computer is back to normal now! whew. No pop ups, nothing running in the back ground, and speed is back to where it was. Thank you!!!
ComboFix 10-01-29.09 - Owner 2010-01-30 10:32:19.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.247.60 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Owner\Desktop\Internet Security 2010.lnk
c:\documents and settings\Owner\Start Menu\Internet Security 2010.lnk
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\windows\system32\15724.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\a.exe
c:\windows\system32\hapoyivu.dll
c:\windows\system32\helper32.dll
c:\windows\system32\hujinuya.dll
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\jayodaye.dll
c:\windows\system32\kifabibu.dll
c:\windows\system32\noveyobe.dll
c:\windows\system32\ps2.bat
c:\windows\system32\smss32.exe
c:\windows\system32\warning.html
c:\windows\system32\wezahevu.dll
c:\windows\system32\winlogon32.exe
c:\windows\system32\yireniye.dll
c:\windows\system32\yojonaso.dll
c:\windows\system32\yuheduwo.dll
c:\windows\system32\zowolage.dll
c:\windows\Tasks\anryxovq.job
c:\windows\unins000.dat
c:\windows\unins000.exe
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 15:49 . 2003-12-30 23:50 ——– d—–w- c:\documents and settings\All Users\Application Data\DIGStream
2010-01-30 15:49 . 2003-08-29 03:15 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-27 19:40 . 2006-06-29 17:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-27 00:58 . 2006-06-29 17:02 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-26 23:41 . 2006-12-23 20:11 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-10 22:56 . 2003-12-24 16:58 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-12-21 19:14 . 2005-02-18 20:19 916480 —-a-w- c:\windows\system32\wininet.dll
2008-06-19 09:16 . 2008-06-19 09:16 118784 —-a-w- c:\program files\mozilla firefox\plugins\MyCamera.dll
2003-08-29 03:16 . 2003-08-29 03:16 32 –sha-w- c:\windows\{14B431FF-99E9-4C1E-8574-051F227CB5BD}.dat
1601-01-01 00:03 . 1601-01-01 00:03 52736 –sha-w- c:\windows\system32\bidubiti.dll.tmp
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\fizelugo.dll
1601-01-01 00:03 . 1601-01-01 00:03 51712 –sha-w- c:\windows\system32\hajulofi.dll
1601-01-01 00:03 . 1601-01-01 00:03 92160 –sha-w- c:\windows\system32\hulujige.dll
1601-01-01 00:03 . 1601-01-01 00:03 52736 –sha-w- c:\windows\system32\jimaneno.dll.tmp
1601-01-01 00:03 . 1601-01-01 00:03 52736 –sha-w- c:\windows\system32\lumekeri.dll.tmp
1601-01-01 00:03 . 1601-01-01 00:03 93696 –sha-w- c:\windows\system32\nifarake.dll
1601-01-01 00:03 . 1601-01-01 00:03 61952 –sha-w- c:\windows\system32\rolirefu.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\suzirowa.dll
1601-01-01 00:03 . 1601-01-01 00:03 51712 –sha-w- c:\windows\system32\vozanije.dll
2003-08-29 03:16 . 2003-08-29 03:16 32 –sha-w- c:\windows\system32\{C6B785D4-A2EC-4320-AADD-7778E174E81D}.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c0fe0be6-08ae-4b27-bb91-ba35694c0375}]
1601-01-01 00:03 51712 –sha-w- c:\windows\system32\vozanije.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\program files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-23 24576]
"NVIEW"="nview.dll" [2003-05-03 835654]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe" [2003-10-29 524288]
"RealPlayer"="c:\program files\Real\RealOne Player\realplay.exe" [2006-06-01 1003520]
"PhotoShow Deluxe Media Manager"="c:\progra~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [2005-05-19 176128]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 90112]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-06-14 49152]
"HPHUPD05"="c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-05-23 483328]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-08-23 151597]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-03 4640768]
"nwiz"="nwiz.exe" [2003-05-03 323584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2003-12-02 54296]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2003-12-02 58392]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-03-18 188416]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-05-18 282624]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-17 28672]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-12-21 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-21 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Configuration Utility.lnk - c:\program files\MA311 PCI Adapter Configuration Utility\wlanutil.exe [2003-12-12 625152]
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\PMremind.exe [2008-9-13 331776]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2003-6-13 233472]
Updates from HP.lnk - c:\program files\Updates from HP\137903\Program\BackWeb-137903.exe [2003-8-23 16384]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-1-28 122880]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 10:50 40960 —-a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli pnfligi.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\Hummingbird\\Connectivity\\8.00\\Exceed\\exceed.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\PCDnldSvr\\PCDnldServer.exe"=
R3 MA311;NETGEAR Wireless LAN Driver;c:\windows\system32\drivers\ma311n51.sys [2003-12-12 7:08 PM 54784]
S2 mrtRate;mrtRate; [x]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 3:22 PM 34064]
.
