Hi Kenny94,
I posted everything you asked yesterday but now i see they didn't come up for some reason i dont quite understand. Anyhow my computer started going crazy again with pop-ups and i repeated all the steps you asked me in your previous post (Vundofix, Combofix) so now i'll post the new logs again as the files have changed and i cant go through with the next steps unless you tell me what i need to delete or fix in hijack. I'm sorry if I messed up, I'm not really good at these things
thanks for your patience.. Oh and I hope you had a great Thanksgiving Day yesterday
VundoFix V6.5.10Checking Java version...
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Scan started at 11:08:18 AM 11/23/2007
Listing files found while scanning....
C:\WINDOWS\system32\mfqxukug.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\mfqxukug.dll
C:\WINDOWS\system32\mfqxukug.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\mfqxukug.dll
C:\WINDOWS\system32\mfqxukug.dll Has been deleted!
Performing Repairs to the registry.
Done!
ComboFixComboFix 07-11-19.3 - User 2007-11-23 11:32:17.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.190 [GMT 0:00]
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\User\Desktop\Live Safety Center.lnk
C:\Documents and Settings\User\Desktop\Online Security Guide.lnk
C:\Documents and Settings\User\Favorites\Online Security Guide.lnk
C:\WINDOWS\system32\__c00DF240.dat
C:\WINDOWS\system32\bbcdd.ini
C:\WINDOWS\system32\bbcdd.ini2
C:\WINDOWS\system32\ddcbb.dll
C:\WINDOWS\system32\mfqxukug.dllbox
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\yircgphn.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.
2007-11-23 11:45 77 --a------ C:\Documents and Settings\User\7501.bat
2007-11-23 11:27 36,864 --a------ C:\Documents and Settings\User\services.exe
2007-11-23 02:04 757,023 ---hs---- C:\WINDOWS\system32\adbuqdsw.ini
2007-11-23 02:04 85,056 --a------ C:\WINDOWS\system32\wsdqubda.dll
2007-11-23 02:04 79,936 --a------ C:\WINDOWS\system32\fbfpntem.dll
2007-11-23 01:58 71,232 --a------ C:\WINDOWS\system32\ewsbshgl.exe
2007-11-23 01:55 145,984 --a------ C:\WINDOWS\system32\todgemdd.dll
2007-11-22 17:10 <DIR> d-------- C:\Documents and Settings\User\Application Data\Grisoft
2007-11-22 17:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-22 17:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-22 15:11 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2007-11-22 15:10 <DIR> d-------- C:\Program Files\LimeWire
2007-11-22 15:10 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-22 13:52 <DIR> d-------- C:\WINDOWS\system32\rMa05yy
2007-11-22 13:52 37,376 --a------ C:\WINDOWS\system32\nnnoljg.dll
2007-11-22 13:08 <DIR> d-------- C:\VundoFix Backups
2007-11-22 13:01 37,376 --a------ C:\WINDOWS\system32\ssqrrro.dll
2007-11-21 14:46 85,056 --a------ C:\WINDOWS\system32\mhltxedi.dll
2007-11-21 12:53 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-20 16:03 755,565 --ahs---- C:\WINDOWS\system32\xfercaqm.ini
2007-11-20 16:03 84,544 --a------ C:\WINDOWS\system32\ymdhyhnl.dll
2007-11-20 14:44 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-20 14:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-20 14:43 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-20 14:28 145,960 --a------ C:\WINDOWS\system32\rvoccnjn.dll
2007-11-20 14:27 37,376 --a------ C:\WINDOWS\system32\mljkjkh.dll
2007-11-17 14:15 <DIR> d-------- C:\Documents and Settings\User\Application Data\Symantec
2007-11-17 14:14 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-17 14:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-17 13:08 36,352 --a------ C:\WINDOWS\system32\nnnlkjk.dll
2007-11-17 00:57 3,107 --a------ C:\Documents and Settings\User\z.dat
2007-11-17 00:57 895 --a------ C:\Documents and Settings\User\x.dat
2007-11-16 16:31 <DIR> d-------- C:\Program Files\Finale NotePad 2008
2007-11-16 16:15 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-11-16 16:12 <DIR> d-------- C:\WINDOWS\system32\rMa18yy
