RexRegum
2008-10-27, 18:34
I've been experiencing the above-listed problems for the past week. I have run Malware Bytes' Antimalware program and Combofix. Please help me decipher whether I am still infected. Here is the Combofix log:
ComboFix 08-10-26.01 - Christine 2008-10-27 11:28:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.835 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Christine\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\msdjf.dll
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.
2008-10-24 21:20 . 2008-10-15 12:34 337,408 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-23 23:06 . 2008-10-23 23:06 <DIR> d-------- C:\Documents and Settings\Christine\Application Data\MailFrontier
2008-10-23 22:54 . 2008-10-09 14:25 1,221,008 --a------ C:\WINDOWS\SYSTEM32\zpeng25.dll
2008-10-22 22:20 . 2008-10-22 22:20 <DIR> d-------- C:\Program Files\ERUNT
2008-10-19 14:36 . 2008-10-19 14:36 <DIR> d-------- C:\Documents and Settings\Christine\Application Data\Malwarebytes
2008-10-19 14:35 . 2008-10-22 18:26 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-19 14:35 . 2008-10-19 14:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-19 14:35 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-10-19 14:35 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\SYSTEM32\en
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-14 14:49 . 2008-09-15 08:12 1,846,400 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys
2008-10-14 14:49 . 2008-09-08 06:41 333,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\srv.sys
2008-10-14 14:48 . 2008-08-14 06:11 2,189,184 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-10-14 14:48 . 2008-08-14 06:09 2,145,280 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-10-14 14:48 . 2008-08-14 05:33 2,066,048 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-10-14 14:48 . 2008-08-14 05:33 2,023,936 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrpamp.exe
2008-09-29 11:00 . 2005-06-10 13:39 53,248 --a------ C:\WINDOWS\SYSTEM32\CNAS0MMK.DLL
2008-09-29 10:57 . 2006-07-05 13:01 200,704 --a------ C:\WINDOWS\SYSTEM32\CNCC4100.DLL
2008-09-29 10:57 . 2006-07-05 13:01 131,072 --a------ C:\WINDOWS\SYSTEM32\CNCLSD23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 110,592 --a------ C:\WINDOWS\SYSTEM32\CNCLST23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 110,592 --a------ C:\WINDOWS\SYSTEM32\CNCLSI23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 98,304 --a------ C:\WINDOWS\SYSTEM32\CNCLSU23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 77,824 --a------ C:\WINDOWS\SYSTEM32\CNCLSC23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 73,728 --a------ C:\WINDOWS\SYSTEM32\CNCL4100.DLL
2008-09-29 10:57 . 2006-07-05 13:01 69,632 --a------ C:\WINDOWS\SYSTEM32\CNCI4100.DLL
2008-09-29 10:57 . 2006-07-05 13:02 49,152 --a------ C:\WINDOWS\SYSTEM32\cncilsc.dll
2008-09-29 10:57 . 2006-04-04 17:42 332 --a------ C:\WINDOWS\SYSTEM32\CNCMFP23.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 15:51 27,197,216 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-27 15:38 360,140 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-26 19:59 44,822 ----a-w C:\Documents and Settings\Christine\Application Data\wklnhst.dat
2008-10-24 02:55 22,251,195 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_10_23_22_54_18_full.dmp.zip
2008-10-21 15:58 85,320 ----a-w C:\Documents and Settings\Christine\Application Data\GDIPFONTCACHEV1.DAT
2008-10-15 19:19 --------- d-----w C:\Program Files\Yahoo!
