"James Uhm" - 2007-07-14 21:28:50 - ComboFix 07-07-14.6 - Service Pack 1 FAT32
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\tuvwtqn.dll
C:\WINDOWS\system32\lvbxrvwv.dll
C:\WINDOWS\system32\dpqcnbgn.dll
C:\WINDOWS\system32\hsrqdccf.dll
C:\WINDOWS\system32\iyvckjvu.exe
C:\WINDOWS\system32\nyygknqe.exe
C:\WINDOWS\system32\pwstoqcw.dll
C:\WINDOWS\system32\tuvwtqn.dll
C:\WINDOWS\SYSTEM32\pqsru.bak1
C:\WINDOWS\SYSTEM32\pqsru.ini
C:\WINDOWS\SYSTEM32\pqsru.bak2
C:\WINDOWS\SYSTEM32\fccdqrsh.ini
C:\WINDOWS\system32\opnolji.dll
C:\WINDOWS\system32\ursqp.dll
C:\WINDOWS\system32\opnolji.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\JAMESU~1\Desktop.\internet explorer.lnk
C:\Program Files\poolsv
C:\Program Files\TTC.dll
C:\tempb9
C:\tempb9\tmpTF.log
C:\temp\iee
C:\temp\iee\tmpZTF.log
C:\temp\tn3
C:\WINDOWS\cfg32a.exe
C:\WINDOWS\cs_cache.ini
C:\WINDOWS\dls0523pmw.exe
C:\WINDOWS\DOWNLO~1\UDC6_0001_D19M1908NetInstaller.exe
C:\WINDOWS\DOWNLO~1\UERS_9999_N91S1502NetInstaller.exe
C:\WINDOWS\offun.exe
C:\WINDOWS\poolsv.exe
C:\WINDOWS\system32\bvvnxaat.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\dwdsregt.exe
C:\WINDOWS\system32\info.txt
C:\WINDOWS\system32\klqeinme.exe
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\o02PrEz
C:\WINDOWS\system32\o02PrEz\o02PrEz1065.exe
C:\WINDOWS\system32\S1
C:\WINDOWS\system32\S1\bk53.exe
C:\WINDOWS\system32\S2
C:\WINDOWS\system32\S2\mwspasrt83122.exe
C:\WINDOWS\system32\S4
C:\WINDOWS\system32\S4\wen2.exe
C:\WINDOWS\system32\S6
C:\WINDOWS\system32\S6\wr613.exe
C:\WINDOWS\system32\S7
C:\WINDOWS\system32\tokiuucp.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\wsnpoem
C:\WINDOWS\system32\zxdnt3d.cfg
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\LEGACY_NET_AGENT
-------\LEGACY_WINDOWS_OVERLAY_COMPONENTS
-------\core
-------\Net Agent
-------\Windows Overlay Components
((((((((((((((((((((((((( Files Created from 2007-06-15 to 2007-07-15 )))))))))))))))))))))))))))))))
2007-07-14 21:26 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-14 11:06 50,688 --a------ C:\WINDOWS\SYSTEM32\qwerty12.exe
2007-06-28 15:54 66,048 -r-hs---- C:\WINDOWS\SYSTEM\svchostw.exe
2007-06-28 15:54 66,048 -r-hs---- C:\WINDOWS\SYSTEM\regserv.exe
2007-06-28 15:54 23,552 -r-hs---- C:\WINDOWS\SYSTEM\svchostw.dll
2007-06-28 15:54 23,552 -r-hs---- C:\WINDOWS\SYSTEM\regserv.dll
2007-06-28 15:54 19,456 -r-hs---- C:\WINDOWS\SYSTEM\svchctrl.dll
2007-06-28 15:54 166,104 --a------ C:\WINDOWS\SYSTEM32\tsdiscon.dll
2007-06-28 15:54 11,776 -r-hs---- C:\WINDOWS\SYSTEM\svchctrl.exe
2007-06-20 01:17 2,624 --a------ C:\WINDOWS\SYSTEM32\ffuakshj.exe
2007-06-19 13:21 190,995 --a------ C:\WINDOWS\SYSTEM32\mpdsregr.exe
2007-06-19 13:14 921,920 -r-hs---- C:\WINDOWS\aikhznfA.exe
2007-06-19 13:14 46,592 --a------ C:\WINDOWS\aikhznf.exe
2007-06-19 13:10 192,628 --a------ C:\WINDOWS\SYSTEM32\rwinqndt.exe
2007-06-19 13:05 <DIR> d-------- C:\Temp
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-23 00:26:42 517,744 ----a-w C:\WINDOWS\system32\skcppl.dll
2007-05-23 00:26:42 468,592 ----a-w C:\WINDOWS\system32\skcbgm.dll
2007-05-23 00:26:42 198,256 ----a-w C:\WINDOWS\system32\skcwmf.dll
2007-05-23 00:26:42 169,584 ----a-w C:\WINDOWS\system32\skcbgm.exe
2007-05-23 00:26:42 145,008 ----a-w C:\WINDOWS\system32\skcbgmf1.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2004-09-03 02:11:54 271 --sh--w C:\Program Files\desktop.ini
2004-09-03 02:11:54 23,357 ---h--w C:\Program Files\folder.htt
