...so, as I was unable to get either bleepingcomputer or geekstogo to open on this, went
to work and downloaded ComboFix there, brought it home, run it....HA HA , think we got the little f&*@er!!!
here's the log:
ComboFix 10-01-19.03 - Bill Schoen 01/19/2010 17:15:36.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.772 [GMT -7:00]
Running from: D:\Combo-Fix.exe
AV: AVG *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Bill Schoen\Start Menu\Internet Security 2010.lnk
C:\LOG.TXT
C:\s
c:\windows\system32\drivers\H8SRTwswuyurgba.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\H8SRTfypqxylkli.dll
c:\windows\system32\h8srtkrl32mainweq.dll
c:\windows\system32\H8SRTqpxeolevxf.dat
c:\windows\system32\H8SRTrijraftdct.dll
c:\windows\system32\h8srtshsyst.dll
c:\windows\system32\H8SRTtatmslptqb.dll
c:\windows\system32\H8SRTuwfiwnxvbf.dll
c:\windows\system32\tmp.reg
c:\windows\system32\warning.html
c:\windows\system32\WORK.DAT
c:\windows\system32\wupd.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
((((((((((((((((((((((((( Files Created from 2009-12-20 to 2010-01-20 )))))))))))))))))))))))))))))))
.
2010-01-18 21:55 . 2010-01-18 21:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-01-18 17:50 . 2010-01-20 00:14 -------- d-----w- c:\program files\Alwil Software
2010-01-18 15:32 . 2010-01-18 15:32 2 --shatr- c:\windows\winstart.bat
2010-01-18 14:48 . 2010-01-18 14:48 -------- d--h--w- c:\windows\system32\GroupPolicy
2010-01-17 14:20 . 2010-01-17 14:20 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-17 14:20 . 2010-01-17 14:20 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-01-10 18:55 . 2009-07-28 22:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-07 06:04 . 2010-01-07 06:05 -------- d-----w- c:\documents and settings\Bill Schoen\Local Settings\Application Data\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-19 23:21 . 2006-11-09 21:09 -------- d-----w- c:\program files\mIRC
2010-01-11 15:28 . 2006-10-06 22:10 -------- d-----w- c:\program files\AltoMP3 Gold
2009-12-13 16:10 . 2009-12-13 15:16 -------- d-----w- c:\program files\Yahoo!
2009-12-13 15:19 . 2009-12-13 15:19 -------- d-----w- c:\documents and settings\Bill Schoen\Application Data\Yahoo!
2009-11-28 02:53 . 2007-05-30 17:09 -------- d-----w- c:\program files\eMusic Download Manager
2009-11-28 02:48 . 2007-11-10 13:36 -------- d-----w- c:\program files\eMusic Remote
2009-11-21 16:36 . 2004-08-04 07:56 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 05:48 . 2004-08-04 07:56 662016 ----a-w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
R0 vburner;vburner;c:\windows\system32\drivers\vburner.sys [8/7/2008 10:06 AM 15872]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/1/2008 7:23 AM 325128]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/1/2008 7:23 AM 107272]
S3 MovRVDrv32;MovRVDrv32;c:\windows\system32\drivers\MovRVDrv32.sys [9/25/2008 7:02 AM 3768]
.
Contents of the 'Scheduled Tasks' folder
2010-01-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 20:21]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Bill Schoen\Application Data\Mozilla\Firefox\Profiles\aq6lfsbn.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.yahoo.comFF - prefs.js: network.proxy.type - 1
FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
.
- - - - ORPHANS REMOVED - - - -
Notify-WgaLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-19 17:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-19 17:33:33 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-20 00:33
Pre-Run: 36,130,811,904 bytes free
Post-Run: 36,102,500,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - E31BF0C2B361038CE0BBA26DDF12E84E
I've done a couple of reboots since, and things seem to be working well:
no hijacked search links
no blocked webpages
no errors
AV software is able to open again and running fine
what next boss?