first of all I dont know much about what im saying here, i'll try my best to be clear..
few days ago my pc got inficted with malware, i have McAfee which didnt detecet anything..anyway i installed spybot 2 days ago, after first check it gave me a list of bad entries, i clicked on fix problems they all got fixed (as it said) but i still can't go to my home page (which is yahoo) anyway today it seems not that i only cant go to my home page even my emails i cant open them it just keeps acting like its loading or somthing it would take the day but nothing will happen all i got is a blank white page, same thing when i try google search i cant make a search..
today spybot foumd 2 Virtumode entries i did as with the prev. entries and clicked fix.. nothing changed i still cant access my homepge or read my emails..
then i istalled combofix and this is the file thing it gave me:
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\AntiSpywareMaster
C:\Program Files\AntiSpywareMaster\asm.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\ktd32.atm
C:\WINDOWS\pskt.ini
C:\WINDOWS\SYSTEM32\AaIklUvw.ini
C:\WINDOWS\SYSTEM32\AaIklUvw.ini2
C:\WINDOWS\system32\anjiofvr.exe
C:\WINDOWS\system32\auvgwwao.ini
C:\WINDOWS\system32\cfrckjmv.ini
C:\WINDOWS\system32\cmguhqrt.ini
C:\WINDOWS\system32\hhrxdsxn.exe
C:\WINDOWS\system32\jvpjvybb.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\SYSTEM32\OoVwaJlm.ini
C:\WINDOWS\SYSTEM32\OoVwaJlm.ini2
C:\WINDOWS\system32\rklkppfy.exe
C:\WINDOWS\system32\rselpxhu.exe
C:\WINDOWS\system32\snlwihph.exe
C:\WINDOWS\system32\vapxdtvf.ini
C:\WINDOWS\system32\vgnigwhl.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-16 to 2008-05-16 )))))))))))))))))))))))))))))))
.
2008-05-15 15:43 . 2008-05-15 15:43 116,736 --a------ C:\WINDOWS\SYSTEM32\oawwgvua.dll
2008-05-15 15:40 . 2008-05-15 15:40 126,464 --a------ C:\WINDOWS\SYSTEM32\fgujqxek.dll
2008-05-15 12:54 . 2008-05-15 12:55 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-15 12:54 . 2008-05-15 13:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-14 15:48 . 2008-05-14 15:48 115,200 --a------ C:\WINDOWS\SYSTEM32\trqhugmc.dll
2008-05-14 15:42 . 2008-05-14 15:42 133,632 --a------ C:\WINDOWS\SYSTEM32\kmyocpqi.dll
2008-05-14 15:38 . 2008-05-14 15:38 125,952 --a------ C:\WINDOWS\SYSTEM32\lciqofcl.dll
2008-05-13 10:12 . 2008-05-13 10:12 132,096 --a------ C:\WINDOWS\SYSTEM32\niwslrtt.dll
2008-05-13 10:06 . 2008-05-13 10:06 115,712 --a------ C:\WINDOWS\SYSTEM32\bbyvjpvj.dll
2008-05-13 10:03 . 2008-05-13 10:03 124,416 --a------ C:\WINDOWS\SYSTEM32\rppfokdm.dll
2008-05-12 10:01 . 2008-05-12 10:01 134,656 --a------ C:\WINDOWS\SYSTEM32\olxxqjak.dll
2008-05-12 10:00 . 2008-05-12 10:00 125,440 --a------ C:\WINDOWS\SYSTEM32\kvxikmas.dll
2008-05-12 03:11 . 2008-05-12 03:11 125,440 --a------ C:\WINDOWS\SYSTEM32\ctqnwxhl.dll
2008-05-11 20:33 . 2008-05-11 20:33 134,656 --a------ C:\WINDOWS\SYSTEM32\bptwyhud.dll
2008-05-11 20:28 . 2008-05-11 20:28 125,440 --a------ C:\WINDOWS\SYSTEM32\nqprhdbe.dll
2008-05-11 20:28 . 2008-05-16 16:12 109,807 --a------ C:\WINDOWS\BM27cc8a52.xml
2008-05-11 17:41 . 2008-05-11 17:40 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-05-11 17:40 . 2008-05-11 17:40 <DIR> d-------- C:\WINDOWS\SYSTEM32\athan
2008-05-11 17:40 . 2008-05-12 23:54 <DIR> d-------- C:\Program Files\Athan
2008-05-11 16:08 . 2008-05-11 16:08 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-05-09 17:15 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\SYSTEM32\hidserv.dll
2008-05-09 17:15 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hidserv.dll
2008-05-08 19:28 . 2008-05-16 16:12 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-08 19:28 . 2008-05-08 19:28 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-30 16:26 . 2008-04-30 16:26 <DIR> d-------- C:\Program Files\HarrysFilters3
2008-04-27 13:04 . 2008-04-27 13:04 <DIR> d-------- C:\Documents and Settings\Rehab\Application Data\Ahead
