ComboFix 08-02-20.2 - MFRECEP 2008-02-20 19:50:11.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.209 [GMT -6:00]
Running from: C:\Documents and Settings\MFRECEP\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\SYSTEM32\jjkmp.ini
C:\WINDOWS\SYSTEM32\jjkmp.ini2
C:\WINDOWS\SYSTEM32\wwujdbiy.ini
C:\WINDOWS\system32\yibdjuww.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-21 to 2008-02-21 )))))))))))))))))))))))))))))))
.
2008-02-20 19:54 . 2008-02-20 19:55 396 --ahs---- C:\WINDOWS\SYSTEM32\jjkmp.ini
2008-02-20 19:29 . 2008-02-20 19:29 <DIR> d-------- C:\WINDOWS\ERUNT
2008-02-20 16:18 . 2008-02-20 16:22 <DIR> d-------- C:\Documents and Settings\MFRECEP\.housecall6.6
2008-02-20 15:50 . 2008-02-20 15:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-19 15:31 . 2008-02-17 00:05 <DIR> d-------- C:\SDFix
2008-02-18 23:19 . 2008-02-18 23:19 248,928 --a------ C:\WINDOWS\SYSTEM32\pmkjj.dll
2008-02-18 22:19 . 2008-02-18 22:19 232,868 --a------ C:\WINDOWS\SYSTEM32\vturo.dll
2008-02-18 13:59 . 2008-02-18 13:59 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-02-18 13:59 . 2008-02-18 13:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-18 13:08 . 2008-02-18 13:08 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-18 13:08 . 2008-02-18 13:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-18 12:06 . 2008-02-18 12:49 1,238,313 --ahs---- C:\WINDOWS\SYSTEM32\9B5900c__.ini
2008-02-10 09:25 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 20:35 --------- d-----w C:\Program Files\AWS
2008-02-19 20:30 --------- d-----w C:\Program Files\Microsoft Money
2008-02-19 20:27 --------- d-----w C:\Program Files\Microsoft Money 2005
2008-02-19 20:11 --------- d-----w C:\Program Files\Hewlett-Packard
2008-02-19 20:09 --------- d--h--w C:\Program Files\Zero G Registry
2008-02-19 19:52 --------- d-----w C:\Program Files\Google
2008-02-10 15:24 --------- d-----w C:\Program Files\Java
2008-02-09 20:27 --------- d-----w C:\Program Files\hp
2008-01-17 22:41 98 ---h--w C:\Documents and Settings\MFRECEP\Application Data\srfvdo.dat
2005-10-06 16:08 143,184 ----a-w C:\Documents and Settings\Brad Hatfield\Application Data\GDIPFONTCACHEV1.DAT
2004-09-21 17:19 212 ---h--w C:\Documents and Settings\Brad Hatfield\Application Data\srfvdo.dat
2007-09-25 16:09 6,480 --sha-w C:\WINDOWS\SYSTEM32\accdd.bak1
2007-09-27 14:10 6,440 --sha-w C:\WINDOWS\SYSTEM32\dccdd.bak1
2007-10-02 14:59 7,170 --sha-w C:\WINDOWS\SYSTEM32\hjjlm.bak1
2007-10-02 14:59 7,170 --sha-w C:\WINDOWS\SYSTEM32\hjjlm.bak2
2007-09-26 14:14 6,480 --sha-w C:\WINDOWS\SYSTEM32\utstv.bak1
2007-10-03 21:21 13,952 --sha-w C:\WINDOWS\SYSTEM32\utstv.bak2
2007-09-28 14:19 6,480 --sha-w C:\WINDOWS\SYSTEM32\wyadd.bak1
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{455F0698-FD9E-4859-BD28-B886A70517A1}]
C:\WINDOWS\system32\gebyw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72E8415E-9C68-4122-B762-2D790573B691}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7DBEC39B-BAAC-4694-A340-665C73A5257D}]
2008-02-18 23:19 248928 --a------ C:\WINDOWS\system32\pmkjj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c19b0128-5aff-408e-b38a-55b6a8107fd2}]
C:\WINDOWS\system32\vvrdvhlx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 07:59 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 07:59 126976]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 15:44 679936]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2002-11-23 02:15 631362]
"PaperPort PTD"="C:\Program Files\Scansoft\PaperPort\pptd40nt.exe" [2003-02-27 02:12 57393]
"IndexSearch"="C:\Program Files\Scansoft\PaperPort\IndexSearch.exe" [2003-02-27 02:40 40960]
"siService.exe"="C:\Program Files\Sunbelt Software\iHateSpam\siService.exe" [2004-01-26 10:57 204800]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 10:35 77824]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"HPLJ Config"="C:\Program Files\Hewlett-Packard\hp LaserJet 3015_3020_3030_3380\SetConfig.exe" [ ]
"SM_IAN"="C:\Program Files\AdvancedCleaner Free\ian_monitor.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec Network Driver Update Warning"="C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE" [2004-04-30 17:02 91256]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\hp\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38 241664]
HP Image Zone Fast Start.lnk - C:\Program Files\hp\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36 53248]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddayw]
C:\WINDOWS\system32\ddayw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcca]
C:\WINDOWS\system32\ddcca.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccd]
C:\WINDOWS\system32\ddccd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcdecy]
efcdecy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljjh]
C:\WINDOWS\system32\mljjh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtstu]
C:\WINDOWS\system32\vtstu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0067748]
C:\WINDOWS\system32\__c0067748.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau C:\WINDOWS\system32\pmkjj.dll
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe [2002-05-08 08:51]
R2 NetAlrt;NetAlrt;C:\WINDOWS\System32\drivers\NetAlrt.sys [2002-05-07 15:05]
R2 NwSapAgent;SAP Agent;C:\WINDOWS\System32\svchost.exe [2004-08-04 01:56]
R2 PlatAlrt;PlatAlrt;C:\WINDOWS\System32\drivers\PlatAlrt.sys [2002-05-07 15:06]
S2 hppecp00;hppecp00;C:\WINDOWS\system32\drivers\hppecp00.sys []
S3 {E6759E0C-470B-44DC-A4A1-627E68BB3A85};AIM 3.0 SI164;C:\WINDOWS\system32\drivers\A302.sys [2002-04-24 16:56]
S3 HPFXBULK;HPFXBULK;C:\WINDOWS\system32\drivers\hpfxbulk.sys [2005-09-20 10:22]
S3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\Drivers\LCcFltr.Sys [2002-11-08 09:50]
S3 NMSCFG;NIC Management Service Configuration Driver;C:\WINDOWS\System32\drivers\NMSCFG.SYS [2002-02-27 08:57]
S3 NMSSvc;Intel(R) NMS;C:\WINDOWS\System32\NMSSvc.exe [2002-02-27 08:57]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 12:52]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-20 19:55:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\pmkjj.dll
-> C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\system32\pmkjj.dll
-> C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Sunbelt Software\iHateSpam\siSpamFilterEngine.exe
C:\Program Files\hp\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2008-02-20 19:58:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-21 01:57:55
ComboFix2.txt 2008-02-20 21:48:02
.
2008-02-13 23:09:11 --- E O F ---