I need some help. Firstly i'm running Windows XP Home SP3. The other day i started with some virus. It came up in Trend micro as Cryp_Morphine. I was able to get rid of that all i'm prety sure. However at the same time i was having an issue with my Windows Auto Update was turned off and it will not let me start it. So after some research i came across the same issue with Windows update from other users and it was suggested to try combo fix. I ran this program last night and after it was complete i re-booted then i was able to get windows update to work again so i ran one more trend micro scan and a mention of a Vundo virus came up. It was quarentined and then i deleted it. well all was good and then today i woke up and checked my comp and the Windows update is disabled again and having the same issue. so i'm under the impression that the virus is still around. Please let me know if i should post the combofix log.
ComboFix 08-09-16.05 - Miko 2008-09-19 8:06:05.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.629 [GMT -4:00]
Running from: C:\Documents and Settings\Miko\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\vFMnmUvw.ini
C:\WINDOWS\system32\vFMnmUvw.ini2
.
((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.
2008-09-19 00:46 . 2008-09-19 00:46 5,769 --a------ C:\WINDOWS\system32\tkxkxmgw.dll
2008-09-19 00:46 . 2008-09-19 00:46 5,747 --a------ C:\WINDOWS\system32\euojlqtv.exe
2008-09-19 00:44 . 2008-09-19 00:44 5,769 --a------ C:\WINDOWS\system32\tjdrywbf.dll
2008-09-19 00:44 . 2008-09-19 00:44 5,767 --a------ C:\WINDOWS\system32\mnhahcxa.dll
2008-09-19 00:30 . 2008-09-19 00:31 16,384 --a------ C:\WINDOWS\DCEBoot.exe
2008-09-18 23:54 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-09-18 21:27 . 2008-09-18 21:32 <DIR> d-------- C:\Program Files\Microsoft Diagnostics and Recovery Toolset
2008-09-18 03:26 . 2008-09-18 03:26 5,509 --a------ C:\WINDOWS\system32\xauyxlrl.dll
2008-09-18 03:23 . 2008-09-18 03:23 5,767 --a------ C:\WINDOWS\system32\ctkiejyv.dll
2008-09-18 03:20 . 2008-09-18 03:20 5,509 --a------ C:\WINDOWS\system32\eeetotxq.dll
2008-09-18 03:17 . 2008-09-18 03:17 5,509 --a------ C:\WINDOWS\system32\afnuytpg.dll
2008-09-18 03:14 . 2008-09-18 03:14 5,769 --a------ C:\WINDOWS\system32\nmavatfn.dll
2008-09-18 03:11 . 2008-09-18 03:11 5,509 --a------ C:\WINDOWS\system32\vyfwfjyn.dll
2008-09-18 03:08 . 2008-09-18 03:08 5,769 --a------ C:\WINDOWS\system32\veygpyan.dll
2008-09-17 21:26 . 2007-12-19 01:59 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-09-17 21:26 . 2008-09-17 21:26 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-17 21:15 . 2008-09-17 21:15 5,769 --a------ C:\WINDOWS\system32\ugrqnnye.dll
2008-09-17 21:01 . 2008-09-17 21:01 252,928 --a------ C:\WINDOWS\system32\wvUmnMFv.dll
2008-09-14 13:07 . 2008-09-14 13:08 <DIR> d-------- C:\Program Files\iTunes
2008-09-14 13:07 . 2008-09-14 13:07 <DIR> d-------- C:\Program Files\iPod
2008-09-14 13:07 . 2008-09-14 13:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-14 13:02 . 2008-09-14 13:03 <DIR> d-------- C:\Program Files\QuickTime
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-09-19 00:59 --------- d-----w C:\Program Files\PeerGuardian2
2008-09-18 03:07 --------- d-----w C:\Documents and Settings\Miko\Application Data\Azureus
2008-09-14 17:02 --------- d-----w C:\Program Files\Common Files\Apple
2008-09-10 07:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-23 18:06 --------- d-----w C:\Program Files\Apple Software Update
2008-08-23 17:50 --------- d-----w C:\Program Files\Safari
2008-08-05 21:48 77,824 ----a-w C:\WINDOWS\system32\kdfapi.dll
2008-08-05 21:48 722,472 ----a-w C:\WINDOWS\system32\kdfmgr.exe
2008-08-05 21:48 192,512 ----a-w C:\WINDOWS\system32\kdfvmgr.exe
2008-08-05 21:44 53,248 ----a-w C:\WINDOWS\system32\Kdfhok.dll
2008-07-20 18:52 --------- d-----w C:\Program Files\Java
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-09 00:28 81,920 ----a-w C:\Documents and Settings\Miko\Application Data\ezpinst.exe
2008-06-09 00:28 47,360 ----a-w C:\Documents and Settings\Miko\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@2008-09-18_23.27.34.99 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-14 00:12:10 430,592 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
