Hey, A few weeks back i have noticed my computer start giving me a bunch of popups that told me how my computer was infected and a bunch of websites kept popping up even with my pop-up blocker on. I started doing numerous virus checks with AVG and it kept getting files that i kept deleting. Then, i decided that i should get some spyware protecting. I downloaded Windows Defender and it showed files too, I also got another spyware program but anyways....It won't let me go to a search engine, or even my e-mail. I am getting pissed off and since someone else here had Virtumonde.dll also, i looked at the post but its best if you guys look at it.
I downloaded combofix and did a report to help you guys out, im not very tech savvy at all so if you have time to explain some of the lingo it would be greatly appreciated.
ComboFix 08-06-04.3 - HP_Owner 2008-06-04 22:12:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.168 [GMT -7:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Svconr
C:\Program Files\Temporary
C:\WINDOWS\BMef495747.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ailffumx.ini
C:\WINDOWS\system32\bemhxdas.ini
C:\WINDOWS\system32\brrafcls.dll
C:\WINDOWS\system32\cjxaeivc.dll
C:\WINDOWS\system32\cosijiry.dll
C:\WINDOWS\system32\cwpbmern.ini
C:\WINDOWS\system32\dawqrwgq.ini
C:\WINDOWS\system32\exmkivfe.dll
C:\WINDOWS\system32\fgrplwdf.dll
C:\WINDOWS\system32\galutigo.dll
C:\WINDOWS\system32\gjjbivkj.dll
C:\WINDOWS\system32\gmwgksws.dll
C:\WINDOWS\system32\iplafrws.dll
C:\WINDOWS\system32\jrrggvxt.dll
C:\WINDOWS\system32\kgbgfkcm.dll
C:\WINDOWS\system32\knaglaxp.dll
C:\WINDOWS\system32\kpaoxvdj.dll
C:\WINDOWS\system32\licqkvle.ini
C:\WINDOWS\system32\LUxIOnnn.ini
C:\WINDOWS\system32\LUxIOnnn.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nbqnnndl.dll
C:\WINDOWS\system32\nrembpwc.dll
C:\WINDOWS\system32\ofwaewfa.dll
C:\WINDOWS\system32\pvxmpcjm.ini
C:\WINDOWS\system32\pxkxjfoh.dll
C:\WINDOWS\system32\qjdyiged.dll
C:\WINDOWS\system32\qnicxtov.ini
C:\WINDOWS\system32\quefgngn.ini
C:\WINDOWS\system32\raxjyhwj.dll
C:\WINDOWS\system32\rmpvcmnc.ini
C:\WINDOWS\system32\rxsbptcs.dll
C:\WINDOWS\system32\sadxhmeb.dll
C:\WINDOWS\system32\tnulcqsa.ini
C:\WINDOWS\system32\vmtsecjf.ini
C:\WINDOWS\system32\wayFgfii.ini
C:\WINDOWS\system32\wayFgfii.ini2
C:\WINDOWS\system32\welbttti.dll
C:\WINDOWS\system32\yayxUOHb.dll
C:\WINDOWS\system32\yhhemgof.ini
C:\WINDOWS\system32\yrngcsuy.dll
C:\WINDOWS\system32\ywufttwt.ini
.
((((((((((((((((((((((((( Files Created from 2008-05-05 to 2008-06-05 )))))))))))))))))))))))))))))))
.
