Combofix Log
ComboFix 08-07-23.2 - pnw 2008-07-23 23:15:51.1 - NTFSx86
Running from: C:\Documents and Settings\pnw\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\.protected
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected
C:\Documents and Settings\pnw\Application Data\FunWebProducts
C:\Documents and Settings\pnw\Application Data\FunWebProducts\Data\pnw\avatar.dat
C:\Documents and Settings\pnw\Application Data\FunWebProducts\Data\pnw\register.dat
C:\Documents and Settings\pnw\Application Data\FunWebProducts\Data\pnw\zbucks.dat
C:\Documents and Settings\pnw\Desktop\Error Cleaner.url
C:\Documents and Settings\pnw\Desktop\Privacy Protector.url
C:\Documents and Settings\pnw\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\pnw\Favorites\Error Cleaner.url
C:\Documents and Settings\pnw\Favorites\Privacy Protector.url
C:\Documents and Settings\pnw\Favorites\Spyware&Malware Protection.url
C:\Documents and Settings\pnw\Start Menu\Programs\Startup\.protected
C:\Program Files\Common Files\wnsxs~1
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\
0.exe
C:\Program Files\PCHealthCenter\
0.gif
C:\Program Files\PCHealthCenter\1.exe
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.exe
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.exe
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\4.exe
C:\Program Files\PCHealthCenter\5.exe
C:\Program Files\PCHealthCenter\7.exe
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\Program Files\VAV
C:\WINDOWS\.protected
C:\WINDOWS\edel.exe
C:\WINDOWS\erms.exe
C:\WINDOWS\evgratsm.dll
C:\WINDOWS\kgxmotapktx.dll
C:\WINDOWS\kgxmotaptbp.dll
C:\WINDOWS\kvxqmtre.dll
C:\WINDOWS\qndsfmao.dll
C:\WINDOWS\system32\agsjruwd.dll
C:\WINDOWS\system32\bpbopurc.dll
C:\WINDOWS\system32\cbXPfDsP.dll
C:\WINDOWS\system32\drivers\etc\.protected
C:\WINDOWS\system32\dwurjsga.ini
C:\WINDOWS\system32\ebtdgjcr.dll
C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\hpxpds.dll
C:\WINDOWS\system32\info.txt
C:\WINDOWS\system32\lgukgmxg.dll
C:\WINDOWS\system32\ogleuv.dll
C:\WINDOWS\system32\opnoLccB.dll
C:\WINDOWS\system32\qwmlloyr.dll
C:\WINDOWS\system32\rqRJbyyV.dll
C:\WINDOWS\system32\urorlp.dll
C:\WINDOWS\system32\VyybJRqr.ini
C:\WINDOWS\system32\VyybJRqr.ini2
C:\WINDOWS\system32\wintisv.exe
C:\WINDOWS\system32\ykrgzc.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-24 to 2008-07-24 )))))))))))))))))))))))))))))))
.
2008-07-23 22:55 . 2008-07-23 22:55 94,848 --a------ C:\WINDOWS\system32\rqwhjduk.dll
2008-07-23 22:55 . 2008-07-24 00:13 44,689 ---hs---- C:\WINDOWS\system32\kudjhwqr.ini
2008-07-22 20:47 . 2008-07-22 22:21 <DIR> d-------- C:\Program Files\XoftSpySE
2008-07-22 19:58 . 2008-07-23 22:54 44,449 --ahs---- C:\WINDOWS\system32\wnaotfwf.ini
2008-07-21 19:13 . 2008-07-21 19:13 43,521 --ahs---- C:\WINDOWS\system32\fujnhkhw.ini
2008-07-21 18:51 . 2008-07-17 10:14 155,648 --a------ C:\WINDOWS\agpqlrfm.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 23:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-04 06:57 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-02 21:57 --------- d-----w C:\Program Files\Microsoft AutoRoute
2008-07-02 21:55 --------- d-----w C:\Program Files\PokerStars.NET
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-27 17:44 --------- d-----w C:\Documents and Settings\pnw\Application Data\Centra
2008-05-26 16:25 --------- d-----w C:\Program Files\PokerStars
2007-08-06 11:14 6,479,904 -csha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-06 11:14 179,744 -csha-w C:\WINDOWS\system32\drivers\fidbox2.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-09-01 10:52 376912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"04d8880a"="C:\WINDOWS\system32\rqwhjduk.dll" [2008-07-23 22:55 94848]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_wcm_McciTrayApp]
--a------ 2005-12-29 10:22 543232 C:\Program Files\btbb_wcm\McciTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 07:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
--a------ 2003-05-21 17:37 229437 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2003-09-01 10:52 376912 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-06-25 10:24 49152 C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ioloDelayModule]
--a------ 2005-06-08 20:31 96256 C:\Program Files\iolo\System Mechanic Professional 6\Delay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
--a------ 2006-02-06 17:52 462935 C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 16:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer]
--a------ 2006-12-20 16:47 557056 C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-01-22 16:08 495616 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-01-22 16:09 98304 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
--a------ 2003-09-05 02:24 65536 C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys [2004-04-14 13:52]
.
Contents of the 'Scheduled Tasks' folder
"2008-07-23 22:47:39 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-12-12 10:09:25 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2004-08-21 16:04:52 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2004-08-21 16:04:54 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-07-23 22:49:32 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-07-22 20:47:28 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{3FCAEB7D-F8AE-4A67-AE6C-57EE1416BB6D} - C:\WINDOWS\qndsfmao.dll
Toolbar-{F4A52746-813B-4276-A8D7-E2ABD0C8C8A8} - C:\WINDOWS\qndsfmao.dll
HKCU-Run-Sys1.exe - C:\Windows\Sys1.exe
HKLM-Run-Sys1.exe - C:\Windows\Sys1.exe
SSODL-evgratsm-{82955011-CE07-44AF-A29A-83B7775A8C92} - C:\WINDOWS\evgratsm.dll
SSODL-kvxqmtre-{8CE6BA66-B3F0-4B86-93B1-0E6EA2FD46DA} - C:\WINDOWS\kvxqmtre.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.search.msn.com
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Start Page = hxxp://www.msn.com
R0 -: HKLM-Main,Search Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*
http://uk.docs.yahoo.com/info/bt_side.html
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.genie.co.uk/
R1 -: HKCU-Internet Settings,ProxyOverride = 127.0.0.1
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O18 -: Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\AATP.DLL
O18 -: WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - C:\Program Files\Microsoft ActiveSync\CENETFLT.DLL
O18 -: WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - C:\Program Files\Microsoft ActiveSync\CENETFLT.DLL
O18 -: WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - C:\Program Files\Microsoft ActiveSync\CENETFLT.DLL
O18 -: WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - C:\Program Files\Microsoft ActiveSync\CENETFLT.DLL
O18 -: WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - C:\Program Files\Microsoft ActiveSync\CENETFLT.DLL
O18 -: WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - C:\Program Files\Microsoft ActiveSync\CENETFLT.DLL
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {05CDEE1D-D109-4992-B72B-6D4F5E2AB731} - hxxp://static.photobox.co.uk/sg/common/ImageUploader4.cab
C:\WINDOWS\Downloaded Program Files\ImageUploader4.inf
C:\WINDOWS\system32\unicows.dll
C:\WINDOWS\Downloaded Program Files\ImageUploader4.ocx
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-24 00:14:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\rqwhjduk.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-07-24 0:31:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-24 00:31:01
Pre-Run: 23,291,969,536 bytes free
Post-Run: 23,298,826,240 bytes free
210 --- E O F --- 2008-07-21 18:16:44