PDA

View Full Version : Virtumonde Keeps coming Back



nhaettan
2008-09-24, 11:03
Good Day..

I use SD and found this virtumonde and remove,. but everytime i restart my computer it keeps coming back. And it keeps creating .dll file and setting it into my start up..

HJT LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:18:04 PM, on 9/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\system32\msconfig.exe /auto
O4 - HKCU\..\Run: [EPSON Stylus C59 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBHP.EXE /FU "C:\WINDOWS\system32\config\SYSTEM~1\LOCALS~1\Temp\E_S258.tmp" /EF "HKCU"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\eHome" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_07] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_08] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\eHome" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O20 - AppInit_DLLs: ,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll qlmsts.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Windows Driver Foundation - User-mode Driver Framework (WudfSvc) - Unknown owner - hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00 (file missing)

--
End of file - 5037 bytes

nhaettan
2008-09-24, 11:29
COMBOFIX LOG

ComboFix 08-09-22.06 - XPPRESP3 2008-09-24 16:23:18.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.808 [GMT 2:00]
Running from: C:\Documents and Settings\XPPRESP3\Desktop\Payslip\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\FBrowserAdvisor
C:\WINDOWS\BM6f6976c6.txt
C:\WINDOWS\BM6f6976c6.xml
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\bwiryjpy.ini
C:\WINDOWS\system32\Cfx32.lic
C:\WINDOWS\system32\cfx32.ocx
C:\WINDOWS\system32\gOrCdMoq.ini
C:\WINDOWS\system32\gOrCdMoq.ini2
C:\WINDOWS\system32\jxkplaya.ini
C:\WINDOWS\system32\lwadxfdc.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mpxjtfgr.ini
C:\WINDOWS\system32\phpiwlyv.ini
C:\WINDOWS\system32\qoMdCrOg.dll
C:\WINDOWS\system32\qvnuppqe.ini
C:\WINDOWS\system32\rtbjrgyl.ini
C:\WINDOWS\system32\rtl60.bpl
C:\WINDOWS\system32\surycjdh.ini
C:\WINDOWS\system32\ufualajq.ini
C:\WINDOWS\system32\vfobjvtk.ini

.
((((((((((((((((((((((((( Files Created from 2008-08-24 to 2008-09-24 )))))))))))))))))))))))))))))))
.

