Combofix/HijackThis logs/Onefabmom
ComboFix 07-09-14.2 - "Kathy roque" 2007-09-16 22:06:00.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.145 [GMT -7:00]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\DOCUME~1\KATHYR~1\APPLIC~1\install.dat
C:\Program Files\poolsv
C:\Program Files\poolsv\k11u72.exe
C:\Program Files\poolsv\YazzleBundle-1549.exe
C:\Temp\fse
C:\WINDOWS\cookies.ini
C:\WINDOWS\icroso~1.net
C:\WINDOWS\icroso~1.net\?icrosoft.NET\
C:\WINDOWS\system32\ahqoklor.ini
C:\WINDOWS\system32\blttcsas.dll
C:\WINDOWS\system32\caejvqsy.ini
C:\WINDOWS\system32\ctqjrxbd.ini
C:\WINDOWS\system32\dbxrjqtc.dll
C:\WINDOWS\system32\eydcilxl.dll
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\fdgjkoqo.exe
C:\WINDOWS\system32\fnpyxigl.dll
C:\WINDOWS\system32\iifcyyy.dll
C:\WINDOWS\system32\jmllm.bak1
C:\WINDOWS\system32\jmllm.bak2
C:\WINDOWS\system32\jmllm.ini
C:\WINDOWS\system32\jmllm.ini2
C:\WINDOWS\system32\jmllm.tmp
C:\WINDOWS\system32\jsiotnru.exe
C:\WINDOWS\system32\knhvvdty.ini
C:\WINDOWS\system32\kyiyeeer.exe
C:\WINDOWS\system32\lgixypnf.ini
C:\WINDOWS\system32\lpqxorto.ini
C:\WINDOWS\system32\lxlicdye.ini
C:\WINDOWS\system32\mllmj.dll
C:\WINDOWS\system32\mtogcmgl.exe
C:\WINDOWS\system32\norksvyg.exe
C:\WINDOWS\system32\otroxqpl.dll
C:\WINDOWS\system32\ppatch~1
C:\WINDOWS\system32\ppatch~1\j?vaw.exe
C:\WINDOWS\system32\rolkoqha.dll
C:\WINDOWS\system32\sascttlb.ini
C:\WINDOWS\system32\savkcwiu.dll
C:\WINDOWS\system32\tbsafmwt.exe
C:\WINDOWS\system32\uiwckvas.ini
C:\WINDOWS\system32\wapiicomsv32.exe
C:\WINDOWS\system32\ysqvjeac.dll
C:\WINDOWS\system32\ytdvvhnk.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_FOPN
((((((((((((((((((((((((( Files Created from 2007-08-17 to 2007-09-17 )))))))))))))))))))))))))))))))
.
2007-09-16 21:55 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-15 23:28 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-11 18:17 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-11 18:17 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-10 16:44 <DIR> d-------- C:\DOCUME~1\KATHYR~1\DoctorWeb
2007-08-25 10:37 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-14 19:03 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-13 08:37 --------- d-------- C:\DOCUME~1\KATHYR~1\APPLIC~1\AdobeUM
2007-09-11 18:24 --------- d-------- C:\Program Files\MSECACHE
2007-09-11 18:21 --------- d-------- C:\Program Files\MySpace
2007-09-09 23:57 --------- d-------- C:\Program Files\America Online 9.0a
2007-08-25 12:50 --------- d-------- C:\Program Files\Norton Internet Security
2007-08-25 12:48 --------- d-------- C:\Program Files\Microsoft Works
2007-08-25 12:40 --------- d-------- C:\Program Files\Google
2007-08-25 12:40 --------- d-------- C:\Program Files\Digital Line Detect
2007-08-25 12:40 --------- d-------- C:\Program Files\Dell Support
2007-08-25 12:36 --------- d-------- C:\Program Files\Common Files\aolshare
2007-08-25 12:36 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-25 12:32 --------- d-------- C:\Program Files\America Online 9.0
2007-08-13 16:10 --------- d-------- C:\Program Files\Symantec
2007-08-13 16:09 --------- d-------- C:\Program Files\SymNetDrv
2007-08-07 11:34 1761042 --ahs---- C:\WINDOWS\system32\qqtwa.ini2
2007-08-06 23:43 1768736 --ahs---- C:\WINDOWS\system32\qqtwa.bak2
2007-08-03 10:51 --------- d-------- C:\Program Files\Apple Software Update
2007-08-03 10:50 --------- d-------- C:\Program Files\Common Files\Apple
2007-08-03 10:50 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-03 10:50 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-08-03 10:31 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-20 08:24 --------- d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\CallingID
2007-07-20 08:20 --------- d-------- C:\DOCUME~1\KATHYR~1\APPLIC~1\CallingID
2007-07-18 11:38 --------- d-------- C:\DOCUME~1\Guest\APPLIC~1\Viewpoint
2007-07-18 11:38 --------- d-------- C:\DOCUME~1\Guest\APPLIC~1\AOL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{17AC83B7-170E-6EFB-7877-49B60C48F1C2}]
C:\WINDOWS\system32\njjdpsrb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A1C9752B-9552-4A04-B29C-38D2626A6C16}]
C:\WINDOWS\system32\awtqq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 17:42]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 21:09]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 21:06]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 21:10]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 15:48]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 14:19]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-05 23:05]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 14:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 14:50]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-26 23:02]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-08 17:03]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-12-09 17:19]
"HostManager"="C:\Program Files\Common Files\AOL\1150322547\ee\AOLSoftware.exe" [2006-09-25 17:52]
"sscRun"="C:\Program Files\Common Files\AOL\1150322547\ee\services\sscFirewallPlugin\ver1_205_1_1\SSCRun.exe" [2006-06-01 07:53]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 05:50]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-04-05 14:33]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-29 18:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-05 11:18]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-08-13 16:09]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"DMX"="C:\Program Files\Dell\Media Experience\DMX.exe" [2005-01-26 23:02]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 14:51]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 22:57]
"Msyvz"="C:\WINDOWS\system32\??pPatch\j?vaw.exe" []
"AOL Fast Start"="C:\Program Files\America Online 9.0a\AOL.exe" [2005-07-11 22:17]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-10-22 13:40:29]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 23:01:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-08-01 22:42:18]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqq]
C:\WINDOWS\system32\awtqq.dll
.
Contents of the 'Scheduled Tasks' folder
"2007-09-13 04:02:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-15 03:00:20 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Kathy roque.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
"2007-09-17 02:03:30 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-16 22:19:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ATWPKT2]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\ATWPKT2.SYS"
.
Completion time: 2007-09-16 22:22:32 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-16 22:21
.
--- E O F ---