sixllamas
2009-02-17, 00:22
Hi,
I ran ComboFix as instructed by the user Shelf Life on Feb 4th to remove Virtumonde and other assorted malware. The log is below. Would someone be able to look over the log and help me continue fixing my laptop?
I really appreciate it. Thanks
---------------------------------------------
ComboFix 09-02-15.01 - me 2009-02-16 16:38:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.226 [GMT -5:00]
Running from: c:\documents and settings\me\My Documents\Downloads\ComboFix.exe
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\me\Application Data\antivirus.exe
c:\documents and settings\me\Application Data\ultra
c:\documents and settings\me\Application Data\ultra\uninstall.bat
c:\documents and settings\me\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\me\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\me\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\GetModule
c:\program files\GetPack
c:\program files\GetPack\GetPack30.exe
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\Mozilla Firefox\components\0dd8225f-7d07-8ea8-02d9-f0a0470a16b5.dll
c:\program files\VnrPack
c:\program files\VnrPack\dicts.gz
c:\program files\VnrPack\trgts.gz
c:\program files\VnrPack\VnrPack22.exe
c:\windows\system32\apaupyct.dll
c:\windows\system32\aruqppej.dll
c:\windows\system32\avrronvv.dll
c:\windows\system32\BaceKkkj.ini
c:\windows\system32\BaceKkkj.ini2
c:\windows\system32\bahrpmje.dll
c:\windows\system32\bbswko.dll
c:\windows\system32\bdcpjqif.dll
c:\windows\system32\biemeutl.dll
c:\windows\system32\bucura.dll
c:\windows\system32\bvuddyku.dll
c:\windows\system32\caokglcu.dll
c:\windows\system32\ccdsbycx.dll
c:\windows\system32\cpwgtx.dll
c:\windows\system32\ddwqye.dll
c:\windows\system32\dmvgjjah.dll_old
c:\windows\system32\dnlcai.dll
c:\windows\system32\dnujld.dll
c:\windows\system32\dyjxop.dll
c:\windows\system32\eaxykknb.dll
c:\windows\system32\ebujqctt.dll
c:\windows\system32\eccfvfhn.dll
c:\windows\system32\ecdsxryb.dll
c:\windows\system32\edqijphl.dll
c:\windows\system32\eosrvgsq.dll
c:\windows\system32\erdqwk.dll
c:\windows\system32\esrocd.dll
c:\windows\system32\fapomx.dll
c:\windows\system32\ffinnvgg.dll
c:\windows\system32\fflweffi.dll
c:\windows\system32\fytbgm.dll
c:\windows\system32\hcpyaruy.dll
c:\windows\system32\hjhdifqt.dll
c:\windows\system32\hjvqdvos.dll
c:\windows\system32\hpnhfgia.dll
c:\windows\system32\hwaeqggv.dll
c:\windows\system32\ihwrpclb.dll
c:\windows\system32\iqtory.dll
c:\windows\system32\jkkKecaB.dll
c:\windows\system32\jorqywmk.dll
c:\windows\system32\jtohfy.dll
c:\windows\system32\kcxohryx.dll
c:\windows\system32\kvtimnwx.dll
c:\windows\system32\lwpjoxfg.dll
c:\windows\system32\lxeptdja.dll
c:\windows\system32\lyhtwecg.dll
c:\windows\system32\mmfqleem.dll
c:\windows\system32\mouijnvg.dll
c:\windows\system32\mttcegkpuejac.dll
c:\windows\system32\mulvcs.dll
c:\windows\system32\mwojbtjf.dll
c:\windows\system32\nexbgx.dll
c:\windows\system32\nnjxithw.dll
c:\windows\system32\nsdogjjk.dll
c:\windows\system32\nthpna.dll
c:\windows\system32\nyinld.dll
c:\windows\system32\octssykw.dll
c:\windows\system32\ovfvqceo.dll
c:\windows\system32\oysfnjmr.dll
c:\windows\system32\pflypofm.dll
c:\windows\system32\pktibs.dll
c:\windows\system32\pponxb.dll
c:\windows\system32\pqnkehqj.dll
c:\windows\system32\puihsx.dll
