This post will have the logs of all the other scans i had performed:
VundoFix V7.0.6
Scan started at 17:20:42 2008-10-28
Listing files found while scanning....
D:\Windows\system32\NCTAudioCDGrabber2.dll
D:\Windows\system32\NCTAudioFile2.dll
D:\Windows\system32\NCTAudioPlayer2.dll
D:\Windows\system32\NCTAudioRecord2.dll
D:\Windows\system32\NCTAVIFile.dll
D:\Windows\system32\NCTQuickTimeFile.dll
D:\Windows\system32\NCTVideoCoreM.dll
D:\Windows\system32\NCTWMAFile2.dll
Beginning removal...
Attempting to delete D:\Windows\system32\NCTAudioCDGrabber2.dll
D:\Windows\system32\NCTAudioCDGrabber2.dll Has been deleted!
Attempting to delete D:\Windows\system32\NCTAudioFile2.dll
D:\Windows\system32\NCTAudioFile2.dll Has been deleted!
Attempting to delete D:\Windows\system32\NCTAudioPlayer2.dll
D:\Windows\system32\NCTAudioPlayer2.dll Has been deleted!
Attempting to delete D:\Windows\system32\NCTAudioRecord2.dll
D:\Windows\system32\NCTAudioRecord2.dll Has been deleted!
Attempting to delete D:\Windows\system32\NCTAVIFile.dll
D:\Windows\system32\NCTAVIFile.dll Has been deleted!
Attempting to delete D:\Windows\system32\NCTQuickTimeFile.dll
D:\Windows\system32\NCTQuickTimeFile.dll Has been deleted!
Attempting to delete D:\Windows\system32\NCTVideoCoreM.dll
D:\Windows\system32\NCTVideoCoreM.dll Has been deleted!
Attempting to delete D:\Windows\system32\NCTWMAFile2.dll
D:\Windows\system32\NCTWMAFile2.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V7.0.6
Scan started at 1:32:48 PM 11/2/2008
Listing files found while scanning....
No infected files were found.
Combofix: I used this application i think three times:
"Other" - 2008-11-04 19:56:32 Service Pack 2 [SAFE MODE]
ComboFix 07-05.27.BV - Running from: "D:\"
((((((((((((((((((((((((((((((( Files Created from 2008-10-04 to 2008-11-04 ))))))))))))))))))))))))))))))))))
2008-11-04 18:55 72,192 --a------ D:\WINDOWS\system32\lpqewhng.dll
2008-11-03 16:22 72,192 --a------ D:\WINDOWS\system32\sgincsoh.dll
2008-11-02 11:12 72,192 --a------ D:\WINDOWS\system32\mkecmtiy.dll
2008-11-02 10:39 71,680 --a------ D:\WINDOWS\system32\udcrfrup.dll
2008-11-01 10:36 311,667 --ahs---- D:\WINDOWS\system32\edeLRqru.ini2
2008-11-01 10:35 282,112 --a------ D:\WINDOWS\system32\urqRLede.dll
2008-10-31 20:38 <DIR> d-------- D:\DOCUME~1\Jahanzeb\APPLIC~1\Malwarebytes
2008-10-31 20:03 <DIR> d-------- D:\DOCUME~1\Other\APPLIC~1\Malwarebytes
2008-10-31 20:02 38,496 --a------ D:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-31 20:02 15,504 --a------ D:\WINDOWS\system32\drivers\mbam.sys
2008-10-31 20:02 <DIR> d-------- D:\Program Files\Malwarebytes' Anti-Malware
2008-10-31 20:02 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
2008-10-28 19:04 7,507,296 --a------ D:\rminstall.exe
2008-10-28 18:41 812,344 --a------ D:\HJTInstall.exe
2008-10-28 18:41 15,083,520 --a------ D:\spybotsd160.exe
2008-10-28 17:20 <DIR> d-------- D:\VundoFix Backups
2008-10-28 12:53 880 --a------ D:\WINDOWS\system32\tmp.reg
2008-10-28 12:50 <DIR> d-------- D:\SmitfraudFix
2008-10-28 12:49 262,144 --ah----- D:\DOCUME~1\ADMINI~1\NTUSER.DAT
2008-10-28 12:33 1,088,512 --a------ D:\ComboFix.exe
2008-10-28 12:17 119,808 --a------ D:\VundoFix.exe
2008-10-28 12:17 1,663,634 --a------ D:\SmitfraudFix.exe
2008-10-27 22:23 <DIR> d-------- D:\Program Files\Avenger
2008-10-27 21:40 49,152 --a------ D:\WINDOWS\nircmd.exe
2008-10-27 20:25 388,608 --a------ D:\WINDOWS\system32\CF19354.exe
2008-10-27 14:35 <DIR> d-------- D:\Program Files\Exterminate It!
