kinghe: great find. thanks for the link.
XpUser: I had meant to reply to your post earlier.. I dont think anyone jumped on my machine while I was gone, but I've definitely been having dificulties lately. I kinda figured something screwy was happening with my machine (I was getting BSODs daily) but I never had time to fix it...just kinda lived with it. Stupid, I know.
jabuck: here are the latest logfiles:
avenger stuff:
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\uxcwrnqc
*******************
Script file located at: \??\C:\WINDOWS\system32\qnebw^hg.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\Documents and Settings\Administrator\keylog.dll deleted successfully.
File C:\WINDOWS\system32\tteootl.dll deleted successfully.
File C:\WINDOWS\system32\nxyrckn.dll deleted successfully.
File C:\WINDOWS\system32\pszcksc.dll deleted successfully.
File C:\WINDOWS\system32\rnuubyh.dll not found!
Deletion of file C:\WINDOWS\system32\rnuubyh.dll failed!
Could not process line:
C:\WINDOWS\system32\rnuubyh.dll
Status: 0xc0000034
File C:\WINDOWS\system32\niyjzml.dll deleted successfully.
File C:\WINDOWS\system32\sabpcni.dll deleted successfully.
File C:\WINDOWS\system32\czpqitl.dll deleted successfully.
File C:\WINDOWS\system32\sofzadm.dll deleted successfully.
File C:\WINDOWS\system32\livtmng.dll deleted successfully.
File C:\WINDOWS\system32\btxcrth.dll deleted successfully.
File C:\WINDOWS\system32\yqnlgpn.dll not found!
Deletion of file C:\WINDOWS\system32\yqnlgpn.dll failed!
Could not process line:
C:\WINDOWS\system32\yqnlgpn.dll
Status: 0xc0000034
File C:\WINDOWS\system32\bwuppni.dll deleted successfully.
File C:\WINDOWS\system32\per.exe not found!
Deletion of file C:\WINDOWS\system32\per.exe failed!
Could not process line:
C:\WINDOWS\system32\per.exe
Status: 0xc0000034
File C:\WINDOWS\system32\internat.dll not found!
Deletion of file C:\WINDOWS\system32\internat.dll failed!
Could not process line:
C:\WINDOWS\system32\internat.dll
Status: 0xc0000034
File C:\Program Files\syeqpqq.exe not found!
Deletion of file C:\Program Files\syeqpqq.exe failed!
Could not process line:
C:\Program Files\syeqpqq.exe
Status: 0xc0000034
File C:\WINDOWS\system32\lqyndxd.dll not found!
Deletion of file C:\WINDOWS\system32\lqyndxd.dll failed!
Could not process line:
C:\WINDOWS\system32\lqyndxd.dll
Status: 0xc0000034
File C:\WINDOWS\system32\hmijrxm.dll not found!
Deletion of file C:\WINDOWS\system32\hmijrxm.dll failed!
Could not process line:
C:\WINDOWS\system32\hmijrxm.dll
Status: 0xc0000034
File C:\WINDOWS\system32\ouyasdg.dll not found!
Deletion of file C:\WINDOWS\system32\ouyasdg.dll failed!
Could not process line:
C:\WINDOWS\system32\ouyasdg.dll
Status: 0xc0000034
File C:\WINDOWS\system32\sgepkl.dll deleted successfully.
File C:\WINDOWS\system32\xtblzo.dll not found!
Deletion of file C:\WINDOWS\system32\xtblzo.dll failed!
Could not process line:
C:\WINDOWS\system32\xtblzo.dll
Status: 0xc0000034
File C:\WINDOWS\system32\nprwxpd.dll deleted successfully.
File C:\WINDOWS\system32\tpzzoqd.dll not found!
Deletion of file C:\WINDOWS\system32\tpzzoqd.dll failed!
Could not process line:
C:\WINDOWS\system32\tpzzoqd.dll
Status: 0xc0000034
File C:\WINDOWS\system32\ylyiasi.dll deleted successfully.
File C:\WINDOWS\system32\kakuvjb.dll not found!
Deletion of file C:\WINDOWS\system32\kakuvjb.dll failed!
