ComboFix Log
ComboFix 08-12-05.02 - TEST 2008-12-06 2:22:16.1 - NTFSx86
Running from: c:\documents and settings\TEST\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\TEST\Application Data\IUpd721
c:\documents and settings\TEST\Application Data\IUpd721\Logs\scns.log
c:\documents and settings\TEST\Application Data\NI.GSCNS
c:\documents and settings\TEST\Application Data\NI.GSCNS\dl.ini
c:\documents and settings\TEST\Application Data\NI.GSCNS\settings.ini
c:\documents and settings\TEST\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\TEST\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\TEST\Local Settings\Temporary Internet Files\fbk.sts
c:\temp\tn3
c:\windows\system32\
0bnRh76B.exe.a_a
c:\windows\system32\1mK0v25X.exe.a_a
c:\windows\system32\digeste.dll
c:\windows\system32\fccyxwtT.dll
c:\windows\system32\gcsmdglx.dll
c:\windows\system32\gvmltkvc.dll
c:\windows\system32\hgGwUnME.dll
c:\windows\system32\hgGwWMfe.dll
c:\windows\system32\hxvhxf.dll
c:\windows\system32\jnwnw64m.exe
c:\windows\system32\mlJBQGAS.dll
c:\windows\system32\ncntokdm.exe
c:\windows\system32\oiujdqyj.dll
c:\windows\system32\prunnet.exe
c:\windows\system32\rwqfkwab.dll
c:\windows\system32\SAGQBJlm.ini
c:\windows\system32\SAGQBJlm.ini2
c:\windows\system32\tcjpvk.dll
c:\windows\system32\wpv211228088479.cpx
c:\windows\system32\zxdnt3d.cfg
c:\windows\Tasks\qrvfxvln.job
c:\windows\wiaserviv.log
c:\windows\system32\drivers\core.cache.dsk . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TNIDRIVER
-------\Service_TnIDriver
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.
2008-12-06 02:40 . 2008-12-06 02:40 <DIR> d-------- c:\temp\tn3
2008-12-05 23:31 . 2008-12-06 00:43 2,362 --a------ c:\windows\system32\tmp.reg
2008-12-05 23:29 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
2008-12-05 23:29 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
2008-12-05 23:29 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
2008-12-05 23:29 . 2008-11-29 17:58 82,944 --a------ c:\windows\system32\o4Patch.exe
2008-12-05 23:29 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
2008-12-05 23:29 . 2008-11-29 17:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
2008-12-05 23:29 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
2008-12-05 23:29 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
2008-12-05 23:29 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
2008-12-05 23:29 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
2008-12-05 02:42 . 2008-12-05 02:42 120 --ahs---- c:\windows\system32\bawkfqwr.ini
2008-12-05 02:36 . 2008-12-05 02:36 114,688 --a------ c:\windows\system32\nawolaso.dll
2008-12-05 02:36 . 2008-12-05 02:36 114,688 --a------ c:\windows\system32\ejsduc.dll
2008-11-30 18:57 . 2008-11-30 18:57 192,466 --a------ c:\windows\system32\g6.exe
2008-11-30 18:54 . 2008-11-30 18:54 32,768 --a------ c:\windows\system32\efcATNEV.dll
2008-11-30 18:45 . 2008-11-30 18:45 86,272 --a------ c:\windows\system32\drivers\isapnpp.sys
2008-11-30 18:45 . 2008-12-06 02:39 932 --------- c:\windows\system32\drivers\core.cache.dsk
2008-11-30 18:44 . 2008-12-06 01:59 <DIR> d-------- c:\windows\system32\vi
2008-11-30 18:44 . 2008-12-06 01:59 <DIR> d-------- c:\windows\system32\op8
2008-11-30 18:44 . 2008-11-30 18:45 <DIR> d-------- c:\windows\system32\IN
2008-11-30 18:44 . 2008-11-30 18:44 <DIR> d-------- c:\windows\system32\giv
2008-11-30 18:44 . 2008-11-30 18:44 <DIR> d-------- c:\windows\system32\gi3
2008-11-30 18:44 . 2008-11-30 18:44 <DIR> d-------- c:\temp\DIV55
2008-11-30 18:43 . 2008-12-01 09:04 <DIR> d-------- c:\windows\system32\TEC
2008-11-30 18:43 . 2008-12-06 02:40 <DIR> d-------- C:\Temp
2008-11-30 18:43 . 2008-11-30 18:43 905,354 --a------ c:\temp\uVN23L.exe
2008-11-30 18:43 . 2008-11-30 18:43 32,768 --a------ c:\windows\system32\vtUnlLDv.dll
2008-11-27 00:59 . 2008-10-24 03:21 455,296 --a------ c:\windows\system32\dllcache\mrxsmb.sys
2008-11-27 00:58 . 2008-09-04 09:15 1,106,944 --a------ c:\windows\system32\dllcache\msxml3.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-06 09:59 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-05 21:08 --------- d-----w c:\program files\Java
2008-12-01 17:03 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-01 08:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-30 13:15 --------- d--h--w c:\documents and settings\TEST\Application Data\Move Networks
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 22:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 22:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 22:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 16:34 337,408 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 17:41 6,066,176 ----a-w c:\windows\system32\dllcache\ieframe.dll
