Combo fix Report:
ComboFix 08-06-09.7 - Camron 2008-06-09 23:47:17.1 - NTFSx86
Running from: C:\Documents and Settings\Camron\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Camron\Application Data\macromedia\Flash Player\#SharedObjects\GXK86TQZ\www.broadcaster.com
C:\Documents and Settings\Camron\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Camron\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\temp\0b9
C:\temp\0b9\tmpTF.log
C:\Temp\bkR11
C:\temp\iee
C:\temp\iee\tmpZTF.log
C:\Temp\isgTi19
C:\WINDOWS\SYSTEM32\acbeg.bak1
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\SYSTEM32\acbeg.tmp
C:\WINDOWS\system32\aioxudrm.ini
C:\WINDOWS\system32\amylkjpa.ini
C:\WINDOWS\system32\axmhsdgy.ini
C:\WINDOWS\SYSTEM32\bbeeg.bak1
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bdwwcego.ini
C:\WINDOWS\system32\bhhsyypc.ini
C:\WINDOWS\system32\csoxjxqf.ini
C:\WINDOWS\system32\cueoybrk.ini
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver\Errorlog.dat
C:\WINDOWS\system32\driver\rundll16.dll
C:\WINDOWS\system32\fqhdnavw.ini
C:\WINDOWS\system32\fubpowxh.ini
C:\WINDOWS\system32\gflxwxtp.ini
C:\WINDOWS\SYSTEM32\gjkmp.ini
C:\WINDOWS\SYSTEM32\gjkmp.ini2
C:\WINDOWS\system32\gyivaqtc.ini
C:\WINDOWS\system32\gyjkvxrf.ini
C:\WINDOWS\system32\hkfwkjax.ini
C:\WINDOWS\SYSTEM32\ijkmp.bak1
C:\WINDOWS\SYSTEM32\ijkmp.bak2
C:\WINDOWS\SYSTEM32\ijkmp.ini2
C:\WINDOWS\SYSTEM32\ijkmp.tmp
C:\WINDOWS\SYSTEM32\ijkmp.tmp2
C:\WINDOWS\system32\inigbtki.ini
C:\WINDOWS\system32\jjevkkxx.ini
C:\WINDOWS\system32\jwhridqf.ini
C:\WINDOWS\SYSTEM32\kjjlm.bak1
C:\WINDOWS\SYSTEM32\kjjlm.bak2
C:\WINDOWS\SYSTEM32\kjjlm.ini2
C:\WINDOWS\SYSTEM32\kjjlm.tmp
C:\WINDOWS\SYSTEM32\kmllm.bak1
C:\WINDOWS\SYSTEM32\kmllm.bak2
C:\WINDOWS\SYSTEM32\kmllm.ini
C:\WINDOWS\SYSTEM32\kmllm.ini2
C:\WINDOWS\SYSTEM32\kmllm.tmp
C:\WINDOWS\system32\ksmqaqns.ini
C:\WINDOWS\system32\kufrefil.ini
C:\WINDOWS\system32\lejifbmi.ini
C:\WINDOWS\system32\lgpnjnwr.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mpeggpcj.ini
C:\WINDOWS\system32\mqmrtsmk.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\myrxkqxx.ini
C:\WINDOWS\system32\nvqgifbl.ini
C:\WINDOWS\system32\o02PrEz
C:\WINDOWS\system32\opuxnpah.ini
C:\WINDOWS\system32\oylupysc.ini
C:\WINDOWS\SYSTEM32\pqstv.ini
C:\WINDOWS\SYSTEM32\pqstv.ini2
C:\WINDOWS\system32\prfgahqp.ini
C:\WINDOWS\system32\qgdybwfb.ini
C:\WINDOWS\system32\qgxudxbd.ini
C:\WINDOWS\system32\qinjbsgg.ini
C:\WINDOWS\SYSTEM32\qpqss.ini
C:\WINDOWS\SYSTEM32\qpqss.ini2
C:\WINDOWS\system32\qtbqirhs.ini
C:\WINDOWS\system32\qycfxwtg.ini
C:\WINDOWS\system32\rmbeordg.ini
C:\WINDOWS\system32\rolkbime.ini
C:\WINDOWS\system32\rpglxhwx.ini
C:\WINDOWS\SYSTEM32\rttss.bak1
C:\WINDOWS\SYSTEM32\rttss.bak2
C:\WINDOWS\SYSTEM32\rttss.ini
C:\WINDOWS\SYSTEM32\rttss.ini2
C:\WINDOWS\SYSTEM32\rttss.tmp
C:\WINDOWS\SYSTEM32\rttss.tmp2
C:\WINDOWS\system32\rybuegti.ini
C:\WINDOWS\system32\srjwpgmg.ini
C:\WINDOWS\system32\stsdvmyw.ini
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T4
C:\WINDOWS\system32\T6
C:\WINDOWS\system32\tfsodfja.ini
C:\WINDOWS\system32\triblmmo.ini
C:\WINDOWS\system32\txdqgevj.ini
C:\WINDOWS\system32\upbshgvm.ini
C:\WINDOWS\system32\veqscvet.ini
C:\WINDOWS\SYSTEM32\vvvwa.bak1
C:\WINDOWS\SYSTEM32\vvvwa.ini2
C:\WINDOWS\SYSTEM32\vvvwa.tmp
C:\WINDOWS\system32\win
C:\WINDOWS\system32\wnscpisv32.exe
C:\WINDOWS\system32\xevlfnst.ini
C:\WINDOWS\system32\xljrpcxj.ini
C:\WINDOWS\system32\xvipdtrq.ini
C:\WINDOWS\SYSTEM32\ycbeg.bak1
C:\WINDOWS\SYSTEM32\ycbeg.ini2
