hfosteriii
2008-04-14, 07:30
I have updated and ran spybot, adaware and nortons av, more than once to no avail. Now I turn to you. The comp in question isn't connected to the internet. I am posting the HTJ and ComboFix logs. Thanks in advance and I'll be sure to thank afterwards.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:47 PM, on 4/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
F:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)
O2 - BHO: (no name) - {4CB690D4-BE97-4CE8-A153-F56463A6E077} - C:\WINDOWS\system32\nnnljjGa.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {78C7963F-A936-47F5-9365-AD7F783F8BEE} - C:\WINDOWS\system32\mlJDvWOG.dll (file missing)
O2 - BHO: (no name) - {7BCBE1BA-53B3-442D-9D0A-3507441C393A} - C:\WINDOWS\system32\rqRJApmj.dll (file missing)
O2 - BHO: (no name) - {A0F860F1-987B-4BFC-AE36-33840CDC50B9} - C:\WINDOWS\system32\qoMggHAS.dll (file missing)
O2 - BHO: (no name) - {BB98B576-2B99-4C67-92BC-C918C4395A7B} - C:\WINDOWS\system32\byXOhEwU.dll (file missing)
O2 - BHO: (no name) - {E17C5AE4-1DA8-4015-B8D9-0CD681973EC7} - C:\WINDOWS\system32\cbXQghHw.dll (file missing)
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [985aaa28] rundll32.exe "C:\WINDOWS\system32\vqqtoctx.dll",b
O4 - HKLM\..\Run: Rundll32.exe "C:\WINDOWS\system32\xrijukog.dll",s
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - https://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://download-games.pogo.com/online2/pogo/luxor_amun_rising/mjolauncher.cab
O20 - Winlogon Notify: urqOHYSL - urqOHYSL.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 7690 bytes
ComboFix 08-04-13.2 - a 2008-04-13 23:43:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.732 [GMT -4:00]
Running from: F:\ComboFix.exe
[b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\gbRve12
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aGjjlnnn.ini
C:\WINDOWS\system32\aGjjlnnn.ini2
C:\WINDOWS\system32\jmpAJRqr.ini
C:\WINDOWS\system32\jmpAJRqr.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rYFgPXbc.ini
C:\WINDOWS\system32\rYFgPXbc.ini2
C:\WINDOWS\system32\SAHggMoq.ini
C:\WINDOWS\system32\SAHggMoq.ini2
C:\WINDOWS\system32\urqOHYSL.dll
C:\WINDOWS\system32\UwEhOXyb.ini
C:\WINDOWS\system32\UwEhOXyb.ini2
C:\WINDOWS\system32\vefkdwqp.ini
C:\WINDOWS\system32\wHhgQXbc.ini
C:\WINDOWS\system32\wHhgQXbc.ini2
C:\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-14 to 2008-04-14 )))))))))))))))))))))))))))))))
.