2008-06-04 22:18 . 2008-06-04 22:18 109,807 --a------ C:\WINDOWS\BMef495747.xml
2008-06-04 22:18 . 2008-06-04 22:18 294 ---hs---- C:\WINDOWS\system32\dawqrwgq.ini
2008-06-04 22:18 . 2008-06-04 22:18 22 --a------ C:\WINDOWS\pskt.ini
2008-06-04 22:06 . 2008-06-04 22:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-04 20:41 . 2008-06-04 20:44 94,208 --a------ C:\WINDOWS\ScUnin.exe
2008-06-04 20:41 . 2008-06-04 20:44 32,930 --a------ C:\WINDOWS\scunin.dat
2008-06-04 20:41 . 2008-06-04 20:44 967 --a------ C:\WINDOWS\ScUnin.pif
2008-06-04 20:32 . 2008-06-04 21:10 153 --a------ C:\WINDOWS\wininit.ini
2008-06-04 19:35 . 2008-06-04 19:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-04 19:35 . 2008-06-04 20:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-04 18:18 . 2008-06-04 18:18 95,232 --a------ C:\WINDOWS\system32\lhxjbjyb.dll
2008-06-04 18:09 . 2008-06-04 18:09 82,432 --a------ C:\WINDOWS\system32\qgwrqwad.dll
2008-06-04 18:06 . 2008-06-04 18:06 91,136 --a------ C:\WINDOWS\system32\neqcfutr.dll
2008-06-04 17:35 . 2008-06-04 21:03 <DIR> d-------- C:\Program Files\Starcraft
2008-06-03 18:05 . 2008-06-03 18:05 280,576 --a------ C:\WINDOWS\system32\nnnOIxUL.dll_old
2008-06-01 22:30 . 2008-06-01 22:30 <DIR> d-------- C:\Program Files\Windows Defender
2008-05-24 11:24 . 2008-05-24 11:24 <DIR> d-------- C:\Program Files\jv16 PowerTools 2008
2008-05-24 11:24 . 2008-05-24 11:24 23 --a------ C:\WINDOWS\system32\fafcfe6_z.ocx
2008-05-24 11:24 . 2008-05-24 11:24 23 --ahs---- C:\WINDOWS\system32\acafedebcfc2_z.dll
2008-05-21 18:23 . 2008-05-26 18:18 <DIR> d-------- C:\Program Files\GameSpy Arcade
2008-05-21 18:22 . 2008-05-21 18:22 <DIR> d-------- C:\Program Files\The Creative Assembly
2008-05-13 15:37 . 2008-06-04 21:10 <DIR> d-------- C:\Program Files\Mozilla Firefox 3 Beta 5
2008-05-13 15:23 . 2008-05-13 15:23 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-10 21:52 . 2008-05-10 21:52 <DIR> d-------- C:\Program Files\Sun
2008-05-10 21:51 . 2008-05-11 10:36 45 --a------ C:\WINDOWS\system32\RPVersion.ini
2008-05-10 21:48 . 2008-05-11 10:57 <DIR> d-------- C:\Program Files\RegistryPatrol3.0
2008-05-08 18:10 . 2008-05-08 18:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-08 18:08 . 2008-05-08 18:08 <DIR> d-------- C:\Program Files\Bonjour
2008-05-08 18:01 . 2008-05-08 18:01 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-08 15:41 . 2008-05-08 15:41 4 --a------ C:\WINDOWS\system32\ulfconfig0103.ulf
2008-05-07 09:30 . 2008-05-07 11:32 754 --a------ C:\WINDOWS\WORDPAD.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-05 00:56 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Azureus
2008-06-02 06:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-05-29 02:57 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-27 01:43 --------- d-----w C:\Program Files\Gamevance
2008-05-27 01:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-27 01:34 --------- d-----w C:\Program Files\LucasArts
2008-05-27 01:29 --------- d-----w C:\Program Files\Real
2008-05-27 01:28 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\My Games
2008-05-27 01:25 --------- d-----w C:\Program Files\Google
2008-05-27 01:24 --------- d-----w C:\Program Files\GameShadow
2008-05-24 19:00 --------- d-----w C:\Program Files\QuickTime
2008-05-24 19:00 --------- d-----w C:\Program Files\LimeWire
2008-05-23 17:52 --------- d-----w C:\Program Files\WarRock
2008-05-11 17:58 --------- d-----w C:\Program Files\Best Buy Rhapsody
2008-05-11 04:51 --------- d-----w C:\Program Files\Java
2008-05-09 01:08 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-09 00:52 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Xfire
2008-05-08 22:27 --------- d--h--w C:\Documents and Settings\HP_Owner\Application Data\ijjigame
2008-04-30 20:30 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\AVG7
2008-04-30 00:13 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-04-29 17:22 --------- d-----w C:\Program Files\Paint.NET
2008-04-29 15:53 --------- d-----w C:\Program Files\Azureus
2008-04-28 23:27 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\TeamViewer
2008-04-28 14:36 --------- d-----w C:\Program Files\iTunes
2008-04-28 14:34 --------- d-----w C:\Program Files\iPod
