Bear4541
Topic Starter
Hello my name is Ryan (WPB Florida). I'm having a heck of a time trying to get rid of some annoying files. I've tryed everything time to ask for help.CAN SOMEONE PLEASE HELP.LOL. My hairs fallin out.
ComboFix 08-12-02.02 - Maja 2008-12-04 2:20:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.222 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Maja\Local Settings\Temporary Internet Files\PwrDvdPlayerSetup.exe
c:\windows\system32\ewagurom.ini
c:\windows\system32\feyujafi.dll
c:\windows\system32\hisekeke.dll
c:\windows\system32\ifajuyef.ini
c:\windows\system32\ihugufek.ini
c:\windows\system32\itofibak.ini
c:\windows\system32\jakegetu.dll
c:\windows\system32\kefuguhi.dll
c:\windows\system32\muhodogu.dll
c:\windows\system32\nuyakete.dll
c:\windows\system32\pasagami.dll
c:\windows\system32\qgcasdgjatvgf.dll
c:\windows\system32\siruguhu.dll
c:\windows\system32\uhuguris.ini
c:\windows\system32\wegubeva.dll
c:\windows\system32\wuyeligo.dll
—– BITS: Possible infected sites —–
hxxp://77.74.48.105
.
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.
2008-12-04 00:36 . 2008-12-04 00:36 d——– c:\program files\PC Drivers HeadQuarters
2008-12-04 00:36 . 2008-12-04 00:36 d——– c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-12-03 23:49 . 2008-12-04 00:38 d–h—– C:\$AVG8.VAULT$
2008-12-03 23:01 . 2008-12-03 23:02 d——– c:\program files\Remove on Reboot
2008-12-03 18:48 . 2008-12-04 01:19 d——– c:\program files\Tweak-XP
2008-12-03 18:47 . 2008-12-03 18:47 d——– c:\program files\Common Files\Wise Installation Wizard
2008-12-03 18:47 . 2008-12-03 18:47 764 –a—— c:\windows\txp-lcn.ini
2008-12-03 17:47 . 2008-12-03 17:51 d——– c:\program files\Spyware Doctor
2008-12-03 17:47 . 2008-12-03 17:47 d——– c:\documents and settings\Maja\Application Data\PC Tools
2008-12-03 17:47 . 2008-12-03 23:05 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-03 17:47 . 2008-08-25 12:36 81,288 –a—— c:\windows\system32\drivers\iksyssec.sys
2008-12-03 17:47 . 2008-08-25 12:36 66,952 –a—— c:\windows\system32\drivers\iksysflt.sys
2008-12-03 17:47 . 2008-08-25 12:36 40,840 –a—— c:\windows\system32\drivers\ikfilesec.sys
2008-12-03 17:47 . 2008-06-02 16:19 29,576 –a—— c:\windows\system32\drivers\kcom.sys
2008-12-03 04:17 . 2007-08-01 22:47 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-12-03 03:48 . 2008-12-03 03:48 d——– c:\program files\Dr Watson
2008-12-03 01:04 . 2008-12-03 02:47 d——– c:\documents and settings\Maja\.housecall6.6
2008-12-02 04:36 . 2008-12-02 04:37 d——– c:\program files\Copernic Desktop Search - Home
2008-12-02 04:23 . 2008-12-03 23:37 d——– c:\windows\system32\drivers\Avg
2008-12-02 04:23 . 2008-12-03 23:37 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-12-02 04:23 . 2008-12-03 23:37 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-12-02 02:47 . 2008-12-02 03:39 153 –a—— c:\windows\wininit.ini
2008-12-02 02:22 . 2008-12-02 02:22 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-02 02:21 . 2008-12-02 02:21 d——– c:\program files\Spybot - Search & Destroy
2008-12-02 01:05 . 2002-08-29 14:00 489,984 –a—— c:\windows\system32\hypertrm.dll
2008-12-02 01:04 . 2008-12-02 01:11 d——– C:\Inetpub
2008-12-02 00:35 . 2008-12-03 18:58 101,520,382 –a—— C:\Ryans bak.reg
2008-12-02 00:31 . 2008-12-02 00:31 10,520 ——— c:\windows\system32\avgrsstx.dll.install_backup
2008-12-02 00:30 . 2008-12-02 04:02 d——– c:\program files\AVG
2008-12-02 00:30 . 2008-12-02 04:23 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-02 00:19 . 2008-12-02 00:19 d——– c:\program files\Panicware
2008-12-01 21:10 . 2001-08-17 13:48 12,160 –a—— c:\windows\system32\drivers\mouhid.sys
2008-12-01 21:10 . 2001-08-17 13:48 12,160 –a–c— c:\windows\system32\dllcache\mouhid.sys
2008-12-01 19:18 . 2008-12-02 00:33 d——– C:\327882R2FWJFW
2008-11-21 22:57 . 2008-11-21 22:57 d——– c:\program files\Phantombility
2008-11-06 10:30 . 2008-11-06 10:30 2,870 –a—— c:\windows\MDVDP.Ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 05:37 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-03 06:56 ——— d—–w c:\program files\RegistryDoctor2008
2008-12-02 06:57 ——— d—–w c:\program files\Yahoo!
