Combo Fix log is as follows :
ComboFix 08-05-12.1 - VAMSHI ATMAKUR 2008-05-14 18:24:29.2 - NTFSx86
Running from: C:\Documents and Settings\VAMSHI ATMAKUR\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\VAMSHI ATMAKUR\Desktop\CFScript.txt
* Created a new restore point
[color=\"red\"]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\maxsv15
C:\Temp\maxsv15\rLCubd.log
C:\VundoFix Backups
C:\VundoFix Backups\cbeeg.bak1.bad
C:\VundoFix Backups\cbeeg.bak2.bad
C:\VundoFix Backups\cbeeg.ini.bad
C:\VundoFix Backups\cbeeg.ini2.bad
C:\VundoFix Backups\cbeeg.tmp.bad
C:\WINDOWS\system32\2033b
C:\WINDOWS\system32\bkEur01
C:\WINDOWS\system32\hNF
C:\WINDOWS\system32\Ndb2
C:\WINDOWS\system32\rgffnjih.ini
C:\WINDOWS\system32\vdTMP
.
((((((((((((((((((((((((( Files Created from 2008-04-14 to 2008-05-14 )))))))))))))))))))))))))))))))
.
2008-05-14 18:16 . 2008-05-14 18:16 <DIR> d-------- C:\WINDOWS\LastGood
2008-05-13 20:24 . 2008-05-13 23:15 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-05-12 21:05 . 2008-05-12 21:05 114,688 --a------ C:\WINDOWS\system32\hijnffgr.dll
2008-05-12 21:02 . 2008-05-12 21:02 132,608 --a------ C:\WINDOWS\system32\vwnbyduq.dll
2008-05-12 20:59 . 2008-05-12 22:20 124,416 --------- C:\WINDOWS\system32\ktkuqcrk.dll
2008-05-12 20:56 . 2008-05-12 20:56 <DIR> d-------- C:\Documents and Settings\VAMSHI ATMAKUR\Application Data\Malwarebytes
2008-05-12 20:56 . 2008-05-12 20:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-12 20:56 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-12 20:56 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-12 20:55 . 2008-05-12 20:56 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-12 20:53 . 2008-05-12 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-05-11 21:22 . 2008-05-12 20:29 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-11 16:08 . 2008-05-11 16:08 125,440 --a------ C:\WINDOWS\system32\iorvuhgh.dll
2008-05-11 16:08 . 2008-05-12 20:59 109,807 --a------ C:\WINDOWS\BM348c2f85.xml
2008-05-11 16:04 . 2008-05-12 22:20 372,224 --------- C:\WINDOWS\system32\fccdcBQI.dll
2008-05-11 15:57 . 2008-05-12 22:20 52,736 --------- C:\WINDOWS\system32\yayxvWMg.dll
2008-05-04 09:52 . 2008-05-04 09:53 <DIR> d-------- C:\Program Files\SopCast
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 00:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-11 23:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-11 21:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-11 21:34 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-05-11 21:34 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-05-11 21:34 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-16 22:29 3,059,712 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-15 09:23 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2007-03-07 13:29 47,344 ----a-w C:\Documents and Settings\VAMSHI ATMAKUR\Application Data\GDIPFONTCACHEV1.DAT
2006-01-08 17:03 560 ----a-w C:\Documents and Settings\VAMSHI ATMAKUR\Application Data\ViewerApp.dat
2004-08-21 14:51 21,447 ----a-w C:\Documents and Settings\VAMSHI ATMAKUR\Favorites.zip
2004-07-31 16:23 0 --sh--r C:\Program Files\q330994.exe
2004-07-23 01:45 1,160,964 ----a-w C:\Documents and Settings\Guest\wrar34b2.exe
