Ok, gmer log, new combofix, and new hjt logs as requested.
GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2008-10-01 08:22:17
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
INT 0x06 \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) EF7D216D
INT 0x0E \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) EF7D1FC2
Code E19C3618 ZwEnumerateKey
Code E19C12F0 ZwFlushInstructionCache
Code 82993543 pIofCallDriver
---- Kernel code sections - GMER 1.0.14 ----
PAGE ntoskrnl.exe!ZwEnumerateKey 80570D64 5 Bytes JMP E19C361C
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80577693 5 Bytes JMP E19C12F4
---- User code sections - GMER 1.0.14 ----
.text C:\WINDOWS\system32\igfxpers.exe[108] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0039000A
.text C:\WINDOWS\system32\wdfmgr.exe[348] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0053000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[492] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00B1000A
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[500] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 003F000A
.text C:\Program Files\Dell\Media Experience\PCMService.exe[508] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0098000A
.text ...
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
---- Modules - GMER 1.0.14 ----
Module \systemroot\system32\drivers\seneka.sys (*** hidden *** ) F87F8000-F8805000 (53248 bytes)
---- Threads - GMER 1.0.14 ----
Thread 4:540 82992C3D
Thread 4:544 829934EA
---- Processes - GMER 1.0.14 ----
Library \\?\globalroot\systemroot\system32\senekapop.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [2024] 0x00A40000
---- Services - GMER 1.0.14 ----
Service C:\WINDOWS\system32\drivers\seneka.sys (*** hidden *** ) [SYSTEM] seneka <-- ROOTKIT !!!
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\seneka.sys
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\seneka.sys@ driver
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\seneka.sys
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\seneka.sys@ driver
Reg HKLM\SYSTEM\CurrentControlSet\Services\seneka
Reg HKLM\SYSTEM\CurrentControlSet\Services\seneka@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\seneka@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\seneka@imagepath \systemroot\system32\drivers\seneka.sys
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\seneka.sys
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\seneka.sys@ driver
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\seneka.sys
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\seneka.sys@ driver
Reg HKLM\SYSTEM\ControlSet002\Services\seneka
Reg HKLM\SYSTEM\ControlSet002\Services\seneka@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\seneka@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\seneka@imagepath \systemroot\system32\drivers\seneka.sys
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\senekapop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\senekapop@LogSessionName stdout
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\senekapop@Active 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\senekapop@ControlFlags 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\senekapop\traceIdentifier
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\senekapop\traceIdentifier@Guid 5f31090b-d990-4e91-b16d-46121d0255aa
