So I ran LSPFix and combofix and there don't appear any apparent signs of the virus now (desktop has been restored and the tast manager function has been restored). Combofix found 6 rootkit files (which I wrote down if they're relevant. However, I can no longer access the internet (I was using WIFI before). I know it's not a network problem because I'm able to access the same network with my work laptop. Also, while my laptop was idle, I got a weird message that popped up. It said that the 'NT Authority System' found there was a problem with the 'DCOM Server Process Launcher' and forced my computer to restart.
Anyways, here are the report you asked me to include:
C:\ComboFix.txt:
ComboFix 09-02-02.04 - Bernlum 2009-02-03 17:06:55.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.502.241 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Bernlum\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Bernlum\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\Bernlum\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\program files\Altnet
c:\program files\Altnet\DBBackup\file-10001-128.sig
c:\program files\Altnet\DBBackup\Sigfiles.db
c:\program files\Altnet\Download Manager\dminfo3.cab
c:\program files\Altnet\Download Manager\dminstall7.cab
c:\program files\Altnet\Download Manager\dmsetup.bmp
c:\program files\Altnet\Download Manager\dmsetupbig.bmp
c:\program files\Altnet\Download Manager\jsinstall.cab
c:\program files\Altnet\Download Manager\jslegals.txt
c:\program files\Altnet\Download Manager\selectdir.txt
c:\program files\Altnet\Download Manager\selectdir1st.txt
c:\program files\Instafinder
c:\program files\Instafinder\uninstall.exe
c:\program files\MorpheusBar\bar\1.bin\M0PLUGIN.DLL
c:\program files\MorpheusBar\bar\1.bin\M0POPSWT.DLL
c:\program files\MorpheusBar\bar\1.bin\NPMORPBR.DLL
c:\program files\Mozilla Firefox\plugins\NPMorpBr.dll
c:\program files\Need2Find
c:\program files\Need2Find\bar\1.bin\N2FFXTBR.JAR
c:\program files\Need2Find\bar\1.bin\N2NTSTBR.JAR
c:\program files\Need2Find\bar\1.bin\PARTNER.DAT
c:\program files\Need2Find\bar\Cache\
0003A190
c:\program files\Need2Find\bar\Cache\
0003A549
c:\program files\Need2Find\bar\Cache\files.ini
c:\program files\Need2Find\bar\History\search
c:\program files\Need2Find\bar\Settings\prevcfg.htm
c:\windows\adaway.lic
c:\windows\Fonts\acrsecB.fon
c:\windows\Fonts\acrsecI.fon
c:\windows\hosts
c:\windows\services.exe
c:\windows\smdat32a.sys
c:\windows\smdat32m.sys
c:\windows\system32\303374.exe
c:\windows\system32\ahtn.htm
c:\windows\system32\arhphhjx.ini
c:\windows\system32\autorun.ini
c:\windows\system32\B.tmp
c:\windows\system32\BdLUCJlm.ini
c:\windows\system32\BdLUCJlm.ini2
c:\windows\system32\bstmyuik.dll
c:\windows\system32\bywbrpfy.ini
c:\windows\system32\C.tmp
c:\windows\system32\djmgshcx.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekapyprtubq.sys
c:\windows\system32\ewjvadsj.ini
c:\windows\system32\exkejjvh.dll
c:\windows\system32\fhqnqkhk.dll
c:\windows\system32\frmwrk32.exe
c:\windows\system32\hqopteuk.ini
c:\windows\system32\hvhjkeyk.dll
c:\windows\system32\ihjemydu.ini
c:\windows\system32\jcayovlk.dll
c:\windows\system32\jxlaeyhe.ini
c:\windows\system32\kfgxlu.dll
c:\windows\system32\kuetpoqh.dll
c:\windows\system32\lksytiai.ini
c:\windows\system32\miozaz.dll
c:\windows\system32\mssvnn.dll
c:\windows\system32\mtgvfyal.ini
c:\windows\system32\mybaqbdf.ini
c:\windows\system32\ndremirh.ini
c:\windows\system32\ntdll64.exe
c:\windows\system32\nwaykdjw.ini
c:\windows\system32\packet.dll
c:\windows\system32\pcsiqqkh.ini
c:\windows\system32\pfypbeou.dll
c:\windows\system32\pgwief.dll
c:\windows\system32\pmnlifff.dll
c:\windows\system32\popbnock.dll
c:\windows\system32\pshyorbm.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\PXbeLRqr.ini
c:\windows\system32\PXbeLRqr.ini2
c:\windows\system32\rhksuwvl.dll
c:\windows\system32\rqRIaWOF.dll
c:\windows\system32\rqRLebXP.dll
c:\windows\system32\rsdbjyow.dll
c:\windows\system32\rsDNoUvw.ini
c:\windows\system32\rsDNoUvw.ini2
c:\windows\system32\rskggamy.dll
c:\windows\system32\ruzbnq.dll
c:\windows\system32\senekabnrevqkk.dll
c:\windows\system32\senekabpywqjse.dat
c:\windows\system32\senekadjbappej.dll
c:\windows\system32\senekakfmbyfrm.dll
c:\windows\system32\senekapop.dll
c:\windows\system32\senekapxmyxidv.dat
c:\windows\system32\test.ttt
c:\windows\system32\uniq.tll
c:\windows\system32\warning.gif
c:\windows\system32\win32hlp.cnf
c:\windows\system32\woyjbdsr.ini
c:\windows\system32\wpcap.dll
c:\windows\system32\wvUoNDsr.dll.vir
c:\windows\system32\xxyyaxxx.dll
c:\windows\system32\yfprbwyb.dll
c:\windows\system32\ytypqfih.ini
c:\windows\Temp\1.EXE
c:\windows\system32\userinit.exe . . . is infected!!
