mdfl.sys [2005-08-17 14:02]
R3 cmo_mdm;Data Modem @ CDMA Drivers;C:\WINDOWS\system32\DRIVERS\cmo_mdm.sys [2005-08-17 14:02]
R3 cmo_serd;Data Modem @ CDMA Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\cmo_serd.sys [2005-08-17 14:04]
R3 qkbfiltr;Quanta HotKey Keyboard Filter Driver;C:\WINDOWS\system32\drivers\qkbfiltr.sys [2006-01-12 12:21]
R3 qmofiltr;Quanta HotKey Mouse Filter Driver;C:\WINDOWS\system32\drivers\qmofiltr.sys [2005-05-05 10:27]
R3 X10Hid;X10 Hid Device;C:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 06:45]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-07-30 17:42]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys []
S3 SMCB000;SMSC CIR HID Miniport Device Driver;C:\WINDOWS\system32\DRIVERS\hidsmsc.sys [2006-01-17 12:30]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder

2008-08-16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-08-12 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Patric.job
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 10:05]

2008-08-18 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 17:21]

2008-08-17 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 17:21]

2008-08-18 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EE0097B2-00A0-48BA-9CB6-A62B33F47A66}.job
- C:\WINDOWS\system32\msfeedssync.exe [2007-08-13 18:36]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-BM1327020e - C:\WINDOWS\system32\ripcjvvw.dll
HKLM-Run-10143192 - C:\WINDOWS\system32\dncxudgg.dll
Notify-xxyxUnol - (no file)


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Patric\Application Data\Mozilla\Firefox\Profiles\r0xjsfdh.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-18 09:42:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\Documents and Settings\Patric\Application Data\skypePM\2008-08-16-0.ezlog 9120 bytes
C:\Documents and Settings\Patric\Application Data\skypePM\2008-08-16-1.ezlog

scan completed successfully
hidden files: 2

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\COMMON~1\X10\Common\X10nets.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-08-18 9:52:42 - machine was rebooted [Patric]
ComboFix-quarantined-files.txt 2008-08-18 13:52:36

Pre-Run: 108,802,461,696 bytes free
Post-Run: 108,818,034,688 bytes free

368 --- E O F --- 2008-07-09 01:04:19
-------------------------------------------------

[I]FYI: Do NOT run 'fixes' before helpers have analyzed the HJT log ;)
(http://forums.spybot.info/showthread.php?t=16806)

pskelley
2008-08-21, 01:07
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

Looking through the other posts i attached the combo fix log
It woud be great if you would look through the directions first.
Do NOT run 'fixes' before helpers have analyzed the HJT loghttp://forums.spybot.info/showthread.php?t=16806

Please download ATF Cleaner by Atribune
http://www.atribune.org/public-beta/ATF-Cleaner.exe
Save it to your Desktop. We will use this later.

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

*Cleaning Prefetch may results in a few slow starts until the folder is repopulated:
http://www.windowsnetworking.com/articles_tutorials/Gaining-Speed-Empty-Prefetch-XP.html

Download Malwarebytes' Anti-Malware to your Desktop
http://www.besttechie.net/tools/mbam-setup.exe

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
* Please post contents of that file & a new HJT log in your next reply.

How is the computer running, any malware issues at all?

Thanks