2008-04-12 18:57 . 2008-04-12 19:02 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-04-12 18:56 . 2006-09-02 18:21 108,728 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-04-12 18:56 . 2006-09-02 18:21 48,824 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-04-12 18:55 . 2008-04-12 18:59 <DIR> d-------- C:\Program Files\Symantec
2008-04-12 18:50 . 2008-04-12 18:53 354 --ahs---- C:\WINDOWS\system32\xtcotqqv.ini
2008-04-12 18:47 . 2008-04-12 18:47 3,648 --a------ C:\WINDOWS\system32\wewgmffb.dll
2008-04-12 18:44 . 2002-01-01 01:08 275,988 --ahs---- C:\WINDOWS\system32\GOWvDJlm.ini
2008-04-12 18:44 . 2002-01-01 01:05 275,874 --ahs---- C:\WINDOWS\system32\GOWvDJlm.ini2
2008-04-12 17:05 . 2008-04-12 17:05 294 --ahs---- C:\WINDOWS\system32\aogfhnjc.ini
2008-04-12 17:02 . 2008-04-12 18:15 94,208 --------- C:\WINDOWS\system32\stwwsqxc.gmt
2008-04-12 16:59 . 2008-04-12 16:59 3,648 --a------ C:\WINDOWS\system32\djwmxqdj.dll
2008-04-12 16:56 . 2008-04-12 16:56 272,384 --a------ C:\WINDOWS\system32\cfrfhzto.yol
2008-04-12 12:28 . 2008-04-12 12:54 294 --ahs---- C:\WINDOWS\system32\ylphyjhn.ini
2008-04-12 12:21 . 2008-04-12 15:36 94,208 --------- C:\WINDOWS\system32\vpcyzqrj.zll
2008-04-12 12:21 . 2008-04-12 12:21 3,648 --a------ C:\WINDOWS\system32\ucdgmody.dll
2008-04-12 12:18 . 2008-04-12 12:18 272,384 --a------ C:\WINDOWS\system32\xoakldvo.pyh
2008-04-12 02:56 . 2008-04-12 12:09 406 --ahs---- C:\WINDOWS\system32\oiwbumsa.ini
2008-04-12 02:53 . 2008-04-12 15:35 274,432 --a------ C:\WINDOWS\system32\iorpusjb.rfi
2008-04-12 02:06 . 2008-04-12 02:06 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-12 02:06 . 2008-04-12 02:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-11 21:17 . 2008-04-11 21:17 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-11 21:03 . 2002-01-01 00:42 1,033 --a------ C:\WINDOWS\wininit.ini
2008-04-11 20:25 . 2008-04-11 20:25 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-11 20:25 . 2008-04-12 01:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-11 19:13 . 2008-04-11 20:14 594 --ahs---- C:\WINDOWS\system32\piivxvyt.ini
2008-04-10 17:59 . 2008-04-10 17:59 414 --ahs---- C:\WINDOWS\system32\lgigijpl.ini
2008-04-09 17:59 . 2008-04-11 12:05 646 --ahs---- C:\WINDOWS\system32\rajfhpfj.ini
2008-04-08 19:12 . 2008-04-09 08:53 1,778 --ahs---- C:\WINDOWS\system32\dshapovf.ini
2008-04-07 19:09 . 2008-04-08 19:09 1,366 --ahs---- C:\WINDOWS\system32\poadruvt.ini
2008-04-06 19:09 . 2008-04-06 19:15 1,306 --ahs---- C:\WINDOWS\system32\jrkkphsf.ini
2008-04-06 11:50 . 2006-02-28 08:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-06 11:48 . 2008-04-06 11:48 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-04-06 11:43 . 2008-04-06 11:43 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-06 11:43 . 2008-04-06 11:45 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-05 18:57 . 2008-04-05 18:57 0 --a------ C:\config.ini
2008-04-05 18:54 . 2008-04-06 19:04 1,186 --ahs---- C:\WINDOWS\system32\egerapcw.ini
2008-04-05 18:47 . 2008-04-05 18:47 414 --ahs---- C:\WINDOWS\system32\mewhaxms.ini
2008-04-05 09:02 . 2008-04-05 18:39 354 --ahs---- C:\WINDOWS\system32\ysdgmqby.ini
2008-04-04 11:26 . 2008-04-04 09:00 294 --ahs---- C:\WINDOWS\system32\kpydqlju.ini
2008-04-04 08:58 . 2008-04-04 08:58 2,386 --ahs---- C:\WINDOWS\system32\kpydqlju.tmp
2008-04-04 01:19 . 2008-04-04 08:51 2,386 --ahs---- C:\WINDOWS\system32\wntjctim.ini
2008-04-03 13:16 . 2008-04-04 01:11 2,266 --ahs---- C:\WINDOWS\system32\vqlkurkl.ini
2008-04-02 13:18 . 2008-04-03 11:43 1,966 --ahs---- C:\WINDOWS\system32\pnwfiwbm.ini
2008-04-01 13:19 . 2008-04-02 12:33 1,786 --ahs---- C:\WINDOWS\system32\urxwnxnp.ini
2008-04-01 13:13 . 2008-04-12 19:26 101,100 --a------ C:\WINDOWS\BM9b6999b4.xml
2008-03-31 13:15 . 2008-04-01 12:01 1,306 --ahs---- C:\WINDOWS\system32\nurbsroy.ini
2008-03-30 13:15 . 2008-03-31 11:33 774 --ahs---- C:\WINDOWS\system32\liqsfqml.ini
2008-03-29 13:13 . 2008-03-30 13:13 534 --ahs---- C:\WINDOWS\system32\vnnjcylr.ini
2008-03-29 01:21 . 2008-03-29 01:21 <DIR> d-------- C:\Documents and Settings\Test\Application Data\alot
2008-03-29 01:18 . 2008-03-29 01:22 <DIR> d--hs---- C:\Documents and Settings\Test\!
2008-03-29 01:18 . 2008-03-29 01:18 3,545,428 --------- C:\Documents and Settings\Test\x1.dat
2008-03-29 00:45 . 2008-03-29 00:45 <DIR> d-------- C:\WINDOWS\system32\aqVreo05
2008-03-29 00:45 . 2008-04-13 23:44 <DIR> d-------- C:\Temp
2008-03-29 00:45 . 2008-03-29 09:43 <DIR> d--hs---- C:\Documents and Settings\a\!
2008-03-29 00:45 . 2008-03-29 09:20 3,545,428 --------- C:\Documents and Settings\a\x1.dat
2008-03-29 00:45 . 2008-03-29 00:45 0 --a------ C:\WINDOWS\system32\taskkill.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-12 23:29 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-12 23:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-12 05:49 --------- d-----w C:\Program Files\WeatherStudio Desktop
2008-04-11 23:58 --------- d-----w C:\Documents and Settings\a\Application Data\LimeWire
2008-04-05 23:58 --------- d-----w C:\Program Files\Google
2008-04-05 22:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 22:56 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-29 04:46 --------- d-----w C:\Program Files\LimeWire
2008-03-18 19:01 --------- d-----w C:\Program Files\support.com
2008-03-15 17:35 144 ----a-w C:\domains.dat
2008-02-26 23:50 --------- d-----w C:\Program Files\Yahoo! Games
2008-02-21 23:23 --------- d-----w C:\Program Files\Norton Security Scan
2002-01-01 05:05 275,874 --sha-w C:\WINDOWS\system32\GOWvDJlm.ini2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB690D4-BE97-4CE8-A153-F56463A6E077}]
C:\WINDOWS\system32\nnnljjGa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{78C7963F-A936-47F5-9365-AD7F783F8BEE}]
C:\WINDOWS\system32\mlJDvWOG.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BCBE1BA-53B3-442D-9D0A-3507441C393A}]
C:\WINDOWS\system32\rqRJApmj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0F860F1-987B-4BFC-AE36-33840CDC50B9}]
C:\WINDOWS\system32\qoMggHAS.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB98B576-2B99-4C67-92BC-C918C4395A7B}]
C:\WINDOWS\system32\byXOhEwU.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E17C5AE4-1DA8-4015-B8D9-0CD681973EC7}]
C:\WINDOWS\system32\cbXQghHw.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 18:17 159744]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 04:42 144784]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"985aaa28"="C:\WINDOWS\system32\vqqtoctx.dll" [ ]
"BM9b6999b4"="C:\WINDOWS\system32\xrijukog.dll" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 03:04 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 21:22 26248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 21:47 8720384]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 15:12:08 16423]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqOHYSL]
urqOHYSL.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-02-28 08:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ddoctorv2]
--a------ 2007-04-19 15:21 198184 C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2007-12-15 18:42 114688 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2007-12-15 18:42 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-12-18 21:47 8720384 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
--a------ 2003-03-11 17:24 86016 C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-15 19:20 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2003-03-17 18:39]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 17:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 17:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 17:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 17:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 17:50]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-06 09:00:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2008-04-12 23:29:56 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - a.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-13 23:49:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\SoftwareDistribution\Download\d61766d223927760d60364c3824ce500\update\update.exe
.
**************************************************************************
.