c:\windows\system32\spoolsv.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_SENEKA
——-\Service_SENEKA
——-\Legacy_PROTECT
——-\Service_NPF
——-\Service_Passthru
——-\Service_protect
((((((((((((((((((((((((( Files Created from 2009-01-04 to 2009-02-04 )))))))))))))))))))))))))))))))
.
2009-02-03 17:00 . 2009-02-03 17:00 0 –a—— c:\windows\system32\5.tmp
2009-02-03 16:44 . 2009-02-03 16:44 32,768 –ah—– c:\documents and settings\Bernlum\vijpfl.exe
2009-02-03 16:44 . 2009-02-03 16:44 1,748 –a—— c:\windows\system32\netsf.inf
2009-02-03 16:44 . 2009-02-03 16:44 695 –a—— c:\windows\system32\netsf_m.inf
2009-02-03 16:23 . 2009-02-03 16:23 d——– c:\program files\XPPoliceAntivirus
2009-02-03 16:23 . 2009-02-03 16:23 79,878 –a—— c:\windows\system32\xp-dc-av.exe
2009-02-03 16:23 . 2009-02-03 16:23 15,360 –a—— c:\windows\iehost.dll
2009-02-03 16:21 . 33,920 c:\windows\system32\drivers\aazzsjzd.sys
2009-02-03 16:15 . 2009-02-03 16:15 137,280 –a—— c:\windows\system32\drivers\ethbgkwk.sys
2009-02-03 16:15 . 2009-02-03 16:15 3,584 –a—— c:\windows\hdicvyrf.exe
2009-02-03 16:10 . 66,560 c:\windows\system32\secupdat.dat
2009-02-03 16:10 . 2009-02-03 16:10 32,768 –ah—– c:\documents and settings\Bernlum\igix.exe
2009-02-03 07:02 . 2009-02-03 07:02 207,360 –a—— c:\program files\LSPFix.exe
2009-02-03 03:20 . 53,248 c:\windows\system32\drivers\ndisio.sys
2009-02-02 21:32 . 2009-02-02 21:32 0 –a—— c:\windows\system32\17.tmp
2009-02-02 21:19 . 2009-02-02 21:19 d——– c:\program files\ERUNT
2009-02-02 21:05 . 2009-02-02 21:05 d——– C:\Rustbfix
2009-02-02 21:02 . 2009-02-02 21:02 812,344 –a—— c:\program files\HJTInstall.exe
2009-02-02 18:22 . 2009-02-02 18:22 d——– c:\program files\Common Files\PC Tools
2009-02-02 17:16 . 2009-02-03 03:21 124 –a—— c:\windows\adobe.bat
2009-02-02 17:16 . 2009-02-02 17:20 5 –a—— c:\windows\_id.dat
2009-02-02 17:07 . 2009-02-02 17:07 128,306 –a—— c:\windows\system32\126_av.exe
2009-02-02 07:05 . 2008-12-16 15:19 4,096 –a—— c:\windows\system32\drivers\Start2Driver.SYS
2009-02-02 06:41 . 2009-02-02 06:41 0 –a—— c:\windows\system32\10.tmp
2009-02-02 06:36 . 2009-02-02 06:36 d——– c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR
2009-02-01 19:32 . 2009-02-01 19:32 d——– c:\documents and settings\All Users\Application Data\TEMP
2009-02-01 15:00 . 2009-02-01 15:00 1,152 –a—— c:\windows\system32\windrv.sys
2009-02-01 14:59 . 2009-02-01 14:59 d——– c:\program files\Common Files\Download Manager
2009-02-01 11:07 . 2009-02-01 11:07 61,440 –a—— c:\windows\system32\chert13-303374.exe
2009-02-01 06:26 . 2009-02-01 06:26 0 –a—— c:\windows\system32\26.tmp
2009-01-31 11:29 . 2009-01-31 11:29 52,736 –a—— c:\windows\system32\euffnmna.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 23:42 90,112 —-a-w c:\windows\DUMP803c.tmp
2009-02-01 17:52 142,848 —-a-w c:\windows\system32\userinit.exe
2009-02-01 17:52 142,848 —-a-w c:\windows\system32\dllcache\userinit.exe
2009-01-31 21:52 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-31 21:52 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-31 21:52 10,520 —-a-w c:\windows\system32\avgrsstx.dll