2004-01-27 18:23:24 3,149 ----a-w C:\Program Files\Common Files\remove_tools.html
2004-01-22 19:03:16 711 ----a-w C:\Program Files\JetShell.ini
2002-10-07 06:28:48 48 ----a-w C:\Program Files\JETVMAIL.INI
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-01-12 20:38 63128 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2006A625-00CC-45FF-93D8-2306E9024BF9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-01-19 23:55 2403392 -ra------ c:\program files\google\googletoolbar4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"axej"="C:\Program Files\xgcf\uqjyrgs.exe" [2004-09-10 15:18]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-03-22 15:23 C:\WINDOWS\KHALMNPR.Exe]
"MP3PAgent"="C:\Program Files\Hanmaro\MediaRose\USBSync\MP3PAgent.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-09-12 01:58]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"@"="" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 05:48]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"@"="" []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders schannel.dll, digest.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rewardnet dùxùüþ
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\4ac8c624-2d76-47f5-951b-4cea31f6d8a1
C:\WINDOWS\System32\bdbamor.exe
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-14 21:38:03
Windows 5.1.2600 Service Pack 1 FAT NTAPI
scanning hidden processes ...
C:\windows\system\svchctrl.exe [1500] 0x811AC020
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
svchctrl = c:\windows\system\svchctrl.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
svchctrl = c:\windows\system\svchctrl.exe
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"svchctrl"="c:\\windows\\system\\svchctrl.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"svchctrl"="c:\\windows\\system\\svchctrl.exe"
Completion time: 2007-07-14 21:38:49 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-14 21:38
--- E O F ---
now here is a copy of my hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 9:41:58 PM, on 7/14/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\xgcf\uqjyrgs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Logitech\SetPoint\kem.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\James Uhm\Desktop\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2006A625-00CC-45FF-93D8-2306E9024BF9} - \
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [axej] C:\Program Files\xgcf\uqjyrgs.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MP3PAgent] C:\Program Files\Hanmaro\MediaRose\USBSync\MP3PAgent.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O13 - Gopher Prefix:
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {00001024-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter24 Class) - http://download.netm...NMStarter24.cab
O16 - DPF: {04E7BADF-F3B9-420D-B82D-8D8CADEFE4F9} (CyImage2Ctl Class) - http://cyimg7.cyworl...pload_10212.cab
O16 - DPF: {447F9423-2046-4267-9B93-11626D001183} (RewardNetwork amLauncher Class) - http://affiliate.rew.../WSgooddayi.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - https://member.netma...kdfense8237.cab
O16 - DPF: {A671DC03-71D0-4CF0-895C-7D4A248FC1F1} (skcbgmset Class) - http://cyimg7.cyworl...e/skcbgmset.cab
O16 - DPF: {AF60D574-F249-4243-8040-5521AAA5BB5E} (PandoraTVSet Class) - http://imgcdn.pandor...ge/pdrtvset.cab
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
any help would be much appreciated!!! thanks!