and finally... the Combofix log file....
and the Combofix log file....
ComboFix 08-03-18.1 - Administrator 2008-03-20 15:28:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.975 [GMT -7:00]
Running from: C:\Download\Adaware\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMd3b0390c.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\khfdbyy.dll
C:\WINDOWS\system32\mljheda.dll
C:\WINDOWS\system32\nqtss.ini
C:\WINDOWS\system32\nqtss.ini2
C:\WINDOWS\system32\pac.txt
.
((((((((((((((((((((((((( Files Created from 2008-02-20 to 2008-03-20 )))))))))))))))))))))))))))))))
.
2008-03-20 13:22 . 2008-03-20 13:22 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-20 13:22 . 2008-03-20 13:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-19 15:59 . 2008-03-19 15:59 93,248 --------- C:\WINDOWS\system32\xqnsbjrv.dll_old
2008-03-19 15:57 . 2008-03-19 15:57 294 --ahs---- C:\WINDOWS\system32\wqmwqljw.ini
2008-03-19 15:56 . 2008-03-19 15:56 88,640 --------- C:\WINDOWS\system32\wjlqwmqw.dll_old
2008-03-19 12:56 . 2008-03-19 12:56 <DIR> d-------- C:\Program Files\Windows Defender
2008-03-19 12:10 . 2004-08-03 15:56 96,768 --a------ C:\WINDOWS\system32\dpcdll.dll.wga
2008-03-19 12:10 . 2001-08-23 04:00 29,338 --a------ C:\WINDOWS\system32\EULA.TXT.wga
2008-03-19 12:10 . 2004-08-03 15:56 24,064 --a------ C:\WINDOWS\system32\pidgen.dll.wga
2008-03-19 12:10 . 2008-03-19 12:10 13,588 --a------ C:\WINDOWS\system32\wpa.bak
2008-03-19 09:59 . 2008-03-19 09:59 <DIR> d-------- C:\VundoFix Backups
2008-03-19 09:19 . 2008-03-19 09:19 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-18 16:18 . 2008-03-18 16:18 <DIR> d-------- C:\Documents and Settings\btech\Application Data\ACT
2008-03-18 16:07 . 2008-03-18 16:24 4,212 --ah----- C:\WINDOWS\system32\zllictbl.dat
2008-03-18 16:06 . 2008-03-19 09:25 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-03-18 16:06 . 2008-03-18 16:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-18 15:52 . 2008-03-18 16:18 474 --ahs---- C:\WINDOWS\system32\oouxuiiv.ini
2008-03-18 15:16 . 2008-03-18 15:15 691,545 --a------ C:\WINDOWS\unins000.exe
2008-03-18 15:16 . 2008-03-18 15:16 2,558 --a------ C:\WINDOWS\unins000.dat
2008-03-18 15:11 . 2008-03-18 15:11 294 --ahs---- C:\WINDOWS\system32\xevhsgvf.ini
2008-03-18 12:15 . 2008-03-18 12:15 44,032 --a------ C:\WINDOWS\system32\cbxyvur.dll.vir
2008-03-18 07:57 . 2008-03-18 07:57 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-18 07:57 . 2008-03-18 07:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 21:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-18 22:35 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-18 17:03 --------- d-----w C:\Program Files\Tigerpaw Business Suite
2008-03-18 14:58 --------- d-----w C:\Program Files\Lavasoft
2008-03-18 14:58 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-03-14 19:11 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-03-06 20:30 --------- d-----w C:\Program Files\Java
2008-03-03 21:38 --------- d-----w C:\Program Files\ACT
2006-05-02 14:55 33,408 ----a-w C:\Documents and Settings\Administrator\g2mdlhlpx.exe
2007-06-27 18:47 88 --sh--r C:\WINDOWS\system32\
06ECD87EA4.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E73CC89-D922-477A-81CC-A208261DC2AD}]
C:\WINDOWS\system32\sstqn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e8d2dc5d-ae25-4bcc-b45c-92e350f78620}]
C:\WINDOWS\system32\xqnsbjrv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 15:56 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36 1207080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 15:42 1404928]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 11:37 28672 C:\WINDOWS\system32\nwtray.exe]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2003-09-29 08:10 81990]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2003-09-10 04:11 135251]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"MediaFace Integration"="C:\Program Files\Fellowes\MediaFACE 4.2\SetHook.exe" [2005-09-05 06:55 53248]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-12-20 21:54 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-01-26 17:57 155648]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"Act.Outlook.Service"="C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe" [2007-03-28 09:43 9728]
"Act! Preloader"="C:\Program Files\ACT\ACT for Windows\ActSage.exe" [2007-03-28 09:38 1015808]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50 217193]
Desktop Connector.LNK - C:\Program Files\Extended Systems\OneBridge Desktop Connector\DesktopConnector.exe [2006-02-09 14:47:56 315392]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 00:49:24 73728]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 01:15:54 65588]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2005-11-01 12:05:33 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Extended Systems\\OneBridge Desktop Connector\\DesktopConnector.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\FileMaker\\FileMaker Pro 5\\FileMaker Pro.exe"=
"C:\\Program Files\\Symantec\\pcAnywhere\\winaw32.exe"=
"C:\\Novell\\GroupWise\\grpwise.exe"=
"C:\\Novell\\GroupWise\\notify.exe"=
"C:\\Program Files\\Microsoft Office\\Office\\OUTLOOK.EXE"=
"C:\\Program Files\\ACT\\ActUpdt.exe"=
"C:\\Program Files\\ACT\\Act for Windows\\ActSage.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 AEP_TDI_DRV;AEP NSP Port Forwarder TDI Driver;C:\WINDOWS\system32\DRIVERS\aeptdipfwd.sys [2006-11-13 14:49]
R2 MSSQL$ACT7;SQL Server (ACT7);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sACT7 []
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-05-04 17:04]
S3 SSLDrv;SSL-VPN NetExtender Adapter;C:\WINDOWS\system32\DRIVERS\SSLDrv.sys [2007-03-26 15:11]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-20 22:36:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-20 15:35:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.exe
-> C:\WINDOWS\system32\NWSHLXNT.dll
-> C:\WINDOWS\system32\NLS\ENGLISH\NWSHLXNR.DLL
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
.
**************************************************************************
.
Completion time: 2008-03-20 15:39:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-20 22:39:04
.
2008-03-19 21:24:44 --- E O F ---