i think i was infected with virtumonde. i read through one of the previous users who was too and followed the directions you gave him. i have my combofix log. so far it combofixhas remedied the problem, but i read on combofix's site that there can still be traces left. i was hoping i could get someone to look over the log. also, let me know if i should post my hjt log. thanks!
ComboFix 08-10-12.01 - Owner 2008-10-13 15:28:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2082 [GMT -6:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\hoawaafv.ini
C:\WINDOWS\system32\iifdawVN.dll
C:\WINDOWS\system32\lryhep.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\namptalo.dll
C:\WINDOWS\system32\NVwadfii.ini
C:\WINDOWS\system32\NVwadfii.ini2
C:\WINDOWS\system32\nxtchyyj.ini
C:\WINDOWS\system32\orfihhao.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\skcfra.dll
C:\WINDOWS\system32\vtUkhiGx.dll
C:\WINDOWS\Tasks\anjvpncn.job
C:\WINDOWS\Tasks\bgqreohb.job
C:\WINDOWS\Tasks\mpfmjuxr.job
C:\WINDOWS\Tasks\reeslxsl.job
C:\WINDOWS\Tasks\wfrxduxp.job
----- BITS: Possible infected sites -----
hxxp://77.74.48.101
.
((((((((((((((((((((((((( Files Created from 2008-09-13 to 2008-10-13 )))))))))))))))))))))))))))))))
.
2008-10-13 13:30 . 2008-10-13 13:30 60,928 --ahs---- C:\WINDOWS\system32\ddcArQig.dll
2008-10-13 13:25 . 2007-08-14 10:12 5,760 --a------ C:\WINDOWS\system32\107F.tmp
2008-10-13 00:48 . 2008-10-13 00:48 <DIR> d-------- C:\Documents and Settings\Owner\.housecall6.6
2008-10-13 00:21 . 2008-10-13 00:21 60,928 --ahs---- C:\WINDOWS\system32\pmnkLFYp.dll
2008-10-12 21:29 . 2008-10-12 21:29 60,928 --ahs---- C:\WINDOWS\system32\cbXNGyaw.dll
2008-10-12 15:53 . 2008-10-12 15:53 60,928 --ahs---- C:\WINDOWS\system32\wvUmmNFw.dll
2008-10-11 15:46 . 2008-10-11 15:46 <DIR> d-------- C:\WINDOWS\system32\EV19
2008-10-11 15:46 . 2008-10-11 15:46 <DIR> d-------- C:\Temp\xp34
2008-10-11 15:46 . 2008-10-11 15:46 <DIR> d-------- C:\Temp
2008-10-11 15:46 . 2008-10-11 15:46 60,928 --ahs---- C:\WINDOWS\system32\jkkHBTnl.dll
2008-10-04 22:40 . 2008-10-04 22:40 <DIR> d-------- C:\Program Files\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-12 05:06 --------- d-----w C:\Program Files\a-squared Free
2008-10-11 21:48 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-06 14:05 --------- d-----w C:\Program Files\PERRLA
2008-09-04 01:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-30 04:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-30 04:34 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-25 05:44 --------- d-----w C:\Program Files\Finale NotePad 2008
2008-08-24 04:47 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-08-22 21:57 --------- d-----w C:\Program Files\Full Tilt Poker
2008-07-31 20:17 22,328 -c--a-w C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys
2008-06-28 17:32 894 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2008-04-08 19:57 336 -c--a-w C:\Program Files\temp995.bat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-03-11 81920]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-19 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-06-06 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-06-06 118784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-07-26 13570048]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-07-26 86016]
"nwiz"="nwiz.exe" [2008-07-26 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HPAiODevice(hp officejet g series) - 1.lnk - C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe [2002-11-20 151552]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-04 15:18 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