c:\windows\system32\qbtyam.dll
c:\windows\system32\qdrhcx.dll
c:\windows\system32\qngcljkq.dll
c:\windows\system32\qorlaz.dll
c:\windows\system32\rgevdg.dll
c:\windows\system32\scqhhb.dll
c:\windows\system32\sjlhahcb.dll
c:\windows\system32\smukhulv.dll
c:\windows\system32\ssanbg.dll
c:\windows\system32\tedhoyyt.dll
c:\windows\system32\tlqugp.dll
c:\windows\system32\tohpeyvo.dll
c:\windows\system32\ttfrdqwr.dll
c:\windows\system32\txrensqr.dll
c:\windows\system32\uapdcv.dll
c:\windows\system32\ubhyrotp.dll
c:\windows\system32\ucddmlwd.dll
c:\windows\system32\ufxsta.dll
c:\windows\system32\unbmpt.dll
c:\windows\system32\usxoqq.dll
c:\windows\system32\vepuxyyg.dll
c:\windows\system32\vfwozm.dll
c:\windows\system32\vjrjiqsd.dll
c:\windows\system32\wiqaqlja.dll
c:\windows\system32\wsxxwyvc.dll
c:\windows\system32\xvxeibfd.dll
c:\windows\system32\ygludplt.dll
c:\windows\system32\ygszva.dll
c:\windows\system32\yhytmurg.dll
c:\windows\system32\ypdunoqs.dll
c:\windows\system32\zbchtb.dll
c:\windows\system32\zgdvsd.dll
c:\windows\system32\zpazrg.dll
c:\windows\system32\zujsnx.dll
c:\windows\system32\zzvbue.dll
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 )))))))))))))))))))))))))))))))
.
2009-02-16 16:32 . 2009-02-16 16:32 <DIR> d-------- C:\32788R22FWJFW.0.tmp
2009-02-16 16:12 . 2009-02-16 16:12 120 --ahs---- c:\windows\system32\mfopylfp.ini
2009-02-15 15:04 . 2009-02-15 15:04 120 --ahs---- c:\windows\system32\aigfhnph.ini
2009-02-15 13:39 . 2009-02-15 13:39 120 --ahs---- c:\windows\system32\xsyrvudi.ini
2009-02-14 13:35 . 2009-02-14 13:35 120 --ahs---- c:\windows\system32\fjtbjowm.ini
2009-02-11 22:08 . 2009-02-11 22:08 120 --ahs---- c:\windows\system32\gyyxupev.ini
2009-02-09 22:04 . 2009-02-09 22:04 120 --ahs---- c:\windows\system32\xwnmitvk.ini
2009-02-08 21:30 . 2009-02-08 21:30 120 --ahs---- c:\windows\system32\qwlntxjc.ini
2009-02-08 08:02 . 2009-02-08 08:02 120 --ahs---- c:\windows\system32\tcypuapa.ini
2009-02-07 10:36 . 2009-02-07 10:36 85,637 --a------ c:\windows\system32\0f995a83-38bc-c050-811c-6ed7c39fa585.exe
2009-02-07 10:36 . 2009-02-07 10:36 48,266 --a------ c:\windows\system32\mdffpnuhgsr.exe
2009-02-06 19:19 . 2009-02-06 19:19 120 --ahs---- c:\windows\system32\gvnjiuom.ini
2009-02-06 09:33 . 2009-02-06 09:33 120 --ahs---- c:\windows\system32\nhhfvwms.ini
2009-02-05 15:52 . 2009-02-05 15:52 672,768 --a------ c:\windows\system32\nsgB.dll
2009-02-03 23:05 . 2009-02-03 23:05 120 --ahs---- c:\windows\system32\pobdqxbs.ini
2009-02-03 22:45 . 2009-02-03 22:45 120 --ahs---- c:\windows\system32\jqheknqp.ini
2009-02-02 22:42 . 2009-02-02 22:42 120 --ahs---- c:\windows\system32\hshapait.ini
2009-02-01 15:11 . 2009-02-01 15:11 120 --ahs---- c:\windows\system32\rgfonwad.ini
2009-01-31 15:00 . 2009-01-31 15:33 <DIR> d-------- c:\program files\RegCure
2009-01-31 14:17 . 2009-01-31 14:17 120 --ahs---- c:\windows\system32\dwlmddcu.ini
2009-01-31 11:06 . 2009-01-31 11:06 120 --ahs---- c:\windows\system32\tyyohdet.ini
2009-01-30 09:15 . 2009-01-30 09:15 120 --ahs---- c:\windows\system32\bchahljs.ini
2009-01-28 22:51 . 2009-01-28 22:51 120 --ahs---- c:\windows\system32\hajjgvmd.ini
2009-01-28 21:42 . 2009-02-03 13:11 543 --a------ c:\windows\wininit.ini
