The link to download combofix doesnt work atm.. i d/l'ed from
http://www.forospyware.com/sUBs/ComboFix.exeWell heres my ComboFix Log..
ComboFix 08-02.05.3 - Owner 2008-02-08 0:13:08.1 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\.protected
C:\Documents and Settings\Owner\Application Data\printer.exe
C:\Program Files\winupdates
C:\WINDOWS\inf\ultra.inf
C:\WINDOWS\system32\ctfmona.exe
C:\WINDOWS\system32\drivers\etc\.protected
C:\WINDOWS\system32\sks~1
C:\WINDOWS\system32\sks~1\scanregw.exe
C:\WINDOWS\system32\strike12.dll
C:\WINDOWS\system32\strike45.dll
C:\WINDOWS\system32\wowfx.dll . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-08 00:17 . 67,584 C:\CD Burning Stash File.bin
2008-02-07 23:30 . 2008-02-07 23:30 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\EasySpywareCleaner.com
2008-02-07 23:29 . 2008-02-07 23:44 <DIR> d-------- C:\Program Files\EasySpywareCleaner
2008-02-07 19:46 . 2008-02-08 00:18 <DIR> d-------- C:\Program Files\NetZero
2008-02-03 23:44 . 2008-02-03 23:44 69,790 --a------ C:\Documents and Settings\Owner\Application Data\32103.exe
2008-02-03 11:11 . 2008-02-03 11:11 269,334 --a------ C:\WINDOWS\system32\knqpsb.bmp
2008-02-03 00:17 . 2008-02-03 00:17 269,334 --a------ C:\WINDOWS\system32\gratcfilsf.bmp
2008-02-02 23:28 . 2008-02-02 23:28 269,334 --a------ C:\WINDOWS\system32\nelsrih.bmp
2008-02-02 10:49 . 2008-02-02 10:49 269,334 --a------ C:\WINDOWS\system32\ormdkbmdonil.bmp
2008-02-02 00:26 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-02 00:24 . 2008-02-02 00:24 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-01 12:27 . 2008-02-01 12:27 269,334 --a------ C:\WINDOWS\system32\dcfmton.bmp
2008-01-31 12:33 . 2008-01-31 12:33 269,334 --a------ C:\WINDOWS\system32\bahsrqtsjit.bmp
2008-01-31 12:28 . 2008-01-31 12:28 1,402 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-31 12:05 . 2008-01-31 12:05 269,334 --a------ C:\WINDOWS\system32\tgnalsb.bmp
2008-01-30 21:30 . 2008-01-30 21:30 269,334 --a------ C:\WINDOWS\system32\elojmlcj.bmp
2008-01-30 20:57 . 2008-01-30 20:57 269,334 --a------ C:\WINDOWS\system32\edgfipgbipsn.bmp
2008-01-30 20:54 . 2008-01-30 20:54 269,334 --a------ C:\WINDOWS\system32\lgbmp.bmp
2008-01-30 17:37 . 2008-01-30 17:37 269,334 --a------ C:\WINDOWS\system32\pkjmd.bmp
2008-01-30 17:11 . 2008-01-30 17:11 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Anti-Virus-Pro.com
2008-01-30 16:33 . 2008-01-30 16:33 269,334 --a------ C:\WINDOWS\system32\nelgjmd.bmp
2008-01-30 16:33 . 2008-01-30 16:33 26,176 --a------ C:\WINDOWS\system32\BluetoothAuthorizationAgent.exe
2008-01-30 16:32 . 2005-05-30 16:36 98,709 --a------ C:\Documents and Settings\Owner\Application Data\sysdefender.exe
2008-01-30 16:20 . 2005-06-12 02:33 18,944 --a------ C:\WINDOWS\system32\wowfx.dll
2008-01-19 16:06 . 2008-01-19 16:06 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-01-17 21:39 . 2008-01-17 21:39 <DIR> d-------- C:\Program Files\Soft-Central
2008-01-17 20:10 . 2008-01-17 20:10 <DIR> d-------- C:\ConTemp
2008-01-17 00:02 . 2008-01-17 23:36 <DIR> d-------- C:\Program Files\NewLive All Audio To Mp3 Converter
2008-01-13 22:57 . 2008-01-13 22:59 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Winamp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 08:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\NetZero
2008-02-06 15:10 --------- d-----w C:\Program Files\LimeWire
2008-02-06 03:52 --------- d-----w C:\Program Files\Graffiti Studio 2.0
2008-02-02 08:26 --------- d-----w C:\Program Files\Java
2008-01-14 06:59 --------- d-----w C:\Program Files\Winamp
2008-01-13 08:48 --------- d-----w C:\Documents and Settings\Owner\Application Data\GetRight Pro
2007-12-20 05:20 --------- d-----w C:\Program Files\Aimb0yd
2007-12-19 21:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-19 21:04 --------- d-----w C:\Program Files\NHN USA
