Virtumonde somehow got onto my system. Having read the previous posts, I ran combofix. Below is my log. I have also tried to use PC-cillian, Spybot Search & Destroy, Vundofix, and Virtumondobegone, all with no effect.
So, here is the log. Any suggestions?
----------------------------------------------------------
ComboFix 08-06-20.4 - Admin 2008-06-21 13:21:57.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1362 [GMT -7:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM93325f8b.xml
C:\WINDOWS\pskt.ini
.
---- Previous Run -------
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aoktlgxe.ini
C:\WINDOWS\system32\cefilnnn.ini
C:\WINDOWS\system32\cefilnnn.ini2
C:\WINDOWS\system32\DMmlSvut.ini
C:\WINDOWS\system32\DMmlSvut.ini2
C:\WINDOWS\system32\fjeploru.ini
C:\WINDOWS\system32\giQtwvut.ini
C:\WINDOWS\system32\giQtwvut.ini2
C:\WINDOWS\system32\hcnfhnpn.ini
C:\WINDOWS\system32\ksvlflir.ini
C:\WINDOWS\system32\lUvGNqru.ini
C:\WINDOWS\system32\lUvGNqru.ini2
C:\WINDOWS\system32\mStsvGgh.ini
C:\WINDOWS\system32\mStsvGgh.ini2
C:\WINDOWS\system32\mVxxHRqr.ini
C:\WINDOWS\system32\mVxxHRqr.ini2
C:\WINDOWS\system32\sqtmdwsu.ini
C:\WINDOWS\system32\tgqfryxw.ini
C:\WINDOWS\system32\tsAayyxx.ini
C:\WINDOWS\system32\tsAayyxx.ini2
.
((((((((((((((((((((((((( Files Created from 2008-05-21 to 2008-06-21 )))))))))))))))))))))))))))))))
.
2008-06-21 11:35 . 2008-06-21 11:35 81,408 --a------ C:\WINDOWS\system32\uswdmtqs.dll
2008-06-21 11:33 . 2008-06-21 11:33 <DIR> d-------- C:\VundoFix Backups
2008-06-21 11:32 . 2008-06-21 11:32 99,328 --a------ C:\WINDOWS\system32\edjuskyk.dll
2008-06-21 11:31 . 2008-06-21 12:45 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-06-21 11:31 . 2008-06-21 11:31 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\PC Tools
2008-06-21 11:31 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-06-21 11:31 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-06-21 11:31 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-06-21 11:31 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-06-21 11:30 . 2008-06-21 11:30 90,112 --a------ C:\WINDOWS\system32\gyflyeby.dll
2008-06-20 23:01 . 2008-06-20 23:01 79,872 --a------ C:\WINDOWS\system32\rilflvsk.dll
2008-06-20 22:58 . 2008-06-20 22:58 99,328 --a------ C:\WINDOWS\system32\yhivctsk.dll
2008-06-20 22:55 . 2008-06-20 22:55 90,624 --a------ C:\WINDOWS\system32\euykjsnv.dll
2008-06-20 20:32 . 2008-06-20 20:32 79,872 --a------ C:\WINDOWS\system32\urolpejf.dll
2008-06-20 20:29 . 2008-06-20 20:29 99,328 --a------ C:\WINDOWS\system32\ulxujeke.dll
2008-06-20 20:26 . 2008-06-20 20:26 90,624 --a------ C:\WINDOWS\system32\qrfjojwa.dll
2008-06-20 18:47 . 2008-06-21 12:16 501 --a------ C:\WINDOWS\wininit.ini
2008-06-20 18:05 . 2008-06-20 18:05 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-20 18:05 . 2008-06-20 18:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-20 01:46 . 2008-06-20 01:46 79,360 --a------ C:\WINDOWS\system32\wxyrfqgt.dll
2008-06-20 01:40 . 2008-06-20 01:40 33,280 --a------ C:\WINDOWS\system32\khfCsqQg.dll.vir
2008-06-19 00:25 . 2008-06-19 00:25 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-06-19 00:24 . 2003-07-19 08:17 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd
2008-06-19 00:24 . 2005-01-02 23:43 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2008-06-17 00:25 . 2008-06-17 00:25 268 --ah----- C:\sqmdata11.sqm
2008-06-17 00:25 . 2008-06-17 00:25 244 --ah----- C:\sqmnoopt11.sqm
2008-06-17 00:20 . 2008-06-17 00:20 <DIR> d-------- C:\Program Files\SweetIM
2008-06-17 00:20 . 2008-06-17 00:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SweetIM
2008-06-16 20:02 . 2008-06-16 20:02 <DIR> d-------- C:\AeriaGames
2008-06-11 01:27 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 01:27 . 2008-06-13 06:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-07 02:35 . 2008-06-07 02:36 <DIR> d-------- C:\Program Files\Picasa2
2008-06-04 02:30 . 2008-06-04 02:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-04 02:30 . 2008-06-04 02:30 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-21 20:12 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-21 20:04 --------- d-----w C:\Documents and Settings\Admin\Application Data\nView_Wallpaper
