I seem to have picked up some virtumonde spyware which I can't get rid of especially the application sstqr.dll. I have tried several anti spyware programs which have had little effect. VundoFix seems to work in the short term but it soon returns. Here is my Combofix Log:
ComboFix 08-01-20.1 - Natasha 2008-01-23 22:22:16.3 - NTFSx86
Running from: C:\Documents and Settings\Natasha\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\QuickPlay\QPService .exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Default Settings\cpqset .exe
C:\Program Files\HPQ\Default Settings\cpqset.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr .exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Kontiki\KHost .exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Logitech\Video\CameraAssistant .exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\Logitech\Video\InstallHelper .exe
C:\Program Files\Logitech\Video\InstallHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr .Exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher .exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr .exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
C:\WINDOWS\system32\rqtss.ini
C:\WINDOWS\system32\rqtss.ini2
C:\WINDOWS\system32\sstqr.dll
C:\WINDOWS\system32\sstqr.exe
C:\WINDOWS\system32\system
C:\WINDOWS\system32\system\AVICAP.DLL
C:\WINDOWS\system32\system\AVIFILE.DLL
C:\WINDOWS\system32\system\COMMDLG.DLL
C:\WINDOWS\system32\system\KEYBOARD.DRV
C:\WINDOWS\system32\system\LZEXPAND.DLL
C:\WINDOWS\system32\system\MCIAVI.DRV
C:\WINDOWS\system32\system\MCISEQ.DRV
C:\WINDOWS\system32\system\MCIWAVE.DRV
C:\WINDOWS\system32\system\MMSYSTEM.DLL
C:\WINDOWS\system32\system\MMTASK.TSK
C:\WINDOWS\system32\system\MOUSE.DRV
C:\WINDOWS\system32\system\MSVIDEO.DLL
C:\WINDOWS\system32\system\OLECLI.DLL
C:\WINDOWS\system32\system\OLESVR.DLL
C:\WINDOWS\system32\system\setup.inf
C:\WINDOWS\system32\system\SHELL.DLL
C:\WINDOWS\system32\system\SOUND.DRV
.
.
((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 )))))))))))))))))))))))))))))))
.
2008-01-23 19:23 . 2008-01-23 19:23 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-23 19:23 . 2008-01-23 19:23 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-22 22:04 . 2008-01-23 22:42 <DIR> d-------- C:\VundoFix Backups
2008-01-22 19:26 . 2008-01-22 19:26 <DIR> d-------- C:\Documents and Settings\Natasha\Application Data\Grisoft
2008-01-22 19:25 . 2008-01-22 19:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-22 19:25 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-21 13:30 . 2008-01-21 13:30 <DIR> d-------- C:\Program Files\CCleaner
2008-01-19 23:33 . 2008-01-19 23:33 <DIR> d-------- C:\Program Files\Avira
2008-01-19 23:33 . 2008-01-19 23:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-01-19 23:31 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-19 23:28 . 2008-01-19 23:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-19 23:14 . 2008-01-19 23:14 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-19 23:07 . 2008-01-19 23:31 <DIR> d-------- C:\Program Files\SpywareGuard
2008-01-19 21:07 . 2008-01-19 21:07 <DIR> d-------- C:\Documents and Settings\Natasha\DoctorWeb
2008-01-19 19:32 . 2008-01-19 19:32 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-19 19:32 . 2008-01-19 19:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-19 19:24 . 2008-01-22 20:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-19 12:31 . 2008-01-19 12:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-19 12:13 . 2008-01-19 20:53 12,288 --a------ C:\WINDOWS\system32\wupeng .exe