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\senekapop\traceIdentifier@BitNames Error Unusual Info Debug
---- EOF - GMER 1.0.14 ----
ComboFix 08-09-25.07 - LAND ROVER SHOP 2008-09-30 13:39:30.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.251 [GMT -4:00]
Running from: C:\Documents and Settings\LAND ROVER SHOP\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LAND ROVER SHOP\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\csnmfoe.exe
C:\WINDOWS\m0_glkP_150908.dll
C:\WINDOWS\SYSTEM32\__c0069CE2.jpg
C:\WINDOWS\SYSTEM32\acbeg.ini2
C:\WINDOWS\SYSTEM32\agfdkneb.dll
C:\WINDOWS\SYSTEM32\ardwax.dll
C:\WINDOWS\SYSTEM32\bhxspm.dll
C:\WINDOWS\SYSTEM32\bsqmpjxm.dll
C:\WINDOWS\SYSTEM32\ctyrpajw.dll
C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk
C:\WINDOWS\system32\drivers\VGAA.sys
C:\WINDOWS\SYSTEM32\eigjhddq.dll
C:\WINDOWS\SYSTEM32\ensyoc.dll
C:\WINDOWS\SYSTEM32\fcarelyv.dll
C:\WINDOWS\SYSTEM32\haivhj.dll
C:\WINDOWS\SYSTEM32\hcrvntoq.dll
C:\WINDOWS\SYSTEM32\ieexplorer32.exe
C:\WINDOWS\SYSTEM32\ierutjvj.dll
C:\WINDOWS\SYSTEM32\ikvroccc.dll
C:\WINDOWS\SYSTEM32\iwlgomcj.dll
C:\WINDOWS\SYSTEM32\jqiclm.dll
C:\WINDOWS\SYSTEM32\jwvrtekn.dll
C:\WINDOWS\SYSTEM32\kdyabqij.dll
C:\WINDOWS\SYSTEM32\kteeffaj.dll
C:\WINDOWS\SYSTEM32\MicroAV.cpl
C:\WINDOWS\SYSTEM32\nexcqa.dll
C:\WINDOWS\SYSTEM32\pdhuzo.dll
C:\WINDOWS\SYSTEM32\pivsxcdm.dll
C:\WINDOWS\SYSTEM32\qvmwvhhm.dll
C:\WINDOWS\SYSTEM32\raqqxyys.dll
C:\WINDOWS\SYSTEM32\rbysuxfq.dll
C:\WINDOWS\SYSTEM32\rfcbsi.dll
C:\WINDOWS\SYSTEM32\rrqss.ini2
C:\WINDOWS\SYSTEM32\rstwa.ini2
C:\WINDOWS\SYSTEM32\sqxemtfu.dll
C:\WINDOWS\SYSTEM32\stutv.ini2
C:\WINDOWS\SYSTEM32\uarkaytg.dll
C:\WINDOWS\SYSTEM32\vcbfjpmx.dll
C:\WINDOWS\SYSTEM32\vcpduqir.dll
C:\WINDOWS\SYSTEM32\vfsfwcqw.dll
C:\WINDOWS\SYSTEM32\vvvwa.ini2
C:\WINDOWS\SYSTEM32\vyskehyj.dll
C:\WINDOWS\SYSTEM32\wpdfto.dll
C:\WINDOWS\SYSTEM32\xyadd.ini2
C:\WINDOWS\SYSTEM32\YUR1.exe
C:\WINDOWS\SYSTEM32\YUR2.exe
C:\WINDOWS\SYSTEM32\YUR3.exe
C:\WINDOWS\SYSTEM32\YUR4.exe
C:\WINDOWS\SYSTEM32\YUR7.exe
C:\WINDOWS\SYSTEM32\YUR8.exe
C:\WINDOWS\SYSTEM32\YUR9.exe
C:\WINDOWS\SYSTEM32\YURB.exe
C:\WINDOWS\SYSTEM32\YURC.exe
C:\WINDOWS\SYSTEM32\YURD.exe
C:\WINDOWS\SYSTEM32\zudxyy.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\CleanupTool
C:\Documents and Settings\All Users\Application Data\CleanupTool\Data\ac
C:\Documents and Settings\All Users\Application Data\CleanupTool\Data\CleanupTool.exe.cer
C:\Documents and Settings\All Users\Application Data\CleanupTool\Data\em
C:\Documents and Settings\All Users\Application Data\CleanupTool\Data\oid
C:\Documents and Settings\All Users\Application Data\CleanupTool\Data\save2.db
C:\Documents and Settings\All Users\Application Data\CleanupTool\Data\user
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\ProxyPal\proxypal.exe
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\agent-en.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\agent-swt-en.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\agent-swt.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\agent.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\key.exe
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\log4j-java1.1.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\log4j.properties