2007-11-16 16:12 <DIR> d-------- C:\WINDOWS\system32\re3
2007-11-16 16:12 <DIR> d-------- C:\Temp\abW9
2007-11-16 16:12 225,294 --a------ C:\Temp\k692W868.exe
2007-11-16 16:12 36,352 --a------ C:\WINDOWS\system32\wvuutuv.dll
2007-11-16 16:12 36,352 --a------ C:\WINDOWS\system32\iifeede.dll
2007-11-16 16:10 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-11 20:40 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-11-11 20:40 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2007-11-11 20:34 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared
2007-11-11 20:34 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2007-11-11 20:34 21,504 --a------ C:\WINDOWS\system32\drivers\motmodem.sys
2007-11-11 20:33 92,064 --a------ C:\Documents and Settings\User\mqdmmdm.sys
2007-11-11 20:33 79,328 --a------ C:\Documents and Settings\User\mqdmserd.sys
2007-11-11 20:33 66,656 --a------ C:\Documents and Settings\User\mqdmbus.sys
2007-11-11 20:33 9,232 --a------ C:\Documents and Settings\User\mqdmmdfl.sys
2007-11-11 20:33 6,208 --a------ C:\Documents and Settings\User\mqdmcmnt.sys
2007-11-11 20:33 5,936 --a------ C:\Documents and Settings\User\mqdmwhnt.sys
2007-11-11 20:33 4,048 --a------ C:\Documents and Settings\User\mqdmcr.sys
2007-11-11 20:22 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2007-11-11 20:22 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2007-11-11 20:21 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2007-11-11 20:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-11-11 20:21 25,600 --a------ C:\Documents and Settings\User\usbsermptxp.sys
2007-11-11 20:21 22,768 --a------ C:\Documents and Settings\User\usbsermpt.sys
2007-11-10 21:45 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-11-10 21:45 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-11-10 21:45 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2007-11-10 21:45 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-11-10 18:17 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2007-11-10 17:16 <DIR> d-------- C:\Program Files\Common Files\xing shared
2007-11-10 17:15 <DIR> d-------- C:\Program Files\Real
2007-11-10 17:15 <DIR> d-------- C:\Program Files\Common Files\Real
2007-11-08 15:23 <DIR> d---s---- C:\Documents and Settings\User\UserData
2007-10-26 13:37 <DIR> d-------- C:\Documents and Settings\Daddy\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-23 11:45 111,757 ----a-w C:\a.exe
2007-11-23 11:44 36,864 ----a-w C:\svchost.exe
2007-11-23 11:31 --------- d-----w C:\Documents and Settings\User\Application Data\LimeWire
2007-11-22 16:39 120 ----a-w C:\n.bat
2007-11-22 15:11 --------- d-----w C:\Program Files\Java
2007-11-20 16:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-20 14:28 0 ----a-w C:\z.dat
2007-11-20 14:28 0 ----a-w C:\x.dat
2007-11-16 16:16 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-16 16:12 35,840 ----a-w C:\WINDOWS\mrofinu1000106.exe
2007-11-14 02:17 --------- d-----w C:\Documents and Settings\User\Application Data\Apple Computer
2007-11-11 22:32 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-10 18:43 --------- d-----w C:\Program Files\QuickTime
2007-11-10 18:25 --------- d-----w C:\Program Files\iTunes
2007-11-10 18:24 --------- d-----w C:\Program Files\iPod
2007-10-25 17:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-25 17:05 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-25 17:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-25 17:01 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-25 16:58 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-18 09:49 --------- d-----w C:\Program Files\Common Files\Apple
2007-10-18 09:46 --------- d-----w C:\Program Files\Apple Software Update
2007-10-18 09:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-01-10 12:15 839,692 ----a-w C:\WINDOWS\Fonts\Crack.exe
2007-01-10 12:15 839,691 --sh--w C:\WINDOWS\Fonts\svchost.exe
2007-01-10 12:15 839,691 --sh--w C:\WINDOWS\Fonts\svchost.exe
.
