Okay, sorry for the delay here are the logs
ComboFix Log:
ComboFix 08-11-02.02 - Durgut 2008-11-02 15:42:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1534 [GMT -5:00]
Running from: C:\Documents and Settings\Durgut\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Durgut\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\7104189AC5924A56AC9E7C0CA135DA3C.TMP
C:\WINDOWS\system32\byXOhiIA.dll
C:\WINDOWS\system32\cbXNFywx.dll
C:\WINDOWS\system32\efcdCsQJ.dll
C:\WINDOWS\system32\hgGabyaa.dll
C:\WINDOWS\system32\prun.exe
C:\WINDOWS\system32\rqRIxxyA.dll
C:\WINDOWS\system32\ssqNHbYP.dll
C:\WINDOWS\system32\xxyvUmnl.dll
C:\WINDOWS\system32\yaywtQKE.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\byXOhiIA.dll
C:\WINDOWS\system32\cbXNFywx.dll
C:\WINDOWS\system32\efcdCsQJ.dll
C:\WINDOWS\system32\hgGabyaa.dll
C:\WINDOWS\system32\mdhash.dll' C:\WINDOWS\system32\mdhsh.sys
C:\WINDOWS\system32\prun.exe
C:\WINDOWS\system32\rqRIxxyA.dll
C:\WINDOWS\system32\ssqNHbYP.dll
C:\WINDOWS\system32\xxyvUmnl.dll
C:\WINDOWS\system32\yaywtQKE.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-02 to 2008-11-02 )))))))))))))))))))))))))))))))
.
2008-10-30 17:18 . 2008-10-30 17:43 3,124 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-30 17:06 . 2008-10-30 17:06 <DIR> d-------- C:\Documents and Settings\Durgut\Application Data\Malwarebytes
2008-10-30 17:06 . 2008-10-22 15:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-30 17:06 . 2008-10-22 15:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-30 17:05 . 2008-10-30 17:06 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-30 17:05 . 2008-10-30 17:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-30 16:36 . 2008-10-30 16:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-30 11:56 . 2008-10-30 12:05 203 --a------ C:\WINDOWS\wininit.ini
2008-10-30 11:38 . 2008-10-30 11:47 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-30 11:38 . 2008-10-30 12:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-30 11:35 . 2008-10-30 11:37 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-30 11:12 . 2008-10-30 11:24 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-10-30 11:01 . 2008-10-30 11:01 0 --a------ C:\WINDOWS\nsreg.dat
2008-10-28 20:16 . 2008-10-28 20:16 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-10-28 20:14 . 2008-10-29 05:42 <DIR> d-------- C:\Program Files\Google
2008-10-28 19:47 . 2008-10-28 20:02 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-10-28 18:39 . 2008-10-28 18:39 <DIR> d-------- C:\WINDOWS\Sun
2008-10-28 18:35 . 2008-10-28 18:35 <DIR> d-------- C:\Program Files\Java
2008-10-28 18:35 . 2008-10-28 18:35 <DIR> d-------- C:\Program Files\Common Files\Java
2008-10-28 18:35 . 2007-05-22 16:39 61,555 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2008-10-28 15:36 . 2008-10-28 15:36 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-10-28 15:34 . 2008-10-28 15:34 <DIR> d-------- C:\Program Files\NOS
2008-10-28 15:34 . 2008-10-28 15:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NOS
2008-10-28 14:55 . 2008-10-28 14:55 <DIR> d-------- C:\WINDOWS\7104189AC5924A56AC9E7C0CA135DA3C.TMP
2008-10-28 14:46 . 2008-10-28 18:33 <DIR> d-------- C:\Program Files\Rail Simulator
2008-10-28 14:16 . 2008-10-28 14:16 <DIR> d-------- C:\Program Files\Ubisoft
2008-10-27 18:06 . 2008-10-27 18:06 <DIR> d-------- C:\Program Files\Watchtower
2008-10-26 21:10 . 2008-10-26 21:10 <DIR> d-------- C:\spoolerlogs
2008-10-26 20:43 . 2008-10-26 20:53 <DIR> d-------- C:\Documents and Settings\Durgut\Application Data\vlc
2008-10-26 20:42 . 2008-10-26 20:42 <DIR> d-------- C:\Program Files\VideoLAN
2008-10-26 20:37 . 2008-10-31 13:37 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-10-26 20:30 . 2008-10-26 20:30 <DIR> d-------- C:\Documents and Settings\Durgut\Application Data\Windows Search
2008-10-26 17:12 . 2008-10-26 17:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-10-26 17:11 . 2008-10-26 17:11 <DIR> d-------- C:\Program Files\LG Soft India
2008-10-26 17:11 . 2004-04-16 10:24 61,440 --a------ C:\WINDOWS\system32\ISUSPM.cpl
2008-10-26 17:03 . 2007-07-30 18:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-10-26 17:03 . 2007-07-30 18:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-10-26 17:02 . 2008-10-26 17:02 <DIR> d-------- C:\WINDOWS\nview
2008-10-26 17:02 . 2008-10-07 12:33 453,152 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-10-26 17:02 . 2008-11-02 15:50 200,819 --a------ C:\WINDOWS\system32\nvapps.xml
2008-10-26 17:02 . 2008-10-07 12:33 18,477 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-10-26 11:46 . 2008-10-26 11:46 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-10-26 11:41 . 2008-10-26 11:41 <DIR> d-------- C:\NVIDIA