2008-10-11 17:40 2,140,672 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-10-11 17:40 1,802,240 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-10-09 18:25 73,104 ----a-w C:\WINDOWS\zllsputility.exe
2008-09-24 20:44 --------- d-----w C:\Documents and Settings\Christine\Application Data\Canon
2008-09-24 20:28 --------- d-----w C:\Documents and Settings\Christine\Application Data\NewSoft
2008-09-22 00:40 2,099,200 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-09-14 12:44 --------- d-----w C:\Program Files\NAIC Classic
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-02 13:19 --------- d-----w C:\Program Files\Audible
2008-08-30 15:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-29 02:58 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-08-29 02:57 --------- d-----w C:\Documents and Settings\Christine\Application Data\Creative
2008-08-29 02:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-29 02:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-29 01:35 --------- d-----w C:\Program Files\Creative
2008-08-29 01:30 --------- d--h--w C:\Program Files\Creative Installation Information
2008-08-29 01:27 --------- d-----w C:\Program Files\Common Files\Creative
2008-08-29 00:55 --------- d-----w C:\Program Files\illiminable
2008-08-29 00:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo
2008-08-29 00:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-08-15 01:12 2,197,504 ----a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2008-04-23 03:30 60,968 ----a-w C:\Documents and Settings\Christine\GoToAssistDownloadHelper.exe
2006-07-07 02:33 136 ----a-w C:\Documents and Settings\June\Application Data\wklnhst.dat
2006-05-15 17:43 8 ----a-w C:\Documents and Settings\Christine\Application Data\usb.dat.bin
2006-05-03 19:42 3,414,632 ----a-w C:\Program Files\msgrplus.exe
2006-05-03 18:54 6,109,920 ----a-w C:\Program Files\clj2550pcl6win2kxp2003-en.exe
2005-06-16 16:42 1,951,432 ----a-w C:\Program Files\Powerpoint Viewer.exe
2004-12-10 22:49 16,706,160 -c--a-w C:\Program Files\AdbeRdr60_enu_full.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-28 700416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-02-25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-25 118784]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-04-22 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-04-22 507904]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-09-01 77824]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-19 53248]
"DwlClient"="c:\Program Files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 323584]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-12-05 50688]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-05-02 270336]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"WrtMon.exe"="C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-11 185896]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-10-09 981904]
C:\Documents and Settings\Christine\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2006-09-08 155648]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2004-09-01 36953]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-09-01 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-04-22 23:31 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
S3 flash;flash;C:\WINDOWS\system32\drivers\flash.sys [2003-08-29 7040]
S3 GoToAssist;GoToAssist;C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe Start=service [ ]
.
Contents of the 'Scheduled Tasks' folder
2004-09-11 C:\WINDOWS\Tasks\ISP signup reminder 1.job
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE [2008-04-13 20:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{043D69B3-B916-426B-93C4-2C6127AD6EE3} - C:\WINDOWS\system32\msdjf.dll
BHO-{295CEBE4-488D-4B05-B51A-2C6AAEF5BCB9} - C:\WINDOWS\system32\msdjf.dll
BHO-{3C2DB88B-0CB4-44BF-9421-BA862A5411A3} - C:\WINDOWS\system32\msdjf.dll
BHO-{6854AE89-1FEB-4696-8DC6-FBE81B121C95} - C:\WINDOWS\system32\msdjf.dll
BHO-{9296DBA9-FD3D-4D61-9611-065038F95DCF} - C:\WINDOWS\system32\msdjf.dll
BHO-{AE9A9601-045E-4573-9667-A688E47EEADC} - C:\WINDOWS\system32\msdjf.dll
BHO-{BA767C30-A901-405E-9F4D-FD230087FEB2} - C:\WINDOWS\system32\msdjf.dll
BHO-{DAE96E3C-DD63-4D3B-BC18-FAA61E6CAE3E} - C:\WINDOWS\system32\msdjf.dll
BHO-{E4713CA9-BD2F-44E3-9A26-5BCA91373C2E} - C:\WINDOWS\system32\msdjf.dll
HKCU-Run-MsnMsgr - C:\Program Files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-Aim6 - C:\Program Files\AIM6\aim6.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.aol.com/
R0 -: HKLM-Main,Start Page = hxxp://www.comcast.net/
R0 -: HKLM-Main,Window Title = Windows Internet Explorer provided by Comcast
O8 -: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 11:48:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\SYSTEM32\LEXBCES.EXE
C:\WINDOWS\SYSTEM32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\SYSTEM32\TCPSVCS.EXE
C:\WINDOWS\SYSTEM32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\WrtProc.exe
C:\WINDOWS\SYSTEM32\WBEM\wmiapsrv.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
.
**************************************************************************
.