2008-06-21 05:34 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 03:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-21 01:11 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-20 15:02 --------- d-----w C:\Documents and Settings\Admin\Application Data\BitTorrent
2008-06-17 03:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-16 07:02 --------- d-----w C:\Program Files\OpenOffice.org1.1.5
2008-06-13 20:09 --------- d-----w C:\Program Files\World of Warcraft
2008-06-02 09:20 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-02 09:18 --------- d-----w C:\Documents and Settings\Admin\Application Data\AdobeUM
2008-05-26 17:19 --------- d-----w C:\Program Files\Bit Che
2008-05-25 14:28 --------- d-----w C:\Program Files\Last.fm
2008-05-19 15:02 --------- d-----w C:\Program Files\Xing
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-03 16:43 --------- d-----w C:\Program Files\WarRock
2008-05-03 16:41 --------- d-----w C:\Program Files\America's Army
2008-05-03 16:34 --------- d-----w C:\Program Files\Yahoo!
2008-05-03 09:18 --------- d-----w C:\Program Files\Apple Software Update
2008-05-03 09:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-05-02 23:22 205,328 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-05-02 23:21 36,368 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-05-02 23:17 1,169,240 ----a-w C:\WINDOWS\system32\drivers\vsapint.sys
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-22 18:29 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-03-22 18:29 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-01-05 04:09 24,192 ----a-w C:\Documents and Settings\Admin\usbsermptxp.sys
2007-01-05 04:09 22,768 ----a-w C:\Documents and Settings\Admin\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{159FAFD9-3F55-4774-87F7-87518ABD9582}]
C:\WINDOWS\system32\tuvSlmMD.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{291BFA1B-B8B7-487E-983F-81B75623D758}]
C:\WINDOWS\system32\hgGvstSm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A73192B-28FE-4836-89C5-F04AF58C7371}]
C:\WINDOWS\system32\urqNGvUl.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9B329E3D-F1C8-4E22-B7D8-C3E2FCE93A02}]
C:\WINDOWS\system32\nnnlifec.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8db6920-1a01-4674-a4ac-bffa184db7d9}]
2008-06-21 11:32 99328 --a------ C:\WINDOWS\system32\edjuskyk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E39559C3-096C-4ED6-957E-DA524602B0C2}]
C:\WINDOWS\system32\rqRHxxVm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F4D25DD9-F62D-4B03-9FB8-5BF6C94BE15D}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 05:00 15360]
"igndlm.exe"="C:\PROGRAM FILES\IGN\DOWNLOAD MANAGER\DLM.EXE" [2007-03-05 13:57 1103480]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-02 01:10 68856]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 13:39 1289000]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-04-30 19:07 843776]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 17:22 7618560]
"nwiz"="nwiz.exe" [2006-06-01 17:22 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 17:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 08:31 1122304]
"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 08:14 497152]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 23:25 28160 C:\WINDOWS\KHALMNPR.Exe]
"CloneCDElbyCDFL"="C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" [2002-11-01 23:33 45056]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2007-01-23 14:26 3429904]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 14:48 479232]
"NWEReboot"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"SweetIM"="C:\Program Files\SweetIM\Messenger\SweetIM.exe" [2008-06-15 13:40 111928]
"90016c17"="C:\WINDOWS\system32\exgltkoa.dll" [ ]
"BM93325f8b"="C:\WINDOWS\system32\gyflyeby.dll" [2008-06-21 11:30 90112]
C:\Documents and Settings\Admin\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-03-01 12:48:54 653312]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-09-12 00:09:01 528384]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2005-09-20 09:26]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-16 14:30:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-21 13:23:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-21 13:24:18
ComboFix-quarantined-files.txt 2008-06-21 20:23:52
Pre-Run: 12,215,361,536 bytes free
Post-Run: 12,200,087,552 bytes free
211 --- E O F --- 2008-06-20 01:59:27
So, here is the log. Any suggestions?