Completion time: 2008-04-13 23:53:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-14 03:53:25
Pre-Run: 37,039,960,064 bytes free
Post-Run: 36,996,100,096 bytes free
.
2008-04-07 07:02:24 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:47 PM, on 4/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
F:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - (no file)
O2 - BHO: (no name) - {4CB690D4-BE97-4CE8-A153-F56463A6E077} - C:\WINDOWS\system32\nnnljjGa.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {78C7963F-A936-47F5-9365-AD7F783F8BEE} - C:\WINDOWS\system32\mlJDvWOG.dll (file missing)
O2 - BHO: (no name) - {7BCBE1BA-53B3-442D-9D0A-3507441C393A} - C:\WINDOWS\system32\rqRJApmj.dll (file missing)
O2 - BHO: (no name) - {A0F860F1-987B-4BFC-AE36-33840CDC50B9} - C:\WINDOWS\system32\qoMggHAS.dll (file missing)
O2 - BHO: (no name) - {BB98B576-2B99-4C67-92BC-C918C4395A7B} - C:\WINDOWS\system32\byXOhEwU.dll (file missing)
O2 - BHO: (no name) - {E17C5AE4-1DA8-4015-B8D9-0CD681973EC7} - C:\WINDOWS\system32\cbXQghHw.dll (file missing)
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [985aaa28] rundll32.exe "C:\WINDOWS\system32\vqqtoctx.dll",b
O4 - HKLM\..\Run: Rundll32.exe "C:\WINDOWS\system32\xrijukog.dll",s
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - https://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://download-games.pogo.com/online2/pogo/luxor_amun_rising/mjolauncher.cab
O20 - Winlogon Notify: urqOHYSL - urqOHYSL.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 7690 bytes
ComboFix 08-04-13.2 - a 2008-04-13 23:43:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.732 [GMT -4:00]
Running from: F:\ComboFix.exe
[b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\gbRve12
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aGjjlnnn.ini
C:\WINDOWS\system32\aGjjlnnn.ini2
C:\WINDOWS\system32\jmpAJRqr.ini
C:\WINDOWS\system32\jmpAJRqr.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rYFgPXbc.ini
C:\WINDOWS\system32\rYFgPXbc.ini2
C:\WINDOWS\system32\SAHggMoq.ini
C:\WINDOWS\system32\SAHggMoq.ini2
C:\WINDOWS\system32\urqOHYSL.dll
C:\WINDOWS\system32\UwEhOXyb.ini
C:\WINDOWS\system32\UwEhOXyb.ini2
C:\WINDOWS\system32\vefkdwqp.ini
C:\WINDOWS\system32\wHhgQXbc.ini
C:\WINDOWS\system32\wHhgQXbc.ini2
C:\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-14 to 2008-04-14 )))))))))))))))))))))))))))))))
.
2008-04-12 18:57 . 2008-04-12 19:02 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-04-12 18:56 . 2006-09-02 18:21 108,728 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-04-12 18:56 . 2006-09-02 18:21 48,824 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-04-12 18:55 . 2008-04-12 18:59 <DIR> d-------- C:\Program Files\Symantec
2008-04-12 18:50 . 2008-04-12 18:53 354 --ahs---- C:\WINDOWS\system32\xtcotqqv.ini
2008-04-12 18:47 . 2008-04-12 18:47 3,648 --a------ C:\WINDOWS\system32\wewgmffb.dll
2008-04-12 18:44 . 2002-01-01 01:08 275,988 --ahs---- C:\WINDOWS\system32\GOWvDJlm.ini
2008-04-12 18:44 . 2002-01-01 01:05 275,874 --ahs---- C:\WINDOWS\system32\GOWvDJlm.ini2
2008-04-12 17:05 . 2008-04-12 17:05 294 --ahs---- C:\WINDOWS\system32\aogfhnjc.ini
2008-04-12 17:02 . 2008-04-12 18:15 94,208 --------- C:\WINDOWS\system32\stwwsqxc.gmt
2008-04-12 16:59 . 2008-04-12 16:59 3,648 --a------ C:\WINDOWS\system32\djwmxqdj.dll