2008-10-26 11:41 . 2008-10-02 09:07 453,152 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-10-26 00:31 . 2008-10-26 00:31 <DIR> dr-h----- C:\Documents and Settings\Durgut\Application Data\SecuROM
2008-10-26 00:31 . 2008-10-28 14:40 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-10-26 00:24 . 2008-10-26 17:03 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-10-26 00:24 . 2008-10-28 14:55 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-26 00:24 . 2008-10-26 17:03 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-10-26 00:24 . 2005-05-26 14:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-10-25 23:45 . 2008-10-25 23:45 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-10-25 23:17 . 2008-10-25 23:17 <DIR> d-------- C:\Documents and Settings\Durgut\Application Data\HP
2008-10-25 23:04 . 2008-10-25 23:04 <DIR> d-------- C:\Documents and Settings\Durgut\Application Data\Canon
2008-10-25 23:04 . 2008-10-25 23:04 18,073 --a------ C:\WINDOWS\CSTBox.INI
2008-10-25 23:01 . 2008-10-25 23:01 <DIR> d-------- C:\Documents and Settings\Durgut\Application Data\Image Zone Express
2008-10-25 22:50 . 2008-10-25 22:50 <DIR> d--h----- C:\WINDOWS\PIF
2008-10-25 22:44 . 2007-04-09 12:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-10-25 22:44 . 2008-10-25 22:44 376 --a------ C:\WINDOWS\ODBC.INI
2008-10-25 22:42 . 2008-10-25 22:42 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-10-25 22:42 . 2008-10-25 23:04 <DIR> d-------- C:\Program Files\Microsoft Works
2008-10-25 22:42 . 2008-10-25 22:42 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-10-25 22:42 . 2008-10-25 22:42 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-10-25 22:41 . 2008-10-25 22:41 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-10-25 22:41 . 2007-11-27 21:56 116,416 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2008-10-25 22:41 . 2007-11-27 21:56 91,328 --a------ C:\WINDOWS\system32\drivers\msfwdrv.sys
2008-10-25 22:39 . 2008-10-26 17:03 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-10-25 22:39 . 2008-10-25 22:39 <DIR> dr-h----- C:\MSOCache
2008-10-25 22:39 . 2008-05-15 15:15 53,168 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2008-10-25 22:36 . 2008-11-02 15:50 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-10-25 22:36 . 2008-10-25 22:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-10-25 22:35 . 2008-10-25 22:35 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-10-25 22:35 . 2008-10-25 22:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-10-25 22:34 . 2008-10-25 22:35 <DIR> d-------- C:\Program Files\Common Files\HP
2008-10-25 22:32 . 2005-10-27 04:51 77,824 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-10-25 22:32 . 2005-10-14 21:42 37,376 --a------ C:\WINDOWS\system32\hpz3l43a.dll
2008-10-25 22:32 . 2008-10-25 22:32 732 --a------ C:\WINDOWS\hpntwksetup.ini
2008-10-25 22:32 . 2008-10-25 22:32 164 --a------ C:\WINDOWS\system32\AddPort.ini
2008-10-25 22:31 . 1998-10-29 15:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-10-25 22:31 . 2005-03-14 11:03 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2008-10-25 22:31 . 2005-03-14 11:05 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2008-10-25 22:31 . 2005-03-08 10:55 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2008-10-25 22:31 . 2007-08-09 02:27 73,728 --a------ C:\WINDOWS\system32\HPZipm12.exe
2008-10-25 22:31 . 2005-03-14 12:39 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe
2008-10-25 22:31 . 2005-03-08 10:55 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2008-10-25 22:31 . 2008-04-13 13:47 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-10-25 22:31 . 2008-04-13 13:47 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-10-25 22:30 . 2008-10-25 23:15 <DIR> d-------- C:\Program Files\HP
2008-10-25 22:30 . 2008-10-25 22:36 104,464 --a------ C:\WINDOWS\HPFins09.dat
2008-10-25 22:30 . 2005-11-01 04:29 3,732 --------- C:\WINDOWS\hpfmdl09.dat
2008-10-25 22:25 . 2008-04-13 13:45 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-10-25 22:25 . 2008-04-13 13:45 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-10-25 22:24 . 2008-10-25 22:24 <DIR> d-------- C:\Program Files\Canon
2008-10-25 22:21 . 2008-10-25 22:21 <DIR> d--h----- C:\CanoScan
2008-10-25 22:21 . 2002-05-24 02:04 389,180 --a------ C:\WINDOWS\system32\UCS32P.DLL
2008-10-25 22:21 . 2003-09-17 16:36 339,968 --a------ C:\WINDOWS\system32\N124UFW.dll
2008-10-25 22:21 . 2002-09-12 00:07 36,864 --a------ C:\WINDOWS\system32\CNQU70.DLL
2008-10-25 22:15 . 2008-10-25 22:15 <DIR> d-------- C:\WINDOWS\system32\GroupPolicy
2008-10-25 22:15 . 2008-10-25 22:15 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-10-25 22:15 . 2008-10-25 22:15 <DIR> d-------- C:\Program Files\Windows Desktop Search
2008-10-25 22:15 . 2008-10-25 22:15 <DIR> d-------- C:\Documents and Settings\Durgut\Application Data\Windows Desktop Search