2008-04-26 06:55 . 2008-04-26 06:55 <DIR> d-------- C:\Program Files\WowChart
2008-04-21 09:37 . 2008-04-21 09:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-21 09:30 . 2008-04-21 09:30 <DIR> d-------- C:\Program Files\Bonjour
2008-04-21 09:20 . 2008-04-21 09:20 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-18 14:05 . 2008-04-18 14:05 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-16 16:07 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\bthmodem.sys
2008-04-16 16:07 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bthmodem.sys
2008-04-16 16:05 . 2004-08-03 22:58 100,992 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\bthpan.sys
2008-04-16 16:05 . 2004-08-03 22:58 100,992 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bthpan.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 16:58 --------- d-----w C:\Documents and Settings\Rehab\Application Data\Skype
2008-05-13 14:07 --------- d-----w C:\Documents and Settings\Rehab\Application Data\skypePM
2008-05-11 14:08 --------- d-----w C:\Program Files\Common Files\Real
2008-04-26 14:25 --------- d-----w C:\Program Files\DivX
2008-04-21 07:30 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-19 07:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-04-16 19:53 --------- d-----w C:\Program Files\Galactic Magnate
2008-04-11 23:39 --------- d-----w C:\Program Files\iTunes
2008-04-11 23:38 --------- d-----w C:\Program Files\iPod
2008-04-11 23:35 --------- d-----w C:\Program Files\QuickTime
2008-04-11 20:36 --------- d-----w C:\Documents and Settings\Rehab\Application Data\Galactic Magnate
2008-04-06 18:16 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-06 12:03 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-02 00:31 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-04-02 00:23 --------- d-----w C:\Program Files\Skype
2008-04-02 00:23 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-02 00:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-03-29 11:18 --------- d-----w C:\Program Files\FLV Player
2008-03-28 10:35 --------- d-----w C:\Documents and Settings\Rehab\Application Data\Creative
2008-03-22 20:37 --------- d-----w C:\Program Files\Safari
2008-03-18 17:08 --------- d-----w C:\Documents and Settings\Rehab\Application Data\ArcSoft
2008-03-18 17:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-18 17:07 --------- d-----w C:\Program Files\Common Files\ArcSoft
2008-03-18 17:06 --------- d-----w C:\Program Files\Philips
2008-03-18 12:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
1999-06-25 07:55 149,504 ----a-w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8a456fa-ab2e-4bbb-a4dd-630e6b055b75}]
2008-05-14 15:42 133632 --a------ C:\WINDOWS\system32\kmyocpqi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8C0A1CF-D6DC-4DAC-90C0-CF87A04B29A0}]
C:\WINDOWS\system32\wvUlkIaA.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 13:23 135168]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 12:43 57344]
"P17Helper"="P17.dll" [2005-05-03 20:38 64512 C:\WINDOWS\SYSTEM32\P17.dll]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-02-22 21:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 12:27 136768]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 19:48 32881]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 07:00 110592 C:\WINDOWS\SYSTEM32\BTHPROPS.CPL]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-11 16:07 185896]
"24ffb9ce"="C:\WINDOWS\system32\trqhugmc.dll" [2008-05-14 15:48 115200]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"combofix"="C:\WINDOWS\system32\CF31426.exe" [2004-08-04 07:00 388608]
"BM27cc8a52"="C:\WINDOWS\system32\lciqofcl.dll" [2008-05-14 15:38 125952]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
TrayMin710.exe.lnk - C:\Program Files\Philips\Philips SPC710NC Webcam\TrayMin710.exe [2008-03-18 19:06:41 278528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe "
"UIHost"="C:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" -tray
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"RemoteControl"=C:\WINDOWS\system32\rmctrl.exe
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
"SoundMan"=SOUNDMAN.EXE
"Kernel and Hardware Abstraction Layer"=KHALMNPR.EXE
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
"phc710"=C:\WINDOWS\vphc700.exe
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ubisoft\\Funatics\\The Settlers II - 10th Anniversary\\bin\\S2DNG.exe"=
"C:\\Program Files\\id Software\\Quake 4\\Quake4.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\drivers\ShldDrv.sys [2005-08-29 14:23]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys [2006-04-25 17:02]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 07:00]
R3 phc700;USB PC Camera (phc710);C:\WINDOWS\system32\DRIVERS\phc700.sys [2005-06-07 15:21]
S3 PIXMC10;JVC Communication PIX-MC10 Driver;C:\WINDOWS\system32\Drivers\pixmc10c.sys [2002-09-27 21:42]
S3 PIXMC10A;JVC PIX-MC10 Audio Capture;C:\WINDOWS\system32\Drivers\pixmc10a.sys [2002-10-04 01:14]
S3 PIXMC10V;JVC PIX-MC10 Video Capture;C:\WINDOWS\system32\Drivers\pixmc10v.sys [2002-11-28 03:13]
S3 SGUARD;SGUARD;C:\WINDOWS\system32\drivers\SGuard.sys []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2007-12-29 23:25]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-05-09 15:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-05-10 19:23:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-16 16:13:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.exe
-> C:\WINDOWS\system32\trqhugmc.dll
-> C:\WINDOWS\system32\lciqofcl.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ati2evxx.exe
C:\WINDOWS\SYSTEM32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\SYSTEM32\MsPMSPSv.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\McAfee\Common Framework\Mctray.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2008-05-16 16:19:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-16 14:18:58
Pre-Run: 25,845,858,304 bytes free
Post-Run: 26,996,879,360 bytes free
238 --- E O F --- 2008-05-16 01:09:18
hope to get help soon, and hope i didnt messed it up :S:S:S
thanx
few days ago my pc got inficted with malware, i have McAfee which didnt detecet anything..anyway i installed spybot 2 days ago, after first check it gave me a list of bad entries, i clicked on fix problems they all got fixed (as it said) but i still can't go to my home page (which is yahoo) anyway today it seems not that i only cant go to my home page even my emails i cant open them it just keeps acting like its loading or somthing it would take the day but nothing will happen all i got is a blank white page, same thing when i try google search i cant make a search..
today spybot foumd 2 Virtumode entries i did as with the prev. entries and clicked fix.. nothing changed i still cant access my homepge or read my emails..
then i istalled combofix and this is the file thing it gave me:
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\AntiSpywareMaster
C:\Program Files\AntiSpywareMaster\asm.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\ktd32.atm
C:\WINDOWS\pskt.ini
C:\WINDOWS\SYSTEM32\AaIklUvw.ini
C:\WINDOWS\SYSTEM32\AaIklUvw.ini2
C:\WINDOWS\system32\anjiofvr.exe
C:\WINDOWS\system32\auvgwwao.ini
C:\WINDOWS\system32\cfrckjmv.ini
C:\WINDOWS\system32\cmguhqrt.ini
C:\WINDOWS\system32\hhrxdsxn.exe
C:\WINDOWS\system32\jvpjvybb.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\SYSTEM32\OoVwaJlm.ini
C:\WINDOWS\SYSTEM32\OoVwaJlm.ini2
C:\WINDOWS\system32\rklkppfy.exe
C:\WINDOWS\system32\rselpxhu.exe
C:\WINDOWS\system32\snlwihph.exe
C:\WINDOWS\system32\vapxdtvf.ini
C:\WINDOWS\system32\vgnigwhl.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-16 to 2008-05-16 )))))))))))))))))))))))))))))))
.