2004-07-23 01:44 9,228,986 ----a-w C:\Documents and Settings\Guest\vlc-0.7.2-win32.exe
2004-07-23 01:41 3,292,584 ----a-w C:\Documents and Settings\Guest\DivXPlayerInstaller.exe
2004-07-31 16:23 0 --sh--r C:\WINDOWS\cvchost.exe
2004-06-28 09:02 2,926 --sha-w C:\WINDOWS\egcng.dat
2004-07-03 03:37 2,926 --sha-w C:\WINDOWS\givip.dat
2004-07-31 16:23 0 --sh--r C:\WINDOWS\msstasks.exe
2004-07-31 16:23 0 --sh--r C:\WINDOWS\mssys.com
2004-07-31 16:23 0 --sh--r C:\WINDOWS\mstaskss.exe
2004-07-31 16:23 0 --sh--r C:\WINDOWS\msxmidi.exe
2004-07-31 16:23 0 --sh--r C:\WINDOWS\ntldr.exe
2004-07-31 16:23 0 --sh--r C:\WINDOWS\rocky.exe
2004-07-31 16:23 0 --sh--r C:\WINDOWS\seksdialer.exe
2004-07-04 04:47 2,926 --sha-w C:\WINDOWS\vjrkb.dat
2004-06-21 09:24 2,926 --sha-w C:\WINDOWS\vsdbk.dat
2004-07-03 22:27 2,926 --sha-w C:\WINDOWS\worst.dat
2004-07-31 16:23 0 --sh--r C:\WINDOWS\system\system.exe
2004-07-31 16:23 0 --sh--r C:\WINDOWS\system\wmscrop.exe
2004-07-31 16:23 0 --sh--r C:\WINDOWS\system32\d2kpax.dll
2004-07-31 16:23 0 --sh--r C:\WINDOWS\system32\d2kpax.exe
2004-07-10 03:00 2,926 --sha-w C:\WINDOWS\system32\dntwj.dat
2004-07-07 21:08 2,926 --sha-w C:\WINDOWS\system32\hahhu.dat
2004-07-31 16:23 0 --sh--r C:\WINDOWS\system32\jac.dll
2004-07-10 00:28 2,926 --sha-w C:\WINDOWS\system32\lmzri.dat
2004-06-27 23:19 2,926 --sha-w C:\WINDOWS\system32\lqvef.dat
2004-07-31 16:23 0 --sh--r C:\WINDOWS\system32\msxslab.dll
2004-07-13 10:44 2,926 --sha-w C:\WINDOWS\system32\qjeuv.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Temp ----
2008-05-11 15:57 1858 --a------ C:\Temp\maxsv15\rLCubd.log
2006-01-22 16:02 18179 --a------ C:\Temp\fftrace.log
2005-12-15 21:05 851 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-12-15-2005-20-02-54.log
2005-11-07 21:54 879 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-11-07-2005-20-52-01.log
2005-10-18 20:42 1562 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-10-18-2005-20-39-35.log
2005-08-20 12:13 1618 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-08-20-2005-12-10-27.log
2005-05-01 18:29 14432 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-05-01-2005-18-26-41.log
2005-05-01 18:29 14432 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-05-01-2005-18-26-39.log
2005-05-01 18:29 14432 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-05-01-2005-18-26-16.log
2005-05-01 18:08 844 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-05-01-2005-18-05-59.log
2005-05-01 18:06 844 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-05-01-2005-18-03-20.log
2005-05-01 17:52 844 --a------ C:\Temp\mxAEFAdminRegDynamicNaming-05-01-2005-17-49-17.log
2003-11-18 09:31 69101 --------- C:\Temp\ETH1.jpg
2003-11-18 09:26 112 --------- C:\Temp\QuickStartGuide.html
(((((((((((((((((((((((((((((
snapshot@2008-05-12_22.50.06.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-13 03:39:25 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-14 23:12:42 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2007-07-27 20:49:02 196,683 ----a-w C:\WINDOWS\system32\lnod32apiA.dll
+ 2007-07-27 20:49:02 225,355 ----a-w C:\WINDOWS\system32\lnod32apiW.dll
+ 2005-12-06 01:25:22 139,264 ----a-w C:\WINDOWS\system32\lnod32umc.dll
+ 2005-12-05 18:37:10 106,496 ----a-w C:\WINDOWS\system32\lnod32upd.dll