Contents of the 'Scheduled Tasks' folder
2010-01-30 c:\windows\Tasks\Norton AntiVirus - Scan my computer.job
- c:\progra~1\NORTON~1\NAVW32.exe [2002-11-15 09:31]
2004-01-09 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-29 19:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://srch-us9.hpwis.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Google; Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate; English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
LSP: SpSubLSP.dll
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\etmra113.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPCIG.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-derirowaki - wezahevu.dll
HKLM-Run-nesurukeb - c:\windows\system32\hapoyivu.dll
SharedTaskScheduler-{f0c266d6-ee2e-47dd-8cfa-22132e89416f} - c:\windows\system32\jilumuyo.dll
SharedTaskScheduler-{76a2b722-7c62-4fdc-8007-6e49c465ce2b} - c:\windows\system32\hapoyivu.dll
SSODL-neletedos-{f0c266d6-ee2e-47dd-8cfa-22132e89416f} - c:\windows\system32\jilumuyo.dll
SSODL-genojomid-{76a2b722-7c62-4fdc-8007-6e49c465ce2b} - c:\windows\system32\hapoyivu.dll
AddRemove-1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC - c:\program files\WildTangent\Apps\GameChannel\Games\1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC\Uninstall.exe
AddRemove-1FEF9671-50F6-4CB0-9E96-304EB14158E0 - c:\program files\WildTangent\Apps\GameChannel\Games\1FEF9671-50F6-4CB0-9E96-304EB14158E0\Uninstall.exe
AddRemove-342970EF-F8DF-4E9B-8477-A1A03E3E15E1 - c:\program files\WildTangent\Apps\GameChannel\Games\342970EF-F8DF-4E9B-8477-A1A03E3E15E1\Uninstall.exe
AddRemove-357ECB62-CD36-4B63-B57E-769D0CA174F4 - c:\program files\WildTangent\Apps\GameChannel\Games\357ECB62-CD36-4B63-B57E-769D0CA174F4\Uninstall.exe
AddRemove-36317AE4-57EC-4F3E-B828-009A3DD96BE8 - c:\program files\WildTangent\Apps\GameChannel\Games\36317AE4-57EC-4F3E-B828-009A3DD96BE8\Uninstall.exe
AddRemove-4F0AE1FB-4082-4A27-8363-05D292D92FB0 - c:\program files\WildTangent\Apps\GameChannel\Games\4F0AE1FB-4082-4A27-8363-05D292D92FB0\Uninstall.exe
AddRemove-53EF27E9-150C-4063-8343-61C45FC6BB98 - c:\program files\WildTangent\Apps\GameChannel\Games\53EF27E9-150C-4063-8343-61C45FC6BB98\Uninstall.exe
AddRemove-5415BC25-6D6C-46C4-B34C-EA8470FE56D5 - c:\program files\WildTangent\Apps\GameChannel\Games\5415BC25-6D6C-46C4-B34C-EA8470FE56D5\Uninstall.exe
AddRemove-5F804D2B-A66D-4F0A-B64E-FBDA3F52E3F8 - c:\program files\WildTangent\Apps\GameChannel\Games\5F804D2B-A66D-4F0A-B64E-FBDA3F52E3F8\Uninstall.exe
AddRemove-62067F4C-84A9-45B9-8573-B90468B0A3EF - c:\program files\WildTangent\Apps\GameChannel\Games\62067F4C-84A9-45B9-8573-B90468B0A3EF\Uninstall.exe
AddRemove-BFBCBAE3-8293-4215-9C4F-C2402C118EDB - c:\program files\WildTangent\Apps\GameChannel\Games\BFBCBAE3-8293-4215-9C4F-C2402C118EDB\Uninstall.exe
AddRemove-C99127BE-FDE5-49BD-9621-BFE5DF19AA34 - c:\program files\WildTangent\Apps\GameChannel\Games\C99127BE-FDE5-49BD-9621-BFE5DF19AA34\Uninstall.exe
AddRemove-D11F7128-8CBD-408B-8BF8-034604DEDD42 - c:\program files\WildTangent\Apps\GameChannel\Games\D11F7128-8CBD-408B-8BF8-034604DEDD42\Uninstall.exe
AddRemove-DA44615A-C243-46A4-8E47-184CFF33CD38 - c:\program files\WildTangent\Apps\GameChannel\Games\DA44615A-C243-46A4-8E47-184CFF33CD38\Uninstall.exe
AddRemove-DF479CEA-34C0-460F-9B56-93BCE4CD4086 - c:\program files\WildTangent\Apps\GameChannel\Games\DF479CEA-34C0-460F-9B56-93BCE4CD4086\Uninstall.exe
AddRemove-GameChannel - c:\program files\WildTangent\Apps\uninstallgamechannel.exe
AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-30 10:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(592)
c:\program files\Softex\OmniPass\opxpgina.dll
- - - - - - - > 'lsass.exe'(648)
c:\windows\pnfligi.dll
c:\windows\system32\WININET.dll
c:\windows\system32\SpSubLSP.dll
- - - - - - - > 'explorer.exe'(2832)
c:\windows\system32\WININET.dll
c:\docume~1\Owner\LOCALS~1\Temp\IadHide4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\pnfligi.dll
c:\windows\system32\webcheck.dll
c:\progra~1\PANICW~1\POP-UP~1\XAHook.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Norton AntiVirus\navapsvc.exe
c:\program files\Softex\OmniPass\Omniserv.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
c:\program files\Common Files\Real\Update_OB\rnathchk.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
c:\windows\system32\rundll32.exe
c:\program files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2010-01-30 11:16:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-30 16:16
ComboFix2.txt 2008-09-03 23:34
Pre-Run: 50,301,153,280 bytes free
Post-Run: 50,355,994,624 bytes free
- - End Of File - - F2211A04B543B3B3293F8B687A8000A2