combofix
ComboFix 08-04-22.5 - Mark Coker 2008-04-25 19:27:25.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.183 [GMT -5:00]
Running from: C:\Documents and Settings\Mark Coker\My Documents\My Pictures\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mark Coker\Desktop\CFScript (2).lnk
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-26 to 2008-04-26 )))))))))))))))))))))))))))))))
.
2008-04-25 18:23 . 2008-04-25 18:23 90,112 --a------ C:\WINDOWS\system32\ufqxczyz.exe
2008-04-24 18:26 . 2008-04-24 18:26 106,496 --a------ C:\WINDOWS\system32\enslihod.exe
2008-04-23 17:54 . 2008-04-24 18:04 1,509,339 --ahs---- C:\WINDOWS\system32\gehxbhof.ini
2008-04-22 08:41 . 2008-04-22 08:41 <DIR> d-------- C:\Documents and Settings\Mark Coker\Application Data\TmpRecentIcons
2008-04-22 07:34 . 2008-04-23 17:54 1,541,089 --ahs---- C:\WINDOWS\system32\lqellgxf.ini
2008-04-21 18:20 . 2008-04-21 18:20 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-21 12:53 . 2008-04-21 12:53 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-21 02:32 . 2008-04-22 07:33 354 --ahs---- C:\WINDOWS\system32\bhyunwps.ini
2008-04-21 01:25 . 2008-04-21 01:25 106,496 --a------ C:\WINDOWS\system32\jczudixy.exe
2008-04-20 14:17 . 2008-04-20 14:17 <DIR> d-------- C:\Documents and Settings\Mark Coker\Application Data\Grisoft
2008-04-20 14:16 . 2008-04-20 14:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-20 14:16 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-20 13:25 . 2008-04-20 13:25 98,304 --a------ C:\WINDOWS\system32\jqdsfanq.exe
2008-04-20 12:55 . 2008-04-20 12:55 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-20 12:55 . 2008-04-20 13:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-20 12:42 . 2008-04-20 04:52 319,488 --a------ C:\WINDOWS\wdpoefan.dll
2008-04-20 12:42 . 2008-04-20 04:52 274,432 --a------ C:\WINDOWS\vadokmxt.dll
2008-04-20 12:42 . 2008-04-19 05:39 270,336 --------- C:\WINDOWS\qnmargolktr.dll
2008-04-20 12:42 . 2008-04-20 04:52 262,144 --a------ C:\WINDOWS\qnmargololr.dll
2008-04-20 12:42 . 2008-04-20 04:52 184,320 --a------ C:\WINDOWS\dpevflbg.dll
2008-04-20 12:42 . 2008-04-20 04:52 98,304 --a------ C:\WINDOWS\olgdqarf.exe
2008-04-20 12:42 . 2008-04-20 04:52 90,112 --a------ C:\WINDOWS\wxvgsdbq.exe
2008-04-20 12:41 . 2008-04-25 18:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\mnytmnqb
2008-04-20 12:41 . 2008-04-20 12:41 106,496 --a------ C:\WINDOWS\system32\utqninyv.exe
2008-04-09 10:15 . 2008-04-25 19:22 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-09 10:15 . 2008-04-09 10:15 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-09 10:14 . 2008-04-09 10:14 <DIR> d-------- C:\Program Files\iTunes
2008-04-09 10:14 . 2008-04-09 10:14 <DIR> d-------- C:\Program Files\iPod
2008-04-09 10:12 . 2008-04-09 10:12 <DIR> d-------- C:\Program Files\QuickTime
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-26 00:22 --------- d-----w C:\Documents and Settings\Mark Coker\Application Data\LimeWire
2008-04-16 15:18 --------- d-----w C:\Program Files\LimeWire
2008-04-11 02:20 --------- d-----w C:\Documents and Settings\Mark Coker\Application Data\Apple Computer
2008-04-09 23:02 5,018 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-04-09 15:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-03-25 21:43 --------- d-----w C:\Program Files\Java
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-06 21:36 --------- d-----w C:\Program Files\Google
2008-03-02 00:06 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-01 23:36 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-01-29 17:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
2006-08-10 02:24 8 -csha-r C:\WINDOWS\system32\4F444FEC9F.sys
.