2008-12-13 05:38 ——— d—–w c:\program files\iTunes
2008-12-13 05:38 ——— d—–w c:\program files\iPod
2008-12-13 05:38 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-13 05:29 ——— d—–w c:\program files\Bonjour
2008-12-12 17:33 3,060,224 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\dllcache\srv.sys
2008-11-25 01:14 107,888 —-a-w c:\windows\system32\CmdLineExt.dll
2008-11-08 01:32 2,109,440 —-a-w c:\windows\system32\dllcache\WMVCore.dll
2008-06-15 23:14 48,831,512 —-a-w c:\program files\avg_free_stf_en_8_100a1323.exe
2008-06-15 21:54 36 —-a-w c:\documents and settings\Bernlum\klextlock.dat
2008-05-17 17:37 1,495,112 —-a-w c:\program files\install_flash_player.exe
2008-05-17 17:31 185,008 —-a-w c:\program files\uninstall_flash_player.exe
2007-03-22 14:54 15,436,440 —-a-w c:\documents and settings\All Users\zapSetup_70_337_000_en.exe
2006-03-28 06:11 6,883,122 —-a-w c:\program files\BitTorrent-Stable.exe
2005-08-17 05:45 899,414 —-a-w c:\program files\SetupDVDDecrypter_3.5.4.0.exe
2009-01-01 23:38 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-01 23:38 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-01 23:38 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-01 23:38 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-01 23:38 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
——- Sigcheck ——-
2007-06-13 03:23 1050624 17513e42330b665d3d88eca65659ecf9 c:\windows\explorer.exe
2007-06-13 03:23 1050624 726a4a3d49b9f3cd8d42a203e2e08b41 c:\windows\system32\dllcache\explorer.exe
2008-04-13 18:12 1051136 e183fb7d75e86a4e09c20f0cf6b3b1d7 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2007-06-13 04:26 1050624 cb63b252210ff0afe9e05490bae916e9 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-04 05:00 1049600 6954a3f58f570cade58186dd5fc4923e c:\windows\$NtUninstallKB938828$\explorer.exe
2004-08-04 05:00 32768 77e2d97fae6aafda9390ad5056e4967c c:\windows\system32\ctfmon.exe
2004-08-04 05:00 32768 61583e3c0c3bb75fb2a8f4a2729d832f c:\windows\system32\dllcache\ctfmon.exe
2008-04-13 18:12 32768 76a819ca7a768c0595bc62d463f0c8bb c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2005-06-10 16:53 75264 1ef589a9b6de7114f8a4903831fcbd16 c:\windows\system32\spoolsv.exe
2005-06-10 16:53 75264 949ccd700c00c8a7df0aeb2a5c15df39 c:\windows\system32\dllcache\spoolsv.exe
2008-04-13 18:12 75264 f942092048bf42617051b45d90669113 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
2005-06-10 17:17 75264 181f8c7f597a5a311f0218c1507cf156 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2004-08-04 05:00 75264 ba9ed66a303bd2ec3b5ca4925594dd89 c:\windows\$NtUninstallKB896423$\spoolsv.exe
2009-02-01 10:52 142848 40775db3c07559628b4caff43c84b49c c:\windows\system32\userinit.exe
2009-02-01 10:52 142848 40775db3c07559628b4caff43c84b49c c:\windows\system32\dllcache\userinit.exe
2008-04-13 18:12 43520 77f0c779937fc5cff0f660fbe6cad156 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-03-28 208896]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-24 2900480]