2008-10-25 22:15 . 2008-03-07 12:02 192,000 -----c--- C:\WINDOWS\system32\dllcache\offfilt.dll
2008-10-25 22:15 . 2008-03-07 12:02 98,304 -----c--- C:\WINDOWS\system32\dllcache\nlhtml.dll
2008-10-25 22:15 . 2008-03-07 12:02 29,696 -----c--- C:\WINDOWS\system32\dllcache\mimefilt.dll
2008-10-25 22:14 . 2008-10-26 11:43 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-10-25 22:14 . 2008-10-25 22:14 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-10-25 22:13 . 2008-10-25 22:13 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-10-25 22:10 . 2008-10-25 22:10 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-25 22:10 . 2008-10-25 22:10 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2008-10-25 22:09 . 2008-04-13 19:11 21,504 --a------ C:\WINDOWS\system32\drivers\hidserv.dll
2008-10-25 22:03 . 2008-10-25 22:03 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-10-25 21:59 . 2008-09-15 07:12 1,846,400 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-25 21:59 . 2008-09-08 05:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-25 21:59 . 2008-06-13 06:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-25 21:58 . 2008-08-14 05:11 2,189,184 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-25 21:58 . 2008-08-14 05:09 2,145,280 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-25 21:58 . 2008-08-14 04:33 2,066,048 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-25 21:58 . 2008-08-14 04:33 2,023,936 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-25 21:58 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-10-25 21:58 . 2008-10-15 11:34 337,408 -----c--- C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-25 21:58 . 2008-05-01 09:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-10-25 21:58 . 2008-05-08 09:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-10-25 21:48 . 2008-10-25 21:48 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-10-25 21:48 . 2008-10-25 21:48 <DIR> d-------- C:\WINDOWS\system32\en
2008-10-25 21:48 . 2008-10-25 21:48 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-25 21:33 . 2008-10-25 21:33 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\ATI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 19:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-27 17:36 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-26 01:55 --------- d-----w C:\Program Files\Realtek
2008-10-26 01:54 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-10-26 01:53 --------- d-----w C:\Documents and Settings\Durgut\Application Data\ATI
2008-10-26 01:48 --------- d-----w C:\Program Files\ATI Technologies
2008-10-26 01:39 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-07 17:33 6,133,856 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-09-25 17:51 115,328 ----a-w C:\WINDOWS\system32\drivers\Rtenicxp.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((( snapshot@2008-11-01_20.42.57.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-21 00:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
- 2000-08-31 12:00:00 28,672 ----a-w C:\WINDOWS\NIRCMD.exe
+ 2000-08-31 13:00:00 28,672 ----a-w C:\WINDOWS\NIRCMD.exe
- 2000-08-31 12:00:00 161,792 ----a-w C:\WINDOWS\SWREG.exe
+ 2000-08-31 13:00:00 161,792 ----a-w C:\WINDOWS\SWREG.exe
- 2008-10-30 16:36:18 70,524 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-11-02 16:14:25 70,524 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-10-30 16:36:18 426,932 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-11-02 16:14:25 426,932 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-11-02 20:51:28 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_258.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-01 1629744]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-06-01 1057328]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-08-08 67112]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-10-07 86016]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_15\bin\jusched.exe" [2007-05-22 32881]
"SkyTel"="SkyTel.EXE" [2006-05-16 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-10-07 C:\WINDOWS\system32\nwiz.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^forteManager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\forteManager.lnk
backup=C:\WINDOWS\pss\forteManager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=C:\WINDOWS\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 11:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\spoolsv.exe"=
R2 OcHealthMon;Windows Live OneCare Health Monitor;C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-08-08 28200]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;C:\WINDOWS\system32\drivers\AtiHdmi.sys [2007-07-20 84992]