2008-10-27 14:02 <DIR> d-------- D:\Program Files\Trend Micro
2008-10-27 12:25 27,904 --a------ D:\WINDOWS\system32\drivers\ndisprot.sys
2008-10-27 12:24 32,256 --a------ D:\WINDOWS\system32\fccbBSkk.dll
2008-10-27 12:24 32,256 --a------ D:\WINDOWS\system32\awtqrqpp.dll
2008-10-14 14:38 <DIR> d-------- D:\DOCUME~1\Other\APPLIC~1\AdobeUM
2008-10-10 16:36 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2008-10-10 13:53 <DIR> d-------- D:\Program Files\Messenger Plus! Live
2008-10-09 13:57 <DIR> d-------- D:\Documents and Settings\Other\Contacts
2008-10-09 13:57 <DIR> d-------- D:\DOCUME~1\Other\Contacts
2008-10-09 13:49 <DIR> d-------- D:\Program Files\Windows Live
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-11-04 13:58:33 -------- d-----w D:\DOCUME~1\Other\APPLIC~1\Skype
2008-11-04 13:31:25 -------- d-----w D:\DOCUME~1\Other\APPLIC~1\skypePM
2008-11-04 08:15:44 -------- d-----w D:\Program Files\DC++
2008-10-31 12:23:46 -------- d-----w D:\DOCUME~1\Other\APPLIC~1\uTorrent
2008-10-30 11:23:37 1,427 ----a-w D:\WINDOWS\mozver.dat
2008-10-15 04:30:07 359,040 ----a-w D:\WINDOWS\system32\drivers\tcpip.sys
2008-09-29 17:32:30 -------- d-----w D:\DOCUME~1\Other\APPLIC~1\dvdcss
2008-09-19 16:00:50 -------- d-----w D:\DOCUME~1\Other\APPLIC~1\Creative
2008-09-16 13:55:48 -------- d-----w D:\Program Files\McAfee
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{000123B4-9B42-4900-B3F7-F4B073EFC214}=D:\Program Files\Orbitdownloader\orbitcth.dll [2007-02-05 13:34]
{53707962-6F74-2D53-2644-206D7942484F}=D:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 14:25]
{7DB2D5A0-7241-4E79-B68D-6309F01C5231}=D:\Program Files\McAfee\VirusScan\scriptsn.dll [2007-10-24 05:51]
{8FBC6088-3303-4856-9992-EE901F543755}=D:\WINDOWS\system32\urqRLede.dll [2008-11-01 10:36]
{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}=D:\WINDOWS\system32\fccbBSkk.dll [2008-10-27 12:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2004-10-29 13:50 D:\WINDOWS\system32\nwiz.exe]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-12 10:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"MsnMsgr"="D:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}"="D:\WINDOWS\system32\fccbBSkk.dll" [2008-10-27 12:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbBSkk]
fccbBSkk.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 D:\WINDOWS\system32\urqRLede
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=D:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
D:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
D:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"xmlprov"=3 (0x3)
"WZCSVC"=3 (0x3)
"WmiApSrv"=3 (0x3)
"Wmi"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"VSS"=3 (0x3)
"UPS"=3 (0x3)
"upnphost"=3 (0x3)
"SysmonLog"=3 (0x3)
"SwPrv"=3 (0x3)
"srservice"=2 (0x2)
"SCardSvr"=3 (0x3)
"RSVP"=3 (0x3)
"RemoteRegistry"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasAuto"=3 (0x3)
"NtmsSvc"=3 (0x3)
"NtLmSsp"=3 (0x3)
"NMIndexingService"=3 (0x3)
"Netlogon"=3 (0x3)
"MSIServer"=3 (0x3)
"MSDTC"=3 (0x3)
"mnmsrvc"=3 (0x3)
"McODS"=3 (0x3)
"LmHosts"=3 (0x3)
"lanmanworkstation"=3 (0x3)
"lanmanserver"=3 (0x3)
"ImapiService"=3 (0x3)
"HTTPFilter"=3 (0x3)
"dmadmin"=3 (0x3)
"COMSysApp"=3 (0x3)
"CiSvc"=3 (0x3)
"Browser"=3 (0x3)
"BITS"=3 (0x3)
"AppMgmt"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
Contents of the 'Scheduled Tasks' folder
2007-10-30 06:46:45 D:\WINDOWS\tasks\McDefragTask.job
2007-10-30 06:46:42 D:\WINDOWS\tasks\McQcTask.job
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-04 20:00:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2008-11-04 20:02:45