Completion time: 2008-10-27 11:53:39 - machine was rebooted [Christine]
ComboFix-quarantined-files.txt 2008-10-27 15:53:30
Pre-Run: 34,449,137,664 bytes free
Post-Run: 34,904,899,584 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
216 --- E O F --- 2008-10-25 14:00:49
ComboFix 08-10-26.01 - Christine 2008-10-27 11:28:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.835 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Christine\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\msdjf.dll
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.
2008-10-24 21:20 . 2008-10-15 12:34 337,408 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-23 23:06 . 2008-10-23 23:06 <DIR> d-------- C:\Documents and Settings\Christine\Application Data\MailFrontier
2008-10-23 22:54 . 2008-10-09 14:25 1,221,008 --a------ C:\WINDOWS\SYSTEM32\zpeng25.dll
2008-10-22 22:20 . 2008-10-22 22:20 <DIR> d-------- C:\Program Files\ERUNT
2008-10-19 14:36 . 2008-10-19 14:36 <DIR> d-------- C:\Documents and Settings\Christine\Application Data\Malwarebytes
2008-10-19 14:35 . 2008-10-22 18:26 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-19 14:35 . 2008-10-19 14:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-19 14:35 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-10-19 14:35 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\SYSTEM32\en
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-14 14:49 . 2008-09-15 08:12 1,846,400 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys
2008-10-14 14:49 . 2008-09-08 06:41 333,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\srv.sys
2008-10-14 14:48 . 2008-08-14 06:11 2,189,184 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-10-14 14:48 . 2008-08-14 06:09 2,145,280 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-10-14 14:48 . 2008-08-14 05:33 2,066,048 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-10-14 14:48 . 2008-08-14 05:33 2,023,936 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrpamp.exe
2008-09-29 11:00 . 2005-06-10 13:39 53,248 --a------ C:\WINDOWS\SYSTEM32\CNAS0MMK.DLL
2008-09-29 10:57 . 2006-07-05 13:01 200,704 --a------ C:\WINDOWS\SYSTEM32\CNCC4100.DLL
2008-09-29 10:57 . 2006-07-05 13:01 131,072 --a------ C:\WINDOWS\SYSTEM32\CNCLSD23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 110,592 --a------ C:\WINDOWS\SYSTEM32\CNCLST23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 110,592 --a------ C:\WINDOWS\SYSTEM32\CNCLSI23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 98,304 --a------ C:\WINDOWS\SYSTEM32\CNCLSU23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 77,824 --a------ C:\WINDOWS\SYSTEM32\CNCLSC23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 73,728 --a------ C:\WINDOWS\SYSTEM32\CNCL4100.DLL
2008-09-29 10:57 . 2006-07-05 13:01 69,632 --a------ C:\WINDOWS\SYSTEM32\CNCI4100.DLL
2008-09-29 10:57 . 2006-07-05 13:02 49,152 --a------ C:\WINDOWS\SYSTEM32\cncilsc.dll
2008-09-29 10:57 . 2006-04-04 17:42 332 --a------ C:\WINDOWS\SYSTEM32\CNCMFP23.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 15:51 27,197,216 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-27 15:38 360,140 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-26 19:59 44,822 ----a-w C:\Documents and Settings\Christine\Application Data\wklnhst.dat
2008-10-24 02:55 22,251,195 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_10_23_22_54_18_full.dmp.zip
2008-10-21 15:58 85,320 ----a-w C:\Documents and Settings\Christine\Application Data\GDIPFONTCACHEV1.DAT
2008-10-15 19:19 --------- d-----w C:\Program Files\Yahoo!