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\maverick-crypto.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\maverick-ssl.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\maverick-util.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\swt-win32-3235.dll
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\swt-win32.jar
C:\Documents and Settings\LAND ROVER SHOP\.sslexplorer\applications\sslexplorer-agent\ui.jar
C:\Documents and Settings\LAND ROVER SHOP\Cookies\land rover
shop@ad.yieldmanager[11].txt
C:\Program Files\CleanupTool
C:\Program Files\CleanupTool\atl71.dll
C:\Program Files\CleanupTool\kernel.dll
C:\Program Files\CleanupTool\License.rtf
C:\Program Files\CleanupTool\mfc71.dll
C:\Program Files\CleanupTool\msvcp71.dll
C:\Program Files\CleanupTool\msvcr71.dll
C:\Program Files\CleanupTool\Readme.rtf
C:\Program Files\CleanupTool\Res\Main.ico
C:\Program Files\CleanupTool\Res\RecycleBin.ico
C:\Program Files\CleanupTool\Res\support.ico
C:\Program Files\CleanupTool\rm.url
C:\Program Files\CleanupTool\sr.log
C:\Program Files\CleanupTool\swupd.log
C:\Program Files\CleanupTool\SysRep.exe
C:\Program Files\CleanupTool\SysRep.exe.Log
C:\Program Files\CleanupTool\SysRep.exe.xml
C:\Program Files\CleanupTool\SysRep.url
C:\Program Files\CleanupTool\transpaid.exe
C:\Program Files\CleanupTool\ucookw.exe
C:\Program Files\CleanupTool\unins000.dat
C:\Program Files\CleanupTool\unins000.exe
C:\Program Files\CleanupTool\urls.ini
C:\Program Files\Common Files\CleanupTool
C:\Program Files\Common Files\CleanupTool\strpmon.exe
C:\Program Files\LimeWire
C:\Program Files\LimeWire\clink.jar
C:\Program Files\LimeWire\commons-httpclient.jar
C:\Program Files\LimeWire\commons-logging.jar
C:\Program Files\LimeWire\commons-net.jar
C:\Program Files\LimeWire\daap.jar
C:\Program Files\LimeWire\GenericWindowsUtils.dll
C:\Program Files\LimeWire\hs_err_pid2600.log
C:\Program Files\LimeWire\i18n.jar
C:\Program Files\LimeWire\icu4j.jar
C:\Program Files\LimeWire\id3v2.jar
C:\Program Files\LimeWire\jcraft.jar
C:\Program Files\LimeWire\jl011.jar
C:\Program Files\LimeWire\jmdns.jar
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\LimeWire\LimeWire.jar
C:\Program Files\LimeWire\LimeWire20.dll
C:\Program Files\LimeWire\log4j.jar
C:\Program Files\LimeWire\logicrypto.jar
C:\Program Files\LimeWire\looks.jar
C:\Program Files\LimeWire\MessagesBundles.jar
C:\Program Files\LimeWire\mp3sp14.jar
C:\Program Files\LimeWire\ProgressTabs.jar
C:\Program Files\LimeWire\themes.jar
C:\Program Files\LimeWire\tritonus.jar
C:\Program Files\LimeWire\vorbis.jar
C:\Program Files\LimeWire\WindowsV5PlusUtils.dll
C:\Program Files\LimeWire\xerces.jar
C:\Program Files\LimeWire\xml-apis.jar
C:\Program Files\MicroAntivirus
C:\Program Files\MicroAntivirus\microAV.cpl
C:\Program Files\MicroAntivirus\microAV.exe
C:\Program Files\MicroAntivirus\microAV.ooo
C:\Program Files\MicroAntivirus\microAV0.dat
C:\Program Files\MicroAntivirus\microAV1.dat
C:\WINDOWS\BM474b71e7.txt
C:\WINDOWS\BM474b71e7.xml
C:\WINDOWS\csnmfoe.exe
C:\WINDOWS\m0_glkP_150908.dll
C:\WINDOWS\pskt.ini
C:\WINDOWS\SYSTEM32\__c0069CE2.jpg
C:\WINDOWS\SYSTEM32\acbeg.ini2
C:\WINDOWS\SYSTEM32\agfdkneb.dll
C:\WINDOWS\SYSTEM32\ardwax.dll
C:\WINDOWS\SYSTEM32\bhxspm.dll
C:\WINDOWS\SYSTEM32\bsqmpjxm.dll
C:\WINDOWS\SYSTEM32\ctyrpajw.dll
C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk
C:\WINDOWS\system32\drivers\VGAA.sys