2008-12-02 02:28 ——— d—–w c:\program files\Symantec_Client_Security
2008-12-02 02:27 ——— d—–w c:\program files\Symantec
2008-12-02 02:26 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-12-02 02:10 ——— d—–w c:\program files\AskTBar
2008-12-01 23:19 ——— d—–w c:\documents and settings\Maja\Application Data\LimeWire
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-19 12:30 ——— d—–w c:\documents and settings\Maja\Application Data\Nero
2008-10-19 04:25 ——— d—–w c:\program files\Common Files\Nero
2008-10-19 03:57 ——— d—–w c:\program files\Windows Sidebar
2008-10-19 03:48 ——— d—–w c:\documents and settings\All Users\Application Data\Nero
2008-10-19 02:44 ——— d—–w c:\program files\Ahead
2008-10-18 01:27 ——— d—–w c:\program files\Sun
2008-10-18 01:27 ——— d—–w c:\program files\Java
2008-10-18 01:26 ——— d—–w c:\program files\Common Files\Java
2008-10-18 01:24 ——— d—–w c:\program files\LimeWire
2008-10-14 03:12 ——— d—–w c:\documents and settings\Maja\Application Data\VirusRemover2008
2008-10-12 23:49 ——— d—–w c:\documents and settings\All Users\Application Data\dqhyzmxi
2008-10-12 23:49 ——— d—–w c:\documents and settings\All Users\Application Data\dilgfory
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe" [2003-10-29 524288]
"BlockAds"="c:\program files\Tweak-XP\blads.exe" [2001-09-02 45056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-03 1261336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Copernic Desktop Search - Home]
–a—— 2008-08-28 14:05 1520640 c:\program files\Copernic Desktop Search - Home\DesktopSearchService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
–a—— 2006-07-02 23:50 700416 c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
–a—— 2008-08-25 12:36 1168264 c:\program files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"NISUM"=3 (0x3)
"NISSERV"=2 (0x2)
"MDM"=2 (0x2)
"idsvc"=3 (0x3)
"gusvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"ACS"=2 (0x2)
"SymPxSvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"EvtEng"=2 (0x2)
"RegSrvc"=2 (0x2)
"S24EventMonitor"=2 (0x2)
"sdAuxService"=2 (0x2)
"sdCoreService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\S24EvMon.exe"=
"c:\\Program Files\\Symantec_Client_Security\\Symantec Client Firewall\\SymPxSvc.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\EvtEng.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgui.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\services.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgwdsvc.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero BackItUp 4\\NBService.exe"=
"c:\\Program Files\\Tweak-XP\\Blads.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-02 97928]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-02 231704]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
S4 NISSERV;Symantec Client Firewall Service;"c:\program files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE" [2003-05-21 79064]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-03 356920]
.
- - - - ORPHANS REMOVED - - - -
BHO-{6cce8ab6-052f-4d10-a866-6bbab0694581} - c:\windows\system32\jakegetu.dll
BHO-{c08eeea3-ddec-3c8d-c8f2-1ebbd8e0f366} - c:\windows\system32\nszF.dll
HKLM-Explorer_Run-Trb65SKVCb - c:\docume~1\Maja\LOCALS~1\Temp\9llCJ4amiU.exe
MSConfigStartUp-CPMe3189b72 - c:\windows\system32\pasagami.dll
MSConfigStartUp-e02ba8ee - c:\windows\system32\feyujafi.dll
MSConfigStartUp-zuniremeru - c:\windows\system32\muhodogu.dll
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 02:25:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\DVDRAMSV.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-12-04 2:27:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 07:27:19
Pre-Run: 240,666,361,856 bytes free
Post-Run: 240,578,842,624 bytes free
190 — E O F — 2008-11-14 17:34:23
———————————————————————————————————————–
AND:
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
Adobe Shockwave Player
Atheros Client Utility
Atheros Client Utility
Atheros Wireless LAN MiniPCI/PCIe card Driver
ATI - Software Uninstall Utility
AVG Free 8.0
AVS DVD Player version 2.4
AVS4YOU Software Navigator 1.2
Bonjour
Copernic Desktop Search - Home
Driver Detective
DVD-RAM Driver
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
hp deskjet 3600
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
Java™ 6 Update 7
LimeWire 4.18.8
mCore
mDrWiFi
mHelp
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
mIWA
mLogView
mMHouse
mPfMgr
mPfWiz
mProSafe
MSN
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
mWlsSafe
mXML
mZConfig
Nero 9 Trial
neroxml
OpenOffice.org Installer 1.0
Phantom Burner
Pop-Up Stopper Free Edition
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Remove on Reboot Shell Extension
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Sonic Encoders
Spyware Doctor 6.0
Symantec Client Firewall
Synaptics Pointing Device Driver
TOSHIBA Virtual Sound
Tweak-XP
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB925876)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Darn i forgot to add that i tryed avg,spybot s&d,Trendmicro,removeONreboot,and ect….,none of the any of them will download updates.all updates for all programs fail, but IE surfs fine
I hope I posted this right.I was reading a posting similar. 1st time.
Thanks
ComboFix 08-12-02.02 - Maja 2008-12-04 2:20:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.222 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Maja\Local Settings\Temporary Internet Files\PwrDvdPlayerSetup.exe
c:\windows\system32\ewagurom.ini
c:\windows\system32\feyujafi.dll
c:\windows\system32\hisekeke.dll
c:\windows\system32\ifajuyef.ini
c:\windows\system32\ihugufek.ini
c:\windows\system32\itofibak.ini
c:\windows\system32\jakegetu.dll
c:\windows\system32\kefuguhi.dll
c:\windows\system32\muhodogu.dll
c:\windows\system32\nuyakete.dll
c:\windows\system32\pasagami.dll
c:\windows\system32\qgcasdgjatvgf.dll
c:\windows\system32\siruguhu.dll
c:\windows\system32\uhuguris.ini
c:\windows\system32\wegubeva.dll
c:\windows\system32\wuyeligo.dll
—– BITS: Possible infected sites —–
hxxp://77.74.48.105
.
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.
2008-12-04 00:36 . 2008-12-04 00:36 d——– c:\program files\PC Drivers HeadQuarters
2008-12-04 00:36 . 2008-12-04 00:36 d——– c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-12-03 23:49 . 2008-12-04 00:38 d–h—– C:\$AVG8.VAULT$
2008-12-03 23:01 . 2008-12-03 23:02 d——– c:\program files\Remove on Reboot
2008-12-03 18:48 . 2008-12-04 01:19 d——– c:\program files\Tweak-XP
2008-12-03 18:47 . 2008-12-03 18:47 d——– c:\program files\Common Files\Wise Installation Wizard
2008-12-03 18:47 . 2008-12-03 18:47 764 –a—— c:\windows\txp-lcn.ini
2008-12-03 17:47 . 2008-12-03 17:51 d——– c:\program files\Spyware Doctor
2008-12-03 17:47 . 2008-12-03 17:47 d——– c:\documents and settings\Maja\Application Data\PC Tools
2008-12-03 17:47 . 2008-12-03 23:05 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-03 17:47 . 2008-08-25 12:36 81,288 –a—— c:\windows\system32\drivers\iksyssec.sys
2008-12-03 17:47 . 2008-08-25 12:36 66,952 –a—— c:\windows\system32\drivers\iksysflt.sys
2008-12-03 17:47 . 2008-08-25 12:36 40,840 –a—— c:\windows\system32\drivers\ikfilesec.sys
2008-12-03 17:47 . 2008-06-02 16:19 29,576 –a—— c:\windows\system32\drivers\kcom.sys
2008-12-03 04:17 . 2007-08-01 22:47 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-12-03 03:48 . 2008-12-03 03:48 d——– c:\program files\Dr Watson
2008-12-03 01:04 . 2008-12-03 02:47 d——– c:\documents and settings\Maja\.housecall6.6
2008-12-02 04:36 . 2008-12-02 04:37 d——– c:\program files\Copernic Desktop Search - Home
2008-12-02 04:23 . 2008-12-03 23:37 d——– c:\windows\system32\drivers\Avg
2008-12-02 04:23 . 2008-12-03 23:37 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-12-02 04:23 . 2008-12-03 23:37 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-12-02 02:47 . 2008-12-02 03:39 153 –a—— c:\windows\wininit.ini
2008-12-02 02:22 . 2008-12-02 02:22 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-02 02:21 . 2008-12-02 02:21 d——– c:\program files\Spybot - Search & Destroy
2008-12-02 01:05 . 2002-08-29 14:00 489,984 –a—— c:\windows\system32\hypertrm.dll
2008-12-02 01:04 . 2008-12-02 01:11 d——– C:\Inetpub
2008-12-02 00:35 . 2008-12-03 18:58 101,520,382 –a—— C:\Ryans bak.reg
2008-12-02 00:31 . 2008-12-02 00:31 10,520 ——— c:\windows\system32\avgrsstx.dll.install_backup
2008-12-02 00:30 . 2008-12-02 04:02 d——– c:\program files\AVG
2008-12-02 00:30 . 2008-12-02 04:23 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-02 00:19 . 2008-12-02 00:19 d——– c:\program files\Panicware
2008-12-01 21:10 . 2001-08-17 13:48 12,160 –a—— c:\windows\system32\drivers\mouhid.sys
2008-12-01 21:10 . 2001-08-17 13:48 12,160 –a–c— c:\windows\system32\dllcache\mouhid.sys
2008-12-01 19:18 . 2008-12-02 00:33 d——– C:\327882R2FWJFW
2008-11-21 22:57 . 2008-11-21 22:57 d——– c:\program files\Phantombility
2008-11-06 10:30 . 2008-11-06 10:30 2,870 –a—— c:\windows\MDVDP.Ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 05:37 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-03 06:56 ——— d—–w c:\program files\RegistryDoctor2008
2008-12-02 06:57 ——— d—–w c:\program files\Yahoo!
