Combofix report....
ComboFix 07-11-19.4 - Arches 2007-11-27 10:42:38.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.116 [GMT -5:00]
Running from: C:\Documents and Settings\Arches\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\Arches\Favorites\Online Security Guide.lnk
C:\WINDOWS\system.exe
C:\WINDOWS\system32\ddayv.dll
C:\WINDOWS\system32\drivers\system.exe
C:\WINDOWS\system32\fhhkj.bak1
C:\WINDOWS\system32\fhhkj.bak2
C:\WINDOWS\system32\fhhkj.ini
C:\WINDOWS\system32\vyadd.bak1
C:\WINDOWS\system32\vyadd.bak2
C:\WINDOWS\system32\vyadd.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-10-27 to 2007-11-27 )))))))))))))))))))))))))))))))
.
2007-11-23 17:14 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-23 15:15 2,765 --a------ C:\a.vbs
2007-11-15 13:32 51,798 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k0
2007-11-15 13:32 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k7
2007-11-15 13:32 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k6
2007-11-15 13:32 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k5
2007-11-15 13:32 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k4
2007-11-15 13:32 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k3
2007-11-15 13:32 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k2
2007-11-15 13:32 64 --a------ C:\WINDOWS\system32\drivers\kmxcfg.u2k1
2007-11-15 11:38 879,784 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2007-11-15 11:38 108,312 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2007-11-15 11:38 32,264 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-11-15 11:38 26,376 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2007-11-15 11:38 21,512 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-11-15 11:38 21,128 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2007-11-15 10:58 85,056 --a------ C:\WINDOWS\system32\yjenlqwm.dll
2007-11-15 10:58 1,074 ---hs---- C:\WINDOWS\system32\mwqlnejy.ini
2007-11-15 10:56 79,936 --a------ C:\WINDOWS\system32\qwifgkbk.dll
2007-11-14 16:05 79,424 --a------ C:\WINDOWS\system32\enbrwbcl.dll
2007-11-14 16:02 144,480 --a------ C:\WINDOWS\system32\ejtigkbu.dll
2007-11-12 10:25 81,472 --a------ C:\WINDOWS\system32\nfxnijgf.dll
2007-11-09 15:20 77,888 --a------ C:\WINDOWS\system32\rxiyeykj.dll
2007-11-09 09:44 954 --ahs---- C:\WINDOWS\system32\sfvdlsaj.ini
2007-11-09 08:35 2,765 --a------ C:\Documents and Settings\Arches\a.vbs
2007-11-08 12:01 2,765 --a------ C:\WINDOWS\a.vbs
2007-11-08 09:42 594 --ahs---- C:\WINDOWS\system32\doicuxvg.ini
2007-11-06 16:07 <DIR> d-------- C:\Program Files\Windows Defender
2007-11-06 16:00 <DIR> d-------- C:\WINDOWS\CAVTemp
2007-11-06 15:53 12,949 --ahs---- C:\WINDOWS\system32\winlogon.scr
2007-11-06 15:53 12,949 ---hs---- C:\Documents and Settings\Arches\winmain.exe
2007-11-06 15:09 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-11-06 15:09 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-11-06 15:09 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-11-06 15:09 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-11-06 15:09 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-11-06 15:08 6,058,496 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-11-06 15:08 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-11-06 15:08 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-11-06 15:08 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-11-06 12:23 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-11-06 12:10 2,180,352 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-11-06 12:10 2,136,064 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2007-11-06 12:10 2,057,600 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2007-11-06 12:10 2,015,744 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2007-11-06 12:09 453,120 -----c--- C:\WINDOWS\system32\dllcache\mrxsmb.sys
2007-11-06 12:09 163,840 -----c--- C:\WINDOWS\system32\dllcache\jgdw400.dll
2007-11-06 12:09 27,648 -----c--- C:\WINDOWS\system32\dllcache\jgpl400.dll
2007-11-06 12:08 28,672 --a------ C:\WINDOWS\system32\verclsid.exe
2007-11-06 11:39 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-06 11:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-06 11:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-06 11:14 115,824 --a------ C:\WINDOWS\UnVet32.exe
2007-11-06 11:14 111,728 --a------ C:\WINDOWS\AVShlExt.dll
2007-11-06 11:14 79,424 --a------ C:\WINDOWS\system32\vetredir.dll
2007-11-06 09:39 <DIR> d-------- C:\Program Files\Common Files\eSellerate
2007-11-06 09:39 <DIR> d-------- C:\Program Files\AnswersThatWork
2007-11-06 09:39 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-06 09:39 614,400 --a------ C:\WINDOWS\system32\ExButton.dll
2007-11-06 09:39 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2007-11-06 09:39 356,352 --a------ C:\WINDOWS\system32\eSellerateEngine.dll
2007-11-06 09:39 212,240 --a------ C:\WINDOWS\system32\RichTx32.ocx
2007-11-06 09:39 118,784 --a------ C:\WINDOWS\system32\eWebControl.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 18:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-15 16:38 --------- d-----w C:\Program Files\Common Files\Scanner
2007-11-15 16:18 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-11-15 16:18 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-11-06 16:57 --------- d-----w C:\Program Files\SystemErrorFixer
2007-11-06 16:57 --------- d-----w C:\Program Files\Common Files\SystemErrorFixer
2007-11-06 16:14 --------- d-----w C:\Program Files\CA
2007-10-25 18:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2007-10-24 13:41 --------- d-----w C:\Documents and Settings\Arches\Application Data\systemerrorfixer
2007-10-24 13:36 --------- d-----r C:\Documents and Settings\All Users\Application Data\systemerrorfixer
2007-10-04 12:54 --------- d-----w C:\Documents and Settings\Arches\Application Data\AdobeUM
2007-10-03 18:20 --------- d-----w C:\Program Files\Common Files\Adobe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23766DF3-9E1D-4B65-B9F4-D13F1B7F5464}]
C:\WINDOWS\system32\jkhhf.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88d00a87-2dbb-494d-ac08-e9227df135e7}]
2007-11-15 10:56 79936 --a------ C:\WINDOWS\system32\qwifgkbk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2D85C1F-F359-4C6B-A43F-566D92D2F325}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"main"="C:\WINDOWS\system32\drivers\system.exe" []
"default"="C:\Documents and Settings\Arches\winmain.exe" [2007-10-19 14:38]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"sysinit"="C:\WINDOWS\system32\drivers\system.exe" []
"winmz"="C:\Documents and Settings\Arches\winmain.exe" [2007-10-19 14:38]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CAVRID"="C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe" [2007-08-20 13:42]
"VTTimer"="VTTimer.exe" [2004-01-15 07:33 C:\WINDOWS\system32\VTTimer.exe]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 09:46]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"18a883eb"="C:\WINDOWS\system32\yjenlqwm.dll" [2007-11-15 10:58]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-16 22:25]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2007-11-15 11:38]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2007-08-14 10:06]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2007-08-14 10:06]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2007-08-14 10:01]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-07-22 02:47:22]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjggfc]
ljjggfc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2007-05-18 14:30 79368 C:\WINDOWS\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddayv.dll
R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys
R0 viamraid;viamraid;C:\WINDOWS\system32\drivers\viamraid.sys
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe"
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe"
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe"
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe"
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 17:38:24 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Arches at 11 38 AM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
"2007-11-24 20:14:00 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Arches at 2 14 PM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
"2007-11-27 15:58:36 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-27 10:57:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
main = C:\WINDOWS\system32\drivers\system.exe???u???u??8=??4=??nf???u???u??$=??A:\autorun.inf???u???u???=??A:\autorun.exe???u???u???<?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
default = C:\Documents and Settings\Arches\winmain.exe?????u???u??0=???u???u??$=??A:\autorun.inf???u???u???=??A:\autorun.exe???u???u???<?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
sysinit = C:\WINDOWS\system32\drivers\system.exe???u???u??8=???u??0=???u???u??$=??A:\autorun.inf???u???u???=??A:\autorun.exe???u???u???<?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
winmz = C:\Documents and Settings\Arches\winmain.exe?????u???u??0=???u???u??$=??A:\autorun.inf???u???u???=??A:\autorun.exe???u???u???<?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-27 11:07:33 - machine was rebooted
.
--- E O F ---