Thanks a lot.
Here are the requested logs:
resultant combofix:
ComboFix 08-12-09.03 - aco 2008-12-11 19:32:16.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.220 [GMT 2:00]
Running from: c:\documents and settings\aco\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\aco\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\afvgjskx.ini
c:\windows\system32\btarqitq.ini
c:\windows\system32\cfuglynx.ini
c:\windows\system32\cwkmnpdp.ini
c:\windows\system32\cxrxptlp.ini
c:\windows\system32\domjjmsj.ini
c:\windows\system32\dsmsykom.ini
c:\windows\system32\eimjhiln.ini
c:\windows\system32\ffvsjxsv.ini
c:\windows\system32\fpevohds.ini
c:\windows\system32\ghesvcas.ini
c:\windows\system32\grgybgos.ini
c:\windows\system32\hlhpwmqw.ini
c:\windows\system32\icovoalg.ini
c:\windows\system32\ictvuvls.ini
c:\windows\system32\iilbnpqs.ini
c:\windows\system32\kbjwqmph.ini
c:\windows\system32\ktryrpdg.ini
c:\windows\system32\lgtqoowj.ini
c:\windows\system32\mlmtfkyv.ini
c:\windows\system32\ocyikufb.ini
c:\windows\system32\onlqqctg.ini
c:\windows\system32\pjmwfllu.ini
c:\windows\system32\PWFiPqru.ini
c:\windows\system32\PWFiPqru.ini2
c:\windows\system32\qeiwxodd.ini
c:\windows\system32\rwcouuqu.ini
c:\windows\system32\thkbuner.ini
c:\windows\system32\thtpunrq.ini
c:\windows\system32\umoelrmg.ini
c:\windows\system32\urqPiFWP.dll
c:\windows\system32\vnwhceip.ini
c:\windows\system32\voicjuho.ini
c:\windows\system32\vykftmlm.dll
c:\windows\system32\wkvfgywv.ini
c:\windows\system32\wwyxpmoj.ini
c:\windows\system32\xbgqggmo.ini
c:\windows\system32\XGijknnn.ini
c:\windows\system32\xpvqeyho.ini
c:\windows\system32\xtvutmdd.ini
c:\windows\system32\ybamatnx.ini
c:\windows\system32\ydelhfoj.ini
.
((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
2008-12-01 21:59 . 2008-12-01 21:59 <DIR> d-------- C:\rsit
2008-12-01 21:59 . 2008-12-06 11:53 <DIR> d-------- c:\program files\trend micro
2008-11-25 07:55 . 2008-12-08 07:33 692,232 --a------ c:\windows\wininit.ini
2008-11-23 17:06 . 2008-11-23 18:34 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-23 17:06 . 2008-11-23 20:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 19:00 --------- d-----w c:\program files\Norton Security Scan
2008-11-24 20:07 --------- d-----w c:\program files\Windows Live
2008-11-23 14:48 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-23 06:40 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-23 06:29 --------- d-----w c:\documents and settings\aco\Application Data\Sony
2008-11-23 06:20 --------- d-----w c:\program files\Google
2008-10-16 12:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 12:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 12:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 12:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 12:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 12:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 12:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 12:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 12:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 12:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-21 15:00 74,752 ----a-w c:\windows\system32\nnnkjiGX.dll
2008-09-21 15:00 221,184 ----a-w c:\windows\system32\lbfqrxss.dll
2008-09-21 15:00 108,544 ----a-w c:\windows\system32\jkkJcBRk.dll
2008-09-21 14:59 97,792 ----a-w c:\windows\system32\akikdpqi.dll
2007-10-27 07:04 774,144 ----a-w c:\program files\RngInterstitial.dll
.
------- Sigcheck -------
2008-05-28 16:26 87552 918e116feae29a433201b7a5400829ba c:\windows\system32\ws2_32.dll
2004-08-04 14:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\dllcache\ws2_32.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-11_10.09.54.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-30 16:18:40 33,624 -c--a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 12:08:58 34,328 -c--a-w c:\windows\system32\dllcache\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2662D0D8-13A2-41BC-9586-0F88EB577774}]
2008-12-11 19:59 295424 --a------ c:\windows\system32\cbXRIBqR.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{748D6EA8-CD59-4682-91E7-AF92F4F2D40E}]
2008-08-01 08:17 32256 --a------ c:\windows\system32\vtUmNDtq.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-11-16 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-16 126976]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-09-07 213054]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-11-01 290816]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2004-11-12 790528]
"WatchDog"="c:\program files\InterVideo\DVD Check\DVDCheck.exe" [2004-10-26 184320]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"AGRSMMSG"="AGRSMMSG.exe" [2004-08-24 c:\windows\AGRSMMSG.exe]
"nMTaskBarService"="nMtsk.exe" [2005-05-06 c:\windows\nMtsk.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-10-26 569405]
DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2007-09-05 184320]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{748D6EA8-CD59-4682-91E7-AF92F4F2D40E}"= "c:\windows\system32\vtUmNDtq.dll" [2008-08-01 32256]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUmNDtq]
2008-08-01 08:17 32256 c:\windows\system32\vtUmNDtq.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 c:\windows\system32\cbXRIBqR
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:UDP"= 443:UDP:*

