I scanned with combo fix, did a quick scan with malware bytes anti malware, and again with hijackthis after disinfecting the files discovered by MBAM and CF.
Here are the logs:
Combofix log:
ComboFix 08-05-15.3 - James 2008-05-16 17:43:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1671 [GMT -7:00]
Running from: C:\Documents and Settings\James\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\ggqcifpb.ini
C:\WINDOWS\system32\jxtonxat.ini
C:\WINDOWS\system32\UxGgNXyb.ini
C:\WINDOWS\system32\UxGgNXyb.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-04-17 to 2008-05-17 )))))))))))))))))))))))))))))))
.
2008-05-16 17:43 . 2008-05-16 17:43 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-16 16:28 . 2008-05-16 16:33 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-16 16:27 . 2008-05-16 16:29 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-16 16:27 . 2008-05-16 16:27 <DIR> d-------- C:\Program Files\AVG
2008-05-16 16:27 . 2008-05-16 16:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-16 16:27 . 2008-05-16 16:27 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-16 16:27 . 2008-05-16 16:27 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-16 16:27 . 2008-05-16 16:27 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-13 19:18 . 2008-05-15 19:33 109,826 --a------ C:\WINDOWS\BM37d828d7.xml
2008-05-11 15:11 . 2008-05-11 15:11 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-05-11 15:11 . 2008-05-14 16:45 <DIR> d-------- C:\Program Files\Crimsonland
2008-05-11 14:56 . 2008-05-11 14:56 <DIR> d-------- C:\Program Files\VstPlugins
2008-05-11 14:56 . 2008-05-11 14:56 <DIR> d-------- C:\Program Files\ASIO4ALL v2
2008-05-11 14:56 . 2002-07-07 15:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-05-11 14:56 . 2006-06-20 01:56 225,280 --a------ C:\WINDOWS\system32\rewire.dll
2008-05-11 14:55 . 2008-05-11 14:55 <DIR> d-------- C:\Program Files\Outsim
2008-05-11 14:54 . 2008-05-11 14:56 <DIR> d-------- C:\Program Files\Image-Line
2008-05-11 12:06 . 2008-05-11 12:06 <DIR> d-------- C:\Program Files\uTorrent
2008-05-11 12:06 . 2008-05-14 16:55 <DIR> d-------- C:\Documents and Settings\James\Application Data\uTorrent
2008-05-09 21:49 . 2008-05-09 21:49 <DIR> d-------- C:\WINDOWS\vocoder
2008-05-09 18:20 . 2008-05-09 20:43 <DIR> d-------- C:\UT2004
2008-05-02 22:21 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2008-05-02 22:21 . 2001-08-17 13:56 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonypvu1.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-17 00:47 --------- d-----w C:\Program Files\Steam
2008-05-16 22:53 --------- d-----w C:\Documents and Settings\James\Application Data\foobar2000
2008-05-11 04:26 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-14 00:20 --------- d-----w C:\Program Files\Real Alternative
2008-04-13 20:31 --------- d-----w C:\Program Files\D-Tools
2008-04-13 20:29 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-04-13 20:17 --------- d-----w C:\Documents and Settings\James\Application Data\dvdcss
2008-04-13 20:16 --------- d-----w C:\Program Files\Handbrake
2008-04-13 19:52 --------- d-----w C:\Program Files\Paint.NET
2008-04-13 19:52 --------- d-----w C:\Program Files\GIMP-2.0
2008-04-13 09:30 --------- d-----w C:\Program Files\hp deskjet 5550 series
2008-04-13 09:30 --------- d-----w C:\Program Files\Hewlett-Packard
2008-04-13 04:26 --------- d-----w C:\Program Files\Unlocker
2008-04-13 03:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-13 03:45 --------- d-----w C:\Program Files\EA GAMES
2008-04-13 03:19 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-13 03:16 --------- d-----w C:\Program Files\CCleaner
2008-04-13 03:03 --------- d-----w C:\Program Files\foobar2000
2008-04-13 02:52 --------- d-----w C:\Program Files\Gabest
2008-04-13 02:49 --------- d-----w C:\Program Files\Auto Shutdown
2008-04-13 02:44 --------- d-----w C:\Documents and Settings\James\Application Data\vlc
2008-04-13 02:43 --------- d-----w C:\Program Files\VideoLAN
2008-04-13 02:40 --------- d-----w C:\Documents and Settings\James\Application Data\Media Player Classic
2008-04-13 02:38 --------- d-----w C:\Program Files\ffdshow
2008-04-12 23:19 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-12 23:11 --------- d-----w C:\Program Files\Intel
2008-04-12 23:10 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-04-12 23:10 --------- d-----w C:\Program Files\Realtek AC97
2008-04-12 23:10 --------- d-----w C:\Program Files\AvRack
2008-04-12 23:01 --------- d-----w C:\Program Files\microsoft frontpage
2007-09-30 05:55 5,717,248 ----a-w C:\Program Files\Foxit Reader.exe
2006-03-20 22:37 5,689,344 ----a-w C:\Program Files\mplayerc.exe
.