2008-01-19 11:29 . 2008-01-19 20:53 262,144 --a------ C:\WINDOWS\system32\ElkCtrl.exe
2008-01-19 10:49 . 2008-01-19 11:33 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 22:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-01-23 22:43 --------- d-----w C:\Program Files\QuickTime
2008-01-23 22:43 --------- d-----w C:\Program Files\MSN Messenger
2008-01-23 22:43 --------- d-----w C:\Program Files\Kontiki
2008-01-23 22:43 --------- d-----w C:\Program Files\iTunes
2008-01-21 13:01 --------- d-----w C:\Program Files\music_now
2008-01-19 21:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-19 21:14 --------- d-----w C:\Program Files\Windows Defender
2008-01-03 23:18 --------- d-----w C:\Program Files\BitZipper
2007-12-03 20:08 --------- d-----w C:\Documents and Settings\Natasha\Application Data\OLYMPUS
2007-12-03 19:50 --------- d-----w C:\Program Files\Graphic Converter 2003
2007-12-03 18:07 --------- d-----w C:\Program Files\Easy DVD CD Cover Maker
2006-09-14 16:33 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
2006-07-25 18:17 0 -c--a-w C:\Documents and Settings\Natasha\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-01-22_21.29.55.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 08:00:00 69,584 ----a-w C:\WINDOWS\system\AVICAP.DLL
+ 2004-08-04 13:00:00 69,584 ----a-w C:\WINDOWS\system\avicap.dll
- 2004-08-04 08:00:00 109,456 ----a-w C:\WINDOWS\system\AVIFILE.DLL
+ 2004-08-04 13:00:00 109,456 ----a-w C:\WINDOWS\system\avifile.dll
- 2004-08-04 08:00:00 32,816 ----a-w C:\WINDOWS\system\COMMDLG.DLL
+ 2004-08-04 13:00:00 32,816 ----a-w C:\WINDOWS\system\commdlg.dll
- 2004-08-04 08:00:00 9,936 ----a-w C:\WINDOWS\system\LZEXPAND.DLL
+ 2004-08-04 13:00:00 9,936 ----a-w C:\WINDOWS\system\lzexpand.dll
- 2004-08-04 08:00:00 68,768 ----a-w C:\WINDOWS\system\MMSYSTEM.DLL
+ 2004-08-04 13:00:00 68,768 ----a-w C:\WINDOWS\system\mmsystem.dll
- 2004-08-04 08:00:00 126,912 ----a-w C:\WINDOWS\system\MSVIDEO.DLL
+ 2004-08-04 13:00:00 126,912 ----a-w C:\WINDOWS\system\msvideo.dll
- 2004-08-04 08:00:00 82,944 ----a-w C:\WINDOWS\system\OLECLI.DLL
+ 2004-08-04 13:00:00 82,944 ----a-w C:\WINDOWS\system\olecli.dll
- 2004-08-04 08:00:00 24,064 ----a-w C:\WINDOWS\system\OLESVR.DLL
+ 2004-08-04 13:00:00 24,064 ----a-w C:\WINDOWS\system\olesvr.dll
- 2004-08-04 08:00:00 5,120 ----a-w C:\WINDOWS\system\SHELL.DLL
+ 2004-08-04 13:00:00 5,120 ----a-w C:\WINDOWS\system\shell.dll
+ 2004-08-04 13:00:00 69,584 ----a-w C:\WINDOWS\system32\dllcache\avicap.dll
+ 2004-08-04 13:00:00 109,456 ----a-w C:\WINDOWS\system32\dllcache\avifile.dll
+ 2004-08-04 13:00:00 32,816 ----a-w C:\WINDOWS\system32\dllcache\commdlg.dll
+ 2004-08-04 13:00:00 9,936 ----a-w C:\WINDOWS\system32\dllcache\lzexpand.dll
+ 2004-08-04 13:00:00 68,768 ----a-w C:\WINDOWS\system32\dllcache\mmsystem.dll
+ 2004-08-04 13:00:00 126,912 ----a-w C:\WINDOWS\system32\dllcache\msvideo.dll
+ 2004-08-04 13:00:00 82,944 ----a-w C:\WINDOWS\system32\dllcache\olecli.dll
+ 2004-08-04 13:00:00 24,064 ----a-w C:\WINDOWS\system32\dllcache\olesvr.dll
+ 2004-08-04 13:00:00 5,120 ----a-w C:\WINDOWS\system32\dllcache\shell.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [ ]
C:\Documents and Settings\Natasha\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 03:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyaxus]
xxyaxus.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
C:\Program Files\Kontiki\KHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
C:\Program Files\HPQ\Default Settings\cpqset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
C:\Program Files\Kontiki\KHost .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