isabled

oVoo UDP port 443
"37674:TCP"= 37674:TCP

oVoo TCP port 37674
"37674:UDP"= 37674:UDP

oVoo UDP port 37674
"37675:UDP"= 37675:UDP

oVoo UDP port 37675
.
Contents of the 'Scheduled Tasks' folder
2008-12-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2008-12-06 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2007-04-19 21:42]
.
- - - - ORPHANS REMOVED - - - -
BHO-{E2BFE171-F495-40EB-AD5F-8BEB3743B4CB} - c:\windows\system32\urqPiFWP.dll
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-11 19:51:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????2?5?4?7??P???? ???B???????????????B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(972)
c:\windows\system32\vtUmNDtq.dll
c:\windows\system32\ACTIVEDS.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\HPQ\Shared\hpqwmi.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-12-11 20:05:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-11 18:05:10
ComboFix2.txt 2008-12-11 08:13:24
Pre-Run: 48,828,866,560 bytes free
Post-Run: 48,804,446,208 bytes free
191 --- E O F --- 2008-05-28 08:01:22
Malwarebytes' Anti-Malware 1.31
Database version: 1489
Windows 5.1.2600 Service Pack 2
12/11/2008 10:36:53 PM
mbam-log-2008-12-11 (22-36-53).txt
Scan type: Full Scan (C:\|)
Objects scanned: 73766
Time elapsed: 1 hour(s), 25 minute(s), 40 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 11
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 98
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\cbXRIBqR.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\iimurpsx.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\vtUmNDtq.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2662d0d8-13a2-41bc-9586-0f88eb577774} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{2662d0d8-13a2-41bc-9586-0f88eb577774} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{748d6ea8-cd59-4682-91e7-af92f4f2d40e} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtumndtq (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{748d6ea8-cd59-4682-91e7-af92f4f2d40e} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2662d0d8-13a2-41bc-9586-0f88eb577774} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{748d6ea8-cd59-4682-91e7-af92f4f2d40e} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{748d6ea8-cd59-4682-91e7-af92f4f2d40e} (Trojan.Vundo) -> Delete on reboot.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\cbxribqr -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\cbxribqr -> Delete on reboot.
Folders Infected:
C:\WINDOWS\system32\netrax18 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\modtrux18 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kBin02 (Trojan.Agent) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\cbXRIBqR.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\RqBIRXbc.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\RqBIRXbc.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vtUmNDtq.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\iimurpsx.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\xsprumii.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\b152.exe.vir (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\bpxgbucx.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\cfhhloqd.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\hrasfyrd.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ixsblocc.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\pbvhlkec.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\pdpnmkwc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\pjsqdtuf.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qhvpfpxt.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qtiqratb.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dedyisev.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dlxfjfgy.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dmyvnnil.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\gxiqvpxk.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\havxyjmq.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ldwyuiue.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ovtdubdf.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\shqgxcur.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\sjikejdr.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\sqpnblii.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tsmrhodx.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tterftuq.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ugoqibwx.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\vykftmlm.dll.vir (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ycqlvvrv.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP188\A0050546.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP188\A0050547.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP188\A0050566.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP188\A0050620.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP188\A0050632.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP188\A0050621.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP189\A0050662.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP189\A0050663.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP189\A0050687.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052724.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052725.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052726.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052727.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052728.exe (Trojan.BHO) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052729.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052730.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052731.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP191\A0052735.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP200\A0059224.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP214\A0059438.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP214\A0059439.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP214\A0059440.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP214\A0059441.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP219\A0059479.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP219\A0059480.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059609.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059627.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059602.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059604.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059605.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059606.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059607.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059608.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059610.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059612.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059613.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059615.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059618.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059619.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059620.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059621.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059623.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059624.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059626.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059628.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059629.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059630.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059631.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP220\A0059632.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{20803278-6F83-4BA6-B058-CA59B00AF8C6}\RP223\A0059771.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXPhgFW.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcCUlIx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcDWPFU.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccbbXoL.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnkJcaX.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rqRIaYrr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vtUNdAsq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGayApQ.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGxYPJC.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljJYQHxV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nnnmlMfc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkkIBRIX.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\akikdpqi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wvUkhggf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wvUkLBqO.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayxUlkH.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
HIJACKTHIS LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:12:52 PM, on 12/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\hkcmd.exe
c:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\nMtsk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.b92.net/indexs.phtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [nMTaskBarService] nMtsk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LifeCam] "c:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
--
End of file - 5673 bytes