Please find attached below combofix log and fresh hjt log
Combofix:
ComboFix 09-11-06.03 - Steve 11/07/2009 12:16.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1473 [GMT -5:00]
Running from: c:\documents and settings\Steve\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\AcroIEHelpe.dll
c:\windows\system32\bomagave.dll
c:\windows\system32\dKkRAyxx.ini
c:\windows\system32\dKkRAyxx.ini2
c:\windows\system32\doguvuvo.dll
c:\windows\system32\leforoju.dll
c:\windows\system32\lidamuvi.dll
c:\windows\system32\musosami.dll
c:\windows\system32\rutomore.dll
c:\windows\system32\togitata.dll
c:\windows\system32\tutuparo.dll
c:\windows\system32\UAs
c:\windows\system32\UAs\3481435183_UAs001.dat
c:\windows\system32\UAs\83041218_UAs001.dat
c:\windows\system32\UAs\AcroRd32_UAs001.dat
c:\windows\system32\UAs\AdobeUpdater_UAs001.dat
c:\windows\system32\UAs\agent_UAs001.dat
c:\windows\system32\UAs\AutoDetect_UAs001.dat
c:\windows\system32\UAs\dwwin_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs002.dat
c:\windows\system32\UAs\Explorer_UAs003.dat
c:\windows\system32\UAs\Explorer_UAs004.dat
c:\windows\system32\UAs\Explorer_UAs005.dat
c:\windows\system32\UAs\helpctr_UAs001.dat
c:\windows\system32\UAs\helpctr_UAs002.dat
c:\windows\system32\UAs\HelpHost_UAs001.dat
c:\windows\system32\UAs\HelpHost_UAs002.dat
c:\windows\system32\UAs\housecall_UAs001.dat
c:\windows\system32\UAs\iexplore_UAs001.dat
c:\windows\system32\UAs\iexplore_UAs002.dat
c:\windows\system32\UAs\iexplore_UAs003.dat
c:\windows\system32\UAs\iexplore_UAs004.dat
c:\windows\system32\UAs\iexplore_UAs005.dat
c:\windows\system32\UAs\iexplore_UAs006.dat
c:\windows\system32\UAs\iexplore_UAs007.dat
c:\windows\system32\UAs\iexplore_UAs008.dat
c:\windows\system32\UAs\iexplore_UAs009.dat
c:\windows\system32\UAs\iexplore_UAs010.dat
c:\windows\system32\UAs\iexplore_UAs011.dat
c:\windows\system32\UAs\install_UAs001.dat
c:\windows\system32\UAs\install_UAs002.dat
c:\windows\system32\UAs\install_UAs003.dat
c:\windows\system32\UAs\javasetup6u16[1]_UAs001.dat
c:\windows\system32\UAs\javasetup6u16[1]_UAs002.dat
c:\windows\system32\UAs\javaw_UAs001.dat
c:\windows\system32\UAs\jre-6u15-windows-i586-iftw_UAs001.dat
c:\windows\system32\UAs\jucheck_UAs001.dat
c:\windows\system32\UAs\jusched_UAs001.dat
c:\windows\system32\UAs\lmi_rescue_UAs001.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs001.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs002.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs003.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs004.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs005.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs006.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs007.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs008.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs009.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs010.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs011.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs012.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs013.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs014.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs015.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs016.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs017.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs018.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs019.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs020.dat
c:\windows\system32\UAs\LuComServer_3_4_UAs021.dat
c:\windows\system32\UAs\mcsync_UAs001.dat
c:\windows\system32\UAs\mcupdmgr_UAs001.dat
c:\windows\system32\UAs\mvtapp_UAs001.dat
c:\windows\system32\UAs\mvtapp_UAs002.dat
c:\windows\system32\UAs\powerdvd_UAs001.dat
c:\windows\system32\UAs\sdasetup[1]_UAs001.dat
c:\windows\system32\UAs\setup_UAs001.dat
c:\windows\system32\UAs\setup_UAs002.dat
c:\windows\system32\UAs\setup_UAs003.dat
c:\windows\system32\UAs\softwareupdate_UAs001.dat
c:\windows\system32\UAs\softwareupdate_UAs002.dat
c:\windows\system32\UAs\ssautorn_UAs001.dat
c:\windows\system32\UAs\Stub_UAs001.dat
c:\windows\system32\UAs\SWHELP~1_UAs001.dat
c:\windows\system32\UAs\SymCUW_UAs001.dat
c:\windows\system32\UAs\symnrt_UAs001.dat
c:\windows\system32\UAs\wgasetup_UAs001.dat
c:\windows\system32\UAs\WgaTray_UAs001.dat
c:\windows\system32\UAs\xpnetdiag_UAs001.dat
c:\windows\system32\woborugu.exe
c:\windows\system32\zufumeba.dll
----- BITS: Possible infected sites -----
hxxp://193.33.61.160
.
