ajplumbing
New member
ComboFix 09-10-11.01 - Jarod 10/13/2009 17:00.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.97 [GMT -5:00]
Running from: c:\documents and settings\Jarod.AJ-71DGB8DRX842\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jarod.AJ-71DGB8DRX842\Desktop\CFScript.txt
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FILE ::
"c:\windows\system32\aujsldjf.ini"
"c:\windows\system32\boyteuvn.ini"
"c:\windows\system32\cxanyqsc.ini"
"c:\windows\system32\emxwwmqs.ini"
"c:\windows\system32\fefvyoch.ini"
"c:\windows\system32\hqsgtpkf.ini"
"c:\windows\system32\hqsrrtdl.ini"
"c:\windows\system32\ibvfnwjo.ini"
"c:\windows\system32\igydveni.ini"
"c:\windows\system32\iwncpcvu.ini"
"c:\windows\system32\krceqpvp.ini"
"c:\windows\system32\lpslsmhy.ini"
"c:\windows\system32\okiwjckq.ini"
"c:\windows\system32\ooafnfuf.ini"
"c:\windows\system32\pmgmteel.ini"
"c:\windows\system32\qunsvikm.ini"
"c:\windows\system32\rkrmotif.ini"
"c:\windows\system32\skhctyvy.ini"
"c:\windows\system32\sthrcjoe.ini"
"c:\windows\system32\trgvnehv.ini"
"c:\windows\system32\uecqapeu.ini"
"c:\windows\system32\uscyyvkg.ini"
"c:\windows\system32\vjjobdwn.ini"
"c:\windows\system32\vlxjxidm.ini"
"c:\windows\system32\yfnuextf.ini"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Installer\8fb2900d.msp
c:\windows\system32\aujsldjf.ini
c:\windows\system32\boyteuvn.ini
c:\windows\system32\cxanyqsc.ini
c:\windows\system32\dumphive.exe
c:\windows\system32\emxwwmqs.ini
c:\windows\system32\fefvyoch.ini
c:\windows\system32\hqsgtpkf.ini
c:\windows\system32\hqsrrtdl.ini
c:\windows\system32\ibvfnwjo.ini
c:\windows\system32\igydveni.ini
c:\windows\system32\iwncpcvu.ini
c:\windows\system32\krceqpvp.ini
c:\windows\system32\lpslsmhy.ini
c:\windows\system32\okiwjckq.ini
c:\windows\system32\ooafnfuf.ini
c:\windows\system32\pmgmteel.ini
c:\windows\system32\Process.exe
c:\windows\system32\qunsvikm.ini
c:\windows\system32\rkrmotif.ini
c:\windows\system32\skhctyvy.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\sthrcjoe.ini
c:\windows\system32\tmp.reg
c:\windows\system32\trgvnehv.ini
c:\windows\system32\uecqapeu.ini
c:\windows\system32\uscyyvkg.ini
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vjjobdwn.ini
c:\windows\system32\vlxjxidm.ini
c:\windows\system32\WS2Fix.exe
c:\windows\system32\yfnuextf.ini
.
((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 )))))))))))))))))))))))))))))))
.