((((((((((((((((((((((((((((( snapshot@2007-11-22_13.52.38.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-17 13:05:04 245,512 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-11-22 16:35:21 262,232 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-04-13 02:19:56 49,248 ----a-w C:\WINDOWS\system32\java.exe
+ 2005-04-13 02:20:04 49,250 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2005-04-13 03:48:54 127,078 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2007-11-13 08:18:04 32,768 ----a-w C:\WINDOWS\system32\rMa05yy\rMa05yy1080.exe
+ 2007-11-23 11:42:17 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_6e4.dat
+ 2006-12-01 22:56:00 96,256 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-12-02 00:25:52 1,101,824 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-02 00:25:56 1,093,120 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-02 00:25:58 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-02 00:26:00 57,856 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-02 00:08:00 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-02 00:08:00 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-02 00:08:00 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-02 00:08:00 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-02 00:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-02 00:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-02 00:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-02 00:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-02 00:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-02 00:46:44 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0a5b6c93-abe6-4181-8d77-8d3c19ec06bd}]
2007-11-23 02:04 79936 --a------ C:\WINDOWS\system32\fbfpntem.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-05-03 16:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 12:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2004-04-15 22:05 C:\WINDOWS\system32\nwiz.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-09-14 22:15 C:\WINDOWS\agrsmmsg.exe]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2003-08-03 23:01]
"00THotkey"="C:\WINDOWS\system32\
00THotkey.exe" [2004-08-11 17:57]
"000StTHK"="000StTHK.exe" [2001-06-24 03:28 C:\WINDOWS\system32\
000StTHK.exe]
"TFncKy"="TFncKy.exe" []
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 09:12]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 16:20]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 21:22]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-13 18:29]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-08 04:55]
"HPHUPD05"="C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe" [2005-07-08 04:55]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 07:38]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2003-12-05 14:41]
"HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2005-07-08 04:55]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-10 17:15]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"Host Process"="C:\WINDOWS\Fonts\svchost.exe" [2007-01-10 12:15]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"a8e6ae54"="C:\WINDOWS\system32\wsdqubda.dll" [2007-11-23 02:04]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-04-05 07:24:12]
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-08-06 20:23:32]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddcbb.dll
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{014a1a62-e2d8-11db-9e31-b27f487ae9fa}]
\Shell\Auto\command - E:\bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{014a1a63-e2d8-11db-9e31-b27f487ae9fa}]
\Shell\Auto\command - bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f907900-e7d7-11db-9e37-000e3539bdbd}]
\Shell\Auto\command - bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43881fb5-e247-11db-9e30-89fb426118fc}]
\Shell\Auto\command - E:\bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ba0fd92-6765-11dc-9e50-000e50921aa4}]
\Shell\Auto\command - bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ba0fd93-6765-11dc-9e50-000e50921aa4}]
\Shell\Auto\command - bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c21a936c-053c-11dc-9e42-000e3539bdbd}]
\Shell\Auto\command - E:\bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e8a687c1-e343-11db-9e35-000e3539bdbd}]
\Shell\Auto\command - E:\bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e8a687c8-e343-11db-9e35-000e3539bdbd}]
\Shell\Auto\command - F:\bittorrent.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
.
Contents of the 'Scheduled Tasks' folder
"2007-11-12 11:18:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-23 11:15:02 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-23 11:44:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-23 11:46:24 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-22 13:54
.
--- E O F ---
HijackThisLogfile of HijackThis v1.99.1
Scan saved at 12:34:29 PM, on 11/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Fonts\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Desktop\geek.exe.exe
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [a8e6ae54] rundll32.exe "C:\WINDOWS\system32\wsdqubda.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe