This time it only took an hour and 20 minutes to run combofix we must be making progress. :thanks:
ComboFix 11-09-19.01 - ME 09/19/2011 19:00:14.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254.114 [GMT -5:00]
Running from: C:\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\ME\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\ME\Local Settings\Application Data\ApplicationHistory\TransferAgent.exe.91f03f4d.ini.inuse
Pass LEGAL for license information. Built Sat Jun 25 23:20 2011c:\windows\
.
Infected copy of c:\windows\system32\drivers\fips.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\fips.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ITLPERF
-------\Service_itlperf
.
.
((((((((((((((((((((((((( Files Created from 2011-08-20 to 2011-09-20 )))))))))))))))))))))))))))))))
.
.
2011-09-19 02:34 . 2011-09-19 02:35 -------- d-----w- C:\f1a57df13e9e481fe205
2011-09-19 01:01 . 2011-09-19 01:02 40780 ----a-w- c:\windows\edokoziyequ.dll
2011-09-18 20:16 . 2011-09-18 20:17 40780 ----a-w- c:\windows\icohigus.dll
2011-09-18 17:46 . 2011-09-18 17:46 40780 ----a-w- c:\windows\osisiyovupomub.dll
2011-09-18 15:33 . 2011-09-18 15:33 40780 ----a-w- c:\windows\ejusomizihawag.dll
2011-09-18 13:22 . 2011-09-18 13:22 40780 ----a-w- c:\windows\ilusubacaxo.dll
2011-09-18 11:08 . 2011-09-18 11:08 40780 ----a-w- c:\windows\azocubuwo.dll
2011-09-18 09:00 . 2011-09-18 09:00 40780 ----a-w- c:\windows\erevawubixaxayug.dll
2011-09-18 06:41 . 2011-09-18 06:41 40780 ----a-w- c:\windows\otuxekuv.dll
2011-09-18 04:29 . 2011-09-18 04:29 40780 ----a-w- c:\windows\utitijih.dll
2011-09-18 02:17 . 2011-09-18 02:17 40780 ----a-w- c:\windows\aludipok.dll
2011-09-18 00:07 . 2011-09-18 00:07 40780 ----a-w- c:\windows\icamabimonusijeg.dll
2011-09-17 22:04 . 2011-09-17 22:04 40780 ----a-w- c:\windows\usevofamana.dll
2011-09-17 19:57 . 2011-09-17 19:58 40780 ----a-w- c:\windows\iwewiwif.dll
2011-09-17 17:52 . 2011-09-17 17:52 40780 ----a-w- c:\windows\aduzacufotizi.dll
2011-09-17 15:49 . 2011-09-17 15:49 40780 ----a-w- c:\windows\uzijidifemeyuda.dll
2011-09-15 08:35 . 2011-09-17 05:26 48016 --sha-w- c:\windows\system32\c_26305.nl_
2011-09-14 01:30 . 2011-09-14 01:31 -------- d-----w- c:\program files\ERUNT
2011-09-13 23:46 . 2011-09-13 23:46 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Sun
2011-09-13 23:43 . 2011-09-19 15:45 0 ----a-w- c:\windows\Twojucenafidac.bin
2011-09-13 23:42 . 2011-09-13 23:42 -------- d-----w- c:\documents and settings\ME\Local Settings\Application Data\{15BBA956-ED8B-4953-9620-753A36A1B56F}
2011-09-13 02:03 . 2011-09-13 02:03 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Macromedia
2011-09-13 02:03 . 2011-09-13 02:03 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Adobe
2011-09-03 10:17 . 2011-09-09 09:12 599040 ------w- c:\windows\system32\dllcache\crypt32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-16 02:35 . 2002-08-29 07:27 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-09-14 00:06 . 2011-09-14 00:06 219136 ----a-w- c:\windows\system32\ineltw32.dll
2011-09-14 00:06 . 2011-09-14 00:06 35840 ----a-w- c:\windows\system32\ilnetw32.dll
2011-09-09 09:12 . 2003-03-20 22:18 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-07-15 13:29 . 2002-08-29 11:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2002-08-29 11:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2002-08-29 11:00 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2004-04-12 03:41 . 2004-04-12 03:41 1268639 ----a-w- c:\program files\TaxCut_2003_Illinois_InstallerB.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"PhotoShow Deluxe Media Manager"="c:\progra~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe" [2005-02-01 163840]
"DellTransferAgent"="c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 135168]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-13 3660848]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-22 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-22 126976]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-27 204800]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-03-25 151597]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-10-06 53248]
"SpeedTouch USB Diagnostics"="c:\program files\Alcatel\SpeedTouch USB\Dragdiag.exe" [2001-03-27 995328]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2010-10-25 36760]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2010-10-25 821144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ilnetw32]
2011-09-14 00:06 35840 ----a-w- c:\windows\SYSTEM32\ilnetw32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\inetworks]
2011-09-14 00:06 35840 ----a-w- c:\windows\SYSTEM32\ilnetw32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\KODAK\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Documents and Settings\\ME\\Desktop\\tdsskiller\\TDSSKiller.exe"=
.
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
R3 SQTECH907B;EZCam(PID_907B_00);c:\windows\system32\Drivers\Capt907B.sys [2005-05-10 61643]
S1 aswSP;avast! Self Protection; [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-04-14 14336]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]
S2 itlperf;Network Location Awarenes;c:\windows\System32\svchost.exe [2008-04-14 14336]
S3 alcan5ln;Alcatel SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\DRIVERS\alcan5ln.sys [2001-03-27 35600]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ITLPERF
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
itnetsvcs REG_MULTI_SZ itlperf
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://dsl.sbc.yahoo.com/
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\update
Trusted Zone: windowsupdate.com\download
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-09-19 19:46
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\windows\2014770103:1208805767.exe 816 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\.application\bootstrap]
@DACL=(02 0000)
@="bootstrap.application.1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\ilnetw32.dll
.
- - - - - - - > 'explorer.exe'(800)
c:\windows\system32\WININET.dll
c:\docume~1\ME\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\windows\wanmpsvc.exe
c:\program files\HP\Digital Imaging\bin\hpqtra08.exe
c:\program files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
c:\program files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Adobe\Acrobat 10.0\Acrobat\LogTransport2.exe
.
**************************************************************************
.
Completion time: 2011-09-19 20:14:45 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-20 01:14
ComboFix2.txt 2011-09-19 18:42
ComboFix3.txt 2008-05-13 05:45
ComboFix4.txt 2008-05-13 02:04
.
Pre-Run: 49,252,249,600 bytes free
Post-Run: 49,248,206,848 bytes free
.
- - End Of File - - 406B2EE5D6D0DEA8F43B917870373AB8