C:\WINDOWS\SYSTEM32\ycbeg.tmp
C:\WINDOWS\system32\yjtjmbkh.ini
C:\WINDOWS\system32\ymnmjtss.ini
C:\WINDOWS\system32\ystem3~1
C:\WINDOWS\Windows_Updater.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-10 to 2008-06-10 )))))))))))))))))))))))))))))))
.
2008-06-09 19:15 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-06-02 00:30 . 2008-06-02 00:30 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-06-02 00:30 . 2008-06-02 00:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-01 19:06 . 2008-06-01 19:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-28 20:48 . 2008-05-28 20:56 <DIR> d-------- C:\Program Files\LimeWire
2008-05-23 20:34 . 2008-05-23 20:34 <DIR> d-------- C:\Documents and Settings\Camron\Application Data\Malwarebytes
2008-05-23 20:31 . 2008-05-23 20:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-23 20:30 . 2008-05-23 20:32 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-23 20:30 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamcatchme.sys
2008-05-23 20:30 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-05-23 19:18 . 2008-05-28 15:18 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-14 12:00 . 2008-05-14 12:00 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-05-14 11:58 . 2008-05-14 11:58 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-05-14 11:37 . 2008-05-14 11:37 754 --a------ C:\WINDOWS\WORDPAD.INI
2008-05-14 01:06 . 2008-05-14 01:07 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-14 00:59 . 2008-05-14 12:00 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-05-14 00:54 . 2008-05-14 11:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-14 00:50 . 2008-05-14 00:50 <DIR> dr-h----- C:\MSOCache
2008-05-13 22:16 . 2007-10-30 12:20 360,064 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys.ORIGINAL
2008-05-13 22:16 . 2007-10-30 12:20 360,064 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys.ORIGINAL
2008-05-13 21:04 . 2008-06-09 19:35 <DIR> d-------- C:\Program Files\Google
2008-05-13 20:57 . 2008-05-13 20:57 2,560 --a------ C:\WINDOWS\SYSTEM32\bitcometres.dll
2008-05-13 20:56 . 2008-06-09 13:02 <DIR> d-------- C:\Downloads
2008-05-13 20:50 . 2008-05-13 22:18 <DIR> d-------- C:\Program Files\BitComet
2008-05-13 20:15 . 2008-05-13 20:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-13 20:14 . 2008-05-13 20:15 <DIR> d-------- C:\Program Files\Viewpoint
2008-05-13 13:41 . 2008-05-13 13:41 <DIR> d-------- C:\Program Files\Apple Software Update
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 00:13 --------- d-----w C:\Program Files\Java
2008-06-06 20:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-06 17:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-04 17:54 --------- d-----w C:\Program Files\Norton 360
2008-06-04 17:49 --------- d-----w C:\Program Files\Antreex
2008-06-04 17:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-14 03:16 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-05-14 00:54 --------- d-----w C:\Program Files\Microsoft Money
2008-05-14 00:50 --------- d-----w C:\Program Files\WordPerfect Office 11
2008-05-14 00:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-14 00:28 --------- d-----w C:\Program Files\KODAK
2008-05-12 04:46 --------- d-----w C:\Documents and Settings\Camron\Application Data\ZoomBrowser EX
2008-05-12 04:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-04-23 02:24 --------- d-----w C:\Program Files\iTunes
2008-04-23 02:23 --------- d-----w C:\Program Files\iPod
