ComboFix 07-12-21.4 - Mine 2007-12-21 1:13:06.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.572 [GMT -6:00]
Running from: C:\Documents and Settings\Mine\Desktop\sims2\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mine\My Documents\CFScript.txt
* Created a new restore point
FILE
C:\DOCUME~1\\LOCALS~1\Temp\rjexejkn.dll
C:\QINDOWS\SYSTEM32\ssqpp.dll
C:\WINDOWS\SYSTEM32\awtqn.dll
C:\WINDOWS\SYSTEM32\ssqpm.dll
C:\WINDOWS\SYSTEM32\vtsqo.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\SYSTEM32\awtqn.dll
C:\WINDOWS\SYSTEM32\ssqpm.dll
C:\WINDOWS\SYSTEM32\vtsqo.dll
.
((((((((((((((((((((((((( Files Created from 2007-11-21 to 2007-12-21 )))))))))))))))))))))))))))))))
.
2007-12-20 23:02 . 2007-12-20 23:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-20 23:00 . 2007-12-20 23:01 <DIR> d-------- C:\Program Files\Yahoo!
2007-12-20 22:05 . 2007-12-20 22:05 <DIR> d-------- C:\Documents and Settings\*****\Application Data\Comodo
2007-12-20 22:05 . 2007-12-20 22:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2007-12-20 22:04 . 2007-12-09 14:36 211 --a------ C:\boot.ini.comodofirewall
2007-12-20 22:03 . 2007-12-20 22:03 <DIR> d-------- C:\Program Files\Comodo
2007-12-20 19:23 . 2007-12-21 01:16 40,625 --ahs---- C:\WINDOWS\SYSTEM32\ppqss.ini2
2007-12-20 19:20 . 2007-12-21 01:16 40,727 --ahs---- C:\WINDOWS\SYSTEM32\ppqss.ini
2007-12-20 16:37 . 2007-12-20 16:37 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-20 15:51 . 2007-12-20 15:51 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-12-20 15:51 . 2007-12-20 15:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-20 14:48 . 2007-12-20 15:49 151 --a------ C:\WINDOWS\wininit.ini
2007-12-20 14:16 . 2007-12-20 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-15 11:49 . 2007-12-15 11:49 <DIR> d-------- C:\Program Files\Common Files\EasyInfo
2007-12-14 09:45 . 2007-12-14 09:45 1,158 --a------ C:\WINDOWS\mozver.dat
2007-12-14 09:41 . 2007-12-14 09:41 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-14 07:32 . 2007-12-14 07:32 314,624 --a------ C:\WINDOWS\SYSTEM32\ssqpp.dll
2007-12-11 17:14 . 2007-12-11 17:14 <DIR> d-------- C:\Program Files\Google
2007-12-11 09:12 . 2007-12-11 09:12 2,422 --a------ C:\WINDOWS\SYSTEM32\wpa.bak
2007-12-11 08:29 . 2007-12-11 08:29 <DIR> d-------- C:\Documents and Settings\*****\Application Data\Grisoft
2007-12-11 08:29 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-12-11 08:05 . 2007-12-11 08:05 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-11 08:05 . 2007-12-20 23:20 <DIR> d-------- C:\Documents and Settings\*****\Application Data\AVG7
2007-12-11 08:05 . 2007-12-11 08:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-11 08:05 . 2007-12-11 08:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-12-11 08:05 . 2007-12-11 08:05 499,712 --a------ C:\WINDOWS\SYSTEM32\msvcp71.dll
2007-12-11 08:05 . 2007-12-11 08:05 348,160 --a------ C:\WINDOWS\SYSTEM32\msvcr71.dll
2007-12-10 05:24 . 2007-12-10 05:24 <DIR> d---s---- C:\Documents and Settings\******\UserData
2007-12-09 16:31 . 2007-12-09 16:31 <DIR> d-------- C:\Program Files\Marvell
2007-12-09 16:29 . 2007-12-09 16:29 <DIR> d-------- C:\WINDOWS\VirtualEar
2007-12-09 16:29 . 2007-12-09 16:29 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-12-09 16:29 . 2007-12-09 16:31 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-12-09 16:29 . 2007-12-09 16:29 <DIR> d-------- C:\Program Files\Analog Devices
2007-12-09 15:05 . 2007-12-09 16:23 <DIR> d-------- C:\Program Files\EA GAMES
2007-12-09 15:05 . 2004-08-17 20:14 442,368 -ra------ C:\WINDOWS\SYSTEM32\vp6vfw.dll
2007-12-09 14:49 . 2005-09-20 10:31 135,168 --a------ C:\WINDOWS\SYSTEM32\igfxres.dll
2007-12-09 14:47 . 2007-12-09 14:47 <DIR> d-------- C:\Program Files\Intel
2007-12-09 14:47 . 2007-12-09 16:29 11,001 --a------ C:\WINDOWS\Ascd_tmp.ini
2007-12-09 14:47 . 2005-04-30 06:30 5,824 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ASUSHWIO.SYS
2007-12-09 14:44 . 2007-12-09 14:44 <DIR> d---s---- C:\WINDOWS\SYSTEM32\Microsoft