2008-04-28 14:22 --------- d-----w C:\Program Files\Apple Software Update
2008-04-11 20:31 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Intuit
2008-04-05 22:41 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-05 22:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intuit
2008-04-05 22:40 --------- d-----w C:\Program Files\TurboTax
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9AEF5EB8-864D-48D1-B511-9479E8D79610}]
C:\WINDOWS\system32\nnnOIxUL.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BACAD5E6-774A-4D09-926C-8D6CB80BA969}]
C:\WINDOWS\system32\iifgFyaw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd8313e8-4684-486b-a642-e44e58f80762}]
2008-06-04 18:18 95232 --a------ C:\WINDOWS\system32\lhxjbjyb.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-17 09:51 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-03 18:43 118784]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 18:53 49152]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 18:42 659456]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 20:02 61440]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-08-07 14:03 180269]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 20:43 233472]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 16:57 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-27 19:39 579072]
"ec7a64db"="C:\WINDOWS\system32\qgwrqwad.dll" [2008-06-04 18:09 82432]
"BMef495747"="C:\WINDOWS\system32\neqcfutr.dll" [2008-06-04 18:06 91136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-05 10:25 219136]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 20:29 39264]
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Games\\Halo Trial\\halo.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
S3 teamviewervpn;TeamViewer VPN Adapter;C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys [2008-01-25 02:12]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-29 16:45:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-05 05:20:46 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-04 22:18:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\dawqrwgq.ini 294 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\qgwrqwad.dll
-> C:\WINDOWS\system32\neqcfutr.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-06-04 22:23:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-05 05:23:36
Pre-Run: 145,845,956,608 bytes free
Post-Run: 146,770,067,456 bytes free
219 --- E O F --- 2008-05-17 10:03:54
I downloaded combofix and did a report to help you guys out, im not very tech savvy at all so if you have time to explain some of the lingo it would be greatly appreciated.
ComboFix 08-06-04.3 - HP_Owner 2008-06-04 22:12:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.168 [GMT -7:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Svconr
C:\Program Files\Temporary
C:\WINDOWS\BMef495747.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ailffumx.ini
C:\WINDOWS\system32\bemhxdas.ini
C:\WINDOWS\system32\brrafcls.dll
C:\WINDOWS\system32\cjxaeivc.dll
C:\WINDOWS\system32\cosijiry.dll
C:\WINDOWS\system32\cwpbmern.ini
C:\WINDOWS\system32\dawqrwgq.ini
C:\WINDOWS\system32\exmkivfe.dll
C:\WINDOWS\system32\fgrplwdf.dll
C:\WINDOWS\system32\galutigo.dll
C:\WINDOWS\system32\gjjbivkj.dll
C:\WINDOWS\system32\gmwgksws.dll
C:\WINDOWS\system32\iplafrws.dll
C:\WINDOWS\system32\jrrggvxt.dll
C:\WINDOWS\system32\kgbgfkcm.dll
C:\WINDOWS\system32\knaglaxp.dll
C:\WINDOWS\system32\kpaoxvdj.dll
C:\WINDOWS\system32\licqkvle.ini
C:\WINDOWS\system32\LUxIOnnn.ini
C:\WINDOWS\system32\LUxIOnnn.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nbqnnndl.dll
C:\WINDOWS\system32\nrembpwc.dll
C:\WINDOWS\system32\ofwaewfa.dll
C:\WINDOWS\system32\pvxmpcjm.ini
C:\WINDOWS\system32\pxkxjfoh.dll
C:\WINDOWS\system32\qjdyiged.dll
C:\WINDOWS\system32\qnicxtov.ini
C:\WINDOWS\system32\quefgngn.ini
C:\WINDOWS\system32\raxjyhwj.dll
C:\WINDOWS\system32\rmpvcmnc.ini
C:\WINDOWS\system32\rxsbptcs.dll
C:\WINDOWS\system32\sadxhmeb.dll
C:\WINDOWS\system32\tnulcqsa.ini
C:\WINDOWS\system32\vmtsecjf.ini
C:\WINDOWS\system32\wayFgfii.ini
C:\WINDOWS\system32\wayFgfii.ini2
C:\WINDOWS\system32\welbttti.dll
C:\WINDOWS\system32\yayxUOHb.dll
C:\WINDOWS\system32\yhhemgof.ini
C:\WINDOWS\system32\yrngcsuy.dll
C:\WINDOWS\system32\ywufttwt.ini
.
