PDA

View Full Version : What else, Virtumondo



karen370401
2008-12-05, 00:20
Thanks guys for all your help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:05:43 PM, on 12/4/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxcicoms.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Lexmark 7300 Series\ezprint.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\GSP\Software\GspTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Graphics Goddess\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=33568
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {1a8fb21f-fbf6-4f8f-8206-3c791f7908df} - C:\WINDOWS\system32\sivotumo.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {60292921-2B78-42AF-B1E6-366D16CA7407} - (no file)
O2 - BHO: (no name) - {66CDB72D-531F-458B-AEAE-49538EA83487} - C:\WINDOWS\system32\khfEXQig.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ljJDTljg.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {8273C160-2187-4E6E-A115-A93651035446} - (no file)
O2 - BHO: (no name) - {ADD3B4D8-1351-4043-AD12-DE22274BF344} - (no file)
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {C70A674C-F9FC-4A56-AAB3-0668BD70F7F8} - (no file)
O2 - BHO: (no name) - {D033A1D5-D042-466F-AD04-EC8048DB642E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: banners4u browser enhancer - {EAB4B5DC-369E-2BA8-61AA-A4B8ABE9A1E2} - C:\WINDOWS\system32\dliowbagkrlwkg.dll
O2 - BHO: (no name) - {EE9210B2-0CF0-4CF4-9EF3-F5D667AC7823} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Mirar - {C201AD26-D1FB-4CA0-98E6-B131F131A440} - C:\WINDOWS\system32\winll77.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [lxcimon.exe] "C:\Program Files\Lexmark 7300 Series\lxcimon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7300 Series\ezprint.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [wobehepivi] Rundll32.exe "C:\WINDOWS\system32\nomifeyi.dll",s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [wobehepivi] Rundll32.exe "C:\WINDOWS\system32\nomifeyi.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [wobehepivi] Rundll32.exe "C:\WINDOWS\system32\nomifeyi.dll",s (User 'NETWORK SERVICE')
O4 - Startup: UMAX VistaAccess.lnk.disabled
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk.disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: GSPTray.lnk = C:\Program Files\GSP\Software\GspTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk.disabled
O4 - Global Startup: Logo Calibration Loader.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe
O4 - Global Startup: ProfileReminder.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe
O4 - Global Startup: Windows Search.lnk.disabled
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228347396984
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{343F1C67-B9FB-420F-925C-7A8C83005BD8}: NameServer = 205.171.3.65,205.171.2.65
O17 - HKLM\System\CS1\Services\Tcpip\..\{343F1C67-B9FB-420F-925C-7A8C83005BD8}: NameServer = 205.171.3.65,205.171.2.65
O17 - HKLM\System\CS2\Services\Tcpip\..\{343F1C67-B9FB-420F-925C-7A8C83005BD8}: NameServer = 205.171.3.65,205.171.2.65
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: hvqcrr.dll fhmxpm.dll,C:\WINDOWS\system32\wepakezu.dll hublnr.dll
O20 - Winlogon Notify: ljJDTljg - C:\WINDOWS\SYSTEM32\ljJDTljg.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Panfilpiimc - Dell Computer Corporation - (no file)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O24 - Desktop Component 0: (no name) - http://office.microsoft.com/_Services/Ont/images/ONTLogo.gif

--
End of file - 11280 bytes

karen370401
2008-12-05, 01:49
Here is the combofix log file:

ComboFix 08-12-04.04 - Graphics Goddess 2008-12-04 16:33:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.650 [GMT -7:00]
Running from: c:\documents and settings\Graphics Goddess\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Graphics Goddess\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\bapgsqit.dll
c:\windows\system32\ctcpinjc.dll
c:\windows\system32\fhmxpm.dll
c:\windows\SYSTEM32\giQXEfhk.ini
c:\windows\system32\giQXEfhk.ini2
c:\windows\system32\gppwxdmt.ini
c:\windows\system32\hublnr.dll
c:\windows\system32\hvqcrr.dll
c:\windows\system32\khfEXQig.dll
c:\windows\system32\nomifeyi.dll
c:\windows\system32\prunnet.exe
c:\windows\system32\qoMETNgG.dll
c:\windows\system32\sivotumo.dll
c:\windows\system32\tmdxwppg.dll
c:\windows\system32\wepakezu.dll
c:\windows\system32\winpfz33.sys
c:\windows\system32\wtmqmoav.dll
c:\windows\system32\yxgfaydx.dll
c:\windows\system32\zumidiba.dll
c:\windows\Tasks\onknveoc.job

.
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.