2008-04-12 16:56 . 2008-04-12 16:56 272,384 --a------ C:\WINDOWS\system32\cfrfhzto.yol
2008-04-12 12:28 . 2008-04-12 12:54 294 --ahs---- C:\WINDOWS\system32\ylphyjhn.ini
2008-04-12 12:21 . 2008-04-12 15:36 94,208 --------- C:\WINDOWS\system32\vpcyzqrj.zll
2008-04-12 12:21 . 2008-04-12 12:21 3,648 --a------ C:\WINDOWS\system32\ucdgmody.dll
2008-04-12 12:18 . 2008-04-12 12:18 272,384 --a------ C:\WINDOWS\system32\xoakldvo.pyh
2008-04-12 02:56 . 2008-04-12 12:09 406 --ahs---- C:\WINDOWS\system32\oiwbumsa.ini
2008-04-12 02:53 . 2008-04-12 15:35 274,432 --a------ C:\WINDOWS\system32\iorpusjb.rfi
2008-04-12 02:06 . 2008-04-12 02:06 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-12 02:06 . 2008-04-12 02:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-11 21:17 . 2008-04-11 21:17 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-11 21:03 . 2002-01-01 00:42 1,033 --a------ C:\WINDOWS\wininit.ini
2008-04-11 20:25 . 2008-04-11 20:25 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-11 20:25 . 2008-04-12 01:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-11 19:13 . 2008-04-11 20:14 594 --ahs---- C:\WINDOWS\system32\piivxvyt.ini
2008-04-10 17:59 . 2008-04-10 17:59 414 --ahs---- C:\WINDOWS\system32\lgigijpl.ini
2008-04-09 17:59 . 2008-04-11 12:05 646 --ahs---- C:\WINDOWS\system32\rajfhpfj.ini
2008-04-08 19:12 . 2008-04-09 08:53 1,778 --ahs---- C:\WINDOWS\system32\dshapovf.ini
2008-04-07 19:09 . 2008-04-08 19:09 1,366 --ahs---- C:\WINDOWS\system32\poadruvt.ini
2008-04-06 19:09 . 2008-04-06 19:15 1,306 --ahs---- C:\WINDOWS\system32\jrkkphsf.ini
2008-04-06 11:50 . 2006-02-28 08:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-06 11:48 . 2008-04-06 11:48 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-04-06 11:43 . 2008-04-06 11:43 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-06 11:43 . 2008-04-06 11:45 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-05 18:57 . 2008-04-05 18:57 0 --a------ C:\config.ini
2008-04-05 18:54 . 2008-04-06 19:04 1,186 --ahs---- C:\WINDOWS\system32\egerapcw.ini
2008-04-05 18:47 . 2008-04-05 18:47 414 --ahs---- C:\WINDOWS\system32\mewhaxms.ini
2008-04-05 09:02 . 2008-04-05 18:39 354 --ahs---- C:\WINDOWS\system32\ysdgmqby.ini
2008-04-04 11:26 . 2008-04-04 09:00 294 --ahs---- C:\WINDOWS\system32\kpydqlju.ini
2008-04-04 08:58 . 2008-04-04 08:58 2,386 --ahs---- C:\WINDOWS\system32\kpydqlju.tmp
2008-04-04 01:19 . 2008-04-04 08:51 2,386 --ahs---- C:\WINDOWS\system32\wntjctim.ini
2008-04-03 13:16 . 2008-04-04 01:11 2,266 --ahs---- C:\WINDOWS\system32\vqlkurkl.ini
2008-04-02 13:18 . 2008-04-03 11:43 1,966 --ahs---- C:\WINDOWS\system32\pnwfiwbm.ini
2008-04-01 13:19 . 2008-04-02 12:33 1,786 --ahs---- C:\WINDOWS\system32\urxwnxnp.ini
2008-04-01 13:13 . 2008-04-12 19:26 101,100 --a------ C:\WINDOWS\BM9b6999b4.xml
2008-03-31 13:15 . 2008-04-01 12:01 1,306 --ahs---- C:\WINDOWS\system32\nurbsroy.ini
2008-03-30 13:15 . 2008-03-31 11:33 774 --ahs---- C:\WINDOWS\system32\liqsfqml.ini
2008-03-29 13:13 . 2008-03-30 13:13 534 --ahs---- C:\WINDOWS\system32\vnnjcylr.ini
2008-03-29 01:21 . 2008-03-29 01:21 <DIR> d-------- C:\Documents and Settings\Test\Application Data\alot
2008-03-29 01:18 . 2008-03-29 01:22 <DIR> d--hs---- C:\Documents and Settings\Test\!
