hi Trevuren! Thanks for your help so far!
Here are the logs:
SDfix
SDFix: Version 1.91
Run by [removed] on Sun 07/15/2007 at 07:34 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
core
ImagePath:
system32\drivers\core.sys
core - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\b128.exe - Deleted
C:\WINDOWS\b136.exe - Deleted
C:\WINDOWS\b138.exe - Deleted
C:\WINDOWS\poolsv.exe - Deleted
C:\WINDOWS\retadpu1000106.exe - Deleted
C:\WINDOWS\retadpu77.exe - Deleted
C:\WINDOWS\svhost.exe - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted
C:\WINDOWS\tcb.pmw - Deleted
C:\WINDOWS\wr.txt - Deleted
Folder C:\Program Files\InetGet2 - Removed
Removing Temp Files…
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
——————
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HTTP-Tunnel\\HTTP-TunnelClient.exe"="C:\\Program Files\\HTTP-Tunnel\\HTTP-TunnelClient.exe:*:Enabled:HTTP-Tunnel Client"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\World of Warcraft\\Launcher.exe"="C:\\World of Warcraft\\Launcher.exe:*:Enabled:World of Warcraft"
"C:\\World of Warcraft\\WoW.exe"="C:\\World of Warcraft\\WoW.exe:*:Enabled:WoW"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.4\\cnc3game.dat"="C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.4\\cnc3game.dat:*:Enabled:Command & Conquer 3 Tiberium Wars"
"C:\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"="C:\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.5\\cnc3game.dat"="C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.5\\cnc3game.dat:*:Enabled:Command & Conquer 3 Tiberium Wars"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"="C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files:
—————
Backups Folder: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\WINDOWS\system32\gebyx.dll
C:\Documents and Settings\Ryan\My Documents\??mantec\r?ndll.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Windows Media Player\mplayer2.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\ragtljaA.exe
C:\WINDOWS\??curity\regsvr32.exe
Finished
VundoFix
VundoFix V6.5.4
Checking Java version…
Java version is 1.4.2.4
Old versions of java are exploitable and should be removed.
Scan started at 7:40:31 PM 7/15/2007
Listing files found while scanning….
C:\windows\system32\efcyyvt.dll
C:\WINDOWS\system32\fhhkj.bak2
C:\WINDOWS\system32\fhhkj.ini
C:\WINDOWS\system32\foxnmvdg.dll
C:\WINDOWS\system32\gdvmnxof.ini
C:\windows\system32\gebyx.dll
C:\windows\system32\ijjnjvbm.ini
C:\WINDOWS\system32\jkhhf.dll
C:\windows\system32\mbvjnjji.dll
C:\windows\system32\xybeg.ini
Beginning removal…
Attempting to delete C:\windows\system32\efcyyvt.dll
C:\windows\system32\efcyyvt.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\fhhkj.bak2
C:\WINDOWS\system32\fhhkj.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\fhhkj.ini
C:\WINDOWS\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\foxnmvdg.dll
C:\WINDOWS\system32\foxnmvdg.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\gdvmnxof.ini
C:\WINDOWS\system32\gdvmnxof.ini Has been deleted!
Attempting to delete C:\windows\system32\gebyx.dll
C:\windows\system32\gebyx.dll Has been deleted!
Attempting to delete C:\windows\system32\ijjnjvbm.ini
C:\windows\system32\ijjnjvbm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\jkhhf.dll Has been deleted!
Attempting to delete C:\windows\system32\mbvjnjji.dll
C:\windows\system32\mbvjnjji.dll Has been deleted!
Attempting to delete C:\windows\system32\xybeg.ini
C:\windows\system32\xybeg.ini Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal…
Attempting to delete C:\WINDOWS\system32\foxnmvdg.dll
C:\WINDOWS\system32\foxnmvdg.dll Has been deleted!
Performing Repairs to the registry.
Done!