2008-09-24 17:59 . 2006-08-09 20:02 75,264 --a------ C:\WINDOWS\system32\E_FLBBHP.DLL
2008-09-24 17:59 . 2006-04-18 20:00 62,976 --a------ C:\WINDOWS\system32\E_FD4BBHP.DLL
2008-09-24 17:59 . 2004-09-10 14:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2008-09-24 17:58 . 2004-08-03 17:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-09-24 17:57 . 2008-09-24 17:57 <DIR> d-------- C:\Program Files\EPSON
2008-09-24 17:57 . 2008-09-24 17:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
2008-09-24 16:08 . 2008-09-24 16:08 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-24 13:11 . 2008-09-24 13:11 113,152 --a------ C:\WINDOWS\system32\fqpeigsq.dll
2008-09-24 13:11 . 2008-09-24 13:11 113,152 --a------ C:\WINDOWS\system32\ciqbde.dll
2008-09-24 13:10 . 2008-09-24 13:10 836,857 --ahs---- C:\WINDOWS\system32\bstxroaw.tmp
2008-09-24 13:10 . 2008-09-24 13:10 99,328 --a------ C:\WINDOWS\system32\krohkskm.dll
2008-09-24 04:59 . 2008-09-24 04:59 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-09-24 04:32 . 2008-09-24 04:32 89,600 --a------ C:\WINDOWS\system32\ktvjbofv.dll
2008-09-24 04:30 . 2008-09-24 04:30 111,616 --a------ C:\WINDOWS\system32\qlmsts.dll
2008-09-24 04:30 . 2008-09-24 04:30 111,616 --a------ C:\WINDOWS\system32\iifmugsh.dll
2008-09-24 04:27 . 2008-09-24 04:27 97,280 --a------ C:\WINDOWS\system32\lslygtcf.dll
2008-09-23 23:52 . 2008-09-23 23:52 111,616 --a------ C:\WINDOWS\system32\vuartk.dll
2008-09-23 23:52 . 2008-09-23 23:52 111,616 --a------ C:\WINDOWS\system32\rbipebap.dll
2008-09-23 17:30 . 2008-09-23 17:31 <DIR> d-------- C:\Program Files\vanBasco's Karaoke Player
2008-09-23 17:28 . 2008-09-23 17:28 <DIR> d-------- C:\Program Files\LimeWire
2008-09-23 06:53 . 2008-09-23 06:53 577,024 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
2008-09-23 06:51 . 2008-09-23 06:51 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-23 06:50 . 2008-09-23 07:39 <DIR> d-------- C:\SDFix
2008-09-22 20:07 . 2008-09-22 20:07 113,152 --a------ C:\WINDOWS\system32\hbwqkn.dll
2008-09-22 20:07 . 2008-09-22 20:07 113,152 --a------ C:\WINDOWS\system32\fdennfim.dll
2008-09-22 17:29 . 2007-02-16 04:23 53,248 --a------ C:\WINDOWS\system32\acr120u.dll
2008-09-22 17:28 . 2005-06-21 09:13 38,912 --a------ C:\WINDOWS\system32\drivers\acr120.sys
2008-09-22 16:37 . 2008-09-22 16:37 113,152 --a------ C:\WINDOWS\system32\qhaallak.dll
2008-09-22 16:37 . 2008-09-22 16:37 113,152 --a------ C:\WINDOWS\system32\ixovmv.dll
2008-09-22 16:36 . 2008-09-22 16:37 99,328 --a------ C:\WINDOWS\system32\hnngofib.dll
2008-09-22 16:06 . 2008-09-22 16:06 114,688 --a------ C:\WINDOWS\system32\rqngql.dll
2008-09-22 16:06 . 2008-09-22 16:06 114,688 --a------ C:\WINDOWS\system32\iqwbrgus.dll
2008-09-22 14:53 . 2008-09-22 14:53 <DIR> d-------- C:\logs
2008-09-22 14:53 . 2008-09-22 14:53 <DIR> d-------- C:\Documents and Settings\XPPRESP3\ChikkaDefault
2008-09-22 14:52 . 2008-09-22 14:52 <DIR> d-------- C:\Program Files\Chikka Messenger
2008-09-22 06:10 . 2008-09-24 09:59 13,030 --a------ C:\PDOXUSRS.NET
2008-09-21 16:04 . 2008-09-21 16:04 114,688 --a------ C:\WINDOWS\system32\qsgqabfj.dll
2008-09-21 16:04 . 2008-09-21 16:04 114,688 --a------ C:\WINDOWS\system32\acwuip.dll
2008-09-20 13:47 . 2008-09-20 13:47 114,688 --a------ C:\WINDOWS\system32\wvnucejg.dll
2008-09-20 13:47 . 2008-09-20 13:47 114,688 --a------ C:\WINDOWS\system32\meqsip.dll
2008-09-20 12:14 . 2008-09-20 12:14 <DIR> d-------- C:\Program
2008-09-19 21:06 . 2008-09-19 19:47 294 --ahs---- C:\WINDOWS\system32\ewbffojx.ini
2008-09-19 19:47 . 2008-09-19 21:06 354 --ahs---- C:\WINDOWS\system32\ewbffojx.ini2
2008-09-19 19:45 . 2008-09-19 19:45 980,971 --ahs---- C:\WINDOWS\system32\ewbffojx.tmp
2008-09-19 13:43 . 2008-09-19 13:43 112,640 --a------ C:\WINDOWS\system32\jidryilb.dll
2008-09-19 05:38 . 2008-09-19 05:38 <DIR> d-------- C:\Program Files\Doblon
2008-09-18 13:44 . 2008-09-18 13:44 112,640 --a------ C:\WINDOWS\system32\qegjzl.dll
2008-09-18 13:44 . 2008-09-18 13:44 112,640 --a------ C:\WINDOWS\system32\gcgcfkcv.dll
2008-09-18 09:23 . 2008-09-18 09:23 <DIR> d-------- C:\Program Files\Raize
2008-09-18 09:23 . 2003-01-27 21:00 1,432,064 --a------ C:\WINDOWS\system32\Rz30Ctls60.bpl
2008-09-18 09:23 . 2003-01-27 21:00 269,312 --a------ C:\WINDOWS\system32\Rz30DBCtls60.bpl
2008-09-18 09:02 . 2003-06-18 11:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-09-18 09:02 . 2008-09-18 09:02 376 --a------ C:\WINDOWS\ODBC.INI
2008-09-18 08:59 . 2008-09-18 08:59 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-09-18 08:58 . 2008-09-18 08:58 <DIR> d-------- C:\Program Files\Microsoft Works
2008-09-18 08:58 . 2008-09-18 08:58 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-09-18 08:57 . 2008-09-18 08:59 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-09-18 08:57 . 2008-09-18 08:57 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-09-18 08:48 . 2008-09-18 08:48 <DIR> dr-h----- C:\MSOCache
2008-09-18 08:35 . 2008-09-18 08:35 <DIR> d-------- C:\Program Files\HiComponents
2008-09-18 08:33 . 2008-09-18 08:33 <DIR> d-------- C:\Program Files\Woll2Woll