2007-12-09 14:44 . 2007-12-09 14:44 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2007-12-09 14:42 . 2004-08-04 06:00 13,463,552 --a--c--- C:\WINDOWS\SYSTEM32\dllcache\hwxjpn.dll
2007-12-09 14:41 . 2007-12-09 14:41 <DIR> d-------- C:\WINDOWS\SYSTEM32\xircom
2007-12-09 14:41 . 2007-12-09 14:41 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-12-09 14:40 . 2007-12-20 15:51 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2007-12-09 14:40 . 2007-12-09 14:41 <DIR> d--hs---- C:\Documents and Settings\All Users\DRM
2007-12-09 14:40 . 2004-08-04 06:00 4,399,505 --a--c--- C:\WINDOWS\SYSTEM32\dllcache\nls302en.lex
2007-12-09 14:40 . 2007-12-09 14:40 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2007-12-09 14:40 . 2007-12-09 14:40 749 -rah----- C:\WINDOWS\SYSTEM32\wuaucpl.cpl.manifest
2007-12-09 14:40 . 2007-12-09 14:40 749 -rah----- C:\WINDOWS\SYSTEM32\sapi.cpl.manifest
2007-12-09 14:40 . 2007-12-09 14:40 749 -rah----- C:\WINDOWS\SYSTEM32\nwc.cpl.manifest
2007-12-09 14:40 . 2007-12-09 14:40 749 -rah----- C:\WINDOWS\SYSTEM32\ncpa.cpl.manifest
2007-12-09 14:40 . 2007-12-09 14:40 749 -rah----- C:\WINDOWS\SYSTEM32\cdplayer.exe.manifest
2007-12-09 14:40 . 2007-12-09 14:40 488 -rah----- C:\WINDOWS\SYSTEM32\WindowsLogon.manifest
2007-12-09 14:40 . 2007-12-09 14:40 488 -rah----- C:\WINDOWS\SYSTEM32\logonui.exe.manifest
2007-12-09 14:37 . 2007-12-09 14:38 <DIR> d-------- C:\WINDOWS\SYSTEM32\MsDtc
2007-12-09 08:34 . 2001-08-17 07:59 3,072 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\audstub.sys
2007-12-09 08:33 . 2004-08-03 16:59 57,472 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\redbook.sys
2007-12-09 08:32 . 2004-08-03 18:56 74,240 --a------ C:\WINDOWS\SYSTEM32\usbui.dll
2007-12-09 08:32 . 2004-08-03 16:59 5,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\intelide.sys
2007-12-09 08:31 . 2007-12-09 15:40 <DIR> dr------- C:\Documents and Settings\All Users\Documents
2007-12-09 08:30 . 2007-12-20 16:39 <DIR> d-------- C:\WINDOWS\SYSTEM32\CatRoot2
2007-12-09 08:30 . 2007-12-09 08:30 <DIR> d-------- C:\WINDOWS\SYSTEM32\CatRoot
2007-12-09 08:30 . 2004-08-04 06:00 1,086,058 -ra------ C:\WINDOWS\SET4.tmp
2007-12-09 08:30 . 2004-08-04 06:00 1,042,903 -ra------ C:\WINDOWS\SET3.tmp
2007-12-09 08:30 . 2004-08-04 06:00 13,753 -ra------ C:\WINDOWS\SET8.tmp
2007-12-09 08:27 . 2007-12-09 14:45 <DIR> d-------- C:\Documents and Settings
2007-12-09 08:24 . 2007-12-09 08:24 512 ---hs---- C:\bootsect.dos
2007-12-09 08:24 . 2007-12-09 14:43 261 --a------ C:\WINDOWS\SYSTEM32\$winnt$.inf
2007-12-09 08:24 . 2007-12-20 22:04 211 ---hs---- C:\boot.ini
2007-12-06 16:02 . 2007-12-06 16:02 19,247 ---hs---- C:\BOOTLOG.PRV
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-27 13:51 5,166 --sh--w C:\SUHDLOG.DAT
.
((((((((((((((((((((((((((((( snapshot@2007-12-20_19.20.47.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-21 04:03:50 75,520 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\cmdmon.sys
+ 2007-12-21 04:03:50 51,328 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\inspect.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60E51DE0-640F-4107-9F1C-A9CC4B7ADB90}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F3755E4-0818-48C5-9EF5-148D27D8D784}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92C52EE7-03D5-4197-819A-DED03FAE6014}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D1DEEB81-204C-4AFB-B361-F81114220DBF}]
2007-12-14 07:32 314624 --a------ C:\WINDOWS\system32\ssqpp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-20 10:18]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 12:41]
"AVG7_CC"="C:\PROGRA~2\Grisoft\AVG7\avgcc.exe" [2007-12-11 08:05]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-12-20 22:03]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~2\Grisoft\AVG7\avgw.exe" [2007-12-11 08:05]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\ssqpp.dll
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-21 01:17:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\ssqpp.dll
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS\system32\ssqpp.dll
.
Completion time: 2007-12-21 1:18:01 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-20 19:21