2009-10-12 16:30 . 2009-10-12 16:30 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-12 16:25 . 2009-10-12 16:25 34 ------w- c:\windows\system32\BD2070N.DAT
2009-10-10 14:52 . 2009-10-10 14:52 -------- d-----w- c:\program files\ESET
2009-10-09 16:39 . 2009-10-09 16:39 -------- d-----w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\Local Settings\Application Data\LogMeIn
2009-10-09 16:39 . 2009-10-09 16:39 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\LogMeIn
2009-10-09 16:39 . 2009-10-09 16:39 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\ICS
2009-10-09 16:39 . 2009-09-29 00:34 28984 ------w- c:\windows\system32\LMIport.dll
2009-10-09 16:39 . 2009-09-29 00:34 83288 ------w- c:\windows\system32\LMIRfsClientNP.dll
2009-10-09 16:39 . 2008-08-11 17:41 47640 ------w- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-10-09 16:39 . 2009-09-29 00:34 87352 ------w- c:\windows\system32\LMIinit.dll
2009-10-09 16:38 . 2009-10-13 08:06 -------- d-----w- c:\program files\LogMeIn
2009-10-09 16:35 . 2009-10-09 16:37 -------- d-----w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\Local Settings\Application Data\Deployment
2009-10-09 16:22 . 2009-10-09 16:23 -------- d-----w- C:\rsit
2009-10-05 23:23 . 2009-10-05 23:23 -------- d-sh--w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\IECompatCache
2009-10-05 16:35 . 2009-10-05 16:36 -------- d-----w- C:\unzip
2009-10-02 18:05 . 2009-10-02 18:05 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-10-02 18:05 . 2009-10-02 18:08 -------- d-----w- c:\program files\SpywareBlaster
2009-10-02 17:18 . 2009-10-02 17:18 -------- d-----w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\Application Data\Malwarebytes
2009-10-02 17:18 . 2009-09-10 19:54 38224 ------w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-02 17:18 . 2009-10-02 17:18 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-10-02 17:18 . 2009-10-02 17:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-02 17:18 . 2009-09-10 19:53 19160 ------w- c:\windows\system32\drivers\mbam.sys
2009-09-30 21:27 . 2009-09-30 21:27 80264 ----a-w- c:\documents and settings\Backup.AJ-71DGB8DRX842\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-30 21:25 . 2009-09-30 21:25 -------- d-sh--w- c:\documents and settings\Backup.AJ-71DGB8DRX842\IETldCache
2009-09-30 20:30 . 2009-09-30 20:30 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-09-30 20:29 . 2009-09-30 20:29 -------- d-----w- c:\program files\MSECache
2009-09-30 20:06 . 2009-09-30 20:06 -------- d-----w- c:\documents and settings\Craig\Local Settings\Application Data\Intuit
2009-09-30 20:00 . 2009-09-30 20:00 -------- d-----w- c:\documents and settings\Craig\Local Settings\Application Data\Mozilla
2009-09-30 19:47 . 2009-09-30 19:47 -------- d-----w- c:\documents and settings\Craig\Local Settings\Application Data\Adobe
2009-09-30 19:44 . 2008-08-07 08:03 -------- d-----w- c:\documents and settings\Craig\Local Settings\Application Data\Microsoft Help
2009-09-30 19:44 . 2009-10-12 16:30 -------- d-----w- c:\documents and settings\Craig
2009-09-22 17:42 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 22:12 . 2008-12-08 22:02 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2009-10-13 22:10 . 2008-12-08 22:02 647200 ----a-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-13 22:10 . 2008-12-08 22:02 3505184 ----a-w- c:\windows\system32\drivers\fidbox.dat
2009-10-13 22:10 . 2008-12-08 22:02 3292 ----a-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-13 22:10 . 2008-12-08 22:02 28464 ----a-w- c:\windows\system32\drivers\fidbox.idx
2009-10-12 16:30 . 2006-08-28 18:17 -------- d-----w- c:\program files\Brownie
2009-10-12 16:25 . 2005-03-03 01:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-30 19:45 . 2009-09-30 19:44 80264 ----a-w- c:\documents and settings\Craig\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-22 12:30 . 2008-12-08 22:04 95259 ------w- c:\windows\system32\drivers\klick.dat
2009-09-22 12:30 . 2008-12-08 22:04 107547 ------w- c:\windows\system32\drivers\klin.dat
2009-09-09 08:02 . 2007-12-12 19:43 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-08-29 12:27 . 2008-06-03 16:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\FLEXnet
2009-08-21 16:26 . 2007-11-13 21:04 80264 ----a-w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-21 08:08 . 2009-08-21 08:08 -------- d-----w- c:\program files\MSBuild
2009-08-21 08:08 . 2009-08-21 08:08 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2003-03-31 12:00 204800 ------w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2003-03-31 12:00 58880 ------w- c:\windows\system32\atl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-03 136600]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2005-02-08 126976]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-12 623992]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-09-09 623880]
