This is the Report after having problems with Win32:Virtumonde-IS (Adw)
Microsoft Windows XP Home Edition 5.1.2600.2.1252.34.1033.18.63 [GMT 2:00]
Running from: C:\Program Files\Combo-Fix.exe
- Created a new restore point
C:\Program Files\180solutions
C:\Program Files\Common Files\SLMSS
C:\Program Files\ISTsvc
C:\Program Files\screensavers.com
C:\Program Files\screensavers.com\Installer\temp\dm767.tmp
C:\Program Files\screensavers.com\Wallpaper\Blue Bottles.jpg
C:\Program Files\screensavers.com\Wallpaper\Flower Cubes.jpg
C:\Program Files\screensavers.com\Wallpaper\Goldfish.jpg
C:\Program Files\screensavers.com\Wallpaper\swpstart.exe
C:\Program Files\screensavers.com\Wallpaper\Thumbs.db
C:\WINDOWS\system32\csloa.dll
C:\WINDOWS\system32\kdsya.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-28 )))))))))))))))))))))))))))))))
.
2008-04-28 15:46 . 2008-04-28 15:46 1,778,287 --a------ C:\Program Files\Combo-Fix.exe
2008-04-11 17:35 . 2004-07-13 21:12 69,632 --------- C:\WINDOWS\erase_SR.exe
2008-04-11 17:08 . 2008-04-11 17:08 d-------- C:\Program Files\XoftSpySE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-03 13:34 100,208 ----a-w C:\Documents and Settings\Ana Hernandez\Application Data\GDIPFONTCACHEV1.DAT
2008-02-28 05:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-02-28 05:06 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-02-28 05:05 --------- d-----w C:\Program Files\AVS4YOU
2006-03-15 09:32 7,531,962 ----a-w C:\Program Files\Accesoremoto a Hogskolan.exe
2004-04-18 14:48 1,649,697 ----a-w C:\Program Files\AWA005XDGI.EXE
2004-04-18 14:33 9,491,469 ----a-w C:\Program Files\TMQ0003BKM.EXE
2004-04-18 12:28 3,056,430 ----a-w C:\Program Files\MI-Z32280803CS04US.EXE
2004-04-12 18:36 9,294,960 ----a-w C:\Program Files\Media Player XP.exe
2005-11-04 16:14 80 --sh–r C:\WINDOWS\system32[u]0[/u]9669F2157.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1}]
C:\PROGRA~1\BARGAI~1\bin2\apuc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Yahoo! Pager”=“C:\Program Files\Yahoo!\Messenger\ypager.exe”
“Cpusave32”=“c:\windows\system32\cpusave32.exe”
“Sndcompat”=“c:\windows\system32\sndcompat.exe”
“Pwr32ctr”=“c:\windows\system32\pwr32ctr.exe”
“Monitormgt”=“c:\windows\system32\monitormgt.exe”
“Pixelsvr”=“c:\windows\system32\pixelsvr.exe”
“Info32x”=“c:\windows\system32\info32x.exe”
“Pixel32”=“c:\windows\system32\pixel32.exe”
“Sndbass”=“c:\windows\system32\sndbass.exe”
“Imagemgt32”=“c:\windows\system32\imagemgt32.exe”
“Cabchk32”=“c:\windows\system32\cabchk32.exe”
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 09:56 15360]
“Octoshape Streaming Services”=“C:\Program Files\Octoshape Streaming Services\Ana Hernandez\OctoshapeClient.exe”
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-05-23 06:58 68856]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-08-06 12:43 23165736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NvCplDaemon”=“NvQTwk”
“ZTgServerSwitch”=“c:\program files\support.com\client\bin\tgcmd.exe” [2001-08-03 19:21 1409024]
“Adulteras en directo”=“C:\Adulteras en directo\Adulteras en directo.exe”
“AdaptecDirectCD”=“C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe” [2003-08-27 12:58 684032]
“LVCOMS”=“C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE” [2001-11-13 15:43 98304]
“Sndcompat”=“c:\windows\system32\sndcompat.exe”
“LWBMOUSE”=“C:\PROGRA~1\WHEELM~1\WHEELM~1\3.11\LWB3DAPP.EXE”