C:\WINDOWS\SYSTEM32\eigjhddq.dll
C:\WINDOWS\SYSTEM32\ensyoc.dll
C:\WINDOWS\SYSTEM32\fcarelyv.dll
C:\WINDOWS\SYSTEM32\haivhj.dll
C:\WINDOWS\SYSTEM32\hcrvntoq.dll
C:\WINDOWS\SYSTEM32\ieexplorer32.exe
C:\WINDOWS\SYSTEM32\ierutjvj.dll
C:\WINDOWS\SYSTEM32\ikvroccc.dll
C:\WINDOWS\SYSTEM32\iwlgomcj.dll
C:\WINDOWS\SYSTEM32\jqiclm.dll
C:\WINDOWS\SYSTEM32\jwvrtekn.dll
C:\WINDOWS\SYSTEM32\kdyabqij.dll
C:\WINDOWS\SYSTEM32\kteeffaj.dll
C:\WINDOWS\SYSTEM32\MicroAV.cpl
C:\WINDOWS\SYSTEM32\nexcqa.dll
C:\WINDOWS\SYSTEM32\pdhuzo.dll
C:\WINDOWS\SYSTEM32\pivsxcdm.dll
C:\WINDOWS\SYSTEM32\qvmwvhhm.dll
C:\WINDOWS\SYSTEM32\raqqxyys.dll
C:\WINDOWS\SYSTEM32\rbysuxfq.dll
C:\WINDOWS\SYSTEM32\rfcbsi.dll
C:\WINDOWS\SYSTEM32\rrqss.ini2
C:\WINDOWS\SYSTEM32\rstwa.ini2
C:\WINDOWS\SYSTEM32\sqxemtfu.dll
C:\WINDOWS\SYSTEM32\stutv.ini2
C:\WINDOWS\SYSTEM32\uarkaytg.dll
C:\WINDOWS\SYSTEM32\vcbfjpmx.dll
C:\WINDOWS\SYSTEM32\vcpduqir.dll
C:\WINDOWS\SYSTEM32\vfsfwcqw.dll
C:\WINDOWS\SYSTEM32\vvvwa.ini2
C:\WINDOWS\SYSTEM32\vyskehyj.dll
C:\WINDOWS\SYSTEM32\wpdfto.dll
C:\WINDOWS\SYSTEM32\xyadd.ini2
C:\WINDOWS\SYSTEM32\YUR1.exe
C:\WINDOWS\SYSTEM32\YUR2.exe
C:\WINDOWS\SYSTEM32\YUR4.exe
C:\WINDOWS\SYSTEM32\YURB.exe
C:\WINDOWS\SYSTEM32\YURC.exe
C:\WINDOWS\SYSTEM32\YURD.exe
C:\WINDOWS\SYSTEM32\zudxyy.dll
C:\x
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_VGAA
-------\Service_VGAA
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-30 )))))))))))))))))))))))))))))))
.
2008-09-30 13:49 . 2008-09-22 03:16 25,088 --a------ C:\WINDOWS\SYSTEM32\YUR7.exe
2008-09-30 13:31 . 2008-09-22 03:16 25,088 --a------ C:\WINDOWS\SYSTEM32\YUR5.exe
2008-09-30 10:05 . 2008-09-30 10:05 444 --a------ C:\WINDOWS\SYSTEM32\d3d8caps.dat
2008-09-30 07:39 . 2008-09-30 07:39 71,814 --a------ C:\WINDOWS\SYSTEM32\twjcqenohpit.exe
2008-09-30 07:37 . 2008-09-30 07:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Software Licensors
2008-09-29 15:58 . 2008-09-29 15:58 <DIR> d-------- C:\Program Files\ESPN
2008-09-23 12:05 . 2008-09-26 18:10 <DIR> d-------- C:\Program Files\PC Doc Pro
2008-09-23 11:37 . 2008-09-23 11:38 <DIR> d--h-c--- C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}
2008-09-23 07:46 . 2008-09-23 07:46 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-09-23 07:34 . 2005-01-19 02:14 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-09-23 07:34 . 2005-02-15 04:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Neoteris
2008-09-23 07:34 . 2005-05-24 14:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Juniper Networks
2008-09-23 07:34 . 2005-01-19 02:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-09-23 07:34 . 2005-01-19 02:08 <DIR> d--h----- C:\Documents and Settings\Administrator\Application Data\Gtek
2008-09-23 07:34 . 2008-09-23 07:46 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-22 09:10 . 2008-09-22 09:10 167,936 --a------ C:\WINDOWS\SYSTEM32\bkaxtagocsczqyer.dll
2008-09-09 07:18 . 2008-09-09 07:18 <DIR> d-------- C:\Documents and Settings\LAND ROVER SHOP\Application Data\Talkback
2008-09-08 17:29 . 2008-09-08 17:29 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-08 16:58 . 2008-09-08 16:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-09-08 16:57 . 2008-09-08 16:57 <DIR> d-------- C:\Program Files\GameHouse
2008-09-08 16:57 . 2008-09-08 16:57 <DIR> d-------- C:\Documents and Settings\LAND ROVER SHOP\Application Data\GameHouse