D:\ComboFix-quarantined-files.txt ... 2008-11-04 20:02
D:\ComboFix2.txt ... 2008-11-02 13:29
D:\ComboFix3.txt ... 2008-10-28 15:54
--- E O F ---
"Jahanzeb" - 2008-11-02 13:23:41 Service Pack 2 [SAFE MODE]
ComboFix 07-05.27.BV - Running from: "D:\"
((((((((((((((((((((((((((((((( Files Created from 2008-10-02 to 2008-11-02 ))))))))))))))))))))))))))))))))))
2008-11-02 11:12 72,192 --a------ D:\WINDOWS\system32\mkecmtiy.dll
2008-11-02 10:39 71,680 --a------ D:\WINDOWS\system32\udcrfrup.dll
2008-11-01 10:36 328,688 --ahs---- D:\WINDOWS\system32\edeLRqru.ini2
2008-11-01 10:35 282,112 --a------ D:\WINDOWS\system32\urqRLede.dll
2008-10-31 20:38 <DIR> d-------- D:\DOCUME~1\Jahanzeb\APPLIC~1\Malwarebytes
2008-10-31 20:03 <DIR> d-------- D:\DOCUME~1\Other\APPLIC~1\Malwarebytes
2008-10-31 20:02 38,496 --a------ D:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-31 20:02 15,504 --a------ D:\WINDOWS\system32\drivers\mbam.sys
2008-10-31 20:02 <DIR> d-------- D:\Program Files\Malwarebytes' Anti-Malware
2008-10-31 20:02 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
2008-10-28 19:04 7,507,296 --a------ D:\rminstall.exe
2008-10-28 18:41 812,344 --a------ D:\HJTInstall.exe
2008-10-28 18:41 15,083,520 --a------ D:\spybotsd160.exe
2008-10-28 17:20 <DIR> d-------- D:\VundoFix Backups
2008-10-28 12:53 880 --a------ D:\WINDOWS\system32\tmp.reg
2008-10-28 12:50 <DIR> d-------- D:\SmitfraudFix
2008-10-28 12:49 262,144 --ah----- D:\DOCUME~1\ADMINI~1\NTUSER.DAT
2008-10-28 12:33 1,088,512 --a------ D:\ComboFix.exe
2008-10-28 12:17 119,808 --a------ D:\VundoFix.exe
2008-10-28 12:17 1,663,634 --a------ D:\SmitfraudFix.exe
2008-10-27 22:23 <DIR> d-------- D:\Program Files\Avenger
2008-10-27 21:40 49,152 --a------ D:\WINDOWS\nircmd.exe
2008-10-27 20:25 388,608 --a------ D:\WINDOWS\system32\CF19354.exe
2008-10-27 14:35 <DIR> d-------- D:\Program Files\Exterminate It!
2008-10-27 14:02 <DIR> d-------- D:\Program Files\Trend Micro
2008-10-27 12:25 27,904 --a------ D:\WINDOWS\system32\drivers\ndisprot.sys
2008-10-27 12:24 32,256 --a------ D:\WINDOWS\system32\fccbBSkk.dll
2008-10-27 12:24 32,256 --a------ D:\WINDOWS\system32\awtqrqpp.dll
2008-10-14 14:38 <DIR> d-------- D:\DOCUME~1\Other\APPLIC~1\AdobeUM
2008-10-10 16:36 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2008-10-10 13:53 <DIR> d-------- D:\Program Files\Messenger Plus! Live
2008-10-09 13:57 <DIR> d-------- D:\DOCUME~1\Other\Contacts
2008-10-09 13:49 <DIR> d-------- D:\Program Files\Windows Live
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-11-01 17:22:48 -------- d-----w D:\Program Files\DC++
2008-10-30 11:23:37 1,427 ----a-w D:\WINDOWS\mozver.dat
2008-10-28 14:35:52 -------- d-----w D:\DOCUME~1\Jahanzeb\APPLIC~1\uTorrent
2008-10-28 12:55:54 -------- d-----w D:\DOCUME~1\Jahanzeb\APPLIC~1\Orbit
2008-10-15 04:30:07 359,040 ----a-w D:\WINDOWS\system32\drivers\tcpip.sys
2008-09-16 13:55:48 -------- d-----w D:\Program Files\McAfee
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{000123B4-9B42-4900-B3F7-F4B073EFC214}=D:\Program Files\Orbitdownloader\orbitcth.dll [2007-02-05 13:34]
{53707962-6F74-2D53-2644-206D7942484F}=D:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 14:25]
{61C44C25-C3DA-4DE4-B568-BB010772382A}=D:\WINDOWS\system32\urqRLede.dll [2008-11-01 10:36]
{7DB2D5A0-7241-4E79-B68D-6309F01C5231}=D:\Program Files\McAfee\VirusScan\scriptsn.dll [2007-10-24 05:51]