“Pixelsvr”=“c:\windows\system32\pixelsvr.exe”
“Vidcompat”=“c:\windows\system32\vidcompat.exe”
“Sndbass”=“c:\windows\system32\sndbass.exe”
“Dvdcompat”=“c:\windows\system32\dvdcompat.exe”
“Dx8compat”=“c:\windows\system32\dx8compat.exe”
“jqiuax”=“ujtcclh.exe”
“Cabchk32”=“c:\windows\system32\cabchk32.exe”
“Monitormgt”=“c:\windows\system32\monitormgt.exe”
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2004-05-06 13:14 98304]
“STOPzilla”=“C:\Program Files\STOPzilla!\Stopzilla.exe”
“TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2004-10-09 19:24 180269]
“OpwareSE2”=“D:\OmnipageSE\OpwareSE2.exe” [2003-05-08 12:00 49152]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe” [2008-02-22 04:25 144784]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 22:16 39792]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
VAIO Action Setup (Server).lnk - C:\Program Files\Sony\VAIO Action Setup\VAServ.exe [2001-09-08 12:51:48 40960]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
Software Kodak EasyShare.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 02:22:40 757760]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
ckpNotify.dll 2004-07-13 22:14 24673 C:\WINDOWS\system32\ckpNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“VIDC.MJPG”= sonymjpg.dll
“VIDC.CTRX”= ctrxvid.drv
“MSVideo”= lvfwwdmt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusOverride”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\support.com\client\bin\tgcmd.exe”=
“C:\Program Files\eMule\emule.exe”=
“C:\Program Files\Real\RealPlayer\realplay.exe”=
“C:\Program Files\Internet Explorer\IEXPLORE.EXE”=
“C:\Program Files\Messenger\MSMSGS.EXE”=
“C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe”=
“C:\WINDOWS\System32\dpvsetup.exe”=
“C:\WINDOWS\System32\rundll32.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\Program Files\Marratech\Marratech6.1\bin\Marratech.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 SonyFanC;FAN Control Device Service;C:\WINDOWS\system32\Drivers\SonyFanC.sys [2001-09-06 16:21]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 V7;V7;C:\WINDOWS\system32\drivers\V7.sys [2000-03-09 11:24]
S2 STOPzilla NT Service;STOPzilla NT Service;C:\Program Files\STOPzilla!\szntsvc.exe
S3 adiusbae;USB ADSL LAN Adapter;C:\WINDOWS\system32\DRIVERS\adiusbae.sys [2002-08-15 11:25]
S3 BCM42XX;Broadcom iLine10™ Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [2001-08-17 12:11]
S3 Boonty Games;Boonty Games;“C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe” [2005-11-06 20:40]
S3 WrKPoET2000;WrKPoET2000;C:\Program Files\WinPoET Broadband Connection\WrKPoET2000.sys
.
Contents of the ‘Scheduled Tasks’ folder
“2002-01-08 17:30:38 C:\WINDOWS\Tasks\Registration reminder 1.job”
- C:\WINDOWS\System32\OOBE\oobebaln.exe
“2002-01-08 17:30:40 C:\WINDOWS\Tasks\Registration reminder 2.job” - C:\WINDOWS\System32\OOBE\oobebaln.exe
.
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-28 16:03:10
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
“LVCOMS”=“C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE”
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\PROGRAM FILES\CHECKPOINT\SECUREMOTE\BIN\SR_WATCHDOG.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
.
Completion time: 2008-04-28 16:11:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-28 14:11:12
Pre-Run: 2,204,708,864 bytes free
Post-Run: 3,525,083,136 bytes free
159 — E O F — 2008-03-12 08:27:33