2008-08-26 14:13 . 2008-09-17 07:51 <DIR> d-------- C:\Program Files\iWin
2008-08-26 08:07 . 2008-08-26 08:07 <DIR> d-------- C:\Documents and Settings\LAND ROVER SHOP\Application Data\iWin
2008-08-26 08:06 . 2008-08-26 08:06 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-08-26 08:06 . 2008-09-17 07:51 <DIR> d-------- C:\Program Files\Family Feud Dream Home
2008-08-22 18:51 . 2008-08-25 09:57 <DIR> d-------- C:\Program Files\Family Feud
2008-08-15 10:38 . 2008-08-15 10:38 <DIR> d-------- C:\Documents and Settings\LAND ROVER SHOP\Application Data\Pogo Games
2008-08-15 10:37 . 2008-09-17 07:52 <DIR> d-------- C:\Program Files\Oberon Media
2008-08-11 12:48 . 2008-08-25 09:58 <DIR> d-------- C:\Program Files\Full Tilt Poker
2008-08-07 11:20 . 2006-04-26 10:58 1,047,552 --a------ C:\WINDOWS\SYSTEM32\mfc71u.dll
2008-08-01 10:16 . 2008-08-01 10:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
2008-08-01 10:16 . 2008-08-01 10:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\en
2008-08-01 10:16 . 2008-08-01 10:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\bits
2008-08-01 10:16 . 2008-08-01 10:16 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-01 10:13 . 2008-08-01 10:17 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-01 10:05 . 2008-08-01 10:05 <DIR> d-------- C:\WINDOWS\EHome
2008-08-01 09:31 . 2004-08-03 22:41 1,041,536 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\hsfdpsp2.sys
2008-08-01 09:31 . 2004-08-03 22:41 685,056 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\hsfcxts2.sys
2008-08-01 09:31 . 2004-08-03 22:41 220,032 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\hsfbs2s2.sys
2008-08-01 09:31 . 2004-07-17 22:55 129,045 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\cxthsfs2.cty
2008-08-01 09:31 . 2004-08-03 22:41 11,868 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mdmxsdk.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-30 17:34 --------- d-----w C:\Documents and Settings\LAND ROVER SHOP\Application Data\Juniper Networks
2008-09-26 22:12 --------- d-----w C:\Program Files\Symantec
2008-09-26 22:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-19 18:38 --------- d-----w C:\Program Files\MUSICMATCH
2008-09-19 18:38 --------- d-----w C:\Documents and Settings\LAND ROVER SHOP\Application Data\Musicmatch
2008-09-18 17:20 --------- d-----w C:\Program Files\Hewlett-Packard
2008-09-18 17:15 --------- d-----w C:\Program Files\IGN
2008-09-18 17:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-18 17:13 --------- d-----w C:\Documents and Settings\LAND ROVER SHOP\Application Data\AdobeUM
2008-09-18 15:04 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-17 12:52 --------- d-----w C:\Program Files\McAfee.com
2008-09-17 12:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-17 12:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-09-17 11:43 --------- d-----w C:\Program Files\Java
2008-09-08 18:23 --------- d-----w C:\Documents and Settings\LAND ROVER SHOP\Application Data\Corel
2008-08-25 13:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-25 13:57 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-09 16:16 --------- d-----w C:\Program Files\Common Files\Software FX Shared
2008-07-30 14:53 --------- d-----w C:\Program Files\Trend Micro
.