2008-05-15 15:43 . 2008-05-15 15:43 116,736 --a------ C:\WINDOWS\SYSTEM32\oawwgvua.dll
2008-05-15 15:40 . 2008-05-15 15:40 126,464 --a------ C:\WINDOWS\SYSTEM32\fgujqxek.dll
2008-05-15 12:54 . 2008-05-15 12:55 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-15 12:54 . 2008-05-15 13:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-14 15:48 . 2008-05-14 15:48 115,200 --a------ C:\WINDOWS\SYSTEM32\trqhugmc.dll
2008-05-14 15:42 . 2008-05-14 15:42 133,632 --a------ C:\WINDOWS\SYSTEM32\kmyocpqi.dll
2008-05-14 15:38 . 2008-05-14 15:38 125,952 --a------ C:\WINDOWS\SYSTEM32\lciqofcl.dll
2008-05-13 10:12 . 2008-05-13 10:12 132,096 --a------ C:\WINDOWS\SYSTEM32\niwslrtt.dll
2008-05-13 10:06 . 2008-05-13 10:06 115,712 --a------ C:\WINDOWS\SYSTEM32\bbyvjpvj.dll
2008-05-13 10:03 . 2008-05-13 10:03 124,416 --a------ C:\WINDOWS\SYSTEM32\rppfokdm.dll
2008-05-12 10:01 . 2008-05-12 10:01 134,656 --a------ C:\WINDOWS\SYSTEM32\olxxqjak.dll
2008-05-12 10:00 . 2008-05-12 10:00 125,440 --a------ C:\WINDOWS\SYSTEM32\kvxikmas.dll
2008-05-12 03:11 . 2008-05-12 03:11 125,440 --a------ C:\WINDOWS\SYSTEM32\ctqnwxhl.dll
2008-05-11 20:33 . 2008-05-11 20:33 134,656 --a------ C:\WINDOWS\SYSTEM32\bptwyhud.dll
2008-05-11 20:28 . 2008-05-11 20:28 125,440 --a------ C:\WINDOWS\SYSTEM32\nqprhdbe.dll
2008-05-11 20:28 . 2008-05-16 16:12 109,807 --a------ C:\WINDOWS\BM27cc8a52.xml
2008-05-11 17:41 . 2008-05-11 17:40 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-05-11 17:40 . 2008-05-11 17:40 <DIR> d-------- C:\WINDOWS\SYSTEM32\athan
2008-05-11 17:40 . 2008-05-12 23:54 <DIR> d-------- C:\Program Files\Athan
2008-05-11 16:08 . 2008-05-11 16:08 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-05-09 17:15 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\SYSTEM32\hidserv.dll
2008-05-09 17:15 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hidserv.dll
2008-05-08 19:28 . 2008-05-16 16:12 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-08 19:28 . 2008-05-08 19:28 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-30 16:26 . 2008-04-30 16:26 <DIR> d-------- C:\Program Files\HarrysFilters3
2008-04-27 13:04 . 2008-04-27 13:04 <DIR> d-------- C:\Documents and Settings\Rehab\Application Data\Ahead
2008-04-26 06:55 . 2008-04-26 06:55 <DIR> d-------- C:\Program Files\WowChart
2008-04-21 09:37 . 2008-04-21 09:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-21 09:30 . 2008-04-21 09:30 <DIR> d-------- C:\Program Files\Bonjour
2008-04-21 09:20 . 2008-04-21 09:20 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-18 14:05 . 2008-04-18 14:05 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-16 16:07 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\bthmodem.sys
2008-04-16 16:07 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bthmodem.sys
2008-04-16 16:05 . 2004-08-03 22:58 100,992 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\bthpan.sys
2008-04-16 16:05 . 2004-08-03 22:58 100,992 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bthpan.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 16:58 --------- d-----w C:\Documents and Settings\Rehab\Application Data\Skype
2008-05-13 14:07 --------- d-----w C:\Documents and Settings\Rehab\Application Data\skypePM
2008-05-11 14:08 --------- d-----w C:\Program Files\Common Files\Real
2008-04-26 14:25 --------- d-----w C:\Program Files\DivX
2008-04-21 07:30 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-19 07:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-04-16 19:53 --------- d-----w C:\Program Files\Galactic Magnate
2008-04-11 23:39 --------- d-----w C:\Program Files\iTunes
2008-04-11 23:38 --------- d-----w C:\Program Files\iPod
2008-04-11 23:35 --------- d-----w C:\Program Files\QuickTime
2008-04-11 20:36 --------- d-----w C:\Documents and Settings\Rehab\Application Data\Galactic Magnate
2008-04-06 18:16 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-06 12:03 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-02 00:31 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-04-02 00:23 --------- d-----w C:\Program Files\Skype