2008-12-03 17:37 . 2008-12-03 17:37 <DIR> d-------- c:\documents and settings\Graphics Goddess\Application Data\Windows Search
2008-12-03 17:05 . 2008-12-03 17:05 <DIR> d-------- c:\documents and settings\Graphics Goddess\Application Data\Windows Desktop Search
2008-12-03 17:04 . 2008-12-03 17:04 <DIR> d-------- c:\windows\SYSTEM32\GroupPolicy
2008-12-03 17:04 . 2008-12-03 17:04 <DIR> d-------- c:\program files\Windows Desktop Search
2008-12-03 17:03 . 2008-03-07 10:02 192,000 --------- c:\windows\SYSTEM32\DLLCACHE\offfilt.dll
2008-12-03 17:03 . 2008-03-07 10:02 98,304 --------- c:\windows\SYSTEM32\DLLCACHE\nlhtml.dll
2008-12-03 17:03 . 2008-03-07 10:02 29,696 --------- c:\windows\SYSTEM32\DLLCACHE\mimefilt.dll
2008-12-03 15:33 . 2008-12-03 15:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-03 15:32 . 2008-12-03 15:32 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-03 13:48 . 2008-12-04 08:54 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-03 13:48 . 2008-12-03 13:48 1,409 --a------ c:\windows\QTFont.for
2008-12-03 13:30 . 2008-12-03 13:29 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2008-12-03 10:49 . 2008-12-03 10:49 0 --a------ C:\LOG58.tmp
2008-12-02 13:37 . 2008-12-02 13:37 282,647 --a------ c:\windows\SYSTEM32\rrwnw64n.exe
2008-12-02 13:23 . 2008-12-02 13:23 <DIR> d-------- c:\windows\SYSTEM32\VC
2008-12-02 13:23 . 2008-12-02 13:23 <DIR> d-------- c:\windows\SYSTEM32\uv9
2008-12-02 13:23 . 2008-12-02 13:23 <DIR> d-------- c:\windows\SYSTEM32\ki3
2008-12-02 13:23 . 2008-12-02 13:23 <DIR> d-------- c:\windows\SYSTEM32\hov
2008-12-02 13:23 . 2008-12-02 13:23 <DIR> d-------- c:\windows\SYSTEM32\bin
2008-12-02 13:23 . 2008-12-02 13:23 <DIR> d-------- c:\temp\DIV55
2008-12-02 13:18 . 2008-12-02 13:18 548,928 --a------ c:\windows\SYSTEM32\qcntlsdl.exe
2008-12-02 13:18 . 2008-12-02 13:18 153,425 --a------ c:\windows\SYSTEM32\g54.exe
2008-12-02 13:18 . 2008-12-02 13:18 64,859 --a------ c:\windows\SYSTEM32\jokopkoktmcsjv.exe
2008-12-02 13:17 . 2008-12-02 13:32 47,598 --a------ c:\windows\SYSTEM32\iciktcbwlubq.exe
2008-12-02 13:15 . 2008-11-21 20:15 401,408 --a------ c:\windows\SYSTEM32\winll77.dll
2008-12-02 13:14 . 2008-12-02 13:14 34,816 --a------ c:\windows\SYSTEM32\ljJDTljg.dll
2008-11-24 09:27 . 2008-11-24 09:42 366,592 --a------ c:\windows\SYSTEM32\dliowbagkrlwkg.dll
2008-11-12 07:32 . 2008-10-24 04:21 455,296 --------- c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-11-12 07:31 . 2008-09-04 10:15 1,106,944 --------- c:\windows\SYSTEM32\DLLCACHE\msxml3.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 22:08 --------- d-----w c:\documents and settings\Graphics Goddess\Application Data\U3
2008-12-04 21:13 --------- d-----w c:\documents and settings\Graphics Goddess\Application Data\OpenOffice.org2
2008-12-03 22:34 --------- d-----w c:\documents and settings\Graphics Goddess\Application Data\Lavasoft
2008-12-03 22:33 --------- d-----w c:\program files\Lavasoft
2008-12-03 20:29 --------- d-----w c:\program files\Java
2008-12-02 21:16 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-02 20:42 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-02 20:38 --------- d-----w c:\program files\VSTASCAN
2008-11-21 14:25 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-30 13:25 --------- d-----w c:\program files\McAfee
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-07 20:40 --------- d-----w c:\program files\FirstClass
2008-06-04 15:04 159,720 ----a-w c:\documents and settings\Graphics Goddess\Application Data\GDIPFONTCACHEV1.DAT
2005-09-06 15:06 33,408 ----a-w c:\documents and settings\Graphics Goddess\g2mdlhlpx.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
2008-12-02 13:14 34816 --a------ c:\windows\system32\ljJDTljg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EAB4B5DC-369E-2BA8-61AA-A4B8ABE9A1E2}]
2008-11-24 09:42 366592 --a------ c:\windows\system32\dliowbagkrlwkg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{C201AD26-D1FB-4CA0-98E6-B131F131A440}"= "c:\windows\system32\winll77.dll" [2008-11-21 401408]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{C201AD26-D1FB-4CA0-98E6-B131F131A440}"= "c:\windows\system32\winll77.dll" [2008-11-21 401408]