((((((((((((((((((((((((( Files Created from 2009-10-07 to 2009-11-07 )))))))))))))))))))))))))))))))
.
2009-11-07 15:23 . 2009-11-07 15:23 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-11-07 15:23 . 2009-11-07 15:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-07 15:02 . 2009-11-07 15:02 -------- d-----w- c:\documents and settings\Steve\Application Data\Malwarebytes
2009-11-04 15:51 . 2009-11-04 15:51 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-11-02 23:22 . 2009-11-02 23:22 -------- d-----w- c:\program files\Trend Micro
2009-11-02 00:06 . 2009-09-16 15:22 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-11-02 00:06 . 2009-09-16 15:22 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-11-02 00:06 . 2009-09-16 15:22 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-11-02 00:05 . 2009-07-16 17:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-11-02 00:05 . 2009-11-02 00:06 -------- d-----w- c:\program files\Common Files\McAfee
2009-11-02 00:05 . 2009-11-02 00:05 -------- d-----w- c:\program files\McAfee.com
2009-11-02 00:05 . 2009-11-02 13:48 -------- d-----w- c:\program files\McAfee
2009-11-02 00:02 . 2009-09-16 15:22 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-11-01 23:59 . 2009-11-02 03:06 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-19 19:50 . 2009-10-19 19:50 2855 ----a-w- C:\NTDETECT.PIF
2009-10-19 19:48 . 2009-10-19 19:48 -------- d--h--w- c:\windows\PIF
2009-10-15 14:35 . 2009-10-15 14:35 18944 ----a-w- c:\windows\system32\CTXFIHLP.EXE
2009-10-15 13:52 . 2009-10-15 14:45 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-09 15:59 . 2009-07-03 17:09 915456 ----a-w- c:\windows\system32\wininet.dll
2009-10-09 15:59 . 2009-07-03 17:09 915456 ----a-w- c:\windows\system32\dllcache\wininet.dll
2009-10-08 21:39 . 2009-10-08 21:39 13 ----a-w- c:\windows\system32\urhtps.dat
2009-10-08 20:12 . 2009-10-15 14:22 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-07 16:28 . 2007-09-10 21:29 -------- d-----w- c:\program files\PokerStars
2009-11-02 13:26 . 2009-11-04 15:15 191374 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2009-11-02 00:07 . 2007-06-10 15:12 20248 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-24 22:50 . 2007-06-10 15:03 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-17 20:43 . 2007-10-25 12:48 -------- d-----w- c:\program files\SecondLife
2009-10-15 13:38 . 2007-06-10 15:06 -------- d-----w- c:\program files\Google
2009-10-12 11:52 . 2007-08-16 01:02 -------- d-----w- c:\program files\Temp
2009-10-04 15:42 . 2009-01-09 16:32 -------- d-----w- c:\program files\RegistryFix7
2009-10-03 15:39 . 2007-07-16 18:49 -------- d-----w- c:\program files\WebEx
2009-10-01 20:17 . 2009-10-01 20:17 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-10-01 20:16 . 2009-10-01 20:16 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-09-16 18:00 . 2007-06-10 14:58 -------- d-----w- c:\program files\Java
2009-09-16 17:59 . 2009-09-16 17:59 152576 ----a-w- c:\documents and settings\Steve\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-09-16 17:32 . 2008-07-07 15:41 61224 ----a-w- c:\documents and settings\Steve\GoToAssistDownloadHelper.exe
2009-09-16 15:22 . 2009-09-16 15:22 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 13:25 . 2009-09-16 13:25 49152 ----a-r- c:\documents and settings\Steve\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA1.exe
2009-09-16 13:25 . 2009-09-16 13:25 49152 ----a-r- c:\documents and settings\Steve\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA.exe
2009-09-16 13:19 . 2009-09-16 13:19 128 ----a-w- c:\documents and settings\Steve\Local Settings\Application Data\fusioncache.dat
2009-09-16 12:44 . 2009-09-16 12:44 2347320 ----a-w- c:\windows\system32\rarcc.dll
2009-09-02 13:53 . 2009-09-02 13:53 112 ----a-w- c:\windows\system32\srvblck2.tmp
2009-08-05 16:13 . 2009-08-05 16:13 90624 --sha-w- c:\windows\system32\kovuzuwa.dll