Could not process line:
C:\WINDOWS\system32\kakuvjb.dll
Status: 0xc0000034
File C:\WINDOWS\system32\yvfskwc.dll deleted successfully.
File C:\WINDOWS\system32\kxtabbb.dll not found!
Deletion of file C:\WINDOWS\system32\kxtabbb.dll failed!
Could not process line:
C:\WINDOWS\system32\kxtabbb.dll
Status: 0xc0000034
File C:\WINDOWS\system32\idarlmi.dll not found!
Deletion of file C:\WINDOWS\system32\idarlmi.dll failed!
Could not process line:
C:\WINDOWS\system32\idarlmi.dll
Status: 0xc0000034
File C:\WINDOWS\system32\fpspspf.dll not found!
Deletion of file C:\WINDOWS\system32\fpspspf.dll failed!
Could not process line:
C:\WINDOWS\system32\fpspspf.dll
Status: 0xc0000034
File C:\WINDOWS\system32\yvizyre.dll deleted successfully.
File C:\WINDOWS\system32\rjlphze.dll not found!
Deletion of file C:\WINDOWS\system32\rjlphze.dll failed!
Could not process line:
C:\WINDOWS\system32\rjlphze.dll
Status: 0xc0000034
File C:\WINDOWS\system32\rfrucym.dll deleted successfully.
File C:\WINDOWS\system32\jcczond.dll not found!
Deletion of file C:\WINDOWS\system32\jcczond.dll failed!
Could not process line:
C:\WINDOWS\system32\jcczond.dll
Status: 0xc0000034
File C:\WINDOWS\system32\bsofrfk.dll deleted successfully.
File C:\WINDOWS\system32\myniube.dll not found!
Deletion of file C:\WINDOWS\system32\myniube.dll failed!
Could not process line:
C:\WINDOWS\system32\myniube.dll
Status: 0xc0000034
File C:\WINDOWS\system32\ayuulpl.dll deleted successfully.
File C:\WINDOWS\system32\nuoyan.dll not found!
Deletion of file C:\WINDOWS\system32\nuoyan.dll failed!
Could not process line:
C:\WINDOWS\system32\nuoyan.dll
Status: 0xc0000034
File C:\WINDOWS\86529671.exe not found!
Deletion of file C:\WINDOWS\86529671.exe failed!
Could not process line:
C:\WINDOWS\86529671.exe
Status: 0xc0000034
File C:\WINDOWS\system32\fcfe.dll not found!
Deletion of file C:\WINDOWS\system32\fcfe.dll failed!
Could not process line:
C:\WINDOWS\system32\fcfe.dll
Status: 0xc0000034
File C:\WINDOWS\system32\ucpphxd.dll deleted successfully.
File C:\WINDOWS\system32\xqahirf.dll deleted successfully.
File C:\WINDOWS\system32\gctydyh.dll deleted successfully.
File C:\WINDOWS\system32\gmsmujj.dll deleted successfully.