[HKEY_CLASSES_ROOT\clsid\{c201ad26-d1fb-4ca0-98e6-b131f131a440}]
[HKEY_CLASSES_ROOT\TypeLib\{206394FE-1056-45D5-B285-2B21A0B62BB5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-05 127035]
"lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2005-09-30 200704]
"EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2005-08-01 94208]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-04 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-03 136600]

c:\documents and settings\Graphics Goddess\Start Menu\Programs\Startup\
UMAX VistaAccess.lnk.disabled [2005-05-16 694]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk.disabled [2006-11-03 2335]
Adobe Reader Speed Launch.lnk.disabled [2006-05-31 1768]
GSPTray.lnk - c:\program files\GSP\Software\GspTray.exe [2005-05-12 323584]
HP Digital Imaging Monitor.lnk.disabled [2005-06-24 1819]
Logo Calibration Loader.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe [2007-03-22 708608]
ProfileReminder.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe [2007-03-22 954368]
Windows Search.lnk.disabled [2008-12-03 1798]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= "c:\windows\system32\ljJDTljg.dll" [2008-12-02 34816]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljJDTljg]
2008-12-02 13:14 34816 c:\windows\SYSTEM32\ljJDTljg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMAXPnP"=c:\program files\Analog Devices\Core\smax4pnp.exe
"RealTray"=c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"QBReminderFlash"="c:\program files\Intuit\QuickBooks 2005\Atom\QBReminder.exe"
"IntelMeM"=c:\program files\Intel\Modem Event Monitor\IntelMEM.exe
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe"
"DXDllRegExe"=dxdllreg.exe
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe"
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe"
"SunJavaUpdateSched"=c:\program files\Java\jre1.5.0_02\bin\jusched.exe
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
"ATIPTA"=c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcipswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\WINDOWS\\SYSTEM32\\lxcicoms.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\GSP\\Software\\GspTray.exe"=
"c:\\WINDOWS\\SYSTEM32\\services.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\Mcshield.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\DRIVERS\tffsport.sys [2006-05-12 149376]
R2 EdgeStat;EdgeStat;\??\c:\windows\system32\drivers\edgestat.sys [2005-05-12 6912]
R2 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service []
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-09-05 203280]
R2 PAR1284;PAR1284;\??\c:\windows\system32\drivers\PAR1284.sys [2005-05-12 51296]
R2 PDIHWCTL;PDIHWCTL;\??\c:\windows\system32\drivers\pdihwctl.sys [2007-03-22 14416]
S1 AEC671X;AEC671X;c:\windows\system32\drivers\AEC671X.SYS [2005-05-16 12128]
S1 bthmodemm;bthmodemm;c:\windows\system32\drivers\bthmodemm.sys []