ComboFix
"Ryan" - 2007-07-15 19:46:42 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\ckihpljs.dll
C:\WINDOWS\system32\elcxjxhe.dll
C:\WINDOWS\system32\awtuuvs.dll
C:\WINDOWS\system32\awtuuvs.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Ryan\APPLIC~1\WinTouch\wintouch.cfg
C:\DOCUME~1\Ryan\APPLIC~1\WinTouch\WinTouch.exe
C:\DOCUME~1\Ryan\APPLIC~1\WinTouch\WTUninstaller.exe
C:\DOCUME~1\Ryan\MYDOCU~1.\mantec~1
C:\DOCUME~1\Ryan\MYDOCU~1.\mantec~1\r?ndll.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\Messenger\rybimo.dll
C:\Program Files\Messenger\rybimo799.dll
C:\Program Files\Online Services\rybimo432.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\poolsv
C:\Program Files\poolsv\k11u72.exe
C:\Program Files\poolsv\svhost.exe
C:\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exe
C:\Program Files\poolsv\wr-1-0000077.exe
C:\Program Files\poolsv\YazzleBundle-1549.exe
C:\Program Files\svhost
C:\Program Files\svhost\wr-1-0000077.exe
C:\Program Files\WindowsUpdate\nipy83122.dll
C:\Program Files\winpop
C:\Program Files\winpop\UnInstall.exe
C:\Program Files\winpop\winpop.exe
C:\temp\tn3
C:\WINDOWS\curity~1
C:\WINDOWS\curity~1\regsvr32.exe
C:\WINDOWS\dls0523pmw.exe
C:\WINDOWS\rau001978.exe
C:\WINDOWS\system32\B0
C:\WINDOWS\system32\B0\mwspasrt83122.exe
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\B1\wr730.exe
C:\WINDOWS\system32\B2
C:\WINDOWS\system32\B2\sten2.exe
C:\WINDOWS\system32\B3
C:\WINDOWS\system32\B4
C:\WINDOWS\system32\B5
C:\WINDOWS\system32\B5\z53.exe
C:\WINDOWS\system32\rcnchhmq.exe
C:\WINDOWS\system32\ussiuorn.exe
C:\WINDOWS\system32\wnstssv.exe
C:\WINDOWS\system32\yehyduvk.exe
C:\WINDOWS\system32\yfowc.dll
C:\WINDOWS\tk58.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_NET_AGENT
——-\Net Agent
((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))
2007-07-15 19:46 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-15 19:40 d——– C:\VundoFix Backups
2007-07-15 19:34 d——– C:\WINDOWS\ERUNT
2007-07-15 17:31 d——– C:\info
2007-07-15 17:23 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-07-15 17:21 d——– C:\WINDOWS\TAV15.1
2007-07-15 16:02 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-15 15:54 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-15 15:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-12 16:48 d——– C:\WINDOWS\pss
2007-07-12 16:33 d——– C:\Program Files\Trend Micro
2007-07-12 16:00 d——– C:\DOCUME~1\Ryan\.housecall6.6
2007-07-12 15:52 d——– C:\WINDOWS\system32\appmgmt
2007-07-12 15:42 49,152 –a—— C:\WINDOWS\xcnse0578.exe
2007-07-12 15:39 d——– C:\Program Files\MSXML 4.0
2007-07-12 15:22 916,352 -r-hs—- C:\WINDOWS\ragtljaA.exe
2007-07-12 15:22 54,784 –a—— C:\WINDOWS\ragtlja.exe
2007-07-12 15:22 49,152 –a—— C:\WINDOWS\TISKY009.exe
2007-07-12 15:22 172,032 –a—— C:\WINDOWS\system32\vnesyfj.dll
2007-07-12 15:22 d——– C:\WINDOWS\system32\driver
2007-07-12 15:22 d——– C:\Tempc2
2007-07-12 15:21 d——– C:\WINDOWS\system32\b10FdUe
2007-07-12 15:21 d——– C:\Temp\brr
2007-07-12 15:21 d——– C:\Temp
2007-07-11 17:05 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Drivers Headquarters
2007-07-11 17:01 176,128 –a—— C:\WINDOWS\system32\nvuide.exe
2007-07-11 17:01 101,120 –a—— C:\WINDOWS\system32\drivers\nvtcp.sys
2007-07-11 17:01 d——– C:\Program Files\Silicon Image
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\nvconrmins.dll
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\NVCOI.DLL
2007-07-11 16:59 289,792 –a—— C:\WINDOWS\system32\idecoins.dll
2007-07-11 16:40 d——– C:\Program Files\Marvell
2007-07-11 16:30 d——– C:\DOCUME~1\Ryan\APPLIC~1\VersionTracker Pro
2007-06-30 23:35 d—s—- C:\Program Files\Xfire
2007-06-30 23:35 d——– C:\DOCUME~1\Ryan\APPLIC~1\Xfire
2007-06-24 18:31 d——– C:\DOCUME~1\Ryan\APPLIC~1\acccore
2007-06-24 18:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-06-24 18:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-06-23 03:18 d——– C:\DOCUME~1\Ryan\APPLIC~1\Yahoo!