2008-12-02 02:28 ——— d—–w c:\program files\Symantec_Client_Security
2008-12-02 02:27 ——— d—–w c:\program files\Symantec
2008-12-02 02:26 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-12-02 02:10 ——— d—–w c:\program files\AskTBar
2008-12-01 23:19 ——— d—–w c:\documents and settings\Maja\Application Data\LimeWire
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-19 12:30 ——— d—–w c:\documents and settings\Maja\Application Data\Nero
2008-10-19 04:25 ——— d—–w c:\program files\Common Files\Nero
2008-10-19 03:57 ——— d—–w c:\program files\Windows Sidebar
2008-10-19 03:48 ——— d—–w c:\documents and settings\All Users\Application Data\Nero
2008-10-19 02:44 ——— d—–w c:\program files\Ahead
2008-10-18 01:27 ——— d—–w c:\program files\Sun
2008-10-18 01:27 ——— d—–w c:\program files\Java
2008-10-18 01:26 ——— d—–w c:\program files\Common Files\Java
2008-10-18 01:24 ——— d—–w c:\program files\LimeWire
2008-10-14 03:12 ——— d—–w c:\documents and settings\Maja\Application Data\VirusRemover2008
2008-10-12 23:49 ——— d—–w c:\documents and settings\All Users\Application Data\dqhyzmxi
2008-10-12 23:49 ——— d—–w c:\documents and settings\All Users\Application Data\dilgfory
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe" [2003-10-29 524288]
"BlockAds"="c:\program files\Tweak-XP\blads.exe" [2001-09-02 45056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-03 1261336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Copernic Desktop Search - Home]
–a—— 2008-08-28 14:05 1520640 c:\program files\Copernic Desktop Search - Home\DesktopSearchService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
–a—— 2006-07-02 23:50 700416 c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
–a—— 2008-08-25 12:36 1168264 c:\program files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"NISUM"=3 (0x3)
"NISSERV"=2 (0x2)
"MDM"=2 (0x2)
"idsvc"=3 (0x3)
"gusvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"ACS"=2 (0x2)
"SymPxSvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"EvtEng"=2 (0x2)
"RegSrvc"=2 (0x2)
"S24EventMonitor"=2 (0x2)
"sdAuxService"=2 (0x2)
"sdCoreService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\S24EvMon.exe"=
"c:\\Program Files\\Symantec_Client_Security\\Symantec Client Firewall\\SymPxSvc.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\EvtEng.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgui.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\services.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgwdsvc.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero BackItUp 4\\NBService.exe"=
"c:\\Program Files\\Tweak-XP\\Blads.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-02 97928]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-02 231704]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
S4 NISSERV;Symantec Client Firewall Service;"c:\program files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE" [2003-05-21 79064]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-03 356920]
.
- - - - ORPHANS REMOVED - - - -
BHO-{6cce8ab6-052f-4d10-a866-6bbab0694581} - c:\windows\system32\jakegetu.dll
BHO-{c08eeea3-ddec-3c8d-c8f2-1ebbd8e0f366} - c:\windows\system32\nszF.dll
HKLM-Explorer_Run-Trb65SKVCb - c:\docume~1\Maja\LOCALS~1\Temp\9llCJ4amiU.exe
MSConfigStartUp-CPMe3189b72 - c:\windows\system32\pasagami.dll
MSConfigStartUp-e02ba8ee - c:\windows\system32\feyujafi.dll
MSConfigStartUp-zuniremeru - c:\windows\system32\muhodogu.dll
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 02:25:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\DVDRAMSV.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-12-04 2:27:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 07:27:19
Pre-Run: 240,666,361,856 bytes free
Post-Run: 240,578,842,624 bytes free
190 — E O F — 2008-11-14 17:34:23
———————————————————————————————————————–
AND:
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
Adobe Shockwave Player
Atheros Client Utility
Atheros Client Utility
Atheros Wireless LAN MiniPCI/PCIe card Driver
ATI - Software Uninstall Utility
AVG Free 8.0
AVS DVD Player version 2.4
AVS4YOU Software Navigator 1.2
Bonjour
Copernic Desktop Search - Home
Driver Detective
DVD-RAM Driver
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
hp deskjet 3600
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
Java™ 6 Update 7
LimeWire 4.18.8
mCore
mDrWiFi
mHelp
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
mIWA
mLogView
mMHouse
mPfMgr
mPfWiz
mProSafe
MSN
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
mWlsSafe
mXML
mZConfig
Nero 9 Trial
neroxml
OpenOffice.org Installer 1.0
Phantom Burner
Pop-Up Stopper Free Edition
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Remove on Reboot Shell Extension
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Sonic Encoders
Spyware Doctor 6.0
Symantec Client Firewall
Synaptics Pointing Device Driver
TOSHIBA Virtual Sound
Tweak-XP
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB925876)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Darn i forgot to add that i tryed avg,spybot s&d,Trendmicro,removeONreboot,and ect….,none of the any of them will download updates.all updates for all programs fail, but IE surfs fine
I hope I posted this right.I was reading a posting similar. 1st time.
Thanks