----------------------------------------------------------
ComboFix 08-06-20.4 - Admin 2008-06-21 13:21:57.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1362 [GMT -7:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM93325f8b.xml
C:\WINDOWS\pskt.ini
.
---- Previous Run -------
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aoktlgxe.ini
C:\WINDOWS\system32\cefilnnn.ini
C:\WINDOWS\system32\cefilnnn.ini2
C:\WINDOWS\system32\DMmlSvut.ini
C:\WINDOWS\system32\DMmlSvut.ini2
C:\WINDOWS\system32\fjeploru.ini
C:\WINDOWS\system32\giQtwvut.ini
C:\WINDOWS\system32\giQtwvut.ini2
C:\WINDOWS\system32\hcnfhnpn.ini
C:\WINDOWS\system32\ksvlflir.ini
C:\WINDOWS\system32\lUvGNqru.ini
C:\WINDOWS\system32\lUvGNqru.ini2
C:\WINDOWS\system32\mStsvGgh.ini
C:\WINDOWS\system32\mStsvGgh.ini2
C:\WINDOWS\system32\mVxxHRqr.ini
C:\WINDOWS\system32\mVxxHRqr.ini2
C:\WINDOWS\system32\sqtmdwsu.ini
C:\WINDOWS\system32\tgqfryxw.ini
C:\WINDOWS\system32\tsAayyxx.ini
C:\WINDOWS\system32\tsAayyxx.ini2
.
((((((((((((((((((((((((( Files Created from 2008-05-21 to 2008-06-21 )))))))))))))))))))))))))))))))
.
2008-06-21 11:35 . 2008-06-21 11:35 81,408 --a------ C:\WINDOWS\system32\uswdmtqs.dll
2008-06-21 11:33 . 2008-06-21 11:33 <DIR> d-------- C:\VundoFix Backups
2008-06-21 11:32 . 2008-06-21 11:32 99,328 --a------ C:\WINDOWS\system32\edjuskyk.dll
2008-06-21 11:31 . 2008-06-21 12:45 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-06-21 11:31 . 2008-06-21 11:31 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\PC Tools
2008-06-21 11:31 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-06-21 11:31 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-06-21 11:31 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-06-21 11:31 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-06-21 11:30 . 2008-06-21 11:30 90,112 --a------ C:\WINDOWS\system32\gyflyeby.dll
2008-06-20 23:01 . 2008-06-20 23:01 79,872 --a------ C:\WINDOWS\system32\rilflvsk.dll
2008-06-20 22:58 . 2008-06-20 22:58 99,328 --a------ C:\WINDOWS\system32\yhivctsk.dll
2008-06-20 22:55 . 2008-06-20 22:55 90,624 --a------ C:\WINDOWS\system32\euykjsnv.dll
2008-06-20 20:32 . 2008-06-20 20:32 79,872 --a------ C:\WINDOWS\system32\urolpejf.dll
2008-06-20 20:29 . 2008-06-20 20:29 99,328 --a------ C:\WINDOWS\system32\ulxujeke.dll
2008-06-20 20:26 . 2008-06-20 20:26 90,624 --a------ C:\WINDOWS\system32\qrfjojwa.dll
2008-06-20 18:47 . 2008-06-21 12:16 501 --a------ C:\WINDOWS\wininit.ini
2008-06-20 18:05 . 2008-06-20 18:05 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-20 18:05 . 2008-06-20 18:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-20 01:46 . 2008-06-20 01:46 79,360 --a------ C:\WINDOWS\system32\wxyrfqgt.dll
2008-06-20 01:40 . 2008-06-20 01:40 33,280 --a------ C:\WINDOWS\system32\khfCsqQg.dll.vir
2008-06-19 00:25 . 2008-06-19 00:25 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-06-19 00:24 . 2003-07-19 08:17 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd
2008-06-19 00:24 . 2005-01-02 23:43 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2008-06-17 00:25 . 2008-06-17 00:25 268 --ah----- C:\sqmdata11.sqm
2008-06-17 00:25 . 2008-06-17 00:25 244 --ah----- C:\sqmnoopt11.sqm
2008-06-17 00:20 . 2008-06-17 00:20 <DIR> d-------- C:\Program Files\SweetIM
2008-06-17 00:20 . 2008-06-17 00:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SweetIM
2008-06-16 20:02 . 2008-06-16 20:02 <DIR> d-------- C:\AeriaGames
2008-06-11 01:27 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 01:27 . 2008-06-13 06:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-07 02:35 . 2008-06-07 02:36 <DIR> d-------- C:\Program Files\Picasa2
2008-06-04 02:30 . 2008-06-04 02:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-04 02:30 . 2008-06-04 02:30 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-21 20:12 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-21 20:04 --------- d-----w C:\Documents and Settings\Admin\Application Data\nView_Wallpaper
2008-06-21 05:34 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 03:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-21 01:11 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-20 15:02 --------- d-----w C:\Documents and Settings\Admin\Application Data\BitTorrent