2008-04-23 01:47 --------- d-----w C:\Program Files\QuickTime
2006-01-14 08:58 45,672 ----a-w C:\Documents and Settings\Camron\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2005-05-25 14:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-01-13 12:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
2006-04-20 07:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 11:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2002-08-29 06:00 332928 244a2f9816bc9b593957281ef577d976 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 01:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
2005-05-25 14:04 359808 88763a98a4c26c409741b4aa162720c9 C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
2006-01-12 21:28 359808 583e063fdc888ca30d05c2724b0d7ef4 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2004-08-04 01:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-05-13 22:16 360064 889d4dfd85b00a13f75209f33f79db2f C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2008-05-13 22:16 360064 889d4dfd85b00a13f75209f33f79db2f C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A40567E6-DCAE-48D2-B799-9B98C1D70A14}]
C:\WINDOWS\system32\ssqpq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1CD0EB2-FFF2-7902-D7F8-61B57708831C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\jgpl4z0]
@={6A587321-EC0D-A00F-0976-657CB8113AE5}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"Duigceol"="C:\WINDOWS\SYSTEM32\?ystem32\??chost.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2006-01-19 12:06 110592]
"mm_server"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe" [2006-01-19 12:06 102400]
"Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-03-29 14:12 290816]
"HostManager"="C:\Program Files\Common Files\AOL\1100847007\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe" [2006-01-19 12:06 11776]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
C:\Documents and Settings\Camron\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyawv]
ddcyawv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcaxut]
efcaxut.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebca]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebb]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjh]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkji]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3894ce0f]
C:\WINDOWS\system32\iktbgini.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2005-10-19 08:59 126976 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2005-10-19 08:59 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0a\\waol.exe"=
"C:\\Program Files\\Dell Computer\\Dell Picture Studio v2.0\\launch.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\AOL\\1100847007\\EE\\aolsoftware.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5100:TCP"= 5100:TCP:Yahoo! Webcam
"9547:TCP"= 9547:TCP:BitComet 9547 TCP
"9547:UDP"= 9547:UDP:BitComet 9547 UDP
S2 OracleOraHome90HTTPServer;OracleOraHome90HTTPServer;C:\oracle\ora90\Apache\Apache\Apache.exe []
S3 OracleOraHome90ClientCache;OracleOraHome90ClientCache;C:\oracle\ora90\BIN\ONRSD.EXE []
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-09 23:54:18 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-09 23:57:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-10 0:12:53
ComboFix-quarantined-files.txt 2008-06-10 05:12:48
Pre-Run: 4,340,097,024 bytes free
Post-Run: 4,315,561,984 bytes free
273 --- E O F --- 2008-05-28 02:16:51