<pre>
----a-w 57,191 2006-07-04 04:09:08 C:\Documents and Settings\James\Desktop\Pictures\tempoary files\New installs\autoshutdownnew .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{477E96FD-D287-435B-82BE-26D75FDB8C40}]
C:\WINDOWS\system32\byXNgGxU.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B3102264-D09D-4322-B625-503FBF18DD7E}]
C:\WINDOWS\system32\wvUoNHwV.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cdb0dad8-691e-434d-86cb-aae059f205d2}]
C:\WINDOWS\system32\jyhnmjux.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2008-04-12 20:17 1271032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 22:32 208952]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2004-08-03 22:32 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2004-08-03 22:32 455168]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 18:39 90112 C:\WINDOWS\soundman.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-03-18 04:00 188416]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-03-12 22:43 81920]
"34eb1b4b"="C:\WINDOWS\system32\bpficqgg.dll" [ ]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-16 16:27 1177368]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B3102264-D09D-4322-B625-503FBF18DD7E}"= C:\WINDOWS\system32\wvUoNHwV.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvUoNHwV]
wvUoNHwV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Steam\\steamapps\\yaostao2\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Steam\\steamapps\\yaostao2\\counter-strike\\hl.exe"=
"C:\\UT2004\\System\\UT2004.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-16 16:27]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-16 16:27]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-16 16:27]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-16 16:27]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{75c37ece-180a-11dd-aee2-00508df7329e}]
\Shell\AutoRun\command - F:\imt8.cmd
\Shell\explore\Command - F:\imt8.cmd
\Shell\open\Command - F:\imt8.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a22cb481-0902-11dd-bac0-00508df7329e}]
\Shell\AutoRun\command - F:\vt6e.cmd
\Shell\explore\Command - F:\vt6e.cmd
\Shell\open\Command - F:\vt6e.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{abafae33-098e-11dd-bac6-00508df7329e}]
\Shell\AutoRun\command - F:\vt6e.cmd
\Shell\explore\Command - F:\vt6e.cmd
\Shell\open\Command - F:\vt6e.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0c8c2c1-08e4-11dd-babd-00508df7329e}]
\Shell\AutoRun\command - G:\vt6e.cmd
\Shell\explore\Command - G:\vt6e.cmd
\Shell\open\Command - G:\vt6e.cmd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-16 17:46:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-16 17:48:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-17 00:48:48
Pre-Run: 47,368,167,424 bytes free
Post-Run: 47,536,410,624 bytes free
181 --- E O F --- 2008-04-14 01:56:18
Malwarebytes log:
Malwarebytes' Anti-Malware 1.12
Database version: 755
Scan type: Quick Scan
Objects scanned: 32648
Time elapsed: 3 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{b3102264-d09d-4322-b625-503fbf18dd7e} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b3102264-d09d-4322-b625-503fbf18dd7e} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{b3102264-d09d-4322-b625-503fbf18dd7e} (Trojan.Vundo) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 5:57:37 PM, on 5/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {477E96FD-D287-435B-82BE-26D75FDB8C40} - C:\WINDOWS\system32\byXNgGxU.dll (file missing)
O2 - BHO: {2d502f95-0eaa-bc68-d434-e1968dad0bdc} - {cdb0dad8-691e-434d-86cb-aae059f205d2} - C:\WINDOWS\system32\jyhnmjux.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [34eb1b4b] rundll32.exe "C:\WINDOWS\system32\bpficqgg.dll",b
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wvUoNHwV - wvUoNHwV.dll (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
Edited by HumpATree123, 17 May 2008 - 10:54 AM.