+ 2007-08-02 23:11:28 253,952 ----a-w C:\WINDOWS\system32\OnlineScannerDLLA.dll
+ 2007-08-02 23:11:14 241,664 ----a-w C:\WINDOWS\system32\OnlineScannerDLLW.dll
+ 2007-08-06 18:17:40 19,456 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll
+ 2007-06-13 16:10:34 77,824 ----a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 22:49 4662776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 21:00 335872]
"CamMonitor"="C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 03:23 90112]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 21:44 65536]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-07-18 20:23 868352]
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2006-02-05 18:26 230512]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2006-02-05 18:26 185456]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2005-04-22 20:49 397312]
"IPInSightLAN 02"="C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" [2003-06-11 02:52 380928]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2004-07-24 11:10:43 18432]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys [2004-04-14 17:52]
R0 sonypvl3;sonypvl3;C:\WINDOWS\system32\drivers\sonypvl3.sys [2004-09-22 12:55]
R1 sonypvf3;sonypvf3;C:\WINDOWS\system32\drivers\sonypvf3.sys [2004-11-15 14:55]
R1 sonypvt3;sonypvt3;C:\WINDOWS\system32\drivers\sonypvt3.sys [2004-12-06 15:26]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2006-09-22 05:05]
R3 WedgeTransport;IPSec Adapter;C:\WINDOWS\system32\DRIVERS\VIPSecMP.sys [2004-03-09 18:20]
S1 sonypvd3;Sony DVD Handycam;C:\WINDOWS\system32\DRIVERS\sonypvd3.sys [2004-12-07 16:00]
S2 pciinfo;HP Pci Information;C:\DOCUME~1\VAMSHI~1\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys []
S3 OracleOraHome92ClientCache;OracleOraHome92ClientCache;C:\oracle\ora92\BIN\ONRSD.EXE [2002-04-26 19:34]
S3 OracleOraHome92SNMPPeerEncapsulator;OracleOraHome92SNMPPeerEncapsulator;C:\oracle\ora92\BIN\ENCSVC.EXE [2002-02-13 08:23]
S3 OracleOraHome92SNMPPeerMasterAgent;OracleOraHome92SNMPPeerMasterAgent;C:\oracle\ora92\BIN\AGNTSVC.EXE [2002-02-13 08:23]
S3 P1001VID;Creative WebCam (WDM);C:\WINDOWS\system32\DRIVERS\P1001Vid.sys [2002-06-03 21:38]
S3 ZSMC0305;ZVC7100 PC CAMERA (VC0305);C:\WINDOWS\system32\Drivers\usbVM305.sys [2006-02-09 15:50]
S4 OracleOraHome92Agent;OracleOraHome92Agent;C:\oracle\ora92\bin\agntsrvc.exe [2002-04-26 17:29]
S4 OracleOraHome92HTTPServer;OracleOraHome92HTTPServer;"C:\oracle\ora92\Apache\Apache\apache.exe" --ntservice []
S4 OracleServiceVAMSHI;OracleServiceVAMSHI;c:\oracle\ora92\bin\ORACLE.EXE VAMSHI []
.
Contents of the 'Scheduled Tasks' folder
"2008-05-14 23:15:58 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2004-07-23 23:08:16 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-14 18:31:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OracleOraHome92PagingServer]
"ImagePath"="C:\oracle\ora92/bin/pagntsrv.exe"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\OracleOraHome92TNSListener]
"ImagePath"="C:\oracle\ora92\BIN\TNSLSNR "
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-05-14 18:41:07
ComboFix-quarantined-files.txt 2008-05-14 23:40:53
ComboFix2.txt 2008-05-13 03:51:14
ComboFix3.txt 2007-06-18 01:16:17
Pre-Run: 23,959,216,128 bytes free
Post-Run: 23,951,253,504 bytes free
203 --- E O F --- 2008-05-09 02:59:52