((((((((((((((((((((((((((((( snapshot@2008-09-26_17.05.44.84 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-26 18:50:40 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2008-09-30 17:31:16 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2008-09-26 18:50:40 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-30 17:31:16 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-26 18:50:40 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-30 17:31:16 32,768 ----a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-02 17:42:09 53,248 ----a-w C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\PostUpdate.exe
+ 2008-09-29 17:30:58 53,248 ----a-w C:\WINDOWS\SYSTEM32\Macromed\Shockwave 10\PostUpdate.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7322440a-0cf9-69c9-65ac-d15311bb45f1}]
2008-09-22 09:10 167936 --a------ C:\WINDOWS\system32\bkaxtagocsczqyer.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-24 68856]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 307200]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"\YUR5.exe"="C:\Windows\system32\YUR5.exe" [2008-09-22 25088]
"\YUR7.exe"="C:\Windows\system32\YUR7.exe" [2008-09-22 25088]
"Antispyware PRO XP"="C:\Documents and Settings\All Users\Application Data\Software Licensors\Antispyware PRO XP\asproxp.exe" [2008-09-30 973824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 114688]
"\YUR5.exe"="C:\Windows\system32\YUR5.exe" [2008-09-22 25088]
"oxgcchgvjzg"="C:\WINDOWS\system32\bkaxtagocsczqyer.dll" [2008-09-22 167936]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-24 68856]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Neoteris\\Secure Application Manager\\dsSamProxy.exe"=
"C:\\WINDOWS\\SYSTEM32\\MSHTA.EXE"=
"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\SYSTEM32\\USMT\\migwiz.exe"=
R2 MicroGuard;MicroGuard Copy Protection;C:\WINDOWS\system32\drivers\mgnt.sys [1998-03-03 40480]
.
- - - - ORPHANS REMOVED - - - -
BHO-{003274BA-4DCC-4EE9-B7E6-164132005889} - (no file)
BHO-{0037A73C-1A77-43A2-BE6D-0D8912CEF312} - (no file)
HKCU-Run-\YUR8.exe - C:\Windows\system32\YUR8.exe
HKLM-Run-\YUR1.exe - C:\Windows\system32\YUR1.exe
HKLM-Run-\YUR3.exe - C:\Windows\system32\YUR3.exe
HKLM-Run-\YUR8.exe - C:\Windows\system32\YUR8.exe
HKLM-Run-\YUR9.exe - C:\Windows\system32\YUR9.exe
Notify-__c0069CE2 - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-30 13:49:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\seneka.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\wdfmgr.exe
C:\WINDOWS\SYSTEM32\wscntfy.exe
C:\WINDOWS\SYSTEM32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2008-09-30 13:52:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-30 17:52:34
ComboFix2.txt 2008-09-26 21:07:43
Pre-Run: 64,554,377,216 bytes free
Post-Run: 64,679,882,752 bytes free
365
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:22 AM, on 10/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\YUR7.exe
C:\Documents and Settings\All Users\Application Data\Software Licensors\Antispyware PRO XP\asproxp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\LAND ROVER SHOP\Application Data\Juniper Networks\Cache Cleaner 5.5.0\dsCacheCleaner.exe
C:\Program Files\Reflection\r2win.exe
C:\Program Files\Trend Micro\HijackThis\rotrhed.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell4me.com/mywaybiz
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: mxlivemedia browser enhancer - {7322440a-0cf9-69c9-65ac-d15311bb45f1} - C:\WINDOWS\system32\bkaxtagocsczqyer.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [\YUR5.exe] C:\Windows\system32\YUR5.exe
O4 - HKLM\..\Run: [oxgcchgvjzg] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\bkaxtagocsczqyer.dll" EntryPoint
O4 - HKLM\..\Run: [MediaPipe P2P Loader] "C:\Program Files\p2pnetworks\mpp2pl.exe" /H
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [\YUR5.exe] C:\Windows\system32\YUR5.exe
O4 - HKCU\..\Run: [\YUR7.exe] C:\Windows\system32\YUR7.exe
O4 - HKCU\..\Run: [Antispyware PRO XP] "C:\Documents and Settings\All Users\Application Data\Software Licensors\Antispyware PRO XP\asproxp.exe" /autorun
O4 - HKCU\..\Run: [Cache Cleaner] C:\Documents and Settings\LAND ROVER SHOP\Application Data\Juniper Networks\Cache Cleaner 5.5.0\dsCacheCleaner.exe -action delete
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://www.accuweather.com
O15 - Trusted Zone:
http://WWW.BLEEPINGCOMPUTER.COM
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) -
https://jaguarcsi.dealerconnection.com/download/CfxIEAx.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
http://www.worldwinner.com/games/shared/wwlaunch.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A453AB0-65AF-4804-AFDB-6CEBA7665D3D}: NameServer = 64.83.0.10,209.137.160.3
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
--
End of file - 7026 bytes