2009-01-28 21:08 . 2009-01-28 21:08 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-01-28 21:08 . 2009-01-28 21:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-25 14:39 . 2009-01-25 14:39 <DIR> d-------- c:\program files\Windows Defender
2009-01-20 20:57 . 2009-01-28 21:12 <DIR> d-------- c:\documents and settings\me\Application Data\Twain
2009-01-20 20:52 . 2009-01-20 20:52 <DIR> d-------- c:\program files\WebShow
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 17:56 39,664 ----a-w c:\documents and settings\me\Application Data\GDIPFONTCACHEV1.DAT
2007-03-12 21:08 3,018,824 ----a-w c:\documents and settings\me\Application Data\prg.exe
2009-02-01 21:41 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2009-02-01 21:41 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-02-01 21:41 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2009-02-01 21:41 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-13 04:05 73,728 ----a-w c:\program files\mozilla firefox\components\srff.dll
2009-02-01 21:41 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08b8c0b0-bc5c-96e4-5dd8-ab1b268cef09}]
2009-02-05 15:52 672768 --a------ c:\windows\system32\nsgB.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\me\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZTgServerSwitch"="c:\program files\support.com\client\bin\tgcmd.exe" [2003-06-23 1409024]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"TPP Auto Loader"="c:\windows\tppaldr.exe" [2001-10-05 118784]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 81920]
"MaxtorOneTouch"="c:\program files\Maxtor\OneTouch\utils\Onetouch.exe" [2006-03-01 712704]
"HKSERV.EXE"="c:\program files\Sony\HotKey Utility\HKserv.exe" [2003-08-14 90112]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-31 335872]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-09-19 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\system32\Ati2mdxx.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-03 108544]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
PowerPanel.lnk - c:\program files\PowerPanel\Program\PcfMgr.exe [2003-11-10 872448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=cpwgtx.dll erdqwk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"vidc.ffds"= c:\progra~1\ffdshow\ffdshow.ax
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-11 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2003-11-07 71961]
S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};\??\c:\windows\TEMP\13.tmp --> c:\windows\TEMP\13.tmp [?]
S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [2003-11-07 24618]
S3 TPP200;USB Storage Adapter V2 (TPP);c:\windows\system32\drivers\TPP200.SYS [2005-07-08 35541]
.
Contents of the 'Scheduled Tasks' folder
2009-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-02-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1000410168-989732751-160940925-1005.job
- c:\documents and settings\me\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:35]
2009-02-16 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2009-01-31 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 12:58]
2009-01-31 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 12:58]
2009-01-26 c:\windows\Tasks\User_Feed_Synchronization-{618D4097-5CCE-4CA0-9B15-79EFB19E2B20}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
2009-01-25 c:\windows\Tasks\zqqgeobs.job
- c:\windows\system32\awtsTLFy.dll [2009-01-05 00:45]
.