((((((((((((((((((((((((( Files Created from 2008-05-05 to 2008-06-05 )))))))))))))))))))))))))))))))
.
2008-06-04 22:18 . 2008-06-04 22:18 109,807 --a------ C:\WINDOWS\BMef495747.xml
2008-06-04 22:18 . 2008-06-04 22:18 294 ---hs---- C:\WINDOWS\system32\dawqrwgq.ini
2008-06-04 22:18 . 2008-06-04 22:18 22 --a------ C:\WINDOWS\pskt.ini
2008-06-04 22:06 . 2008-06-04 22:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-04 20:41 . 2008-06-04 20:44 94,208 --a------ C:\WINDOWS\ScUnin.exe
2008-06-04 20:41 . 2008-06-04 20:44 32,930 --a------ C:\WINDOWS\scunin.dat
2008-06-04 20:41 . 2008-06-04 20:44 967 --a------ C:\WINDOWS\ScUnin.pif
2008-06-04 20:32 . 2008-06-04 21:10 153 --a------ C:\WINDOWS\wininit.ini
2008-06-04 19:35 . 2008-06-04 19:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-04 19:35 . 2008-06-04 20:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-04 18:18 . 2008-06-04 18:18 95,232 --a------ C:\WINDOWS\system32\lhxjbjyb.dll
2008-06-04 18:09 . 2008-06-04 18:09 82,432 --a------ C:\WINDOWS\system32\qgwrqwad.dll
2008-06-04 18:06 . 2008-06-04 18:06 91,136 --a------ C:\WINDOWS\system32\neqcfutr.dll
2008-06-04 17:35 . 2008-06-04 21:03 <DIR> d-------- C:\Program Files\Starcraft
2008-06-03 18:05 . 2008-06-03 18:05 280,576 --a------ C:\WINDOWS\system32\nnnOIxUL.dll_old
2008-06-01 22:30 . 2008-06-01 22:30 <DIR> d-------- C:\Program Files\Windows Defender
2008-05-24 11:24 . 2008-05-24 11:24 <DIR> d-------- C:\Program Files\jv16 PowerTools 2008
2008-05-24 11:24 . 2008-05-24 11:24 23 --a------ C:\WINDOWS\system32\fafcfe6_z.ocx
2008-05-24 11:24 . 2008-05-24 11:24 23 --ahs---- C:\WINDOWS\system32\acafedebcfc2_z.dll
2008-05-21 18:23 . 2008-05-26 18:18 <DIR> d-------- C:\Program Files\GameSpy Arcade
2008-05-21 18:22 . 2008-05-21 18:22 <DIR> d-------- C:\Program Files\The Creative Assembly
2008-05-13 15:37 . 2008-06-04 21:10 <DIR> d-------- C:\Program Files\Mozilla Firefox 3 Beta 5
2008-05-13 15:23 . 2008-05-13 15:23 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-10 21:52 . 2008-05-10 21:52 <DIR> d-------- C:\Program Files\Sun
2008-05-10 21:51 . 2008-05-11 10:36 45 --a------ C:\WINDOWS\system32\RPVersion.ini
2008-05-10 21:48 . 2008-05-11 10:57 <DIR> d-------- C:\Program Files\RegistryPatrol3.0
2008-05-08 18:10 . 2008-05-08 18:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-08 18:08 . 2008-05-08 18:08 <DIR> d-------- C:\Program Files\Bonjour
2008-05-08 18:01 . 2008-05-08 18:01 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-08 15:41 . 2008-05-08 15:41 4 --a------ C:\WINDOWS\system32\ulfconfig0103.ulf
2008-05-07 09:30 . 2008-05-07 11:32 754 --a------ C:\WINDOWS\WORDPAD.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-05 00:56 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Azureus
2008-06-02 06:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-05-29 02:57 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-27 01:43 --------- d-----w C:\Program Files\Gamevance
2008-05-27 01:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-27 01:34 --------- d-----w C:\Program Files\LucasArts
2008-05-27 01:29 --------- d-----w C:\Program Files\Real
2008-05-27 01:28 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\My Games
2008-05-27 01:25 --------- d-----w C:\Program Files\Google
2008-05-27 01:24 --------- d-----w C:\Program Files\GameShadow
2008-05-24 19:00 --------- d-----w C:\Program Files\QuickTime
