New combo fix log:
ComboFix 08-11-07.01 - HP_Administrator 2008-11-08 14:52:58.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1125 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
The following files were disabled during the run:
c:\windows\system32\nigobani.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\epikusik.ini
c:\windows\system32\iriyined.ini
.
((((((((((((((((((((((((( Files Created from 2008-10-08 to 2008-11-08 )))))))))))))))))))))))))))))))
.
2008-11-07 17:03 . 2008-11-07 17:03 d——– C:\_OTMoveIt
2008-11-06 03:09 . 2008-10-03 11:41 6,066,176 ——— c:\windows\system32\dllcache\ieframe.dll
2008-11-06 03:09 . 2007-04-17 03:32 2,455,488 ——— c:\windows\system32\dllcache\ieapfltr.dat
2008-11-06 03:09 . 2007-03-07 23:10 991,232 ——— c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-06 03:09 . 2008-08-26 01:24 459,264 ——— c:\windows\system32\dllcache\msfeeds.dll
2008-11-06 03:09 . 2008-08-26 01:24 383,488 ——— c:\windows\system32\dllcache\ieapfltr.dll
2008-11-06 03:09 . 2008-08-26 01:24 267,776 ——— c:\windows\system32\dllcache\iertutil.dll
2008-11-06 03:09 . 2008-08-26 01:24 63,488 ——— c:\windows\system32\dllcache\icardie.dll
2008-11-06 03:09 . 2008-08-26 01:24 52,224 ——— c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-06 03:09 . 2008-08-25 02:38 13,824 ——— c:\windows\system32\dllcache\ieudinit.exe
2008-11-05 21:21 . 2008-11-05 21:21 d——– c:\documents and settings\HP_Administrator\Application Data\Uniblue
2008-11-05 19:21 . 2008-11-05 21:51 d——– c:\documents and settings\HP_Administrator\.housecall6.6
2008-11-04 23:09 . 2008-11-04 23:09 d——– c:\documents and settings\NetworkService\Application Data\AdobeUM
2008-11-04 19:44 . 2008-11-08 14:58 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-04 19:44 . 2008-11-08 14:56 1,409 –a—— c:\windows\QTFont.for
2008-11-04 18:20 . 2008-11-05 16:58 d——– c:\program files\Spybot - Search & Destroy
2008-11-04 18:20 . 2008-11-04 19:44 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-04 04:15 . 2008-11-04 04:15 d——– c:\program files\ERUNT
2008-11-03 15:36 . 2008-11-07 17:06 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-03 15:36 . 2008-11-03 15:36 d——– c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2008-11-03 15:36 . 2008-11-03 15:36 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-03 15:36 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-03 15:36 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-03 04:32 . 2008-11-03 05:10 d——– c:\documents and settings\All Users\Application Data\ZILLAbar
2008-11-03 04:30 . 2008-11-03 04:30 d——– c:\documents and settings\HP_Administrator\Application Data\STOPzilla!
2008-11-03 03:21 . 2008-11-03 03:21 d——– c:\program files\Common Files\iS3
2008-11-03 03:21 . 2008-11-03 20:44 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2008-11-03 03:21 . 2008-11-03 03:21 d——– c:\documents and settings\All Users\Application Data\SITEguard
2008-11-02 13:00 . 2008-11-05 16:02 d——– c:\documents and settings\NetworkService\Application Data\AVGTOOLBAR
2008-10-31 18:28 . 2008-10-31 18:28 d——– c:\program files\WinAVIVideoConverter
2008-10-10 14:33 . 2008-10-10 14:33 d——– c:\documents and settings\HP_Administrator\Application Data\Media Player Classic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-08 20:59 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\Hamachi
2008-11-08 16:22 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\uTorrent
2008-11-08 03:53 ——— d—–w c:\program files\WarCraft III
2008-11-08 01:55 ——— d—–w c:\program files\Garena
2008-11-05 22:30 ——— d—–w c:\program files\EternityRO
2008-11-05 21:19 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-11-05 18:10 ——— d—–w c:\documents and settings\All Users\Application Data\HP
2008-11-02 23:25 ——— d—–w c:\program files\uTorrent
2008-11-01 02:29 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\dvdcss
2008-10-30 19:35 ——— d—–w c:\program files\EuphRO
2008-10-10 20:05 ——— d—–w c:\program files\Combined Community Codec Pack
2008-10-02 19:21 ——— d—–w c:\program files\NVIDIA nTune Performance Application
2008-10-02 19:21 ——— d—–w c:\program files\NVIDIA Corporation
2008-10-02 19:09 22,328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-02 19:09 22,328 —-a-w c:\documents and settings\HP_Administrator\Application Data\PnkBstrK.sys
2008-10-02 19:08 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-02 18:15 ——— d—–w c:\program files\Activision
2008-09-15 05:29 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-09-15 05:26 ——— d—–w c:\program files\Lavasoft
2008-09-15 05:26 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-09-12 16:58 ——— d—–w c:\program files\Windows Live Safety Center
2008-09-10 13:58 ——— d—–w c:\program files\MSN Messenger
2008-09-10 13:58 ——— d—–w c:\program files\Messenger Plus! Live
2008-09-06 15:08 394 —-a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2008-09-06 15:06 56,032 —-a-w c:\documents and settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-09-29 06:38 251 —-a-w c:\program files\wt3d.ini
.