- - - - ORPHANS REMOVED - - - -
BHO-{155DDBE3-4BCA-4D03-A337-A5CADF31D1AA} - (no file)
BHO-{2FDFDB58-D7BE-44AF-9C8D-92247D172F0B} - (no file)
BHO-{5332CF2D-B814-58F2-55BC-4E872765CC76} - c:\windows\system32\mttcegkpuejac.dll
BHO-{77c96e76-97d7-4ab3-9ff1-1f592b002bd9} - c:\windows\system32\erdqwk.dll
BHO-{85B09DAA-13A1-4E5F-9B61-E7DBAD115373} - c:\windows\system32\jkkKecaB.dll
BHO-{a93362db-35dc-4629-b61b-be0b320a6791} - (no file)
BHO-{DBF8D289-D7FD-46AE-92FB-88362B3F16E6} - (no file)
HKCU-Run-VnrPack22 - c:\program files\VnrPack\VnrPack22.exe
HKCU-Run-GetPack30 - c:\program files\GetPack\GetPack30.exe
Notify-fccyvSJA - fccyvSJA.dll
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/webhp
uInternet Settings,ProxyServer = servidor:80
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
Trusted Zone: bwaypartners.com\mail
FF - ProfilePath - c:\documents and settings\me\Application Data\Mozilla\Firefox\Profiles\ipvjcdkg.default\
FF - component: c:\program files\Mozilla Firefox\components\srff.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-16 16:48:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]
"ImagePath"="\??\c:\windows\TEMP\13.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1000410168-989732751-160940925-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1000410168-989732751-160940925-1005\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-1000410168-989732751-160940925-1005)
@Allowed: (Read) (S-1-5-21-1000410168-989732751-160940925-1005)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
c:\program files\Maxtor\OneTouch\Utils\SyncServices.exe
c:\program files\Sony\HotKey Utility\HKWnd.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2009-02-16 16:55:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-16 21:55:17
Pre-Run: 2,068,529,152 bytes free
Post-Run: 2,089,091,072 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
317 --- E O F --- 2009-02-16 21:54:19
[B]Edit
09-01-31 http://forums.spybot.info/showthread.php?t=45113
I ran ComboFix as instructed by the user Shelf Life on Feb 4th to remove Virtumonde and other assorted malware. The log is below. Would someone be able to look over the log and help me continue fixing my laptop?
I really appreciate it. Thanks
---------------------------------------------
ComboFix 09-02-15.01 - me 2009-02-16 16:38:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.226 [GMT -5:00]
Running from: c:\documents and settings\me\My Documents\Downloads\ComboFix.exe
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\me\Application Data\antivirus.exe
c:\documents and settings\me\Application Data\ultra
c:\documents and settings\me\Application Data\ultra\uninstall.bat
c:\documents and settings\me\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\me\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\me\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\GetModule
c:\program files\GetPack
c:\program files\GetPack\GetPack30.exe
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\Mozilla Firefox\components\0dd8225f-7d07-8ea8-02d9-f0a0470a16b5.dll
c:\program files\VnrPack
c:\program files\VnrPack\dicts.gz
c:\program files\VnrPack\trgts.gz
c:\program files\VnrPack\VnrPack22.exe
c:\windows\system32\apaupyct.dll