"eRecoveryService"="c:\windows\System32\Check.exe" [2005-03-23 266240]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-02-08 147456]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2008-11-04 434176]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"hdicvyrf.exe"="c:\windows\hdicvyrf.exe" [2009-02-03 3584]
"PoliceAV"="c:\program files\XPPoliceAntivirus\xppolice.exe" [2009-02-03 1312768]
c:\documents and settings\Bernlum\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 58368]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 14:52 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll pgwief.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aazzsjzd.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"="1"
"FirewallOverride"=dword:00000001
"AntiVirusDisableNotify"="1"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Acrochallenge\\acrochallenge.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 aazzsjzd;aazzsjzd;c:\windows\system32\Drivers\aazzsjzd.sys –> c:\windows\system32\Drivers\aazzsjzd.sys [?]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-06-15 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-06-15 107272]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-09-10 903960]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-09-10 298264]
R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2005-08-12 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2005-08-12 78208]
R2 Start2Driver;Start2Driver;c:\windows\system32\drivers\Start2Driver.SYS [2009-02-02 4096]
S1 ethbgkwk;ethbgkwk;c:\windows\system32\drivers\ethbgkwk.sys [2009-02-03 137280]
S1 ethcyevp;ethcyevp;c:\windows\system32\drivers\ethcyevp.sys –> c:\windows\system32\drivers\ethcyevp.sys [?]
S1 ethdiwxk;ethdiwxk;c:\windows\system32\drivers\ethdiwxk.sys –> c:\windows\system32\drivers\ethdiwxk.sys [?]
S1 ethejrsq;ethejrsq;c:\windows\system32\drivers\ethejrsq.sys –> c:\windows\system32\drivers\ethejrsq.sys [?]
S1 ethetxtw;ethetxtw;c:\windows\system32\drivers\ethetxtw.sys –> c:\windows\system32\drivers\ethetxtw.sys [?]
S1 ethfguaq;ethfguaq;c:\windows\system32\drivers\ethfguaq.sys –> c:\windows\system32\drivers\ethfguaq.sys [?]
S1 ethphyvg;ethphyvg;c:\windows\system32\drivers\ethphyvg.sys –> c:\windows\system32\drivers\ethphyvg.sys [?]
S1 ethsmyhp;ethsmyhp;c:\windows\system32\drivers\ethsmyhp.sys –> c:\windows\system32\drivers\ethsmyhp.sys [?]
S1 ethvywvs;ethvywvs;c:\windows\system32\drivers\ethvywvs.sys –> c:\windows\system32\drivers\ethvywvs.sys [?]
S1 glaide32;glaide32;\??\c:\windows\system32\drivers\glaide32.sys –> c:\windows\system32\drivers\glaide32.sys [?]
S1 Start1Driver;Start1Driver; [x]
.
Contents of the 'Scheduled Tasks' folder
2009-02-03 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2009-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-02-04 c:\windows\Tasks\oldlkzau.job
- c:\windows\system32\nnnOihHa.dll []
2009-02-04 c:\windows\Tasks\widiocnr.job
- c:\windows\system32\geBuUlME.dll []
.