S3 getPlus(R) Helper;getPlus(R) Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S3 LGDDCDevice;LGDDCDevice;C:\Program Files\LG Soft India\forteManager\bin\I2CDriver.sys [2007-12-24 14336]
S3 LGII2CDevice;LGII2CDevice;C:\Program Files\LG Soft India\forteManager\bin\PII2CDriver.sys [2007-12-24 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {A75BF1D0-C7C3-CB55-EE17-3225387FD154} /qb
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-02 15:50:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\searchindexer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Completion time: 2008-11-02 15:53:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-02 20:52:57
ComboFix2.txt 2008-11-02 00:43:20
Pre-Run: 142,573,150,208 bytes free
Post-Run: 142,565,863,424 bytes free
277 --- E O F --- 2008-10-26 03:22:07
HijackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:55:46, on 11/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Java\j2re1.4.2_15\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\regeditnewb.exe.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_15\bin\jusched.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1224987278678
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1224993225546
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 6736 bytes
MBAM Log:
Malwarebytes' Anti-Malware 1.30
Database version: 1357
Windows 5.1.2600 Service Pack 3
11/2/2008 10:17:47 PM
mbam-log-2008-11-02 (22-17-47).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 130135
Time elapsed: 32 minute(s), 9 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 51
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Qoobox\Quarantine\C\WINDOWS\system32\awttrspq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\bbkpaw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\beguuneu.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\byXOhiIA.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\cbXNFywx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ddcCtSIX.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\efcdCsQJ.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fccbaxuT.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fkqruamb.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\hgGabyaa.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jobioybp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jpdpyexy.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jqxquo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\lglfkpks.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\lkpapbso.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\lsjvpjfi.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\nswwba.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\prun.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qemdoi.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qgqeeswi.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\rqRIxxyA.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ssqNHbYP.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\wqewrstf.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\xxyvUmnl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\yaywtQKE.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP58\A0018552.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025829.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025830.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025831.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025832.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025833.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025834.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025836.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025837.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025838.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025839.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025840.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025841.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025845.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025846.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025847.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP62\A0025842.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0025999.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0026000.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0026001.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0026002.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0026003.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0026004.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0026005.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0026006.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5A512BA6-E25D-4204-8EE4-9CD980899A98}\RP63\A0026007.dll (Trojan.Vundo) -> Quarantined and deleted successfully.