c:\windows\system32\aruqppej.dll
c:\windows\system32\avrronvv.dll
c:\windows\system32\BaceKkkj.ini
c:\windows\system32\BaceKkkj.ini2
c:\windows\system32\bahrpmje.dll
c:\windows\system32\bbswko.dll
c:\windows\system32\bdcpjqif.dll
c:\windows\system32\biemeutl.dll
c:\windows\system32\bucura.dll
c:\windows\system32\bvuddyku.dll
c:\windows\system32\caokglcu.dll
c:\windows\system32\ccdsbycx.dll
c:\windows\system32\cpwgtx.dll
c:\windows\system32\ddwqye.dll
c:\windows\system32\dmvgjjah.dll_old
c:\windows\system32\dnlcai.dll
c:\windows\system32\dnujld.dll
c:\windows\system32\dyjxop.dll
c:\windows\system32\eaxykknb.dll
c:\windows\system32\ebujqctt.dll
c:\windows\system32\eccfvfhn.dll
c:\windows\system32\ecdsxryb.dll
c:\windows\system32\edqijphl.dll
c:\windows\system32\eosrvgsq.dll
c:\windows\system32\erdqwk.dll
c:\windows\system32\esrocd.dll
c:\windows\system32\fapomx.dll
c:\windows\system32\ffinnvgg.dll
c:\windows\system32\fflweffi.dll
c:\windows\system32\fytbgm.dll
c:\windows\system32\hcpyaruy.dll
c:\windows\system32\hjhdifqt.dll
c:\windows\system32\hjvqdvos.dll
c:\windows\system32\hpnhfgia.dll
c:\windows\system32\hwaeqggv.dll
c:\windows\system32\ihwrpclb.dll
c:\windows\system32\iqtory.dll
c:\windows\system32\jkkKecaB.dll
c:\windows\system32\jorqywmk.dll
c:\windows\system32\jtohfy.dll
c:\windows\system32\kcxohryx.dll
c:\windows\system32\kvtimnwx.dll
c:\windows\system32\lwpjoxfg.dll
c:\windows\system32\lxeptdja.dll
c:\windows\system32\lyhtwecg.dll
c:\windows\system32\mmfqleem.dll
c:\windows\system32\mouijnvg.dll
c:\windows\system32\mttcegkpuejac.dll
c:\windows\system32\mulvcs.dll
c:\windows\system32\mwojbtjf.dll
c:\windows\system32\nexbgx.dll
c:\windows\system32\nnjxithw.dll
c:\windows\system32\nsdogjjk.dll
c:\windows\system32\nthpna.dll
c:\windows\system32\nyinld.dll
c:\windows\system32\octssykw.dll
c:\windows\system32\ovfvqceo.dll
c:\windows\system32\oysfnjmr.dll
c:\windows\system32\pflypofm.dll
c:\windows\system32\pktibs.dll
c:\windows\system32\pponxb.dll
c:\windows\system32\pqnkehqj.dll
c:\windows\system32\puihsx.dll
c:\windows\system32\qbtyam.dll
c:\windows\system32\qdrhcx.dll
c:\windows\system32\qngcljkq.dll
c:\windows\system32\qorlaz.dll
c:\windows\system32\rgevdg.dll
c:\windows\system32\scqhhb.dll
c:\windows\system32\sjlhahcb.dll
c:\windows\system32\smukhulv.dll
c:\windows\system32\ssanbg.dll
c:\windows\system32\tedhoyyt.dll
c:\windows\system32\tlqugp.dll
c:\windows\system32\tohpeyvo.dll
c:\windows\system32\ttfrdqwr.dll
c:\windows\system32\txrensqr.dll
c:\windows\system32\uapdcv.dll
c:\windows\system32\ubhyrotp.dll
c:\windows\system32\ucddmlwd.dll
c:\windows\system32\ufxsta.dll
c:\windows\system32\unbmpt.dll
c:\windows\system32\usxoqq.dll
c:\windows\system32\vepuxyyg.dll
c:\windows\system32\vfwozm.dll
c:\windows\system32\vjrjiqsd.dll
c:\windows\system32\wiqaqlja.dll
c:\windows\system32\wsxxwyvc.dll
c:\windows\system32\xvxeibfd.dll
c:\windows\system32\ygludplt.dll
c:\windows\system32\ygszva.dll
c:\windows\system32\yhytmurg.dll
c:\windows\system32\ypdunoqs.dll
c:\windows\system32\zbchtb.dll
c:\windows\system32\zgdvsd.dll
c:\windows\system32\zpazrg.dll
c:\windows\system32\zujsnx.dll
c:\windows\system32\zzvbue.dll
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 )))))))))))))))))))))))))))))))
.