"HPWQTOOLBOX"="c:\program files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe" [2005-06-03 335872]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-21 208616]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-21 185872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-29 88363]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-3-12 984352]
QuickBooks Web Connector.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe [2009-2-9 300328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 00:34 87352 ------w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"cmdService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Intuit\\QuickBooks Enterprise Solutions 9.0\\QBDBMgrN.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 7:29 PM 33808]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [8/11/2008 12:41 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [10/9/2009 11:39 AM 47640]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 8:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 7:06 PM 24592]
S0 Yyp47;Yyp47; [x]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {5B503C1B-72F6-40A8-A4CD-6552003A68C5} = 205.171.3.65,205.171.2.65
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks Enterprise Solutions 9.0\HelpAsyncPluggableProtocol.dll
DPF: {03A89EFD-E023-8500-A22D-45F77558EB4C} - hxxp://ilinc.actsoft.com/iLinc8/download/ilinci85.dll
DPF: {03A89EFD-E023-9000-A22D-45F77558EB4C} - hxxp://ilinc.actsoft.com/iLinc/download/AXCltInstall.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\Jarod.AJ-71DGB8DRX842\Application Data\Mozilla\Firefox\Profiles\9wp9r1ue.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\extensions\npmozax@real.com\plugins\npmozax.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-ShockwaveFlash - c:\windows\System32\Macromed\Flash\FlashUtil9c.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-13 17:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1116)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(3020)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\ramaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-10-13 17:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-13 22:17
Pre-Run: 165,643,579,392 bytes free
Post-Run: 165,595,873,280 bytes free
241 --- E O F --- 2009-10-13 08:01
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.97 [GMT -5:00]
Running from: c:\documents and settings\Jarod.AJ-71DGB8DRX842\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jarod.AJ-71DGB8DRX842\Desktop\CFScript.txt
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FILE ::
"c:\windows\system32\aujsldjf.ini"
"c:\windows\system32\boyteuvn.ini"
"c:\windows\system32\cxanyqsc.ini"
"c:\windows\system32\emxwwmqs.ini"
"c:\windows\system32\fefvyoch.ini"
"c:\windows\system32\hqsgtpkf.ini"
"c:\windows\system32\hqsrrtdl.ini"
"c:\windows\system32\ibvfnwjo.ini"
"c:\windows\system32\igydveni.ini"
"c:\windows\system32\iwncpcvu.ini"
"c:\windows\system32\krceqpvp.ini"
"c:\windows\system32\lpslsmhy.ini"
"c:\windows\system32\okiwjckq.ini"
"c:\windows\system32\ooafnfuf.ini"
"c:\windows\system32\pmgmteel.ini"
"c:\windows\system32\qunsvikm.ini"
"c:\windows\system32\rkrmotif.ini"
"c:\windows\system32\skhctyvy.ini"
"c:\windows\system32\sthrcjoe.ini"
"c:\windows\system32\trgvnehv.ini"
"c:\windows\system32\uecqapeu.ini"
"c:\windows\system32\uscyyvkg.ini"
"c:\windows\system32\vjjobdwn.ini"
"c:\windows\system32\vlxjxidm.ini"
"c:\windows\system32\yfnuextf.ini"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Installer\8fb2900d.msp
c:\windows\system32\aujsldjf.ini
c:\windows\system32\boyteuvn.ini
c:\windows\system32\cxanyqsc.ini
c:\windows\system32\dumphive.exe
c:\windows\system32\emxwwmqs.ini
c:\windows\system32\fefvyoch.ini
c:\windows\system32\hqsgtpkf.ini
c:\windows\system32\hqsrrtdl.ini
c:\windows\system32\ibvfnwjo.ini
c:\windows\system32\igydveni.ini
c:\windows\system32\iwncpcvu.ini
c:\windows\system32\krceqpvp.ini
c:\windows\system32\lpslsmhy.ini
c:\windows\system32\okiwjckq.ini
c:\windows\system32\ooafnfuf.ini
c:\windows\system32\pmgmteel.ini
c:\windows\system32\Process.exe
c:\windows\system32\qunsvikm.ini
c:\windows\system32\rkrmotif.ini
c:\windows\system32\skhctyvy.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\sthrcjoe.ini
c:\windows\system32\tmp.reg
c:\windows\system32\trgvnehv.ini
c:\windows\system32\uecqapeu.ini
c:\windows\system32\uscyyvkg.ini
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vjjobdwn.ini
c:\windows\system32\vlxjxidm.ini
c:\windows\system32\WS2Fix.exe
c:\windows\system32\yfnuextf.ini
.