File C:\WINDOWS\system32\kmkcmkm.dll deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
--
here's the hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 9:18:51 AM, on 4/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\MacOpener\FORMATM.EXE
C:\Program Files\Alias\Maya6.5\docs\wrapper.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE
C:\Program Files\Alias\Maya6.5\docs\jre\bin\java.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Iomega\REV System Software\RevUDF.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Iomega\REV System Software\imiconxp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\MacOpener\MacName.exe
C:\Program Files\Locate\Locate32.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {17BF8265-182C-ACC7-E148-035E7812F862} - C:\WINDOWS\system32\nxyrckn.dll (file missing)
O2 - BHO: (no name) - {1AF171AE-BF57-16F1-1E98-029E0A637B4B} - C:\WINDOWS\system32\pszcksc.dll (file missing)
O2 - BHO: (no name) - {306FD9C9-02FA-E96B-FB4D-03BEF7248387} - C:\WINDOWS\system32\rnuubyh.dll (file missing)
O2 - BHO: (no name) - {3370977D-04C5-6609-1400-05E9A107769D} - C:\WINDOWS\system32\niyjzml.dll (file missing)
O2 - BHO: (no name) - {35359AF1-776B-187A-704D-051A47AE3CA3} - C:\WINDOWS\system32\sabpcni.dll (file missing)
O2 - BHO: (no name) - {36A03F58-048D-0CED-EF99-00E7BD51FE79} - C:\WINDOWS\system32\czpqitl.dll (file missing)
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: (no name) - {51F398D1-B5CD-F473-7F9F-0B7FD54B87AE} - C:\WINDOWS\system32\sofzadm.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54B28AA4-61C6-0044-6293-003D3FF07768} - C:\WINDOWS\system32\livtmng.dll (file missing)
O2 - BHO: (no name) - {57CD3B52-F85B-912E-E029-0324EF8E1CE9} - C:\WINDOWS\system32\btxcrth.dll (file missing)
O2 - BHO: (no name) - {57D29FA1-1D44-7FE5-3D6D-0488299A898F} - C:\WINDOWS\system32\yqnlgpn.dll (file missing)
O2 - BHO: (no name) - {71AB6E1D-F6BC-0FEE-C637-0169C8856252} - C:\WINDOWS\system32\bwuppni.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Miramar Systems, Inc.] C:\Program Files\Miramar\PC MACLAN\atmsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\MacOpener\MacLic.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\system32\per.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [SysTray] C:\Program Files\syeqpqq.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\imiconxp.exe
O4 - HKLM\..\Run: [hmijrxm.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\hmijrxm.dll,lqyndxd
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [sgepkl.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\sgepkl.dll,ouyasdg
O4 - HKLM\..\Run: [nprwxpd.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nprwxpd.dll,xtblzo
O4 - HKLM\..\Run: [ylyiasi.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ylyiasi.dll,tpzzoqd
O4 - HKLM\..\Run: [yvfskwc.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\yvfskwc.dll,kakuvjb
O4 - HKLM\..\Run: [idarlmi.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\idarlmi.dll,kxtabbb
O4 - HKLM\..\Run: [yvizyre.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\yvizyre.dll,fpspspf
O4 - HKLM\..\Run: [rfrucym.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rfrucym.dll,rjlphze
O4 - HKLM\..\Run: [bsofrfk.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\bsofrfk.dll,jcczond
O4 - HKLM\..\Run: [ayuulpl.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ayuulpl.dll,myniube
O4 - HKLM\..\Run: [tteootl.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tteootl.dll,nuoyan
O4 - HKLM\..\Run: [soft2] C:\WINDOWS\86529671.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Locate32 Autorun.lnk = ?
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: MacName.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/active...
O21 - SSODL: nrczwhAHVgZ - {D4B4C901-7E1E-63AB-F574-E4D2B3F06752} - C:\WINDOWS\system32\fcfe.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AppleTalk Messenger (ATMsg) - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\MacOpener\FORMATM.EXE" /SERVICE (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Program Files\Alias\Maya6.5\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya6.5\docs\Wrapper.conf (file missing)
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf (file missing)
O23 - Service: Miramar AppleTalk File Server - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE
O23 - Service: Miramar AppleTalk Print Server - Miramar Systems Inc. - C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RevUDFService - Iomega Corp - C:\Program Files\Iomega\REV System Software\RevUDF.exe
--
And now the combofix log:
"Administrator" - 07-04-27 9:22:11 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Program Files\Mozilla Firefox\"