{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}=D:\WINDOWS\system32\fccbBSkk.dll [2008-10-27 12:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2004-10-29 13:50 D:\WINDOWS\system32\nwiz.exe]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-12 10:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pop-Up-Blocker"="" []
"TransparentIcons"="" []
"BlockAds"="" []
"Tweak-XP"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}"="D:\WINDOWS\system32\fccbBSkk.dll" [2008-10-27 12:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbBSkk]
fccbBSkk.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 D:\WINDOWS\system32\urqRLede
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=D:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
D:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
D:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"xmlprov"=3 (0x3)
"WZCSVC"=3 (0x3)
"WmiApSrv"=3 (0x3)
"Wmi"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"VSS"=3 (0x3)
"UPS"=3 (0x3)
"upnphost"=3 (0x3)
"SysmonLog"=3 (0x3)
"SwPrv"=3 (0x3)
"srservice"=2 (0x2)
"SCardSvr"=3 (0x3)
"RSVP"=3 (0x3)
"RemoteRegistry"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasAuto"=3 (0x3)
"NtmsSvc"=3 (0x3)
"NtLmSsp"=3 (0x3)
"NMIndexingService"=3 (0x3)
"Netlogon"=3 (0x3)
"MSIServer"=3 (0x3)
"MSDTC"=3 (0x3)
"mnmsrvc"=3 (0x3)
"McODS"=3 (0x3)
"LmHosts"=3 (0x3)
"lanmanworkstation"=3 (0x3)
"lanmanserver"=3 (0x3)
"ImapiService"=3 (0x3)
"HTTPFilter"=3 (0x3)
"dmadmin"=3 (0x3)
"COMSysApp"=3 (0x3)
"CiSvc"=3 (0x3)
"Browser"=3 (0x3)
"BITS"=3 (0x3)
"AppMgmt"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
Contents of the 'Scheduled Tasks' folder
2007-10-30 06:46:45 D:\WINDOWS\tasks\McDefragTask.job
2007-10-30 06:46:42 D:\WINDOWS\tasks\McQcTask.job
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-02 13:27:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2008-11-02 13:29:55
D:\ComboFix-quarantined-files.txt ... 2008-11-02 13:29
D:\ComboFix2.txt ... 2008-10-28 15:54
D:\ComboFix3.txt ... 2008-10-27 21:40
--- E O F ---
"Jahanzeb" - 2008-10-28 13:35:19 Service Pack 2 [SAFE MODE]
ComboFix 07-05.27.BV - Running from: "D:\"
((((((((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 ))))))))))))))))))))))))))))))))))
2008-10-28 13:05 <DIR> dr-hs---- D:\resycled
2008-10-28 12:53 600 --a------ D:\WINDOWS\system32\tmp.reg
2008-10-28 12:50 88,576 --a------ D:\WINDOWS\system32\AntiXPVSTFix.exe
2008-10-28 12:50 87,552 --a------ D:\WINDOWS\system32\VACFix.exe
2008-10-28 12:50 82,944 --a------ D:\WINDOWS\system32\o4Patch.exe
2008-10-28 12:50 82,944 --a------ D:\WINDOWS\system32\IEDFix.exe
2008-10-28 12:50 82,944 --a------ D:\WINDOWS\system32\IEDFix.C.exe
2008-10-28 12:50 82,432 --a------ D:\WINDOWS\system32\404Fix.exe
2008-10-28 12:50 53,248 --a------ D:\WINDOWS\system32\Process.exe
2008-10-28 12:50 51,200 --a------ D:\WINDOWS\system32\dumphive.exe
2008-10-28 12:50 289,144 --a------ D:\WINDOWS\system32\VCCLSID.exe
2008-10-28 12:50 288,417 --a------ D:\WINDOWS\system32\SrchSTS.exe
2008-10-28 12:50 25,600 --a------ D:\WINDOWS\system32\WS2Fix.exe
2008-10-28 12:50 <DIR> d-------- D:\SmitfraudFix
2008-10-28 12:49 262,144 --ah----- D:\DOCUME~1\ADMINI~1\NTUSER.DAT
2008-10-28 12:33 1,088,512 --a------ D:\ComboFix.exe
2008-10-28 12:17 119,808 --a------ D:\VundoFix.exe
2008-10-28 12:17 1,663,634 --a------ D:\SmitfraudFix.exe
2008-10-27 22:23 <DIR> d-------- D:\Program Files\Avenger
2008-10-27 21:40 49,152 --a------ D:\WINDOWS\nircmd.exe
2008-10-27 21:02 2,048 --a------ D:\WINDOWS\system32\kgblktnm.exe
2008-10-27 20:59 71,680 --a------ D:\WINDOWS\system32\xymnejph.dll
2008-10-27 20:25 388,608 --a------ D:\WINDOWS\system32\CF19354.exe
2008-10-27 14:35 <DIR> d-------- D:\Program Files\Exterminate It!