C:\Program Files\Logitech\Video\CameraAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
C:\Program Files\Logitech\Video\InstallHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lsass]
C:\WINDOWS\lsass .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 15:18]
R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 15:37]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 16:31:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-23 22:52:17 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-11 20:12:42 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Natasha.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-23 22:49:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-23 22:58:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-23 22:58:23
ComboFix2.txt 2008-01-22 21:31:45
ComboFix3.txt 2008-01-21 00:15:44
ComboFix 08-01-20.1 - Natasha 2008-01-23 22:22:16.3 - NTFSx86
Running from: C:\Documents and Settings\Natasha\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\QuickPlay\QPService .exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Default Settings\cpqset .exe
C:\Program Files\HPQ\Default Settings\cpqset.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr .exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Kontiki\KHost .exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Logitech\Video\CameraAssistant .exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\Logitech\Video\InstallHelper .exe
C:\Program Files\Logitech\Video\InstallHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr .Exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher .exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr .exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
C:\WINDOWS\system32\rqtss.ini
C:\WINDOWS\system32\rqtss.ini2
C:\WINDOWS\system32\sstqr.dll
C:\WINDOWS\system32\sstqr.exe
C:\WINDOWS\system32\system
C:\WINDOWS\system32\system\AVICAP.DLL
C:\WINDOWS\system32\system\AVIFILE.DLL
C:\WINDOWS\system32\system\COMMDLG.DLL
C:\WINDOWS\system32\system\KEYBOARD.DRV
C:\WINDOWS\system32\system\LZEXPAND.DLL
C:\WINDOWS\system32\system\MCIAVI.DRV
C:\WINDOWS\system32\system\MCISEQ.DRV
C:\WINDOWS\system32\system\MCIWAVE.DRV
C:\WINDOWS\system32\system\MMSYSTEM.DLL
C:\WINDOWS\system32\system\MMTASK.TSK
C:\WINDOWS\system32\system\MOUSE.DRV
C:\WINDOWS\system32\system\MSVIDEO.DLL
C:\WINDOWS\system32\system\OLECLI.DLL
C:\WINDOWS\system32\system\OLESVR.DLL
C:\WINDOWS\system32\system\setup.inf
C:\WINDOWS\system32\system\SHELL.DLL
C:\WINDOWS\system32\system\SOUND.DRV
Code:
<pre>
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe ---> QooBox
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe ---> QooBox
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe ---> QooBox
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe ---> QooBox
C:\Program Files\HP\QuickPlay\QPService .exe ---> QooBox
C:\Program Files\HPQ\Default Settings\cpqset .exe ---> QooBox
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe ---> QooBox
C:\Program Files\HPQ\Quick Launch Buttons\EabServr .exe ---> QooBox
C:\Program Files\iTunes\iTunesHelper .exe ---> QooBox
C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe ---> QooBox
C:\Program Files\Kontiki\KHost .exe ---> QooBox
C:\Program Files\Logitech\Video\CameraAssistant .exe ---> QooBox
C:\Program Files\Logitech\Video\InstallHelper .exe ---> QooBox
C:\Program Files\MSN Messenger\MsnMsgr .Exe ---> QooBox
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher .exe ---> QooBox
C:\Program Files\WildTangent\Apps\CDA\GameDrvr .exe ---> QooBox
C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe ---> QooBox
</pre>
.