+ 2008-07-19 02:09:44 563,912 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2008-04-14 00:12:41 111,104 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2008-07-19 02:10:42 53,448 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2008-04-14 00:12:11 1,135,616 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2008-07-19 02:09:42 1,811,656 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2008-04-14 00:12:11 112,640 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2008-07-19 02:09:46 325,832 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
- 2008-04-14 00:12:11 32,256 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2008-07-19 02:10:20 36,552 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
- 2008-04-14 00:12:11 120,320 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-07-30 23:19:46 203,096 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2008-07-19 02:09:44 563,912 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\Ser viceStartup\wuapi.dll\7.2.6001.784\wuapi.dll
+ 2007-07-30 23:18:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\Ser viceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2007-07-30 23:19:12 43,352 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\Ser viceStartup\wups2.dll\7.0.6000.381\wups2.dll
- 2008-04-14 00:12:11 120,320 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 23:19:46 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB73E5B7-205B-47F7-B655-0313A4D53CB1}]
2008-09-17 21:01 252928 --a------ C:\WINDOWS\system32\wvUmnMFv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2007-11-15 18:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= ma_cmidn.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Miko^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Miko\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-09-03 20:12 111936 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2005-05-19 09:47 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3200]
--a------ 2002-06-30 23:05 74752 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC 2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 07:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 14:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 2005-06-10 05:21 217088 C:\Program Files\Microsoft IntelliPoint\point32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-09-10 17:40 289576 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
--a------ 2004-12-22 09:21 823296 C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
--a------ 2008-02-16 05:01 492808 C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
--a------ 2005-09-18 18:40 1421824 C:\Program Files\PeerGuardian2\pg2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\type32]
--a------ 2005-06-10 05:24 196608 C:\Program Files\Microsoft IntelliType Pro\type32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
--a------ 2008-07-29 15:52 1398024 C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationA gent]
--a------ 2008-04-13 20:12 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP
xpsp2res.dll,-22009
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sy s [2007-08-03 46112]
R3 BCM42XX;Broadcom iLine10(tm) Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [2001-08-17 54271]
S2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [ ]
S2 spydetector;spydetector;C:\Program Files\Spyware Process Detector\spydetector.sys [ ]
S3 MA_CMIDI;%EVOL_USB.SvcDesc%;C:\WINDOWS\system32\dr ivers\ma_cmidi.sys [2005-06-14 21888]
S3 mirrorv3;mirrorv3;C:\WINDOWS\system32\DRIVERS\rmin iv3.sys [2006-11-01 3328]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1C354B1A-389C-1A9F-E28F-6D3674FBCB19}]
C:\DOCUME~1\Miko\LOCALS~1\Temp\Temporary Directory 2 for 000 PowerISO v3.7 With Keygen.zip\PowerISO v3.7 With Keygen\my_profile.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{9a1f5ed8-5fd6-415b-abd2-3d4994f1fab4} - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/keyword/%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 08:15:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\searchindexer.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\WINDOWS\system32\imapi.exe
.