2008-10-27 14:02 <DIR> d-------- D:\Program Files\Trend Micro
2008-10-27 13:56 2,048 --a------ D:\WINDOWS\system32\fxddodac.exe
2008-10-27 13:55 71,680 --a------ D:\WINDOWS\system32\rkrwacpk.dll
2008-10-27 12:32 71,680 --------- D:\WINDOWS\system32\iekwwjgj.dll
2008-10-27 12:31 355,431 --ahs---- D:\WINDOWS\system32\QWaHRqru.ini2
2008-10-27 12:29 281,600 --------- D:\WINDOWS\system32\urqRHaWQ.dll
2008-10-27 12:25 27,904 --a------ D:\WINDOWS\system32\drivers\ndisprot.sys
2008-10-27 12:24 32,256 --a------ D:\WINDOWS\system32\fccbBSkk.dll
2008-10-27 12:24 32,256 --a------ D:\WINDOWS\system32\awtqrqpp.dll
2008-10-27 12:24 <DIR> d-------- D:\WINDOWS\system32\675873
2008-10-14 14:38 <DIR> d-------- D:\DOCUME~1\Other\APPLIC~1\AdobeUM
2008-10-10 16:36 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2008-10-10 13:53 <DIR> d-------- D:\Program Files\Messenger Plus! Live
2008-10-09 13:57 <DIR> d-------- D:\Documents and Settings\Other\Contacts
2008-10-09 13:57 <DIR> d-------- D:\DOCUME~1\Other\Contacts
2008-10-09 13:49 <DIR> d-------- D:\Program Files\Windows Live
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-10-28 03:53:11 -------- d-----w D:\Program Files\DC++
2008-10-19 05:39:20 -------- d-----w D:\DOCUME~1\Jahanzeb\APPLIC~1\Orbit
2008-10-15 04:30:07 359,040 ----a-w D:\WINDOWS\system32\drivers\tcpip.sys
2008-09-27 08:19:12 -------- d-----w D:\DOCUME~1\Jahanzeb\APPLIC~1\uTorrent
2008-09-16 13:55:48 -------- d-----w D:\Program Files\McAfee
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{000123B4-9B42-4900-B3F7-F4B073EFC214}=D:\Program Files\Orbitdownloader\orbitcth.dll [2007-02-05 13:34]
{476CC7E8-4123-4298-B064-35F12003B861}=D:\WINDOWS\system32\urqRHaWQ.dll [2008-10-27 12:30]
{53707962-6F74-2D53-2644-206D7942484F}=D:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 14:25]
{7DB2D5A0-7241-4E79-B68D-6309F01C5231}=D:\Program Files\McAfee\VirusScan\scriptsn.dll [2007-10-24 05:51]
{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}=D:\WINDOWS\system32\fccbBSkk.dll [2008-10-27 12:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2004-10-29 13:50 D:\WINDOWS\system32\nwiz.exe]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-12 10:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"Tok-Cirrhatus"="D:\Documents and Settings\Other\Local Settings\Application Data\smss.exe" []
"MsnMsgr"="D:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{A177C1C1-EF04-4FCC-8A4B-FE956DC0A099}"="D:\WINDOWS\system32\fccbBSkk.dll" [2008-10-27 12:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbBSkk]
fccbBSkk.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 D:\WINDOWS\system32\urqRHaWQ
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=D:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
D:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
D:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"xmlprov"=3 (0x3)
"WZCSVC"=3 (0x3)
"WmiApSrv"=3 (0x3)
"Wmi"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"VSS"=3 (0x3)
"UPS"=3 (0x3)
"upnphost"=3 (0x3)
"SysmonLog"=3 (0x3)
"SwPrv"=3 (0x3)
"srservice"=2 (0x2)
"SCardSvr"=3 (0x3)
"RSVP"=3 (0x3)
"RemoteRegistry"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasAuto"=3 (0x3)
"NtmsSvc"=3 (0x3)
"NtLmSsp"=3 (0x3)
"NMIndexingService"=3 (0x3)
"Netlogon"=3 (0x3)
"MSIServer"=3 (0x3)
"MSDTC"=3 (0x3)
"mnmsrvc"=3 (0x3)
"McODS"=3 (0x3)
"LmHosts"=3 (0x3)
"lanmanworkstation"=3 (0x3)