2009-02-16 16:32 . 2009-02-16 16:32 <DIR> d-------- C:\32788R22FWJFW.0.tmp
2009-02-16 16:12 . 2009-02-16 16:12 120 --ahs---- c:\windows\system32\mfopylfp.ini
2009-02-15 15:04 . 2009-02-15 15:04 120 --ahs---- c:\windows\system32\aigfhnph.ini
2009-02-15 13:39 . 2009-02-15 13:39 120 --ahs---- c:\windows\system32\xsyrvudi.ini
2009-02-14 13:35 . 2009-02-14 13:35 120 --ahs---- c:\windows\system32\fjtbjowm.ini
2009-02-11 22:08 . 2009-02-11 22:08 120 --ahs---- c:\windows\system32\gyyxupev.ini
2009-02-09 22:04 . 2009-02-09 22:04 120 --ahs---- c:\windows\system32\xwnmitvk.ini
2009-02-08 21:30 . 2009-02-08 21:30 120 --ahs---- c:\windows\system32\qwlntxjc.ini
2009-02-08 08:02 . 2009-02-08 08:02 120 --ahs---- c:\windows\system32\tcypuapa.ini
2009-02-07 10:36 . 2009-02-07 10:36 85,637 --a------ c:\windows\system32\0f995a83-38bc-c050-811c-6ed7c39fa585.exe
2009-02-07 10:36 . 2009-02-07 10:36 48,266 --a------ c:\windows\system32\mdffpnuhgsr.exe
2009-02-06 19:19 . 2009-02-06 19:19 120 --ahs---- c:\windows\system32\gvnjiuom.ini
2009-02-06 09:33 . 2009-02-06 09:33 120 --ahs---- c:\windows\system32\nhhfvwms.ini
2009-02-05 15:52 . 2009-02-05 15:52 672,768 --a------ c:\windows\system32\nsgB.dll
2009-02-03 23:05 . 2009-02-03 23:05 120 --ahs---- c:\windows\system32\pobdqxbs.ini
2009-02-03 22:45 . 2009-02-03 22:45 120 --ahs---- c:\windows\system32\jqheknqp.ini
2009-02-02 22:42 . 2009-02-02 22:42 120 --ahs---- c:\windows\system32\hshapait.ini
2009-02-01 15:11 . 2009-02-01 15:11 120 --ahs---- c:\windows\system32\rgfonwad.ini
2009-01-31 15:00 . 2009-01-31 15:33 <DIR> d-------- c:\program files\RegCure
2009-01-31 14:17 . 2009-01-31 14:17 120 --ahs---- c:\windows\system32\dwlmddcu.ini
2009-01-31 11:06 . 2009-01-31 11:06 120 --ahs---- c:\windows\system32\tyyohdet.ini
2009-01-30 09:15 . 2009-01-30 09:15 120 --ahs---- c:\windows\system32\bchahljs.ini
2009-01-28 22:51 . 2009-01-28 22:51 120 --ahs---- c:\windows\system32\hajjgvmd.ini
2009-01-28 21:42 . 2009-02-03 13:11 543 --a------ c:\windows\wininit.ini
2009-01-28 21:08 . 2009-01-28 21:08 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-01-28 21:08 . 2009-01-28 21:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-25 14:39 . 2009-01-25 14:39 <DIR> d-------- c:\program files\Windows Defender
2009-01-20 20:57 . 2009-01-28 21:12 <DIR> d-------- c:\documents and settings\me\Application Data\Twain
2009-01-20 20:52 . 2009-01-20 20:52 <DIR> d-------- c:\program files\WebShow
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 17:56 39,664 ----a-w c:\documents and settings\me\Application Data\GDIPFONTCACHEV1.DAT
2007-03-12 21:08 3,018,824 ----a-w c:\documents and settings\me\Application Data\prg.exe
2009-02-01 21:41 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2009-02-01 21:41 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-02-01 21:41 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2009-02-01 21:41 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-13 04:05 73,728 ----a-w c:\program files\mozilla firefox\components\srff.dll
2009-02-01 21:41 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08b8c0b0-bc5c-96e4-5dd8-ab1b268cef09}]
2009-02-05 15:52 672768 --a------ c:\windows\system32\nsgB.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\me\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZTgServerSwitch"="c:\program files\support.com\client\bin\tgcmd.exe" [2003-06-23 1409024]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"TPP Auto Loader"="c:\windows\tppaldr.exe" [2001-10-05 118784]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 81920]
"MaxtorOneTouch"="c:\program files\Maxtor\OneTouch\utils\Onetouch.exe" [2006-03-01 712704]
"HKSERV.EXE"="c:\program files\Sony\HotKey Utility\HKserv.exe" [2003-08-14 90112]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-31 335872]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-09-19 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\system32\Ati2mdxx.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-03 108544]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
PowerPanel.lnk - c:\program files\PowerPanel\Program\PcfMgr.exe [2003-11-10 872448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=cpwgtx.dll erdqwk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"vidc.ffds"= c:\progra~1\ffdshow\ffdshow.ax
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-11 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2003-11-07 71961]
S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};\??\c:\windows\TEMP\13.tmp --> c:\windows\TEMP\13.tmp [?]