((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 )))))))))))))))))))))))))))))))
.
2009-10-12 16:30 . 2009-10-12 16:30 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-12 16:25 . 2009-10-12 16:25 34 ------w- c:\windows\system32\BD2070N.DAT
2009-10-10 14:52 . 2009-10-10 14:52 -------- d-----w- c:\program files\ESET
2009-10-09 16:39 . 2009-10-09 16:39 -------- d-----w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\Local Settings\Application Data\LogMeIn
2009-10-09 16:39 . 2009-10-09 16:39 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\LogMeIn
2009-10-09 16:39 . 2009-10-09 16:39 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\ICS
2009-10-09 16:39 . 2009-09-29 00:34 28984 ------w- c:\windows\system32\LMIport.dll
2009-10-09 16:39 . 2009-09-29 00:34 83288 ------w- c:\windows\system32\LMIRfsClientNP.dll
2009-10-09 16:39 . 2008-08-11 17:41 47640 ------w- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-10-09 16:39 . 2009-09-29 00:34 87352 ------w- c:\windows\system32\LMIinit.dll
2009-10-09 16:38 . 2009-10-13 08:06 -------- d-----w- c:\program files\LogMeIn
2009-10-09 16:35 . 2009-10-09 16:37 -------- d-----w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\Local Settings\Application Data\Deployment
2009-10-09 16:22 . 2009-10-09 16:23 -------- d-----w- C:\rsit
2009-10-05 23:23 . 2009-10-05 23:23 -------- d-sh--w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\IECompatCache
2009-10-05 16:35 . 2009-10-05 16:36 -------- d-----w- C:\unzip
2009-10-02 18:05 . 2009-10-02 18:05 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-10-02 18:05 . 2009-10-02 18:08 -------- d-----w- c:\program files\SpywareBlaster
2009-10-02 17:18 . 2009-10-02 17:18 -------- d-----w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\Application Data\Malwarebytes
2009-10-02 17:18 . 2009-09-10 19:54 38224 ------w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-02 17:18 . 2009-10-02 17:18 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-10-02 17:18 . 2009-10-02 17:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-02 17:18 . 2009-09-10 19:53 19160 ------w- c:\windows\system32\drivers\mbam.sys
2009-09-30 21:27 . 2009-09-30 21:27 80264 ----a-w- c:\documents and settings\Backup.AJ-71DGB8DRX842\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-30 21:25 . 2009-09-30 21:25 -------- d-sh--w- c:\documents and settings\Backup.AJ-71DGB8DRX842\IETldCache
2009-09-30 20:30 . 2009-09-30 20:30 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-09-30 20:29 . 2009-09-30 20:29 -------- d-----w- c:\program files\MSECache
2009-09-30 20:06 . 2009-09-30 20:06 -------- d-----w- c:\documents and settings\Craig\Local Settings\Application Data\Intuit
2009-09-30 20:00 . 2009-09-30 20:00 -------- d-----w- c:\documents and settings\Craig\Local Settings\Application Data\Mozilla
2009-09-30 19:47 . 2009-09-30 19:47 -------- d-----w- c:\documents and settings\Craig\Local Settings\Application Data\Adobe
2009-09-30 19:44 . 2008-08-07 08:03 -------- d-----w- c:\documents and settings\Craig\Local Settings\Application Data\Microsoft Help
2009-09-30 19:44 . 2009-10-12 16:30 -------- d-----w- c:\documents and settings\Craig
2009-09-22 17:42 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 22:12 . 2008-12-08 22:02 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2009-10-13 22:10 . 2008-12-08 22:02 647200 ----a-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-13 22:10 . 2008-12-08 22:02 3505184 ----a-w- c:\windows\system32\drivers\fidbox.dat
2009-10-13 22:10 . 2008-12-08 22:02 3292 ----a-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-13 22:10 . 2008-12-08 22:02 28464 ----a-w- c:\windows\system32\drivers\fidbox.idx
