Combofix Log
Here is my log from the combofix...thanks for your help!
ComboFix 09-07-31.04 - Waylon 08/01/2009 8:12.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.98 [GMT -7:00]
Running from: c:\documents and settings\Waylon.WAY\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\alurm.exe
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\Ssk.log
c:\documents and settings\Waylon.WAY\Local Settings\Temporary Internet Files\ahiqoqamod.ban
c:\documents and settings\Waylon.WAY\Local Settings\Temporary Internet Files\bowatiny.lib
c:\documents and settings\Waylon.WAY\Local Settings\Temporary Internet Files\jyxafuz._dl
c:\documents and settings\Waylon\Application Data\Sskcwrd.dll
c:\documents and settings\Waylon\Application Data\Sskknwrd.dll
c:\documents and settings\Waylon\Local Settings\Temporary Internet Files\Ssk.log
c:\documents and settings\Waylon\Local Settings\Temporary Internet Files\Tvm.log
C:\lswmv.ini
c:\program files\AWS\WEATHE~1\MINIBU~1.DLL
c:\program files\Common Files\inetget
c:\program files\Common Files\inetget\mc-58-12-0000106.exe
c:\program files\Common Files\inetget2
c:\program files\Common Files\inetget2\mc-58-12-0000106.exe
c:\program files\Common Files\mc-58-12-0000106.exe
c:\program files\Common Files\services.exe
c:\program files\Common Files\system32.dll
c:\program files\Common Files\uninstall information
c:\program files\Common Files\windows
c:\program files\Common Files\windows\AutoIt3.exe
c:\program files\Common Files\windows\mc-58-12-0000106.exe
c:\program files\Common Files\windows\psapi.dll
c:\program files\Common Files\windows\services32.exe
c:\program files\CSBB
c:\program files\CSBB\CSV7P28.exe
c:\program files\dns
c:\program files\dns\affid.dat
c:\program files\dns\Catcher.dll
c:\program files\dns\cwebpage.dll
c:\program files\dns\gui.exe
c:\program files\dns\regexp.dat
c:\program files\dns\regexpDate.dat
c:\program files\dns\uid.dat
c:\program files\dns\urls.dat
c:\program files\dns\version.txt
c:\program files\dns\x.bmp
c:\program files\e2g
c:\program files\e2g\data19
c:\program files\e2g\IeBHOs.dll
c:\program files\MyWay
c:\program files\quick links
c:\program files\quick links\uninst.exe
c:\program files\SurfAccuracy
c:\program files\SurfAccuracy\SAcc.cfg
c:\program files\SurfAccuracy\SAcc.exe
c:\program files\SurfAccuracy\SAccU.exe
c:\recycler\S-1-5-21-4024994690-1321446302-4065617495-1006
c:\recycler\S-1-5-21-4024994690-1321446302-4065617495-500
c:\windows\system32\_scui.cpl
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\wisdstr.exe
c:\windows\system32\xwreg32.dll
Infected copy of c:\windows\system32\drivers\beep.sys was found and disinfected
Restored copy from - c:\system volume information\_restore{460CC4EB-9EEE-4AE4-81F3-BC4CF43187BA}\RP913\A0034778.sys
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\system volume information\_restore{460CC4EB-9EEE-4AE4-81F3-BC4CF43187BA}\RP913\A0034780.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-07-01 to 2009-08-01 )))))))))))))))))))))))))))))))
.