((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 )))))))))))))))))))))))))))))))
.
2008-01-23 19:23 . 2008-01-23 19:23 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-23 19:23 . 2008-01-23 19:23 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-22 22:04 . 2008-01-23 22:42 <DIR> d-------- C:\VundoFix Backups
2008-01-22 19:26 . 2008-01-22 19:26 <DIR> d-------- C:\Documents and Settings\Natasha\Application Data\Grisoft
2008-01-22 19:25 . 2008-01-22 19:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-22 19:25 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-21 13:30 . 2008-01-21 13:30 <DIR> d-------- C:\Program Files\CCleaner
2008-01-19 23:33 . 2008-01-19 23:33 <DIR> d-------- C:\Program Files\Avira
2008-01-19 23:33 . 2008-01-19 23:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-01-19 23:31 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-19 23:28 . 2008-01-19 23:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-19 23:14 . 2008-01-19 23:14 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-19 23:07 . 2008-01-19 23:31 <DIR> d-------- C:\Program Files\SpywareGuard
2008-01-19 21:07 . 2008-01-19 21:07 <DIR> d-------- C:\Documents and Settings\Natasha\DoctorWeb
2008-01-19 19:32 . 2008-01-19 19:32 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-19 19:32 . 2008-01-19 19:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-19 19:24 . 2008-01-22 20:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-19 12:31 . 2008-01-19 12:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-19 12:13 . 2008-01-19 20:53 12,288 --a------ C:\WINDOWS\system32\wupeng .exe
2008-01-19 11:29 . 2008-01-19 20:53 262,144 --a------ C:\WINDOWS\system32\ElkCtrl.exe
2008-01-19 10:49 . 2008-01-19 11:33 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 22:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-01-23 22:43 --------- d-----w C:\Program Files\QuickTime
2008-01-23 22:43 --------- d-----w C:\Program Files\MSN Messenger
2008-01-23 22:43 --------- d-----w C:\Program Files\Kontiki
2008-01-23 22:43 --------- d-----w C:\Program Files\iTunes
2008-01-21 13:01 --------- d-----w C:\Program Files\music_now
2008-01-19 21:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-19 21:14 --------- d-----w C:\Program Files\Windows Defender
2008-01-03 23:18 --------- d-----w C:\Program Files\BitZipper
2007-12-03 20:08 --------- d-----w C:\Documents and Settings\Natasha\Application Data\OLYMPUS
2007-12-03 19:50 --------- d-----w C:\Program Files\Graphic Converter 2003
2007-12-03 18:07 --------- d-----w C:\Program Files\Easy DVD CD Cover Maker
2006-09-14 16:33 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
2006-07-25 18:17 0 -c--a-w C:\Documents and Settings\Natasha\Application Data\wklnhst.dat
.