((((((((((((((((((((((((((((((( Files Created from 2007-03-27 to 2007-04-27 ))))))))))))))))))))))))))))))))))
2007-04-27 09:13 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\Juniper Networks
2007-04-27 09:13 <DIR> d-------- C:\avenger
2007-04-26 22:59 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-04-26 22:44 <DIR> d-------- C:\VundoFix Backups
2007-04-26 19:11 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-05 14:12 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-04-05 14:11 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-04-05 11:39 <DIR> d-------- C:\spoolerlogs
2007-03-28 18:03 <DIR> d-------- C:\DOCUME~1\NETWOR~1\Application Data\Juniper Networks
2007-03-28 18:02 <DIR> d-------- C:\Program Files\Juniper Networks
2007-03-28 18:02 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\Juniper Networks
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-03 10:27 73 --a------ C:\WINDOWS\system32\ssprs.dll
2007-04-03 10:27 205 --a------ C:\WINDOWS\system32\lsprst7.dll
2007-03-17 09:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-16 11:42 -------- d-------- C:\Program Files\mixmeister bpm analyzer
2007-03-08 11:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-02-05 16:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-02-01 10:22 54272 --a------ C:\WINDOWS\system32\tmpwisc1.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{17BF8265-182C-ACC7-E148-035E7812F862} C:\WINDOWS\system32\nxyrckn.dll [x]
{1AF171AE-BF57-16F1-1E98-029E0A637B4B} C:\WINDOWS\system32\pszcksc.dll [x]
{306FD9C9-02FA-E96B-FB4D-03BEF7248387} C:\WINDOWS\system32\rnuubyh.dll [x]
{3370977D-04C5-6609-1400-05E9A107769D} C:\WINDOWS\system32\niyjzml.dll [x]
{35359AF1-776B-187A-704D-051A47AE3CA3} C:\WINDOWS\system32\sabpcni.dll [x]
{36A03F58-048D-0CED-EF99-00E7BD51FE79} C:\WINDOWS\system32\czpqitl.dll [x]
{45AD732C-2CE2-4666-B366-B2214AD57A49} C:\Program Files\Desktop Sidebar\sbhelp.dll
{51F398D1-B5CD-F473-7F9F-0B7FD54B87AE} C:\WINDOWS\system32\sofzadm.dll [x]
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{54B28AA4-61C6-0044-6293-003D3FF07768} C:\WINDOWS\system32\livtmng.dll [x]
{57CD3B52-F85B-912E-E029-0324EF8E1CE9} C:\WINDOWS\system32\btxcrth.dll [x]
{57D29FA1-1D44-7FE5-3D6D-0488299A898F} C:\WINDOWS\system32\yqnlgpn.dll [x]
{71AB6E1D-F6BC-0FEE-C637-0169C8856252} C:\WINDOWS\system32\bwuppni.dll [x]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
{AE7CD045-E861-484f-8273-0445EE161910} C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NVRaidService"="C:\\WINDOWS\\system32\\nvraidservice.exe"
"NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Miramar Systems, Inc."="C:\\Program Files\\Miramar\\PC MACLAN\\atmsg.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"MacLicense"="\"C:\\Program Files\\MacOpener\\MacLic.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"ControlPanel"="C:\\WINDOWS\\system32\\per.exe internat.dll,LoadKeyboardProfile"
"SysTray"="C:\\Program Files\\syeqpqq.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
@=""
"Iomega ImIconXP"="C:\\Program Files\\Iomega\\REV System Software\\imiconxp.exe"
"hmijrxm.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\hmijrxm.dll,lqyndxd"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"sgepkl.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\sgepkl.dll,ouyasdg"
"nprwxpd.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\nprwxpd.dll,xtblzo"
"ylyiasi.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\ylyiasi.dll,tpzzoqd"
"yvfskwc.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\yvfskwc.dll,kakuvjb"
"idarlmi.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\idarlmi.dll,kxtabbb"
"yvizyre.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\yvizyre.dll,fpspspf"
"rfrucym.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\rfrucym.dll,rjlphze"
"bsofrfk.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\bsofrfk.dll,jcczond"
"ayuulpl.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\ayuulpl.dll,myniube"
"tteootl.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\tteootl.dll,nuoyan"
"soft2"="C:\\WINDOWS\\86529671.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=dword:00000000
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=dword:00000000
"NoThemesTab"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"nrczwhAHVgZ"="{D4B4C901-7E1E-63AB-F574-E4D2B3F06752}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-04-27 09:26:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-27 9:26:36
C:\ComboFix-quarantined-files.txt ... 07-04-27 09:26
C:\ComboFix2.txt ... 07-04-26 22:59
--
here's the combofix quarantine folder...not much to read:
[code]
Folder PATH listing
Volume serial number is D4B4-C900
C:\QOOBOX
\---Quarantine
\---Registry_backups
[/code]
--
OK... do your stuff. Thanks again everyone!
-Dave