2007-06-22 03:10 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-06-22 03:00 d——– C:\Program Files\uTorrent
2007-06-22 03:00 d——– C:\DOCUME~1\Ryan\APPLIC~1\uTorrent
2007-06-20 16:00 d——– C:\Program Files\Western Digital Technologies
2007-06-19 16:38 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-06-19 16:38 d——– C:\Program Files\Yahoo!
2007-06-19 16:38 d——– C:\Program Files\Common Files\Scanner
2007-06-19 16:38 d——– C:\DOCUME~1\Ryan\APPLIC~1\Logitech
2007-06-19 16:38 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\LogiShrd
2007-06-19 16:37 69,632 –a—— C:\WINDOWS\system32\KemXML.dll
2007-06-19 16:37 56,080 –a—— C:\WINDOWS\KHALMNPR.Exe
2007-06-19 16:37 36,112 –a—— C:\WINDOWS\system32\drivers\LMouFilt.Sys
2007-06-19 16:37 34,832 –a—— C:\WINDOWS\system32\drivers\LHidFilt.Sys
2007-06-19 16:37 28,688 –a—— C:\WINDOWS\system32\drivers\LUsbFilt.sys
2007-06-19 16:37 163,840 –a—— C:\WINDOWS\system32\kemutb.dll
2007-06-19 16:37 135,168 –a—— C:\WINDOWS\system32\KemUtil.dll
2007-06-19 16:37 110,592 –a—— C:\WINDOWS\system32\KemWnd.dll
2007-06-19 16:37 1,419,024 –a—— C:\WINDOWS\system32\WdfCoInstaller01005.dll
2007-06-19 16:36 d——– C:\Program Files\Logitech
2007-06-19 16:36 d——– C:\Program Files\Common Files\Logitech
2007-06-19 16:36 d——– C:\DOCUME~1\Ryan\APPLIC~1\InstallShield
2007-06-19 16:36 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
2007-06-19 13:22 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-06-18 00:22 d——– C:\ProgramData
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-16 02:47:56 ——– d–h–w C:\Program Files\WindowsUpdate
2007-07-16 02:47:56 ——– d—–w C:\Program Files\Online Services
2007-07-16 02:47:56 ——– d—–w C:\Program Files\Messenger
2007-07-15 07:39:22 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-07-15 07:38:33 103,736 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-07-12 23:46:30 ——– d—–w C:\Program Files\AIM6
2007-07-12 22:55:22 ——– d—–w C:\Program Files\Replay Music 2
2007-07-12 22:54:13 ——– d—–w C:\Program Files\Google
2007-07-12 22:53:41 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-12 22:53:39 ——– d—–w C:\Program Files\Electronic Arts
2007-07-12 22:52:57 ——– d—–w C:\Program Files\Steam
2007-07-12 22:52:28 ——– d—–w C:\Program Files\Azureus
2007-07-01 08:18:42 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Azureus
2007-06-22 10:10:12 2,414 —-a-w C:\WINDOWS\mozver.dat
2007-06-19 23:38:00 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-06-19 23:37:56 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2007-06-19 23:37:48 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-06-14 23:35:01 ——– d—–w C:\Program Files\Viewpoint
2007-06-14 23:34:47 ——– d—–w C:\Program Files\Common Files\AOL
2007-06-14 23:33:53 335 —-a-w C:\WINDOWS\nsreg.dat
2007-06-14 23:21:17 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Google
2007-06-13 02:25:35 63,040 —-a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-06-12 22:17:17 384 —-a-w C:\WINDOWS\system32\DVCStateBkp-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2007-06-12 22:17:17 384 —-a-w C:\WINDOWS\system32\DVCState-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2007-06-12 21:41:18 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\DMCache