2008-06-17 03:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-16 07:02 --------- d-----w C:\Program Files\OpenOffice.org1.1.5
2008-06-13 20:09 --------- d-----w C:\Program Files\World of Warcraft
2008-06-02 09:20 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-02 09:18 --------- d-----w C:\Documents and Settings\Admin\Application Data\AdobeUM
2008-05-26 17:19 --------- d-----w C:\Program Files\Bit Che
2008-05-25 14:28 --------- d-----w C:\Program Files\Last.fm
2008-05-19 15:02 --------- d-----w C:\Program Files\Xing
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-03 16:43 --------- d-----w C:\Program Files\WarRock
2008-05-03 16:41 --------- d-----w C:\Program Files\America's Army
2008-05-03 16:34 --------- d-----w C:\Program Files\Yahoo!
2008-05-03 09:18 --------- d-----w C:\Program Files\Apple Software Update
2008-05-03 09:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-05-02 23:22 205,328 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-05-02 23:21 36,368 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-05-02 23:17 1,169,240 ----a-w C:\WINDOWS\system32\drivers\vsapint.sys
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-22 18:29 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-03-22 18:29 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-01-05 04:09 24,192 ----a-w C:\Documents and Settings\Admin\usbsermptxp.sys
2007-01-05 04:09 22,768 ----a-w C:\Documents and Settings\Admin\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{159FAFD9-3F55-4774-87F7-87518ABD9582}]
C:\WINDOWS\system32\tuvSlmMD.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{291BFA1B-B8B7-487E-983F-81B75623D758}]
C:\WINDOWS\system32\hgGvstSm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A73192B-28FE-4836-89C5-F04AF58C7371}]
C:\WINDOWS\system32\urqNGvUl.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9B329E3D-F1C8-4E22-B7D8-C3E2FCE93A02}]
C:\WINDOWS\system32\nnnlifec.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8db6920-1a01-4674-a4ac-bffa184db7d9}]
2008-06-21 11:32 99328 --a------ C:\WINDOWS\system32\edjuskyk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E39559C3-096C-4ED6-957E-DA524602B0C2}]
C:\WINDOWS\system32\rqRHxxVm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F4D25DD9-F62D-4B03-9FB8-5BF6C94BE15D}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 05:00 15360]
"igndlm.exe"="C:\PROGRAM FILES\IGN\DOWNLOAD MANAGER\DLM.EXE" [2007-03-05 13:57 1103480]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-02 01:10 68856]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 13:39 1289000]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-04-30 19:07 843776]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 17:22 7618560]
"nwiz"="nwiz.exe" [2006-06-01 17:22 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 17:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 08:31 1122304]
"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 08:14 497152]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 23:25 28160 C:\WINDOWS\KHALMNPR.Exe]
"CloneCDElbyCDFL"="C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" [2002-11-01 23:33 45056]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2007-01-23 14:26 3429904]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 14:48 479232]
"NWEReboot"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"SweetIM"="C:\Program Files\SweetIM\Messenger\SweetIM.exe" [2008-06-15 13:40 111928]
"90016c17"="C:\WINDOWS\system32\exgltkoa.dll" [ ]
"BM93325f8b"="C:\WINDOWS\system32\gyflyeby.dll" [2008-06-21 11:30 90112]
C:\Documents and Settings\Admin\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-03-01 12:48:54 653312]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-09-12 00:09:01 528384]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"C:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2005-09-20 09:26]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-16 14:30:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-21 13:23:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-21 13:24:18
ComboFix-quarantined-files.txt 2008-06-21 20:23:52
Pre-Run: 12,215,361,536 bytes free
Post-Run: 12,200,087,552 bytes free
211 --- E O F --- 2008-06-20 01:59:27