--a--c--- 2002-02-04 23:32 53248 C:\Program Files\REGSHAVE\REGSHAVE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a--c--- 2003-10-31 20:42 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
--a------ 2005-03-11 08:08 81920 C:\PROGRA~1\Sony\SONICS~1\SSAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-01-19 11:04 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"UFC Media Manager Tray"="C:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" /CustomId:UFC
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Call of Duty Game of the Year Edition\\CoDMP.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 NVR0FLASHDev;NVR0FLASHDev;C:\WINDOWS\nvflash.sys [2008-05-23 36640]
R2 UpdateCenterService;Update Center Service;C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe [2008-05-23 114688]
S3 CachemanXPService;CachemanXP;C:\PROGRA~1\CACHEM~1\CachemanXP.exe [2007-04-25 244224]
S3 ICDUSB2;Sony IC Recorder (P);C:\WINDOWS\system32\Drivers\ICDUSB2.sys [2002-11-28 39048]
S3 IHLCZD;IHLCZD;C:\DOCUME~1\Owner\LOCALS~1\Temp\IHLCZD.exe [ ]
S3 ILQ;ILQ;C:\DOCUME~1\Owner\LOCALS~1\Temp\ILQ.exe [ ]
S3 MEMSWEEP2;MEMSWEEP2;C:\WINDOWS\system32\4.tmp [ ]
S3 usb2vcom;DKU-5 Connectivity Adapter Cable;C:\WINDOWS\system32\DRIVERS\usb2vcom.sys [2005-08-05 28704]
S4 RLQIPNK;RLQIPNK;C:\DOCUME~1\Owner\LOCALS~1\Temp\RLQIPNK.exe [ ]
S4 TPKNK;TPKNK;C:\DOCUME~1\Owner\LOCALS~1\Temp\TPKNK.exe [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bff3008a-f38c-11db-96a8-0011115e689e}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-10-13 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -
BHO-{662E0FD1-3D32-491E-98F7-B2C8FD84B823} - (no file)
BHO-{738332C2-FF7C-409A-913A-2E9452DAB796} - (no file)
BHO-{956CF4B4-2B51-4CDB-A2A1-B83747CD3113} - C:\WINDOWS\system32\iifdawVN.dll
BHO-{9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\system32\vtUkhiGx.dll
BHO-{d921d81e-a341-4461-8d96-f284734b987b} - C:\WINDOWS\system32\skcfra.dll
HKCU-Run-DriverUpdaterPro - C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
ShellExecuteHooks-{9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\system32\vtUkhiGx.dll
Notify-AtiExtEvent - (no file)
Notify-vtUkhiGx - (no file)
MSConfigStartUp-StartCCC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSConfigStartUp-updateMgr - C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O16 -: {5A9D4578-6649-4692-921B-ACA9ADAB007C}
O16 -: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43}
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-13 15:35:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\C:\WINDOWS\system32\4.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
.
**************************************************************************
.
Completion time: 2008-10-13 15:43:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-13 21:43:48
Pre-Run: 2,348,998,656 bytes free
Post-Run: 2,249,175,040 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
207 --- E O F --- 2008-10-09 16:34:27
ComboFix 08-10-12.01 - Owner 2008-10-13 15:28:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2082 [GMT -6:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\hoawaafv.ini
C:\WINDOWS\system32\iifdawVN.dll
C:\WINDOWS\system32\lryhep.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\namptalo.dll
C:\WINDOWS\system32\NVwadfii.ini
C:\WINDOWS\system32\NVwadfii.ini2
C:\WINDOWS\system32\nxtchyyj.ini
C:\WINDOWS\system32\orfihhao.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\skcfra.dll
C:\WINDOWS\system32\vtUkhiGx.dll
C:\WINDOWS\Tasks\anjvpncn.job
C:\WINDOWS\Tasks\bgqreohb.job
C:\WINDOWS\Tasks\mpfmjuxr.job
C:\WINDOWS\Tasks\reeslxsl.job
C:\WINDOWS\Tasks\wfrxduxp.job
----- BITS: Possible infected sites -----
hxxp://77.74.48.101
.
((((((((((((((((((((((((( Files Created from 2008-09-13 to 2008-10-13 )))))))))))))))))))))))))))))))
.