************************************************** ************************
.
Completion time: 2008-09-19 8:20:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 12:19:53
ComboFix2.txt 2008-09-19 03:29:18
Pre-Run: 33,464,020,992 bytes free
Post-Run: 33,452,814,336 bytes free
222
ComboFix 08-09-16.05 - Miko 2008-09-19 8:06:05.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.629 [GMT -4:00]
Running from: C:\Documents and Settings\Miko\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\vFMnmUvw.ini
C:\WINDOWS\system32\vFMnmUvw.ini2
.
((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.
2008-09-19 00:46 . 2008-09-19 00:46 5,769 --a------ C:\WINDOWS\system32\tkxkxmgw.dll
2008-09-19 00:46 . 2008-09-19 00:46 5,747 --a------ C:\WINDOWS\system32\euojlqtv.exe
2008-09-19 00:44 . 2008-09-19 00:44 5,769 --a------ C:\WINDOWS\system32\tjdrywbf.dll
2008-09-19 00:44 . 2008-09-19 00:44 5,767 --a------ C:\WINDOWS\system32\mnhahcxa.dll
2008-09-19 00:30 . 2008-09-19 00:31 16,384 --a------ C:\WINDOWS\DCEBoot.exe
2008-09-18 23:54 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-09-18 21:27 . 2008-09-18 21:32 <DIR> d-------- C:\Program Files\Microsoft Diagnostics and Recovery Toolset
2008-09-18 03:26 . 2008-09-18 03:26 5,509 --a------ C:\WINDOWS\system32\xauyxlrl.dll
2008-09-18 03:23 . 2008-09-18 03:23 5,767 --a------ C:\WINDOWS\system32\ctkiejyv.dll
2008-09-18 03:20 . 2008-09-18 03:20 5,509 --a------ C:\WINDOWS\system32\eeetotxq.dll
2008-09-18 03:17 . 2008-09-18 03:17 5,509 --a------ C:\WINDOWS\system32\afnuytpg.dll
2008-09-18 03:14 . 2008-09-18 03:14 5,769 --a------ C:\WINDOWS\system32\nmavatfn.dll
2008-09-18 03:11 . 2008-09-18 03:11 5,509 --a------ C:\WINDOWS\system32\vyfwfjyn.dll
2008-09-18 03:08 . 2008-09-18 03:08 5,769 --a------ C:\WINDOWS\system32\veygpyan.dll
2008-09-17 21:26 . 2007-12-19 01:59 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-09-17 21:26 . 2008-09-17 21:26 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-17 21:15 . 2008-09-17 21:15 5,769 --a------ C:\WINDOWS\system32\ugrqnnye.dll
2008-09-17 21:01 . 2008-09-17 21:01 252,928 --a------ C:\WINDOWS\system32\wvUmnMFv.dll
2008-09-14 13:07 . 2008-09-14 13:08 <DIR> d-------- C:\Program Files\iTunes
2008-09-14 13:07 . 2008-09-14 13:07 <DIR> d-------- C:\Program Files\iPod
2008-09-14 13:07 . 2008-09-14 13:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-14 13:02 . 2008-09-14 13:03 <DIR> d-------- C:\Program Files\QuickTime
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-09-19 00:59 --------- d-----w C:\Program Files\PeerGuardian2
2008-09-18 03:07 --------- d-----w C:\Documents and Settings\Miko\Application Data\Azureus
2008-09-14 17:02 --------- d-----w C:\Program Files\Common Files\Apple
2008-09-10 07:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-23 18:06 --------- d-----w C:\Program Files\Apple Software Update
2008-08-23 17:50 --------- d-----w C:\Program Files\Safari
2008-08-05 21:48 77,824 ----a-w C:\WINDOWS\system32\kdfapi.dll
2008-08-05 21:48 722,472 ----a-w C:\WINDOWS\system32\kdfmgr.exe
2008-08-05 21:48 192,512 ----a-w C:\WINDOWS\system32\kdfvmgr.exe
2008-08-05 21:44 53,248 ----a-w C:\WINDOWS\system32\Kdfhok.dll
2008-07-20 18:52 --------- d-----w C:\Program Files\Java
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-09 00:28 81,920 ----a-w C:\Documents and Settings\Miko\Application Data\ezpinst.exe
2008-06-09 00:28 47,360 ----a-w C:\Documents and Settings\Miko\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@2008-09-18_23.27.34.99 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-14 00:12:10 430,592 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
+ 2008-07-19 02:09:44 563,912 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2008-04-14 00:12:41 111,104 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2008-07-19 02:10:42 53,448 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2008-04-14 00:12:11 1,135,616 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2008-07-19 02:09:42 1,811,656 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2008-04-14 00:12:11 112,640 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2008-07-19 02:09:46 325,832 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