2008-04-02 00:23 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-02 00:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-03-29 11:18 --------- d-----w C:\Program Files\FLV Player
2008-03-28 10:35 --------- d-----w C:\Documents and Settings\Rehab\Application Data\Creative
2008-03-22 20:37 --------- d-----w C:\Program Files\Safari
2008-03-18 17:08 --------- d-----w C:\Documents and Settings\Rehab\Application Data\ArcSoft
2008-03-18 17:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-18 17:07 --------- d-----w C:\Program Files\Common Files\ArcSoft
2008-03-18 17:06 --------- d-----w C:\Program Files\Philips
2008-03-18 12:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
1999-06-25 07:55 149,504 ----a-w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8a456fa-ab2e-4bbb-a4dd-630e6b055b75}]
2008-05-14 15:42 133632 --a------ C:\WINDOWS\system32\kmyocpqi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8C0A1CF-D6DC-4DAC-90C0-CF87A04B29A0}]
C:\WINDOWS\system32\wvUlkIaA.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 13:23 135168]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 12:43 57344]
"P17Helper"="P17.dll" [2005-05-03 20:38 64512 C:\WINDOWS\SYSTEM32\P17.dll]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-02-22 21:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 12:27 136768]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 19:48 32881]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 07:00 110592 C:\WINDOWS\SYSTEM32\BTHPROPS.CPL]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-11 16:07 185896]
"24ffb9ce"="C:\WINDOWS\system32\trqhugmc.dll" [2008-05-14 15:48 115200]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"combofix"="C:\WINDOWS\system32\CF31426.exe" [2004-08-04 07:00 388608]
"BM27cc8a52"="C:\WINDOWS\system32\lciqofcl.dll" [2008-05-14 15:38 125952]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
TrayMin710.exe.lnk - C:\Program Files\Philips\Philips SPC710NC Webcam\TrayMin710.exe [2008-03-18 19:06:41 278528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe "
"UIHost"="C:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" -tray
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"RemoteControl"=C:\WINDOWS\system32\rmctrl.exe
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
"SoundMan"=SOUNDMAN.EXE
"Kernel and Hardware Abstraction Layer"=KHALMNPR.EXE
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
"phc710"=C:\WINDOWS\vphc700.exe
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ubisoft\\Funatics\\The Settlers II - 10th Anniversary\\bin\\S2DNG.exe"=
"C:\\Program Files\\id Software\\Quake 4\\Quake4.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\drivers\ShldDrv.sys [2005-08-29 14:23]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys [2006-04-25 17:02]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 07:00]
R3 phc700;USB PC Camera (phc710);C:\WINDOWS\system32\DRIVERS\phc700.sys [2005-06-07 15:21]
S3 PIXMC10;JVC Communication PIX-MC10 Driver;C:\WINDOWS\system32\Drivers\pixmc10c.sys [2002-09-27 21:42]
S3 PIXMC10A;JVC PIX-MC10 Audio Capture;C:\WINDOWS\system32\Drivers\pixmc10a.sys [2002-10-04 01:14]
S3 PIXMC10V;JVC PIX-MC10 Video Capture;C:\WINDOWS\system32\Drivers\pixmc10v.sys [2002-11-28 03:13]
S3 SGUARD;SGUARD;C:\WINDOWS\system32\drivers\SGuard.sys []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2007-12-29 23:25]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-05-09 15:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-05-10 19:23:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-16 16:13:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.exe
-> C:\WINDOWS\system32\trqhugmc.dll
-> C:\WINDOWS\system32\lciqofcl.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ati2evxx.exe
C:\WINDOWS\SYSTEM32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\SYSTEM32\MsPMSPSv.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\McAfee\Common Framework\Mctray.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2008-05-16 16:19:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-16 14:18:58
Pre-Run: 25,845,858,304 bytes free
Post-Run: 26,996,879,360 bytes free
238 --- E O F --- 2008-05-16 01:09:18
hope to get help soon, and hope i didnt messed it up :S:S:S
thanx