2009-08-05 04:13 . 2009-08-05 04:13 91136 --sha-w- c:\windows\system32\sumonibe.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-21 7204864]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"Popup"="c:\program files\Dell SAS RAID Storage Manager\MegaPopup\Popup.exe" [2006-08-15 77920]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"QuickTime Task"="c:\program files\quicktime\qttask.exe" [2008-11-11 413696]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"combofix"="c:\combofix\CF15096.exe" [2009-11-07 389120]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2005-11-08 16384]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2009-10-15 18944]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscs vc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"c:\\WINDOWS\\system32\\DKabcoms.exe"=
"c:\\Program Files\\Dell SAS RAID Storage Manager\\MegaPopup\\popup.exe"=
"c:\\Documents and Settings\\Steve\\Desktop\\WS_FTP32.EXE"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\MetalsoftProtection\\ProtectServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\Dassault Systemes\\B18\\intel_a\\code\\bin\\CNEXT.exe"=
"c:\\Program Files\\NewTek\\LightWave 3D 9.2\\Programs\\hub.exe"=
"c:\\Program Files\\NewTek\\LightWave 3D 9.2\\Programs\\modeler.exe"=
"c:\\Program Files\\Dassault Systemes\\B16\\intel_a\\code\\bin\\CNEXT.exe"=
"c:\\WINDOWS\\explorer.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\WINDOWS\\system32\\services.exe"=
"c:\\Program Files\\Internet Explorer\\iexplore.exe"=
"c:\\WINDOWS\\system32\\CTXFIHLP.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\lsass.exe"=
"c:\\FabriWIN_2\\cadcam.exe"=
"c:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.2\\Apps\\apdproxy.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Dell SAS RAID Storage Manager\\JRE\\bin\\javaw.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"135:TCP"= 135:TCP

COM
R1 LUMDriver;LUMDriver;c:\windows\system32\drivers\LUMDriver.sys [4/24/2007 7:52 AM 16688]
R2 BBDemon;Backbone Service;c:\program files\Dassault Systemes\B18\intel_a\code\bin\CATSysDemon.exe [5/4/2007 1:24 PM 36864]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [6/15/2007 5:22 PM 2368]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe -service --> c:\windows\system32\DKabcoms.exe -service [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-11-02 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-02 17:22]
2009-11-02 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-02 17:22]
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us
uDefault_Page_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070610
Trusted Zone: internet
Trusted Zone: mcafee.com
.
- - - - ORPHANS REMOVED - - - -
BHO-{015BE035-984B-4381-A5D8-5ED7467F47ED} - c:\windows\system32\AcroIEHelpe.dll
BHO-{4CF670AA-1E5E-4D53-9E9F-39A386E98293} - c:\windows\system32\xxyARkKd.dll
BHO-{a5f313d4-dbdc-4d39-b560-a6d10db6ae37} - tiledovo.dll
BHO-{F5F14E7A-F59D-45a0-BDC5-A9F5454F0BCF} - c:\windows\system32\iehelper.dll
HKCU-Run-RegistryMechanic - c:\program files\Registry Mechanic\RegMech.exe
HKCU-Run-system tool - c:\program files\nxupaq\fjhgsysguard.exe
HKLM-Run-AudioDrvEmulator - c:\program files\Creative\Shared Files\Module Loader\DLLML.exe
HKLM-Run-DVDLauncher - c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
HKLM-Run-DLA - c:\windows\System32\DLA\DLACTRLW.EXE
HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
HKLM-Run-83041218 - c:\docume~1\alluse~1\applic~1\83041218\83041218.exe
HKLM-Run-system tool - c:\program files\nxupaq\fjhgsysguard.exe
HKLM-Run-15330618 - c:\documents and settings\All Users\Application Data\15330618\15330618.exe
HKLM-Run-93548231 - c:\docume~1\ALLUSE~1\APPLIC~1\93548231\93548231.exe
HKLM-Run-04188526 - c:\docume~1\ALLUSE~1\APPLIC~1\04188526\04188526.exe
HKLM-Run-55141723 - c:\documents and settings\All Users\Application Data\55141723\55141723.exe
HKLM-Run-22888432 - c:\documents and settings\All Users\Application Data\22888432\22888432.exe
HKLM-Run-59350729 - c:\documents and settings\All Users\Application Data\59350729\59350729.exe
HKLM-Run-05261519 - c:\documents and settings\All Users\Application Data\05261519\05261519.exe
HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe
HKLM-Run-75182730 - c:\documents and settings\All Users\Application Data\75182730\75182730.exe
HKLM-Run-33785632 - c:\documents and settings\All Users\Application Data\33785632\33785632.exe
HKLM-Run-55069429 - c:\documents and settings\All Users\Application Data\55069429\55069429.exe
HKLM-Run-88229938 - c:\documents and settings\All Users\Application Data\88229938\88229938.exe
HKLM-Run-80959637 - c:\documents and settings\All Users\Application Data\80959637\80959637.exe
HKLM-Run-53667431 - c:\documents and settings\All Users\Application Data\53667431\53667431.exe
HKLM-Run-15228018 - c:\documents and settings\All Users\Application Data\15228018\15228018.exe
HKLM-Run-44839533 - c:\documents and settings\All Users\Application Data\44839533\44839533.exe
HKLM-Run-48328328 - c:\documents and settings\All Users\Application Data\48328328\48328328.exe
HKLM-Run-73554226 - c:\documents and settings\All Users\Application Data\73554226\73554226.exe
HKLM-Run-39805934 - c:\documents and settings\All Users\Application Data\39805934\39805934.exe
HKLM-Run-20421312 - c:\docume~1\ALLUSE~1\APPLIC~1\20421312\20421312.exe
HKLM-Run-08956432 - c:\documents and settings\All Users\Application Data\08956432\08956432.exe
HKLM-Run-lovoterib - c:\windows\system32\bomagave.dll
HKLM-Run-witudaguwe - musosami.dll
SharedTaskScheduler-{c6ad942f-967a-4bd1-b5ad-24aac6cc254c} - c:\windows\system32\hiluguba.dll
SharedTaskScheduler-{76a47896-a2b7-4962-bccc-3654137f2a24} - c:\windows\system32\rofegivu.dll
SharedTaskScheduler-{e60d3d0e-fd91-4e04-9c6f-9870cd25fe87} - c:\windows\system32\nikijaru.dll
SharedTaskScheduler-{a0bac1b8-6fac-4c1c-ba80-882224a09ffe} - c:\windows\system32\guharufa.dll
SharedTaskScheduler-{6c095b9a-d44a-48df-b3c7-1b7642b7ac68} - c:\windows\system32\rudadiza.dll
SharedTaskScheduler-{d6a207ef-9b4e-4526-a7c8-f58159feb8f8} - c:\windows\system32\bomagave.dll
SSODL-sofejowew-{c6ad942f-967a-4bd1-b5ad-24aac6cc254c} - c:\windows\system32\hiluguba.dll
SSODL-pusitidul-{76a47896-a2b7-4962-bccc-3654137f2a24} - c:\windows\system32\rofegivu.dll
SSODL-diwijeriy-{e60d3d0e-fd91-4e04-9c6f-9870cd25fe87} - c:\windows\system32\nikijaru.dll
SSODL-gomekuyik-{a0bac1b8-6fac-4c1c-ba80-882224a09ffe} - c:\windows\system32\guharufa.dll
SSODL-bezunujuw-{6c095b9a-d44a-48df-b3c7-1b7642b7ac68} - c:\windows\system32\rudadiza.dll
SSODL-vihorirok-{d6a207ef-9b4e-4526-a7c8-f58159feb8f8} - c:\windows\system32\bomagave.dll
Notify-urqQiGAT - urqQiGAT.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-07 12:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2009-11-07 12:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-07 17:25
Pre-Run: 86,386,442,240 bytes free
Post-Run: 88,800,940,032 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut
- - End Of File - - BC9B6F91E3A42C0AF67FB76DD949CD4D
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:27:26 PM, on 11/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dassault Systemes\B18\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070610
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [Popup] "C:\Program Files\Dell SAS RAID Storage Manager\MegaPopup\Popup.exe"
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://*.mcafee.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) -
http://appldnld.apple.com.edgesuite....x/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} (View22RTEv4 Class) -
http://merillat.view22.com/release_3...iew22RTEv4.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/is...89/mcfscan.cab
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B18\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: dkab_device - - C:\WINDOWS\system32\DKabcoms.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: MRMonitor (MegaMonitorSrv) - Unknown owner - C:\Program Files\Dell SAS RAID Storage Manager\MegaMonitor\mrmonitor.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SSMFramework (MSMFramework) - Unknown owner - C:\Program Files\Dell SAS RAID Storage Manager\Framework\VivaldiFramework.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
--
End of file - 6632 bytes
Thank you in advance for all your help
Smessi