2009-08-01 15:28 . 2004-08-04 07:56 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2009-08-01 15:28 . 2004-08-04 07:56 50176 ----a-w- c:\windows\system32\proquota.exe
2009-08-01 15:24 . 2001-08-23 12:00 4224 -c--a-w- c:\windows\system32\dllcache\beep.sys
2009-08-01 15:24 . 2001-08-23 12:00 4224 ----a-w- c:\windows\system32\drivers\beep.sys
2009-07-31 05:26 . 2009-07-31 05:26 -------- d-----w- c:\program files\Trend Micro
2009-07-30 05:05 . 2009-07-30 05:09 -------- d-----w- c:\program files\Spybot - Search & Destroy4
2009-07-30 03:58 . 2009-07-30 05:03 -------- d-----w- c:\program files\Spybot - Search & Destroy3
2009-07-30 03:08 . 2009-07-30 03:31 -------- d-----w- c:\program files\Spybot - Search & Destroy2
2009-07-28 02:33 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-07-28 02:33 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-07-26 18:31 . 2007-03-29 12:56 8192 -c----w- c:\windows\system32\dllcache\bitsprx2.dll
2009-07-26 18:31 . 2007-03-29 12:56 7168 -c----w- c:\windows\system32\dllcache\bitsprx4.dll
2009-07-26 18:31 . 2007-03-29 12:56 7168 -c----w- c:\windows\system32\dllcache\bitsprx3.dll
2009-07-26 18:31 . 2007-03-29 12:56 7168 ------w- c:\windows\system32\bitsprx4.dll
2009-07-26 18:31 . 2007-03-29 12:56 18944 -c----w- c:\windows\system32\dllcache\qmgrprxy.dll
2009-07-26 18:31 . 2007-03-29 12:56 409600 -c----w- c:\windows\system32\dllcache\qmgr.dll
2009-07-25 20:47 . 2009-07-25 20:47 16888 ----a-w- c:\documents and settings\Waylon.WAY\Local Settings\Application Data\ivypinuf.dll
2009-07-25 20:47 . 2009-07-25 20:47 12539 ----a-w- c:\documents and settings\Waylon.WAY\Local Settings\Application Data\otiz.exe
2009-07-25 20:47 . 2009-07-25 20:47 17557 ----a-w- c:\windows\system32\mimy.pif
2009-07-25 20:47 . 2009-07-25 20:47 16338 ----a-w- c:\documents and settings\Waylon.WAY\Local Settings\Application Data\awom.dat
2009-07-25 20:47 . 2009-07-25 20:47 16114 ----a-w- c:\windows\dyvo.com
2009-07-25 20:47 . 2009-07-25 20:47 13805 ----a-w- c:\documents and settings\Waylon.WAY\Application Data\uhugicy.pif
2009-07-25 20:47 . 2009-07-25 20:47 12878 ----a-w- c:\program files\Common Files\wiruk.bin
2009-07-25 20:47 . 2009-07-25 20:47 12711 ----a-w- c:\windows\system32\finowikec.vbs
2009-07-25 20:47 . 2009-07-25 20:47 10654 ----a-w- c:\documents and settings\Waylon.WAY\Application Data\eqafu.bat
2009-07-25 20:42 . 2009-07-25 20:42 43008 ----a-w- C:\ynee.exe
2009-07-25 20:42 . 2009-07-25 20:42 21504 ----a-w- C:\srgaupnr.exe
2009-07-25 20:42 . 2009-07-25 20:42 22016 ----a-w- C:\dfncp.exe
2009-07-25 09:02 . 2009-07-25 12:17 -------- d-----w- c:\program files\Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-01 15:27 . 2001-08-23 12:00 407040 ----a-w- c:\windows\system32\netlogon.dll
2009-07-30 05:12 . 2005-11-08 03:26 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-07-30 00:25 . 2007-01-28 01:43 -------- d-----w- c:\program files\MySpace
2009-07-30 00:21 . 2005-05-10 01:36 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-25 20:47 . 2009-07-25 20:47 11700 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\pitodime.dat
2009-07-25 20:41 . 2006-12-01 01:30 1744 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-29 02:03 . 2009-01-10 02:09 1915520 ----a-w- c:\documents and settings\Waylon.WAY\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-06-16 14:55 . 2001-08-23 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2001-08-23 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:27 . 2001-08-23 12:00 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-07 15:44 . 2001-08-23 12:00 344064 ----a-w- c:\windows\system32\localspl.dll
2003-10-02 21:28 . 2003-10-02 21:28 54272 --sha-w- c:\program files\Thumbs.db
2002-04-28 22:59 . 2002-04-28 22:59 150288 ----a-w- c:\program files\kmd.exe
2002-04-28 22:58 . 2002-04-28 22:58 27741 ----a-w- c:\program files\m2k.zip
2002-04-19 07:12 . 2002-04-19 07:12 2817176 ----a-w- c:\program files\ppview97.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-29 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-21 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
Contents of the 'Scheduled Tasks' folder
2009-07-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]
2009-08-01 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-07-26 22:31]
2009-08-01 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-03-25 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: cbs.com\www
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-01 09:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\pctspk.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-08-01 10:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-01 17:09
Pre-Run: 9,210,544,128 bytes free
Post-Run: 14,101,520,384 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
198 --- E O F --- 2009-07-30 00:27