I've recently been picking up Virtumonde on my system scans with Spybot S&D. I ran ComboFix (log is below) and then I ran HijackThis (renamed scanner.exe, log below).
ComboFix Log:
ComboFix 07-11-06.4 - imkleats 2007-11-06 22:17:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1390 [GMT -7:00]
Running from: C:\Documents and Settings\imkleats\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\svchost.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\g2
C:\WINDOWS\system32\g2\caws83122.exe
C:\WINDOWS\system32\h1
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\r2
C:\WINDOWS\system32\r2\wr31drs.exe
C:\WINDOWS\system32\ybadd.ini
C:\z.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 )))))))))))))))))))))))))))))))
.
2007-11-06 14:22 35,328 --a------ C:\WINDOWS\system32\wvurqrq.dll
2007-11-06 14:22 82 --a------ C:\n.bat
2007-11-06 14:22 0 --a------ C:\z.dat
2007-11-06 13:48 <DIR> d-------- C:\VundoFix Backups
2007-11-06 13:16 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 12:33 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-06 12:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-06 12:18 338 --a------ C:\WINDOWS\system32\gsoxlnxo.dll
2007-11-04 16:51 35,328 --a------ C:\WINDOWS\system32\wvusrsr.dll
2007-11-04 16:51 786 --a------ C:\8464.bat
2007-11-04 16:50 <DIR> d-------- C:\WINDOWS\system32\Mz18r
2007-11-04 16:50 <DIR> d-------- C:\Temp\mZOr
2007-11-04 16:50 <DIR> d-------- C:\Temp
2007-11-04 16:50 86,080 --a------ C:\WINDOWS\system32\opqursri.dll
2007-11-04 16:49 32,768 --a------ C:\pdf.exe
2007-11-04 16:47 78,912 --a------ C:\WINDOWS\system32\wexivemi.dll
2007-11-04 01:53 78,912 --a------ C:\WINDOWS\system32\jnfntvtd.dll
2007-11-02 23:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-02 23:06 <DIR> d-------- C:\Program Files\Security Task Manager
2007-11-02 23:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-11-02 23:05 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-11-02 23:01 35,328 --a------ C:\WINDOWS\system32\awtrpqq.dll
2007-10-25 23:19 74,752 --a------ C:\WINDOWS\cadkasdeinst01e.exe
2007-10-16 17:42 <DIR> d-------- C:\Documents and Settings\imkleats\.pcgen
2007-10-15 11:54 <DIR> d-------- C:\Program Files\OpenRPG171
2007-10-09 23:22 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-10-09 23:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-10-09 23:13 <DIR> d-------- C:\Documents and Settings\imkleats\Application Data\SystemRequirementsLab
2007-10-09 20:10 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2007-10-09 15:53 582,656 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-07 05:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-07 04:41 --------- d-----w C:\Documents and Settings\imkleats\Application Data\FrostWire
2007-11-06 19:32 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-04 16:26 --------- d-----w C:\Program Files\Trend Micro
2007-11-03 03:36 --------- d-s---w C:\Program Files\Xfire
2007-10-29 19:31 --------- d-----w C:\Program Files\AIM6
2007-10-29 19:30 --------- d-----w C:\Program Files\Viewpoint
2007-10-29 19:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-29 19:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-27 08:46 11,973 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-27 07:50 --------- d-----w C:\Documents and Settings\imkleats\Application Data\Azureus
2007-10-27 04:20 --------- d-----w C:\Program Files\EA GAMES
2007-10-22 04:41 --------- d-----w C:\Documents and Settings\imkleats\Application Data\Xfire
2007-10-17 00:47 --------- d-----w C:\Program Files\World of Warcraft
2007-10-16 20:17 --------- d-----w C:\Documents and Settings\imkleats\Application Data\Aim
2007-10-11 07:07 --------- d-----w C:\Program Files\SPSS
2007-10-06 20:38 --------- d-----w C:\Program Files\Electronic Arts
2007-09-29 00:33 --------- d-----w C:\Program Files\iTunes
2007-09-29 00:33 --------- d-----w C:\Program Files\iPod
2007-09-26 15:39 --------- d-----w C:\Documents and Settings\imkleats\Application Data\U3
2007-09-18 01:46 --------- d-----w C:\Program Files\Azureus
2007-09-17 21:40 35,856 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-09-17 21:40 202,768 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-09-17 21:31 1,126,072 ----a-w C:\WINDOWS\system32\drivers\VsapiNT.sys
2007-08-22 03:34 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-02-01 01:22 26,328 ----a-w C:\Documents and Settings\imkleats\Application Data\GDIPFONTCACHEV1.DAT
2007-01-10 18:15 839,686 ----a-w C:\WINDOWS\Fonts\Crack.exe
2007-01-10 18:15 839,685 --sh--w C:\WINDOWS\Fonts\svchost.exe
2007-01-10 18:15:15 839,685 --sh--w C:\WINDOWS\Fonts\svchost.exe
.