2007-12-11 08:00 --------- d-----w C:\Program Files\iTunes
2007-12-09 19:37 --------- d-----w C:\Program Files\WinAce
2007-12-09 19:34 --------- d-----w C:\Program Files\HGI
2007-12-08 09:13 --------- d-----w C:\Program Files\Trend Micro
2006-07-31 05:15 40 ----a-w C:\Documents and Settings\Owner\language.dat
2006-07-19 05:47 3,072 --sha-w C:\Program Files\Thumbs.db
2005-10-16 03:56 280,064 ----a-w C:\Documents and Settings\Owner\Application Data\tizhook.bin
2005-10-16 03:54 297,281 ----a-w C:\Documents and Settings\Owner\Application Data\tizupd.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [2007-03-06 16:00 1629184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 13:55 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 13:51 118784]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-06-30 14:56 2376928]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-10-18 09:58 278528]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 02:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-08 18:44 155648]
"!xSpeed"="C:\!xSpeedPro\!xSpeedPro.exe" [2003-10-21 23:29 32256]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"ctfmona"="C:\WINDOWS\System32\ctfmona.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\wowfx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, xlibgfl254.dll, wowfx.dll
R3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\System32\DRIVERS\loop.sys [2001-08-17 11:53]
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\System32\Drivers\BW2NDIS5.sys []
S3 CEDRIVER53;CEDRIVER53;C:\Program Files\Cheat Engine\dbk32.sys []
S3 dump_wmimmc;dump_wmimmc;c:\ijji\ENGLISH\Gunbound Revolution\GameGuard\dump_wmimmc.sys []
S3 kaspersky1;kaspersky1;C:\Documents and Settings\Owner\Desktop\MSHACKS\KASPERSKY\kaspersky.sys []
S3 mqdmbus;Motorola DM Composite Driver (WDM);C:\WINDOWS\System32\DRIVERS\mqdmbus.sys [2006-07-13 12:58]
S3 mqdmmdfl;Motorola USB Modem (Filter);C:\WINDOWS\System32\DRIVERS\mqdmmdfl.sys [2006-07-13 13:02]
S3 mqdmmdm;Motorola USB Modem;C:\WINDOWS\System32\DRIVERS\mqdmmdm.sys [2006-07-13 13:03]
S3 mqdmserd;Motorola USB Diag;C:\WINDOWS\System32\DRIVERS\mqdmserd.sys [2006-07-13 13:03]
S3 Revolution1;Revolution1;C:\Documents and Settings\Owner\Desktop\Game Stuffed\MH\gb\Revolution_Engine_8.3_ShaK3\SHAK3.sys [2007-07-01 22:26]
S3 sejt1;sejt1;C:\Documents and Settings\Owner\Desktop\Akuma Engine\sejt.sys []
S3 SiwvidStart;SiwvidStart;C:\DOCUME~1\Owner\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\siwvid.sys []
S3 xp1;xp1;C:\Documents and Settings\Owner\Desktop\xpengine\xp.sys []
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-08 00:17:09
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2800.1106]
-> C:\!xSpeedPro\hook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
**************************************************************************
.
Completion time: 2008-02-08 0:21:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 08:21:03
I still cant seem to get rid of that darn wowfx.dll
HJThis Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:02:16 AM, on 2/8/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\BCMSMMSG.exe
C:\!xSpeedPro\!xSpeedPro.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HiJack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 64.136.29.30;64.136.21.30;64.136.29.34;searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.windows.com;*.pogo.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkassociates.com;*photosite.com;*.dir.untd.com;*.prod.untd.com;*.2mdn.net;cf.netzero.net;qs.netzero.net;<local>
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!xSpeed] C:\!xSpeedPro\!xSpeedPro.exe reg
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{87D431DF-8AFE-4B41-9517-0448F1B5EAC1}: NameServer = 64.136.52.73 64.136.44.73
O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
--
End of file - 4151 bytes