((((((((((((((((((((((((((((( snapshot_2008-11-07_15.45.05.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\11-8-2008\ERDNT.EXE
+ 2008-11-08 15:52:14 13,283,328 —-a-w c:\windows\ERDNT\AutoBackup\11-8-2008\Users\
00000001\ntuser.dat
+ 2008-11-08 15:52:14 2,985,984 —-a-w c:\windows\ERDNT\AutoBackup\11-8-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\AutoBackup\2008-11-08\ERDNT.EXE
+ 2008-11-08 20:59:38 13,303,808 —-a-w c:\windows\ERDNT\AutoBackup\2008-11-08\Users\
00000001\ntuser.dat
+ 2008-11-08 20:59:39 2,985,984 —-a-w c:\windows\ERDNT\AutoBackup\2008-11-08\Users\
00000002\UsrClass.dat
+ 2008-07-04 13:52:46 10,520 —-a-w c:\windows\system32\avgrsstx.dll
+ 2008-11-08 16:19:48 86,580 –sha-w c:\windows\system32\deniyiri.dll
+ 2008-11-08 04:19:25 86,580 ——w c:\windows\system32\kisukipe.dll
+ 2008-11-08 04:19:25 92,212 –sha-w c:\windows\system32\merumebe.dll
+ 2008-11-08 21:00:14 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_aac.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0be5b88b-ca63-4c98-8837-cdfb94e7837e}]
c:\windows\system32\lotuvowu.dll [BU]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-05-28 180269]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2003-07-13 155648]
"Smart Start UP"="c:\program files\NewSoft\Smart Start UP\PnPDetect.exe" [2003-01-21 98304]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-02 1234712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-07-11 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-04 81920]
"fumenuyero"="c:\windows\system32\memilimi.dll" [BU]
"34d4f0c4"="c:\windows\system32\deniyiri.dll" [2008-11-08 86580]
"CPM37e7c358"="c:\windows\system32\nigobani.dll" [BU]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2007-12-04 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2008-06-08 625952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless USB Utility.lnk - c:\program files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe [2005-10-28 1404928]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-05-28 36903]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\nigobani.dll" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nigobani.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.NSVI"= NSVIDEO.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\patchget.dat"=
"c:\\Ntreev\\Grand Chase\\main.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\WarCraft III\\lancraft.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\WINDOWS\\ehome\\ehtray.exe"=
"c:\\Program Files\\MSN Messenger\\usnsvc.exe"=
R0 Achernar;Achernar - SCSI Command Filters;c:\windows\system32\Drivers\Achernar.sys [2004-02-11 16855]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-30 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-07-04 76040]
R3 Aldebaran;Aldebaran - SCSI Command Filters;c:\windows\system32\Drivers\Aldebaran.sys [2004-02-11 21808]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2006-09-26 21920]
S2 Ca536av;FashionCam Video Camera Device;c:\windows\system32\Drivers\Ca536av.sys [2003-09-05 514859]
S2 RPCM;Remote Procedure Manager(TPM);c:\program files\Common Files\Microsoft Shared\Speech\csvde.exe [ ]
S3 npkycryp;npkycryp;c:\documents and settings\HP_Administrator\Desktop\Stuff\Ragnorok\EuphRO\npkycryp.sys [ ]
S3 USBCamera;FashionCam Digital Still Camera Device;c:\windows\system32\Drivers\Bulk536.sys [2003-05-14 11048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-11-08 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ttfh0r5c.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF -: plugin - c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmnqmp07030901.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-08 14:58:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\system32\iriyined.ini 121 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: c:\windows\explorer.exe
-> ?:\windows\System32\CSCDLL.dll
.
———————— Other Running Processes ————————
.
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\dllhost.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2008-11-08 15:04:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-08 21:04:04
ComboFix2.txt 2008-11-08 00:14:17
ComboFix3.txt 2008-11-07 21:45:48
ComboFix4.txt 2008-11-04 02:11:37
Pre-Run: 156,714,946,560 bytes free
Post-Run: 156,683,612,160 bytes free
268 — E O F — 2008-11-01 10:48:44