2008-10-11 17:40 2,140,672 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-10-11 17:40 1,802,240 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-10-09 18:25 73,104 ----a-w C:\WINDOWS\zllsputility.exe
2008-09-24 20:44 --------- d-----w C:\Documents and Settings\Christine\Application Data\Canon
2008-09-24 20:28 --------- d-----w C:\Documents and Settings\Christine\Application Data\NewSoft
2008-09-22 00:40 2,099,200 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-09-14 12:44 --------- d-----w C:\Program Files\NAIC Classic
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-02 13:19 --------- d-----w C:\Program Files\Audible
2008-08-30 15:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-29 02:58 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-08-29 02:57 --------- d-----w C:\Documents and Settings\Christine\Application Data\Creative
2008-08-29 02:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-29 02:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-29 01:35 --------- d-----w C:\Program Files\Creative
2008-08-29 01:30 --------- d--h--w C:\Program Files\Creative Installation Information
2008-08-29 01:27 --------- d-----w C:\Program Files\Common Files\Creative
2008-08-29 00:55 --------- d-----w C:\Program Files\illiminable
2008-08-29 00:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo
2008-08-29 00:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-08-15 01:12 2,197,504 ----a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2008-04-23 03:30 60,968 ----a-w C:\Documents and Settings\Christine\GoToAssistDownloadHelper.exe
2006-07-07 02:33 136 ----a-w C:\Documents and Settings\June\Application Data\wklnhst.dat
2006-05-15 17:43 8 ----a-w C:\Documents and Settings\Christine\Application Data\usb.dat.bin
2006-05-03 19:42 3,414,632 ----a-w C:\Program Files\msgrplus.exe
2006-05-03 18:54 6,109,920 ----a-w C:\Program Files\clj2550pcl6win2kxp2003-en.exe
2005-06-16 16:42 1,951,432 ----a-w C:\Program Files\Powerpoint Viewer.exe
2004-12-10 22:49 16,706,160 -c--a-w C:\Program Files\AdbeRdr60_enu_full.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-28 700416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-02-25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-25 118784]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-04-22 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-04-22 507904]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-09-01 77824]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-19 53248]
"DwlClient"="c:\Program Files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 323584]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-12-05 50688]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-05-02 270336]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"WrtMon.exe"="C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-11 185896]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-10-09 981904]
C:\Documents and Settings\Christine\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2006-09-08 155648]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2004-09-01 36953]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-09-01 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-04-22 23:31 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
S3 flash;flash;C:\WINDOWS\system32\drivers\flash.sys [2003-08-29 7040]
S3 GoToAssist;GoToAssist;C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe Start=service [ ]
.
Contents of the 'Scheduled Tasks' folder
2004-09-11 C:\WINDOWS\Tasks\ISP signup reminder 1.job
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE [2008-04-13 20:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{043D69B3-B916-426B-93C4-2C6127AD6EE3} - C:\WINDOWS\system32\msdjf.dll
BHO-{295CEBE4-488D-4B05-B51A-2C6AAEF5BCB9} - C:\WINDOWS\system32\msdjf.dll
BHO-{3C2DB88B-0CB4-44BF-9421-BA862A5411A3} - C:\WINDOWS\system32\msdjf.dll
BHO-{6854AE89-1FEB-4696-8DC6-FBE81B121C95} - C:\WINDOWS\system32\msdjf.dll
BHO-{9296DBA9-FD3D-4D61-9611-065038F95DCF} - C:\WINDOWS\system32\msdjf.dll
BHO-{AE9A9601-045E-4573-9667-A688E47EEADC} - C:\WINDOWS\system32\msdjf.dll
BHO-{BA767C30-A901-405E-9F4D-FD230087FEB2} - C:\WINDOWS\system32\msdjf.dll
BHO-{DAE96E3C-DD63-4D3B-BC18-FAA61E6CAE3E} - C:\WINDOWS\system32\msdjf.dll
BHO-{E4713CA9-BD2F-44E3-9A26-5BCA91373C2E} - C:\WINDOWS\system32\msdjf.dll
HKCU-Run-MsnMsgr - C:\Program Files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-Aim6 - C:\Program Files\AIM6\aim6.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.aol.com/
R0 -: HKLM-Main,Start Page = hxxp://www.comcast.net/
R0 -: HKLM-Main,Window Title = Windows Internet Explorer provided by Comcast
O8 -: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 11:48:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\SYSTEM32\LEXBCES.EXE
C:\WINDOWS\SYSTEM32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\SYSTEM32\TCPSVCS.EXE
C:\WINDOWS\SYSTEM32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\WrtProc.exe
C:\WINDOWS\SYSTEM32\WBEM\wmiapsrv.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
.
**************************************************************************
.
Completion time: 2008-10-27 11:53:39 - machine was rebooted [Christine]
ComboFix-quarantined-files.txt 2008-10-27 15:53:30
Pre-Run: 34,449,137,664 bytes free
Post-Run: 34,904,899,584 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
216 --- E O F --- 2008-10-25 14:00:49