S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [2003-11-07 24618]
S3 TPP200;USB Storage Adapter V2 (TPP);c:\windows\system32\drivers\TPP200.SYS [2005-07-08 35541]
.
Contents of the 'Scheduled Tasks' folder
2009-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-02-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1000410168-989732751-160940925-1005.job
- c:\documents and settings\me\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:35]
2009-02-16 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2009-01-31 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 12:58]
2009-01-31 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 12:58]
2009-01-26 c:\windows\Tasks\User_Feed_Synchronization-{618D4097-5CCE-4CA0-9B15-79EFB19E2B20}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
2009-01-25 c:\windows\Tasks\zqqgeobs.job
- c:\windows\system32\awtsTLFy.dll [2009-01-05 00:45]
.
- - - - ORPHANS REMOVED - - - -
BHO-{155DDBE3-4BCA-4D03-A337-A5CADF31D1AA} - (no file)
BHO-{2FDFDB58-D7BE-44AF-9C8D-92247D172F0B} - (no file)
BHO-{5332CF2D-B814-58F2-55BC-4E872765CC76} - c:\windows\system32\mttcegkpuejac.dll
BHO-{77c96e76-97d7-4ab3-9ff1-1f592b002bd9} - c:\windows\system32\erdqwk.dll
BHO-{85B09DAA-13A1-4E5F-9B61-E7DBAD115373} - c:\windows\system32\jkkKecaB.dll
BHO-{a93362db-35dc-4629-b61b-be0b320a6791} - (no file)
BHO-{DBF8D289-D7FD-46AE-92FB-88362B3F16E6} - (no file)
HKCU-Run-VnrPack22 - c:\program files\VnrPack\VnrPack22.exe
HKCU-Run-GetPack30 - c:\program files\GetPack\GetPack30.exe
Notify-fccyvSJA - fccyvSJA.dll
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/webhp
uInternet Settings,ProxyServer = servidor:80
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
Trusted Zone: bwaypartners.com\mail
FF - ProfilePath - c:\documents and settings\me\Application Data\Mozilla\Firefox\Profiles\ipvjcdkg.default\
FF - component: c:\program files\Mozilla Firefox\components\srff.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-16 16:48:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]
"ImagePath"="\??\c:\windows\TEMP\13.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1000410168-989732751-160940925-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1000410168-989732751-160940925-1005\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-1000410168-989732751-160940925-1005)
@Allowed: (Read) (S-1-5-21-1000410168-989732751-160940925-1005)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
c:\program files\Maxtor\OneTouch\Utils\SyncServices.exe
c:\program files\Sony\HotKey Utility\HKWnd.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2009-02-16 16:55:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-16 21:55:17
Pre-Run: 2,068,529,152 bytes free
Post-Run: 2,089,091,072 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
317 --- E O F --- 2009-02-16 21:54:19
[B]Edit
09-01-31 http://forums.spybot.info/showthread.php?t=45113