2008-09-18 08:01 . 2008-09-18 08:16 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-09-18 08:01 . 2008-09-18 08:16 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-09-18 08:00 . 2008-09-24 16:26 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-09-18 08:00 . 2008-09-24 16:26 3,268,640 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-18 08:00 . 2008-09-24 15:32 286,752 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-18 08:00 . 2008-09-24 16:26 27,664 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-18 08:00 . 2008-09-24 15:32 3,108 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-18 07:56 . 2008-09-18 07:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2008-09-18 06:50 . 2007-03-28 08:08 390,240 --a------ C:\WINDOWS\system32\SigPlus.ocx
2008-09-18 06:30 . 2008-09-18 06:31 <DIR> d-------- C:\Program Files\IDNow
2008-09-17 18:48 . 2008-09-17 19:07 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
2008-09-17 18:46 . 2008-09-17 18:46 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-09-17 18:35 . 2008-09-17 18:35 850 --a------ C:\WINDOWS\system32\ProductTweaks.xml
2008-09-17 18:35 . 2008-09-17 18:35 385 --a------ C:\WINDOWS\system32\user_gensett.xml
2008-09-17 18:31 . 2008-09-17 18:31 <DIR> d-------- C:\WINDOWS\system32\logs
2008-09-17 18:30 . 2008-09-17 18:46 <DIR> d-------- C:\Program Files\BitDefender
2008-09-17 18:28 . 2008-09-17 18:29 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-09-17 18:27 . 2008-09-17 18:30 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-09-17 13:44 . 2008-09-17 13:44 113,152 --a------ C:\WINDOWS\system32\joudgj.dll
2008-09-17 13:44 . 2008-09-17 13:44 113,152 --a------ C:\WINDOWS\system32\gokduodb.dll
2008-09-17 11:53 . 2008-09-17 11:53 <DIR> d-------- C:\Program Files\uTorrent
2008-09-17 11:53 . 2008-09-23 18:23 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\uTorrent
2008-09-17 11:39 . 2008-09-17 11:39 <DIR> d---s---- C:\Documents and Settings\XPPRESP3\UserData
2008-09-17 10:38 . 2008-09-19 21:00 269 --a------ C:\WINDOWS\wininit.ini
2008-09-17 09:45 . 2007-09-03 11:13 393,216 --a------ C:\WINDOWS\system32\GDS32.DLL
2008-09-17 09:31 . 2008-09-17 09:31 <DIR> d-------- C:\Program Files\Firebird
2008-09-17 08:52 . 2008-09-17 08:52 <DIR> d--h----- C:\Documents and Settings\XPPRESP3\Application Data\yahoo!
2008-09-17 08:47 . 2008-09-17 08:47 <DIR> d--h----- C:\WINDOWS\PIF
2008-09-17 08:31 . 2008-09-17 08:31 <DIR> d-------- C:\Program Files\Opera
2008-09-17 07:56 . 2008-09-17 07:59 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2008-09-17 07:56 . 2008-09-17 07:56 <DIR> d-------- C:\Program Files\Borland
2008-09-17 07:50 . 2008-09-17 07:50 <DIR> d-------- C:\Program Files\Devrace
2008-09-17 07:47 . 2008-09-17 08:46 <DIR> d-------- C:\wamp
2008-09-17 07:40 . 2008-09-17 07:40 113,152 --a------ C:\WINDOWS\system32\pvrduvok.dll
2008-09-17 07:40 . 2008-09-17 07:40 113,152 --a------ C:\WINDOWS\system32\crqnkp.dll
2008-09-17 05:49 . 2008-09-17 05:49 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\vlc
2008-09-17 05:40 . 2008-09-23 19:26 <DIR> d-------- C:\Documents and Settings\XPPRESP3\Application Data\LimeWire
2008-09-17 05:39 . 2008-09-17 05:39 <DIR> d-------- C:\Program Files\Java
2008-09-17 05:39 . 2008-06-09 20:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-17 05:35 . 2008-09-17 05:35 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-17 05:12 . 2008-09-17 05:12 <DIR> d-------- C:\Program Files\VideoLAN
2008-09-17 04:23 . 2008-09-17 04:23 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-09-16 21:07 . 2008-09-17 05:32 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2008-09-16 21:06 . 2008-09-17 08:54 <DIR> d-------- C:\Program Files\Yahoo!
2008-09-16 17:27 . 2007-07-26 11:09 520,192 -r------- C:\WINDOWS\RtlExUpd.dll
2008-09-16 17:27 . 2008-09-16 17:27 315,392 --a------ C:\WINDOWS\HideWin.exe
2008-09-16 17:26 . 2008-09-16 14:30 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-09-16 17:26 . 2008-09-16 14:30 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-09-16 17:26 . 2006-12-19 22:00 41,600 -ra------ C:\WINDOWS\system32\drivers\SiSGbeXP.sys
2008-09-16 17:26 . 2006-10-11 05:33 10,288 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-09-16 17:26 . 2008-09-16 17:26 9,404 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-09-16 17:26 . 2004-08-12 20:56 5,810 -ra------ C:\WINDOWS\system32\drivers\ASACPI.sys
2008-09-16 14:34 . 2008-09-16 14:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\nView_Profiles
2008-09-16 14:31 . 2001-08-10 06:00 1,262,956 --a------ C:\WINDOWS\system32\XMNT2001.EXE
2008-09-16 14:31 . 2001-08-10 06:00 3,252 --------- C:\WINDOWS\system32\drivers\PQNTDRV.SYS
2008-09-16 14:30 . 2008-09-16 14:30 <DIR> d-------- C:\Program Files\PowerQuest
2008-09-16 13:29 . 2008-09-16 13:29 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-09-16 13:14 . 2008-09-16 13:18 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-16 13:14 . 2008-09-16 13:27 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-09-16 13:05 . 2008-09-16 13:05 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-16 12:35 . 2008-09-24 16:26 88,723 --a------ C:\WINDOWS\system32\nvapps.xml
2008-09-16 12:34 . 2008-09-16 12:44 <DIR> d-------- C:\WINDOWS\nview
2008-09-16 12:34 . 2007-04-19 13:14 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-09-16 12:34 . 2007-04-19 06:26 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 14:41 --------- d-----w C:\Program Files\DAMN NFO Viewer
2008-09-16 14:37 --------- d-----w C:\Program Files\Unlocker
2008-09-16 14:37 --------- d-----w C:\Program Files\Graphics
2008-09-16 14:37 --------- d-----w C:\Program Files\Desktop
.