((((((((((((((((((((((((((((( snapshot@2007-11-06_13.38.27.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-06 19:17:41 71,196 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-07 04:43:39 71,196 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-06 19:17:41 432,914 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-07 04:43:39 432,914 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C096738-7999-4135-8AC7-1DC226702F8E}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BCC73622-F72D-4277-803C-D65565A0947F}]
2007-11-02 23:01 35328 --a------ C:\WINDOWS\system32\awtrpqq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DE87EC15-FD2A-4343-B58E-4A689B442B18}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-21 04:03]
"nwiz"="nwiz.exe" [2006-03-21 04:03 C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2006-03-21 04:03 C:\WINDOWS\system32\nvhotkey.dll]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-06-22 00:48]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 14:30 C:\WINDOWS\stsystra.exe]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-04-06 12:58]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 09:48]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 18:15]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 18:29]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 08:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 08:44]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 07:47]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 10:14]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 04:33]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 14:32]
"LogitechCameraAssistant"="C:\Program Files\Logitech\Video\CameraAssistant.exe" [2005-12-07 09:26]
"LogitechVideo[inspector]"="C:\Program Files\Logitech\Video\InstallHelper.exe" [2005-12-07 09:33]
"LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 16:22]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
"NvMediaCenter"="NvMCTray.dll" [2006-03-21 04:03 C:\WINDOWS\system32\nvmctray.dll]
"Host Process"="C:\WINDOWS\Fonts\svchost.exe" [2007-01-10 11:15]
"c092fa9a"="C:\WINDOWS\system32\opqursri.dll" [2007-11-04 16:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 18:39]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-23 17:43]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 08:20]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 11:28]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2007-09-14 18:06]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 16:28:28]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-23 17:43:13]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Monitor Apache Servers.lnk - C:\Apache 2.2\bin\ApacheMonitor.exe [2006-07-27 15:52:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{BCC73622-F72D-4277-803C-D65565A0947F}"= C:\WINDOWS\system32\awtrpqq.dll [2007-11-02 23:01 35328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtrpqq]
awtrpqq.dll 2007-11-02 23:01 35328 C:\WINDOWS\system32\awtrpqq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kqyuwyqn]
kqyuwyqn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddaby.dll
R3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
S2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe
S3 Apache2.2;Apache2.2;"C:\Apache 2.2\bin\httpd.exe" -k runservice
S3 WINIO;WINIO;\??\C:\WINDOWS\system32\winio.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-02 23:46:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-06 22:28:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-06 22:33:18 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-06 13:41
.
--- E O F ---
ComboFix Log:
ComboFix 07-11-06.4 - imkleats 2007-11-06 22:17:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1390 [GMT -7:00]
Running from: C:\Documents and Settings\imkleats\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\svchost.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\g2
C:\WINDOWS\system32\g2\caws83122.exe
C:\WINDOWS\system32\h1
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\r2
C:\WINDOWS\system32\r2\wr31drs.exe
C:\WINDOWS\system32\ybadd.ini
C:\z.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 )))))))))))))))))))))))))))))))
.
2007-11-06 14:22 35,328 --a------ C:\WINDOWS\system32\wvurqrq.dll
2007-11-06 14:22 82 --a------ C:\n.bat
2007-11-06 14:22 0 --a------ C:\z.dat
2007-11-06 13:48 <DIR> d-------- C:\VundoFix Backups
2007-11-06 13:16 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 12:33 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-06 12:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-06 12:18 338 --a------ C:\WINDOWS\system32\gsoxlnxo.dll
2007-11-04 16:51 35,328 --a------ C:\WINDOWS\system32\wvusrsr.dll
2007-11-04 16:51 786 --a------ C:\8464.bat
2007-11-04 16:50 <DIR> d-------- C:\WINDOWS\system32\Mz18r
2007-11-04 16:50 <DIR> d-------- C:\Temp\mZOr
2007-11-04 16:50 <DIR> d-------- C:\Temp
2007-11-04 16:50 86,080 --a------ C:\WINDOWS\system32\opqursri.dll
2007-11-04 16:49 32,768 --a------ C:\pdf.exe
2007-11-04 16:47 78,912 --a------ C:\WINDOWS\system32\wexivemi.dll
2007-11-04 01:53 78,912 --a------ C:\WINDOWS\system32\jnfntvtd.dll
2007-11-02 23:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-02 23:06 <DIR> d-------- C:\Program Files\Security Task Manager
2007-11-02 23:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-11-02 23:05 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-11-02 23:01 35,328 --a------ C:\WINDOWS\system32\awtrpqq.dll
2007-10-25 23:19 74,752 --a------ C:\WINDOWS\cadkasdeinst01e.exe
2007-10-16 17:42 <DIR> d-------- C:\Documents and Settings\imkleats\.pcgen
2007-10-15 11:54 <DIR> d-------- C:\Program Files\OpenRPG171
2007-10-09 23:22 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-10-09 23:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-10-09 23:13 <DIR> d-------- C:\Documents and Settings\imkleats\Application Data\SystemRequirementsLab