2009-10-12 16:30 . 2006-08-28 18:17 -------- d-----w- c:\program files\Brownie
2009-10-12 16:25 . 2005-03-03 01:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-30 19:45 . 2009-09-30 19:44 80264 ----a-w- c:\documents and settings\Craig\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-22 12:30 . 2008-12-08 22:04 95259 ------w- c:\windows\system32\drivers\klick.dat
2009-09-22 12:30 . 2008-12-08 22:04 107547 ------w- c:\windows\system32\drivers\klin.dat
2009-09-09 08:02 . 2007-12-12 19:43 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-08-29 12:27 . 2008-06-03 16:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\FLEXnet
2009-08-21 16:26 . 2007-11-13 21:04 80264 ----a-w- c:\documents and settings\Jarod.AJ-71DGB8DRX842\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-21 08:08 . 2009-08-21 08:08 -------- d-----w- c:\program files\MSBuild
2009-08-21 08:08 . 2009-08-21 08:08 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2003-03-31 12:00 204800 ------w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2003-03-31 12:00 58880 ------w- c:\windows\system32\atl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-03 136600]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2005-02-08 126976]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-12 623992]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-09-09 623880]
"HPWQTOOLBOX"="c:\program files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe" [2005-06-03 335872]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-21 208616]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-21 185872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-29 88363]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-3-12 984352]
QuickBooks Web Connector.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe [2009-2-9 300328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 00:34 87352 ------w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"cmdService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Intuit\\QuickBooks Enterprise Solutions 9.0\\QBDBMgrN.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 7:29 PM 33808]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [8/11/2008 12:41 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [10/9/2009 11:39 AM 47640]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 8:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 7:06 PM 24592]
S0 Yyp47;Yyp47; [x]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {5B503C1B-72F6-40A8-A4CD-6552003A68C5} = 205.171.3.65,205.171.2.65
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks Enterprise Solutions 9.0\HelpAsyncPluggableProtocol.dll
DPF: {03A89EFD-E023-8500-A22D-45F77558EB4C} - hxxp://ilinc.actsoft.com/iLinc8/download/ilinci85.dll
DPF: {03A89EFD-E023-9000-A22D-45F77558EB4C} - hxxp://ilinc.actsoft.com/iLinc/download/AXCltInstall.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\Jarod.AJ-71DGB8DRX842\Application Data\Mozilla\Firefox\Profiles\9wp9r1ue.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\extensions\npmozax@real.com\plugins\npmozax.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-ShockwaveFlash - c:\windows\System32\Macromed\Flash\FlashUtil9c.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-13 17:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1116)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(3020)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\ramaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-10-13 17:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-13 22:17
Pre-Run: 165,643,579,392 bytes free
Post-Run: 165,595,873,280 bytes free
241 --- E O F --- 2009-10-13 08:01