2008-03-29 01:18 . 2008-03-29 01:18 3,545,428 --------- C:\Documents and Settings\Test\x1.dat
2008-03-29 00:45 . 2008-03-29 00:45 <DIR> d-------- C:\WINDOWS\system32\aqVreo05
2008-03-29 00:45 . 2008-04-13 23:44 <DIR> d-------- C:\Temp
2008-03-29 00:45 . 2008-03-29 09:43 <DIR> d--hs---- C:\Documents and Settings\a\!
2008-03-29 00:45 . 2008-03-29 09:20 3,545,428 --------- C:\Documents and Settings\a\x1.dat
2008-03-29 00:45 . 2008-03-29 00:45 0 --a------ C:\WINDOWS\system32\taskkill.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-12 23:29 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-12 23:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-12 05:49 --------- d-----w C:\Program Files\WeatherStudio Desktop
2008-04-11 23:58 --------- d-----w C:\Documents and Settings\a\Application Data\LimeWire
2008-04-05 23:58 --------- d-----w C:\Program Files\Google
2008-04-05 22:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 22:56 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-29 04:46 --------- d-----w C:\Program Files\LimeWire
2008-03-18 19:01 --------- d-----w C:\Program Files\support.com
2008-03-15 17:35 144 ----a-w C:\domains.dat
2008-02-26 23:50 --------- d-----w C:\Program Files\Yahoo! Games
2008-02-21 23:23 --------- d-----w C:\Program Files\Norton Security Scan
2002-01-01 05:05 275,874 --sha-w C:\WINDOWS\system32\GOWvDJlm.ini2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB690D4-BE97-4CE8-A153-F56463A6E077}]
C:\WINDOWS\system32\nnnljjGa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{78C7963F-A936-47F5-9365-AD7F783F8BEE}]
C:\WINDOWS\system32\mlJDvWOG.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BCBE1BA-53B3-442D-9D0A-3507441C393A}]
C:\WINDOWS\system32\rqRJApmj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0F860F1-987B-4BFC-AE36-33840CDC50B9}]
C:\WINDOWS\system32\qoMggHAS.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB98B576-2B99-4C67-92BC-C918C4395A7B}]
C:\WINDOWS\system32\byXOhEwU.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E17C5AE4-1DA8-4015-B8D9-0CD681973EC7}]
C:\WINDOWS\system32\cbXQghHw.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 18:17 159744]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 04:42 144784]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"985aaa28"="C:\WINDOWS\system32\vqqtoctx.dll" [ ]
"BM9b6999b4"="C:\WINDOWS\system32\xrijukog.dll" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 03:04 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 21:22 26248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 21:47 8720384]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 15:12:08 16423]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqOHYSL]
urqOHYSL.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-02-28 08:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ddoctorv2]
--a------ 2007-04-19 15:21 198184 C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2007-12-15 18:42 114688 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2007-12-15 18:42 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-12-18 21:47 8720384 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
--a------ 2003-03-11 17:24 86016 C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-15 19:20 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2003-03-17 18:39]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 17:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 17:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 17:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 17:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 17:50]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-06 09:00:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2008-04-12 23:29:56 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - a.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-13 23:49:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\SoftwareDistribution\Download\d61766d223927760d60364c3824ce500\update\update.exe
.
**************************************************************************
.
Completion time: 2008-04-13 23:53:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-14 03:53:25
Pre-Run: 37,039,960,064 bytes free
Post-Run: 36,996,100,096 bytes free
.
2008-04-07 07:02:24 --- E O F ---