2007-10-09 20:10 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2007-10-09 15:53 582,656 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-07 05:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-07 04:41 --------- d-----w C:\Documents and Settings\imkleats\Application Data\FrostWire
2007-11-06 19:32 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-04 16:26 --------- d-----w C:\Program Files\Trend Micro
2007-11-03 03:36 --------- d-s---w C:\Program Files\Xfire
2007-10-29 19:31 --------- d-----w C:\Program Files\AIM6
2007-10-29 19:30 --------- d-----w C:\Program Files\Viewpoint
2007-10-29 19:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-29 19:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-27 08:46 11,973 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-27 07:50 --------- d-----w C:\Documents and Settings\imkleats\Application Data\Azureus
2007-10-27 04:20 --------- d-----w C:\Program Files\EA GAMES
2007-10-22 04:41 --------- d-----w C:\Documents and Settings\imkleats\Application Data\Xfire
2007-10-17 00:47 --------- d-----w C:\Program Files\World of Warcraft
2007-10-16 20:17 --------- d-----w C:\Documents and Settings\imkleats\Application Data\Aim
2007-10-11 07:07 --------- d-----w C:\Program Files\SPSS
2007-10-06 20:38 --------- d-----w C:\Program Files\Electronic Arts
2007-09-29 00:33 --------- d-----w C:\Program Files\iTunes
2007-09-29 00:33 --------- d-----w C:\Program Files\iPod
2007-09-26 15:39 --------- d-----w C:\Documents and Settings\imkleats\Application Data\U3
2007-09-18 01:46 --------- d-----w C:\Program Files\Azureus
2007-09-17 21:40 35,856 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-09-17 21:40 202,768 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-09-17 21:31 1,126,072 ----a-w C:\WINDOWS\system32\drivers\VsapiNT.sys
2007-08-22 03:34 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-02-01 01:22 26,328 ----a-w C:\Documents and Settings\imkleats\Application Data\GDIPFONTCACHEV1.DAT
2007-01-10 18:15 839,686 ----a-w C:\WINDOWS\Fonts\Crack.exe
2007-01-10 18:15 839,685 --sh--w C:\WINDOWS\Fonts\svchost.exe
2007-01-10 18:15:15 839,685 --sh--w C:\WINDOWS\Fonts\svchost.exe
.
((((((((((((((((((((((((((((( snapshot@2007-11-06_13.38.27.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-06 19:17:41 71,196 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-07 04:43:39 71,196 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-06 19:17:41 432,914 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-07 04:43:39 432,914 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C096738-7999-4135-8AC7-1DC226702F8E}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BCC73622-F72D-4277-803C-D65565A0947F}]
2007-11-02 23:01 35328 --a------ C:\WINDOWS\system32\awtrpqq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DE87EC15-FD2A-4343-B58E-4A689B442B18}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-21 04:03]
"nwiz"="nwiz.exe" [2006-03-21 04:03 C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2006-03-21 04:03 C:\WINDOWS\system32\nvhotkey.dll]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-06-22 00:48]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 14:30 C:\WINDOWS\stsystra.exe]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-04-06 12:58]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 09:48]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 18:15]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 18:29]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 08:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 08:44]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 07:47]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 10:14]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 04:33]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 14:32]
"LogitechCameraAssistant"="C:\Program Files\Logitech\Video\CameraAssistant.exe" [2005-12-07 09:26]
"LogitechVideo[inspector]"="C:\Program Files\Logitech\Video\InstallHelper.exe" [2005-12-07 09:33]
"LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 16:22]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
"NvMediaCenter"="NvMCTray.dll" [2006-03-21 04:03 C:\WINDOWS\system32\nvmctray.dll]
"Host Process"="C:\WINDOWS\Fonts\svchost.exe" [2007-01-10 11:15]
"c092fa9a"="C:\WINDOWS\system32\opqursri.dll" [2007-11-04 16:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 18:39]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-23 17:43]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 08:20]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 11:28]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2007-09-14 18:06]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 16:28:28]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-23 17:43:13]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Monitor Apache Servers.lnk - C:\Apache 2.2\bin\ApacheMonitor.exe [2006-07-27 15:52:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{BCC73622-F72D-4277-803C-D65565A0947F}"= C:\WINDOWS\system32\awtrpqq.dll [2007-11-02 23:01 35328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtrpqq]
awtrpqq.dll 2007-11-02 23:01 35328 C:\WINDOWS\system32\awtrpqq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kqyuwyqn]
kqyuwyqn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddaby.dll
R3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
S2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe
S3 Apache2.2;Apache2.2;"C:\Apache 2.2\bin\httpd.exe" -k runservice
S3 WINIO;WINIO;\??\C:\WINDOWS\system32\winio.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-02 23:46:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-06 22:28:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-06 22:33:18 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-06 13:41
.
--- E O F ---