- 2008-04-14 00:12:11 32,256 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2008-07-19 02:10:20 36,552 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
- 2008-04-14 00:12:11 120,320 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-07-30 23:19:46 203,096 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2008-07-19 02:09:44 563,912 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\Ser viceStartup\wuapi.dll\7.2.6001.784\wuapi.dll
+ 2007-07-30 23:18:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\Ser viceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2007-07-30 23:19:12 43,352 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\Ser viceStartup\wups2.dll\7.0.6000.381\wups2.dll
- 2008-04-14 00:12:11 120,320 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 23:19:46 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB73E5B7-205B-47F7-B655-0313A4D53CB1}]
2008-09-17 21:01 252928 --a------ C:\WINDOWS\system32\wvUmnMFv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2007-11-15 18:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= ma_cmidn.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Miko^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Miko\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-09-03 20:12 111936 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2005-05-19 09:47 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3200]
--a------ 2002-06-30 23:05 74752 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S10IC 2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 07:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 14:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 2005-06-10 05:21 217088 C:\Program Files\Microsoft IntelliPoint\point32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-09-10 17:40 289576 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
--a------ 2004-12-22 09:21 823296 C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
--a------ 2008-02-16 05:01 492808 C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
--a------ 2005-09-18 18:40 1421824 C:\Program Files\PeerGuardian2\pg2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\type32]
--a------ 2005-06-10 05:24 196608 C:\Program Files\Microsoft IntelliType Pro\type32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
--a------ 2008-07-29 15:52 1398024 C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationA gent]
--a------ 2008-04-13 20:12 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP

R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sy s [2007-08-03 46112]
R3 BCM42XX;Broadcom iLine10(tm) Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [2001-08-17 54271]
S2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [ ]
S2 spydetector;spydetector;C:\Program Files\Spyware Process Detector\spydetector.sys [ ]
S3 MA_CMIDI;%EVOL_USB.SvcDesc%;C:\WINDOWS\system32\dr ivers\ma_cmidi.sys [2005-06-14 21888]
S3 mirrorv3;mirrorv3;C:\WINDOWS\system32\DRIVERS\rmin iv3.sys [2006-11-01 3328]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1C354B1A-389C-1A9F-E28F-6D3674FBCB19}]
C:\DOCUME~1\Miko\LOCALS~1\Temp\Temporary Directory 2 for 000 PowerISO v3.7 With Keygen.zip\PowerISO v3.7 With Keygen\my_profile.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{9a1f5ed8-5fd6-415b-abd2-3d4994f1fab4} - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/keyword/%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 08:15:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\M-Audio MA_CMIDI\MA_CMIDI_Inst.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\searchindexer.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\WINDOWS\system32\imapi.exe
.
************************************************** ************************
.
Completion time: 2008-09-19 8:20:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 12:19:53
ComboFix2.txt 2008-09-19 03:29:18
Pre-Run: 33,464,020,992 bytes free
Post-Run: 33,452,814,336 bytes free
222