- - - - ORPHANS REMOVED - - - -
BHO-{1f5edaaf-48b2-41ec-b286-4a2b541194c1} - c:\windows\system32\pgwief.dll
BHO-{2A1626E5-AC92-428E-A674-838171024755} - c:\windows\system32\rqRLebXP.dll
BHO-{47F48EA6-A725-45B9-A89F-7D0C9AFDC421} - c:\windows\system32\mlJCULdB.dll
BHO-{4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - c:\program files\Need2Find\bar\1.bin\ND2FNBAR.DLL
BHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\pmnlifff.dll
BHO-{b265416b-b512-4b8b-aa86-13e2888bc0d7} - c:\windows\system32\exkejjvh.dll
BHO-{C9C42510-9B21-41c1-9DCD-8382A2D07C61} - c:\windows\system32\iehelper.dll
HKLM-Run-Hsekihumevixi - c:\windows\Kmasirumecahal.dll
HKLM-Run-Uyotuhe - c:\windows\iwiluqiz.dll
HKLM-Run-SNM - c:\program files\SpyNoMore\SNM.exe
HKU-Default-Run-phefgxrf.exe - c:\windows\phefgxrf.exe
HKU-Default-Run-fqdzhuid.exe - c:\windows\fqdzhuid.exe
HKU-Default-Run-services - c:\windows\services.exe
HKLM-Explorer_Run-services - c:\windows\services.exe
HKCU-Explorer_Run-services - c:\windows\services.exe
HKU-Default-Explorer_Run-services - c:\windows\services.exe
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\pmnlifff.dll
Notify-iifgedax - iifgedax.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://mytelus.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?6e57dbecc5f7432aa2822e9de4323594
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?6e57dbecc5f7432aa2822e9de4323594
FF - ProfilePath - c:\documents and settings\Bernlum\Application Data\Mozilla\Firefox\Profiles\2n2tzd2r.Default User8\
FF - prefs.js: browser.search.selectedEngine - Dictionary.com
FF - prefs.js: browser.startup.homepage - hxxp://www.mytelus.com/new_homepage/
FF - prefs.js: network.proxy.type - 4
FF - component: c:\progra~1\MOZILL~1\extensions\[removed]\components\qfaservices.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-03 17:14:42
Windows 5.1.2600 Service Pack 2 FAT NTAPI
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\system32\drivers\seneka.sys 0 bytes
c:\windows\system32\drivers\senekayotoitjd.sys 0 bytes
c:\windows\system32\drivers\senekautxsmdwf.sys 98304 bytes
c:\windows\system32\drivers\senekapyprtubq.sys 98304 bytes
c:\docume~1\Bernlum\LOCALS~1\Temp\seneka000 0 bytes
c:\windows\system32\senekacjiwicvv.dll 65536 bytes
c:\windows\system32\senekapop.dll 0 bytes
c:\windows\system32\senekaulnsviwq.dll 32768 bytes
c:\windows\system32\senekaqhtowpte.dll 32768 bytes
c:\windows\system32\senekadjbappej.dll 65536 bytes
c:\windows\system32\senekapxmyxidv.dat 65536 bytes
c:\windows\system32\senekabnrevqkk.dll 32768 bytes
c:\windows\system32\senekakfmbyfrm.dll 32768 bytes
c:\windows\system32\senekabpywqjse.dat 32768 bytes
c:\windows\system32\senekacksjcrgb.dat 32768 bytes
scan completed successfully
hidden files: 15
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\seneka]
"imagepath"="\systemroot\system32\drivers\senekautxsmdwf.sys"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(588)
c:\program files\Bonjour\mdnsNSP.dll
.
———————— Other Running Processes ————————
.
c:\program files\INTEL\WIRELESS\BIN\EVTENG.EXE
c:\program files\INTEL\WIRELESS\BIN\S24EVMON.EXE
c:\program files\COMMON FILES\ARCSOFT\CONNECTION SERVICE\BIN\ACSERVICE.EXE
c:\acer\EMANAGER\ANBMSERV.EXE
c:\program files\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\program files\AVG\AVG8\AVGWDSVC.EXE
c:\program files\BONJOUR\MDNSRESPONDER.EXE
c:\program files\INTEL\WIRELESS\BIN\REGSRVC.EXE
c:\program files\AVG\AVG8\AVGRSX.EXE
c:\program files\AVG\AVG8\AVGEMC.EXE
c:\program files\AVG\AVG8\AVGNSX.EXE
c:\program files\AVG\AVG8\AVGCSRVX.EXE
c:\program files\CANON\CAL\CALMAIN.EXE
c:\program files\ACER\ERECOVERY\MONITOR.EXE
c:\program files\IPOD\BIN\IPODSERVICE.EXE
.
**************************************************************************
.
Completion time: 2009-02-03 17:17:07 - machine was rebooted [Bernlum]
ComboFix-quarantined-files.txt 2009-02-04 00:17:04
Pre-Run: 6,592,626,688 bytes free
Post-Run: 7,613,415,424 bytes free
384 — E O F — 2009-01-14 23:17:31
Newest HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:23:03 PM, on 03/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\explorer.exe
C:\acer\epm\epm-dm.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://mytelus.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BhoApp Class - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\WINDOWS\iehost.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: MorpheusToolbar BHO - {3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Morpheus Toolbar - {3F3714A9-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\1.bin\MORPHBAR.DLL
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-18\..\Run: [hdicvyrf.exe] C:\WINDOWS\hdicvyrf.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [PoliceAV] C:\Program Files\XPPoliceAntivirus\xppolice.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [hdicvyrf.exe] C:\WINDOWS\hdicvyrf.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?6e57dbecc5f7432aa2822e9de4323594
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?6e57dbecc5f7432aa2822e9de4323594
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) -
http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll pgwief.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
–
End of file - 8044 bytes