2008-10-13 13:30 . 2008-10-13 13:30 60,928 --ahs---- C:\WINDOWS\system32\ddcArQig.dll
2008-10-13 13:25 . 2007-08-14 10:12 5,760 --a------ C:\WINDOWS\system32\107F.tmp
2008-10-13 00:48 . 2008-10-13 00:48 <DIR> d-------- C:\Documents and Settings\Owner\.housecall6.6
2008-10-13 00:21 . 2008-10-13 00:21 60,928 --ahs---- C:\WINDOWS\system32\pmnkLFYp.dll
2008-10-12 21:29 . 2008-10-12 21:29 60,928 --ahs---- C:\WINDOWS\system32\cbXNGyaw.dll
2008-10-12 15:53 . 2008-10-12 15:53 60,928 --ahs---- C:\WINDOWS\system32\wvUmmNFw.dll
2008-10-11 15:46 . 2008-10-11 15:46 <DIR> d-------- C:\WINDOWS\system32\EV19
2008-10-11 15:46 . 2008-10-11 15:46 <DIR> d-------- C:\Temp\xp34
2008-10-11 15:46 . 2008-10-11 15:46 <DIR> d-------- C:\Temp
2008-10-11 15:46 . 2008-10-11 15:46 60,928 --ahs---- C:\WINDOWS\system32\jkkHBTnl.dll
2008-10-04 22:40 . 2008-10-04 22:40 <DIR> d-------- C:\Program Files\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-12 05:06 --------- d-----w C:\Program Files\a-squared Free
2008-10-11 21:48 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-06 14:05 --------- d-----w C:\Program Files\PERRLA
2008-09-04 01:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-30 04:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-30 04:34 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-25 05:44 --------- d-----w C:\Program Files\Finale NotePad 2008
2008-08-24 04:47 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-08-22 21:57 --------- d-----w C:\Program Files\Full Tilt Poker
2008-07-31 20:17 22,328 -c--a-w C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys
2008-06-28 17:32 894 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2008-04-08 19:57 336 -c--a-w C:\Program Files\temp995.bat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-03-11 81920]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-19 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-06-06 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-06-06 118784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-07-26 13570048]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-07-26 86016]
"nwiz"="nwiz.exe" [2008-07-26 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HPAiODevice(hp officejet g series) - 1.lnk - C:\Program Files\Hewlett-Packard\AiO\hp officejet g series\Bin\hpoavn07.exe [2002-11-20 151552]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-04 15:18 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
--a--c--- 2002-02-04 23:32 53248 C:\Program Files\REGSHAVE\REGSHAVE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a--c--- 2003-10-31 20:42 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
--a------ 2005-03-11 08:08 81920 C:\PROGRA~1\Sony\SONICS~1\SSAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-01-19 11:04 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"UFC Media Manager Tray"="C:\Program Files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" /CustomId:UFC
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Call of Duty Game of the Year Edition\\CoDMP.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 NVR0FLASHDev;NVR0FLASHDev;C:\WINDOWS\nvflash.sys [2008-05-23 36640]
R2 UpdateCenterService;Update Center Service;C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe [2008-05-23 114688]
S3 CachemanXPService;CachemanXP;C:\PROGRA~1\CACHEM~1\CachemanXP.exe [2007-04-25 244224]
S3 ICDUSB2;Sony IC Recorder (P);C:\WINDOWS\system32\Drivers\ICDUSB2.sys [2002-11-28 39048]
S3 IHLCZD;IHLCZD;C:\DOCUME~1\Owner\LOCALS~1\Temp\IHLCZD.exe [ ]
S3 ILQ;ILQ;C:\DOCUME~1\Owner\LOCALS~1\Temp\ILQ.exe [ ]
S3 MEMSWEEP2;MEMSWEEP2;C:\WINDOWS\system32\4.tmp [ ]
S3 usb2vcom;DKU-5 Connectivity Adapter Cable;C:\WINDOWS\system32\DRIVERS\usb2vcom.sys [2005-08-05 28704]
S4 RLQIPNK;RLQIPNK;C:\DOCUME~1\Owner\LOCALS~1\Temp\RLQIPNK.exe [ ]
S4 TPKNK;TPKNK;C:\DOCUME~1\Owner\LOCALS~1\Temp\TPKNK.exe [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bff3008a-f38c-11db-96a8-0011115e689e}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-10-13 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -
BHO-{662E0FD1-3D32-491E-98F7-B2C8FD84B823} - (no file)
BHO-{738332C2-FF7C-409A-913A-2E9452DAB796} - (no file)
BHO-{956CF4B4-2B51-4CDB-A2A1-B83747CD3113} - C:\WINDOWS\system32\iifdawVN.dll
BHO-{9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\system32\vtUkhiGx.dll
BHO-{d921d81e-a341-4461-8d96-f284734b987b} - C:\WINDOWS\system32\skcfra.dll
HKCU-Run-DriverUpdaterPro - C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
ShellExecuteHooks-{9E91EF7B-6846-45C3-A8AB-67CF7C900783} - C:\WINDOWS\system32\vtUkhiGx.dll
Notify-AtiExtEvent - (no file)
Notify-vtUkhiGx - (no file)
MSConfigStartUp-StartCCC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSConfigStartUp-updateMgr - C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O16 -: {5A9D4578-6649-4692-921B-ACA9ADAB007C}
O16 -: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43}
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-13 15:35:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\C:\WINDOWS\system32\4.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
.
**************************************************************************
.
Completion time: 2008-10-13 15:43:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-13 21:43:48
Pre-Run: 2,348,998,656 bytes free
Post-Run: 2,249,175,040 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
207 --- E O F --- 2008-10-09 16:34:27