2008-05-24 19:00 --------- d-----w C:\Program Files\LimeWire
2008-05-23 17:52 --------- d-----w C:\Program Files\WarRock
2008-05-11 17:58 --------- d-----w C:\Program Files\Best Buy Rhapsody
2008-05-11 04:51 --------- d-----w C:\Program Files\Java
2008-05-09 01:08 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-09 00:52 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Xfire
2008-05-08 22:27 --------- d--h--w C:\Documents and Settings\HP_Owner\Application Data\ijjigame
2008-04-30 20:30 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\AVG7
2008-04-30 00:13 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-04-29 17:22 --------- d-----w C:\Program Files\Paint.NET
2008-04-29 15:53 --------- d-----w C:\Program Files\Azureus
2008-04-28 23:27 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\TeamViewer
2008-04-28 14:36 --------- d-----w C:\Program Files\iTunes
2008-04-28 14:34 --------- d-----w C:\Program Files\iPod
2008-04-28 14:22 --------- d-----w C:\Program Files\Apple Software Update
2008-04-11 20:31 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Intuit
2008-04-05 22:41 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-05 22:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intuit
2008-04-05 22:40 --------- d-----w C:\Program Files\TurboTax
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9AEF5EB8-864D-48D1-B511-9479E8D79610}]
C:\WINDOWS\system32\nnnOIxUL.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BACAD5E6-774A-4D09-926C-8D6CB80BA969}]
C:\WINDOWS\system32\iifgFyaw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd8313e8-4684-486b-a642-e44e58f80762}]
2008-06-04 18:18 95232 --a------ C:\WINDOWS\system32\lhxjbjyb.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-17 09:51 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-03 18:43 118784]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 18:53 49152]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 18:42 659456]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 20:02 61440]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-08-07 14:03 180269]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 20:43 233472]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 16:57 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-27 19:39 579072]
"ec7a64db"="C:\WINDOWS\system32\qgwrqwad.dll" [2008-06-04 18:09 82432]
"BMef495747"="C:\WINDOWS\system32\neqcfutr.dll" [2008-06-04 18:06 91136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-05 10:25 219136]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 20:29 39264]
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Games\\Halo Trial\\halo.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
S3 teamviewervpn;TeamViewer VPN Adapter;C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys [2008-01-25 02:12]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-29 16:45:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-05 05:20:46 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-04 22:18:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\dawqrwgq.ini 294 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\qgwrqwad.dll
-> C:\WINDOWS\system32\neqcfutr.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-06-04 22:23:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-05 05:23:36
Pre-Run: 145,845,956,608 bytes free
Post-Run: 146,770,067,456 bytes free
219 --- E O F --- 2008-05-17 10:03:54