S1 DMX3191;DMX3191;c:\windows\system32\drivers\DMX3191.SYS [2005-05-16 17700]
S1 RIODRVV;RIODRVV;c:\windows\system32\drivers\RIODRVV.sys []
S2 UDNT;UDNT;c:\windows\system32\drivers\UDNT.sys [2005-05-16 76260]
S3 Abp4avmrdm;Abp4avmrdm; []
S3 Cosnp4s;Cosnp4s; []
S3 eyeonedp;eye-one display;c:\windows\system32\DRIVERS\eyeonedp.sys [2007-03-22 44344]
S3 Ini9umlipr;Ini9umlipr; []
S3 Inpenmv;Inpenmv; []
S3 Panfilpiimc;Panfilpiimc; []
S4 Pscrrofbtsd;Pscrrofbtsd; []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{948c99a1-d8ba-11dc-b489-00132001fb5c}]
\Shell\AutoRun\command - f:\jdsecure\Windows\JDSecure31.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7b8257b-de04-11db-b359-00132001fb5c}]
\Shell\AutoRun\command - F:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{def102e6-057a-11dd-b4bc-00132001fb5c}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f138dfe2-c5df-11dc-b46e-00132001fb5c}]
\Shell\AutoRun\command - F:\update.bat
.
Contents of the 'Scheduled Tasks' folder

2008-08-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-11-28 c:\windows\Tasks\RecordNow!.job
- c:\progra~1\Sonic\RECORD~1\RECORD~1.EXE [2004-09-07 05:01]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0FEB0A16-8AD7-41C0-AE92-635C6D3EDACB} - (no file)
BHO-{1a8fb21f-fbf6-4f8f-8206-3c791f7908df} - c:\windows\system32\sivotumo.dll
BHO-{404FA673-2FC0-4681-BA1A-E978590F666E} - c:\windows\system32\khfEXQig.dll
BHO-{60292921-2B78-42AF-B1E6-366D16CA7407} - (no file)
BHO-{66CDB72D-531F-458B-AEAE-49538EA83487} - (no file)
BHO-{8273C160-2187-4E6E-A115-A93651035446} - (no file)
BHO-{ADD3B4D8-1351-4043-AD12-DE22274BF344} - (no file)
BHO-{C70A674C-F9FC-4A56-AAB3-0668BD70F7F8} - (no file)
BHO-{D033A1D5-D042-466F-AD04-EC8048DB642E} - (no file)
BHO-{EE9210B2-0CF0-4CF4-9EF3-F5D667AC7823} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.dell4me.com/myway
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
TCP: {343F1C67-B9FB-420F-925C-7A8C83005BD8} = 205.171.3.65,205.171.2.65
FireFox -: Profile - c:\documents and settings\Graphics Goddess\Application Data\Mozilla\Firefox\Profiles\iu96lyof.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 16:39:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\ljJDTljg.dll

- - - - - - - > 'explorer.exe'(332)
c:\program files\McAfee\SiteAdvisor\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\SYSTEM32\BRSS01A.EXE
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Application Accelerator\IAANTmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SYSTEM32\lxcicoms.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\SYSTEM32\searchindexer.exe
c:\windows\SYSTEM32\searchprotocolhost.exe
c:\windows\SYSTEM32\searchfilterhost.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-12-04 16:43:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 23:43:02

Pre-Run: 83,674,513,408 bytes free
Post-Run: 83,626,704,896 bytes free

299 --- E O F --- 2008-11-13 01:14:55