2008-10-01 00:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\dllcache\srv.sys
2008-04-30 07:05 54,704 ----a-w c:\documents and settings\TEST\Application Data\GDIPFONTCACHEV1.DAT
2006-06-20 06:05 24,192 ----a-w c:\documents and settings\TEST\usbsermptxp.sys
2006-06-20 06:05 22,768 ----a-w c:\documents and settings\TEST\usbsermpt.sys
2008-09-05 10:09 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090520080906\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
2008-11-30 18:43 32768 --a------ c:\windows\system32\vtUnlLDv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e8338388-3a50-4aa9-a502-9aa159d07164}]
2008-12-05 02:36 114688 --a------ c:\windows\system32\ejsduc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-10-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-10-30 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-24 282624]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 71328]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2006-02-25 100056]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-09-25 229952]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-04-30 208958]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2003-03-06 90182]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-12 83360]
Yahoo! Autosync.lnk - c:\program files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe [2007-08-21 391680]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= "c:\windows\system32\vtUnlLDv.dll" [2008-11-30 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUnlLDv]
2008-11-30 18:43 32768 c:\windows\system32\vtUnlLDv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=hxvhxf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14941:UDP"= 14941:UDP:Limewire
"14941:TCP"= 14941:TCP:Limewire
"6346:TCP"= 6346:TCP:Shareaza
"6346:UDP"= 6346:UDP:Shareaza
"8630:TCP"= 8630:TCP:BitComet 8630 TCP
"8630:UDP"= 8630:UDP:BitComet 8630 UDP
R1 isapnpp;isapnpp;c:\windows\system32\drivers\isapnpp.sys [2008-11-30 86272]
R2 SVKP;SVKP;\??\c:\windows\system32\SVKP.sys [2007-05-16 2368]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{04012ce3-1042-11dd-b672-00c09f7fcf84}]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8a05aef0-1bba-11dc-b601-00c09f7fcf84}]
\Shell\AutoRun\command - cmd.exe
.
Contents of the 'Scheduled Tasks' folder
2008-10-04 c:\windows\Tasks\Norton AntiVirus - Scan my computer - TEST.job
- c:\progra~1\NORTON~1\Navw32.exe [2003-11-24 15:46]
2008-12-06 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-13 17:38]
.
- - - - ORPHANS REMOVED - - - -
BHO-{2047f108-a625-45da-99fd-acb8525dd246} - c:\windows\system32\hxvhxf.dll
BHO-{68596735-550E-45F4-AEB9-7DF99A672028} - (no file)
BHO-{88DF2256-8BE5-49C2-9A5D-A15BA64DC806} - c:\windows\system32\mlJBQGAS.dll
BHO-{9DFA0BC8-CC49-4066-AEC9-ABCC32121D72} - (no file)
BHO-{e38d5e0a-3d06-42d2-8bc0-9223f070fadf} - (no file)
.
------- Supplementary Scan -------
.
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
- c:\windows\Downloaded Program Files\RhapX.inf
FireFox -: Profile - c:\documents and settings\TEST\Application Data\Mozilla\Firefox\Profiles\h7r1eo9p.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://search.shareazaweb.com/
FF -: plugin - c:\documents and settings\TEST\Application Data\Mozilla\Firefox\Profiles\h7r1eo9p.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF -: plugin - c:\program files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npsnapfish.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-06 02:42:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????6?0?9?8??????? ???B???????????????B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\vtUnlLDv.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Network Associates\VirusScan\vstskmgr.exe
c:\program files\Norton AntiVirus\NAVAPSVC.EXE
c:\windows\system32\HPZipm12.exe
c:\program files\Norton AntiVirus\SAVSCAN.EXE
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2008-12-06 2:59:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-06 10:59:25
Pre-Run: 15,197,118,464 bytes free
Post-Run: 15,164,887,040 bytes free
240 --- E O F --- 2008-11-27 11:07:44
-------------------------------------
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)
Posters who start topics at multiple sites for their PC problem waste valuable volunteer resources, so please don't. Our analysts assist people at several forums.
The Waiting Room: Post here if waiting for help longer than four days
Do NOT run 'FIXES' before helpers have analyzed the HJT log