------- Sigcheck -------

2005-07-13 03:07 360448 0601f83f6784c220ee302f03f702316e C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4521294b-5996-473e-b9a9-64044adb8365}]
2008-09-24 04:30 111616 --a------ C:\WINDOWS\system32\qlmsts.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus C59 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBHP.EXE" [2006-09-21 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 7700480]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 86016]
"MSConfig"="C:\WINDOWS\system32\msconfig.exe" [2005-10-15 169984]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 201992]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-20 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2007-04-19 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6c5a455a]
--a------ 2008-09-24 04:32 89600 C:\WINDOWS\system32\ktvjbofv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-10 21:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ChikkaDefault]
--a------ 2007-08-28 11:11 36864 C:\PROGRA~1\CHIKKA~1\CHIKKA~1.4\ChikkaLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 18:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-09 22:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 11:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 2007-08-03 07:22 1826816 C:\WINDOWS\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe [2007-09-03 81920]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe [2007-09-03 2002944]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S3 ACR120;ACR120 USB Driver (Proprietary Mode);C:\WINDOWS\system32\Drivers\acr120.sys [2005-06-21 38912]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-09-24 306432]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00

*Newly Created Service* - HELPSVC
.
- - - - ORPHANS REMOVED - - - -

BHO-{034E9F25-FAF0-4CEA-A028-61398E0B184E} - C:\WINDOWS\system32\qoMdCrOg.dll
MSConfigStartUp-BM6f6976c6 - C:\WINDOWS\system32\oyhuliaw.dll


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\XPPRESP3\Application Data\Mozilla\Firefox\Profiles\ys0kk3vd.default\
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-24 16:26:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
------------------------ Other Running Processes ------------------------
.
C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
.
**************************************************************************
.
Completion time: 2008-09-24 16:30:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-24 14:30:18

Pre-Run: 28,038,557,696 bytes free
Post-Run: 27,958,272,000 bytes free

270