((((((((((((((((((((((((((((( snapshot@2008-04-24_18.30.02.87 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-24 23:24:57 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-26 00:22:31 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2DACE5B7-FC7B-44BA-8E40-8BA43D0DD870}]
C:\WINDOWS\system32\opnnMgeb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A2E5A36A-C7E9-4220-AD4D-70802B6C4522}]
C:\WINDOWS\system32\mlJDtuvS.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EFA665C4-6D72-4B8B-8286-045E879FCAE8}]
2008-04-19 05:39 270336 --------- C:\WINDOWS\qnmargolktr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FFFDFF87-2CFE-40D6-9480-33E97FEC4362}]
2008-04-20 04:52 262144 --a------ C:\WINDOWS\qnmargololr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{87F195A2-E583-4FE1-9649-3333E6FE1A61}"= "C:\WINDOWS\dpevflbg.dll" [2008-04-20 04:52 184320]
[HKEY_CLASSES_ROOT\clsid\{87f195a2-e583-4fe1-9649-3333e6fe1a61}]
[HKEY_CLASSES_ROOT\dpevflbg.1]
[HKEY_CLASSES_ROOT\TypeLib\{6D1E583A-D2AA-4ACA-ACE8-451F73C609F1}]
[HKEY_CLASSES_ROOT\dpevflbg]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"gkcmkdia"="C:\WINDOWS\system32\utqninyv.exe" [2008-04-20 12:41 106496]
"wlcdvhuf"="C:\WINDOWS\system32\jqdsfanq.exe" [2008-04-20 13:25 98304]
"jpswmoha"="C:\WINDOWS\system32\jczudixy.exe" [2008-04-21 01:25 106496]
"wkzpajmt"="C:\WINDOWS\system32\enslihod.exe" [2008-04-24 18:26 106496]
"fmdujodc"="C:\WINDOWS\system32\ufqxczyz.exe" [2008-04-25 18:23 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 13:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 13:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 13:50 114688]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 03:12 98304]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 19:05 1117184]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-13 23:36 185896]
"FLMOFFICE4DMOUSE"="C:\Program Files\Browser Mouse\mouse32a.exe" [2007-02-24 08:49 360448]
"FLMK08KB"="C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE" [2007-02-24 08:53 207360]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"b0c19ea7"="C:\WINDOWS\system32\fohbxheg.dll" [ ]
C:\Documents and Settings\Mark Coker\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-02-08 16:32:57 147456]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-08-03 10:37:22 24576]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 05:33:46 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"wAjNZooqdJ"= C:\Documents and Settings\All Users\Application Data\mnytmnqb\wtwbivcr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"wAjNZooqdJ"= C:\Documents and Settings\All Users\Application Data\mnytmnqb\wtwbivcr.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"vadokmxt"= {2AAB91CA-A79F-4888-87C9-9D5B3A793576} - C:\WINDOWS\vadokmxt.dll [2008-04-20 04:52 274432]
"wdpoefan"= {D9605006-00CC-4325-BB4C-17C16C34DC0B} - C:\WINDOWS\wdpoefan.dll [2008-04-20 04:52 319488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efCurPff]
efCurPff.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-21 23:20:18 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-20 02:48:01 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\system32\rundll32.exelC:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.5.30.2.sxt _RegistrationOffer@16
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-25 19:29:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-25 19:30:54
ComboFix-quarantined-files.txt 2008-04-26 00:30:32
ComboFix2.txt 2008-04-24 23:30:25
Pre-Run: 42,524,950,528 bytes free
Post-Run: 42,516,041,728 bytes free
173 --- E O F --- 2008-04-10 08:02:28