Code:
<pre>
----a-w 249,896 2008-01-22 21:21:10 C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt .exe
----a-w 52,848 2008-01-19 20:53:26 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
----a-w 68,856 2008-01-19 20:54:05 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w 1,460,560 2008-01-19 20:54:17 C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
----a-w 692,316 2008-01-19 20:53:34 C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
----a-w 102,492 2008-01-19 20:53:20 C:\Program Files\Synaptics\SynTP\SynTPLpr .exe
----a-w 1,231,872 2008-01-19 20:53:45 C:\Program Files\Windows Defender\MSASCui .exe
----a-w 679,936 2008-01-18 23:41:34 C:\WINDOWS\CREATOR\Remind_XP .exe
----a-w 1,187,840 2008-01-19 20:53:36 C:\WINDOWS\SMINST\RecGuard .exe
----a-w 12,288 2008-01-19 20:53:55 C:\WINDOWS\system32\wupeng .exe
</pre>
((((((((((((((((((((((((((((( snapshot@2008-01-22_21.29.55.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 08:00:00 69,584 ----a-w C:\WINDOWS\system\AVICAP.DLL
+ 2004-08-04 13:00:00 69,584 ----a-w C:\WINDOWS\system\avicap.dll
- 2004-08-04 08:00:00 109,456 ----a-w C:\WINDOWS\system\AVIFILE.DLL
+ 2004-08-04 13:00:00 109,456 ----a-w C:\WINDOWS\system\avifile.dll
- 2004-08-04 08:00:00 32,816 ----a-w C:\WINDOWS\system\COMMDLG.DLL
+ 2004-08-04 13:00:00 32,816 ----a-w C:\WINDOWS\system\commdlg.dll
- 2004-08-04 08:00:00 9,936 ----a-w C:\WINDOWS\system\LZEXPAND.DLL
+ 2004-08-04 13:00:00 9,936 ----a-w C:\WINDOWS\system\lzexpand.dll
- 2004-08-04 08:00:00 68,768 ----a-w C:\WINDOWS\system\MMSYSTEM.DLL
+ 2004-08-04 13:00:00 68,768 ----a-w C:\WINDOWS\system\mmsystem.dll
- 2004-08-04 08:00:00 126,912 ----a-w C:\WINDOWS\system\MSVIDEO.DLL
+ 2004-08-04 13:00:00 126,912 ----a-w C:\WINDOWS\system\msvideo.dll
- 2004-08-04 08:00:00 82,944 ----a-w C:\WINDOWS\system\OLECLI.DLL
+ 2004-08-04 13:00:00 82,944 ----a-w C:\WINDOWS\system\olecli.dll
- 2004-08-04 08:00:00 24,064 ----a-w C:\WINDOWS\system\OLESVR.DLL
+ 2004-08-04 13:00:00 24,064 ----a-w C:\WINDOWS\system\olesvr.dll
- 2004-08-04 08:00:00 5,120 ----a-w C:\WINDOWS\system\SHELL.DLL
+ 2004-08-04 13:00:00 5,120 ----a-w C:\WINDOWS\system\shell.dll
+ 2004-08-04 13:00:00 69,584 ----a-w C:\WINDOWS\system32\dllcache\avicap.dll
+ 2004-08-04 13:00:00 109,456 ----a-w C:\WINDOWS\system32\dllcache\avifile.dll
+ 2004-08-04 13:00:00 32,816 ----a-w C:\WINDOWS\system32\dllcache\commdlg.dll
+ 2004-08-04 13:00:00 9,936 ----a-w C:\WINDOWS\system32\dllcache\lzexpand.dll
+ 2004-08-04 13:00:00 68,768 ----a-w C:\WINDOWS\system32\dllcache\mmsystem.dll
+ 2004-08-04 13:00:00 126,912 ----a-w C:\WINDOWS\system32\dllcache\msvideo.dll
+ 2004-08-04 13:00:00 82,944 ----a-w C:\WINDOWS\system32\dllcache\olecli.dll
+ 2004-08-04 13:00:00 24,064 ----a-w C:\WINDOWS\system32\dllcache\olesvr.dll
+ 2004-08-04 13:00:00 5,120 ----a-w C:\WINDOWS\system32\dllcache\shell.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [ ]
C:\Documents and Settings\Natasha\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 03:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyaxus]
xxyaxus.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
C:\Program Files\Kontiki\KHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
C:\Program Files\HPQ\Default Settings\cpqset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
C:\Program Files\Kontiki\KHost .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
C:\Program Files\Logitech\Video\CameraAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
C:\Program Files\Logitech\Video\InstallHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lsass]
C:\WINDOWS\lsass .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 15:18]
R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 15:37]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 16:31:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-23 22:52:17 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-11 20:12:42 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Natasha.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-23 22:49:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-23 22:58:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-23 22:58:23
ComboFix2.txt 2008-01-22 21:31:45
ComboFix3.txt 2008-01-21 00:15:44