2007-06-12 21:28:28 ——– d—–w C:\Program Files\Common Files\InstallShield
2007-05-28 04:24:38 ——– d—–w C:\Program Files\MSN Messenger
2007-05-24 05:01:36 ——– d—–w C:\Program Files\Replay Music
2007-05-24 05:01:35 737,280 —-a-w C:\WINDOWS\iun6002.exe
2007-05-21 08:36:17 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\dvdcss
2007-05-21 04:06:01 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-05-21 02:46:03 108,144 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-05-19 19:02:05 ——– d—–w C:\DOCUME~1\Ryan\APPLIC~1\Help
2007-05-16 19:50:33 ——– d—–w C:\Program Files\HTTP-Tunnel
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-14 03:03:36 451,072 —-a-w C:\WINDOWS\Radeon Omega Drivers v3.8.330 Uninstall.exe
2007-05-12 03:50:29 98,304 —-a-w C:\WINDOWS\system32CmdLineExt.dll
2007-05-06 03:09:34 184 —-a-w C:\WINDOWS\system32\e000001.dat
2007-05-06 02:25:03 664 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-05 03:50:53 0 –sha-r C:\MSDOS.SYS
2007-05-05 03:50:53 0 –sha-r C:\IO.SYS
2007-05-05 03:50:53 0 —-a-w C:\CONFIG.SYS
2007-05-05 03:50:53 0 —-a-w C:\AUTOEXEC.BAT
2007-05-05 03:48:38 21,640 —-a-w C:\WINDOWS\system32\emptyregdb.dat
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-18 15:59:40 98,600 —-a-w C:\WINDOWS\system32\COMMONFX.DLL
2007-04-17 05:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:44:20 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 05:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6BC50FD2-7903-46E3-8C47-A73A3199C7F6}]
C:\WINDOWS\system32\jkhhf.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c3c7a106-84e0-4963-bd31-ab15abe15072}]
2007-07-12 15:22 172032 –a—— C:\WINDOWS\system32\vnesyfj.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="atiptaxx.exe" [2006-02-21 17:05 C:\WINDOWS\system32\atiptaxx.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" []
"Wsdu"="C:\WINDOWS\CURITY~1\regsvr32.exe" []
"Fzrull"="C:\Documents and Settings\Ryan\My Documents\??mantec\r?ndll.exe" []
"SfKg6w"="C:\Documents and Settings\Ryan\Application Data\Microsoft\Windows\qwphjtg.exe" [2007-07-15 16:07]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\Autorun.exe
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-15 19:49:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-15 19:49:46 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-15 19:49
— E O F —
Renamed HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:54:51 PM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6BC50FD2-7903-46E3-8C47-A73A3199C7F6} - C:\WINDOWS\system32\jkhhf.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {c3c7a106-84e0-4963-bd31-ab15abe15072} - C:\WINDOWS\system32\vnesyfj.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Wsdu] "C:\WINDOWS\CURITY~1\regsvr32.exe" -vt yazb
O4 - HKCU\..\Run: [Fzrull] "C:\Documents and Settings\Ryan\My Documents\??mantec\r?ndll.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
–
End of file - 3332 bytes
Thanks again!