"lanmanserver"=3 (0x3)
"ImapiService"=3 (0x3)
"HTTPFilter"=3 (0x3)
"dmadmin"=3 (0x3)
"COMSysApp"=3 (0x3)
"CiSvc"=3 (0x3)
"Browser"=3 (0x3)
"BITS"=3 (0x3)
"AppMgmt"=3 (0x3)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78a3c12-86d6-11dc-8690-806d6172696f}]
AutoRun\command- D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com c:
Open\command- C:\resycled\boot.com c:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78a3c13-86d6-11dc-8690-806d6172696f}]
AutoRun\command- D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com d:
Open\command- D:\resycled\boot.com d:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78a3c14-86d6-11dc-8690-806d6172696f}]
AutoRun\command- D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com e:
Open\command- E:\resycled\boot.com e:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a78a3c15-86d6-11dc-8690-806d6172696f}]
AutoRun\command- D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com f:
Open\command- F:\resycled\boot.com f:
Contents of the 'Scheduled Tasks' folder
2007-10-30 06:46:45 D:\WINDOWS\tasks\McDefragTask.job
2007-10-30 06:46:42 D:\WINDOWS\tasks\McQcTask.job
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-28 15:48:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2008-10-28 15:54:21 - machine was rebooted
D:\ComboFix-quarantined-files.txt ... 2008-10-28 15:54
D:\ComboFix2.txt ... 2008-10-27 21:40
--- E O F ---
2004-08-04 03:56 69120 --a------ D:\Qoobox\Quarantine\D\WINDOWS\system32\kdbnl.exe.vir
2008-08-15 10:11 26624 --a------ D:\Qoobox\Quarantine\D\WINDOWS\system32\a.exe.vir
2008-10-28 13:38 24692 --a------ D:\Qoobox\Quarantine\Registry_backups\winlogon.reg.cf
Folder PATH listing
Volume serial number is 9C49-5401
D:\QOOBOX
\---Quarantine
+---D
| \---WINDOWS
| \---system32
| a.exe.vir
| kdbnl.exe.vir
|
\---Registry_backups
winlogon.reg.cf
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at D:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Completed script processing.
*******************
Finished! Terminate.
SmitFraudFix v2.367
Scan done at 20:20:12.81, 2008-11-04
Run from D:\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» DNS Before Fix
Description: Intel(R) PRO/100+ Management Adapter with Alert On LAN* - Packet Scheduler Miniport
DNS Server Search Order: 203.81.204.3
DNS Server Search Order: 203.81.204.23
HKLM\SYSTEM\CCS\Services\Tcpip\..\{92D437AF-0B8A-4735-975E-2D5679051DBA}: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CS2\Services\Tcpip\..\{92D437AF-0B8A-4735-975E-2D5679051DBA}: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CS3\Services\Tcpip\..\{92D437AF-0B8A-4735-975E-2D5679051DBA}: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=203.81.204.3 203.81.204.23
»»»»»»»»»»»»»»»»»»»»»»»» DNS After Fix
Description: Intel(R) PRO/100+ Management Adapter with Alert On LAN* - Packet Scheduler Miniport
DNS Server Search Order: 203.81.204.3
DNS Server Search Order: 203.81.204.23
HKLM\SYSTEM\CCS\Services\Tcpip\..\{92D437AF-0B8A-4735-975E-2D5679051DBA}: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CS2\Services\Tcpip\..\{92D437AF-0B8A-4735-975E-2D5679051DBA}: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CS3\Services\Tcpip\..\{92D437AF-0B8A-4735-975E-2D5679051DBA}: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=203.81.204.3 203.81.204.23
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=203.81.204.3 203.81.204.23