Combofix
combofix log
ComboFix 08-06-15.4 - Marcy 2008-06-15 23:11:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.287 [GMT -4:00]
Running from: C:\Documents and Settings\Marcy\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\CKQqAcdd.ini
C:\WINDOWS\system32\CKQqAcdd.ini2
C:\WINDOWS\system32\ddcAqQKC.dll
C:\WINDOWS\system32\DgfOoUtv.ini2
C:\WINDOWS\system32\JTsuxyay.ini
C:\WINDOWS\system32\JTsuxyay.ini2
C:\WINDOWS\system32\knVGOnnn.ini
C:\WINDOWS\system32\knVGOnnn.ini2
C:\WINDOWS\system32\lkwvkxap.ini
C:\WINDOWS\system32\lllkknmp.ini
C:\WINDOWS\system32\lllkknmp.ini2
C:\WINDOWS\system32\pmnOFXon.dll
C:\WINDOWS\system32\vulpjirf.ini
.
((((((((((((((((((((((((( Files Created from 2008-05-16 to 2008-06-16 )))))))))))))))))))))))))))))))
.
2008-06-15 21:24 . 2008-06-15 21:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-15 21:24 . 2008-06-15 21:24 <DIR> d-------- C:\Documents and Settings\Marcy\Application Data\Malwarebytes
2008-06-15 21:24 . 2008-06-15 21:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-15 21:24 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-15 21:24 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-15 19:15 . 2008-06-15 20:22 <DIR> d-------- C:\Documents and Settings\Marcy\.housecall6.6
2008-06-08 20:04 . 2008-06-08 20:04 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-08 20:04 . 2008-06-08 20:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-08 15:02 . 2008-06-08 15:02 691,545 --a------ C:\WINDOWS\unins000.exe
2008-06-08 15:02 . 2008-06-08 15:02 2,543 --a------ C:\WINDOWS\unins000.dat
2008-05-26 20:20 . 2008-06-15 23:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-26 20:20 . 2008-05-26 20:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-26 20:19 . 2008-05-26 20:19 <DIR> d-------- C:\Program Files\iPod
2008-05-26 20:18 . 2008-05-26 20:19 <DIR> d-------- C:\Program Files\iTunes
2008-05-25 20:40 . 2008-05-25 20:40 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-05-25 20:40 . 2008-05-25 20:40 <DIR> d-------- C:\WINDOWS\system32\en
2008-05-25 20:40 . 2008-05-25 20:40 <DIR> d-------- C:\WINDOWS\system32\bits
2008-05-25 20:40 . 2008-05-25 20:40 <DIR> d-------- C:\WINDOWS\l2schemas
2008-05-25 20:24 . 2008-05-25 20:43 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-05-25 18:22 . 2008-04-13 20:12 712,704 --a------ C:\WINDOWS\system32\windowscodecs.dll
2008-05-25 18:22 . 2008-04-13 20:12 346,112 --a------ C:\WINDOWS\system32\windowscodecsext.dll
2008-05-25 18:22 . 2008-04-13 20:12 276,992 --a------ C:\WINDOWS\system32\wmphoto.dll
2008-05-25 18:22 . 2008-04-13 20:12 69,120 --a------ C:\WINDOWS\system32\wlanapi.dll
2008-05-25 18:20 . 2004-08-03 22:41 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2008-05-25 18:19 . 2008-04-13 20:12 412,160 --a------ C:\WINDOWS\system32\photometadatahandler.dll
2008-05-25 18:18 . 2008-04-13 20:12 1,737,856 --a------ C:\WINDOWS\system32\mtxparhd.dll
2008-05-25 18:17 . 2008-04-13 20:12 155,136 --a------ C:\WINDOWS\system32\mssha.dll
2008-05-25 18:17 . 2008-04-13 14:14 76,800 --a------ C:\WINDOWS\system32\msshavmsg.dll
2008-05-25 18:16 . 2008-04-13 20:11 397,312 --a------ C:\WINDOWS\system32\mmcex.dll
2008-05-25 18:16 . 2008-04-13 20:11 184,320 --a------ C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-05-25 18:16 . 2008-04-13 20:11 106,496 --a------ C:\WINDOWS\system32\mmcfxcommon.dll
2008-05-25 18:16 . 2008-04-13 20:12 33,792 --a------ C:\WINDOWS\system32\mmcperf.exe
2008-05-25 18:15 . 2008-04-13 20:11 61,440 --a------ C:\WINDOWS\system32\kmsvc.dll
2008-05-25 18:15 . 2008-04-13 20:11 37,376 --a------ C:\WINDOWS\system32\l2gpstore.dll
2008-05-25 18:15 . 2008-04-13 20:09 6,144 --a------ C:\WINDOWS\system32\kbdpash.dll
2008-05-25 18:14 . 2008-04-13 20:09 6,144 --a------ C:\WINDOWS\system32\kbdnepr.dll
2008-05-25 18:14 . 2008-04-13 20:09 6,144 --a------ C:\WINDOWS\system32\kbdiultn.dll
2008-05-25 18:14 . 2008-04-13 20:09 6,144 --a------ C:\WINDOWS\system32\kbdbhc.dll
2008-05-25 18:13 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-05-25 18:13 . 2004-08-03 22:41 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2008-05-25 18:13 . 2004-08-03 22:41 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2008-05-25 18:13 . 2008-04-13 20:11 32,285 --a------ C:\WINDOWS\system32\hsfcisp2.dll
2008-05-25 18:13 . 2008-04-13 20:12 10,752 --a------ C:\WINDOWS\system32\smtpapi.dll
2008-05-25 18:13 . 2008-04-13 20:12 9,728 --a------ C:\WINDOWS\system32\rwnh.dll
2008-05-25 18:13 . 2008-04-13 14:43 9,728 --a------ C:\WINDOWS\system32\comsdupd.exe
2008-05-25 18:13 . 2007-06-21 01:52 974 --a------ C:\WINDOWS\system32\pid.inf
2008-05-25 18:11 . 2008-04-13 20:11 650,752 --a------ C:\WINDOWS\system32\dot3ui.dll
2008-05-25 18:10 . 2008-04-13 20:11 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-05-25 18:09 . 2008-04-13 20:11 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-05-25 18:09 . 2008-04-13 20:11 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-05-25 18:09 . 2008-04-13 20:11 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-05-25 18:09 . 2008-04-13 20:11 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-05-25 18:09 . 2008-04-13 20:11 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-05-25 18:09 . 2008-04-13 20:11 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-05-25 18:09 . 2008-04-13 20:11 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-05-25 18:09 . 2008-04-13 20:11 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-16 01:21 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-16 01:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-15 23:09 --------- d-----w C:\Program Files\Coupons
2008-06-11 05:51 --------- d-----w C:\Program Files\Trend Micro
2008-06-08 20:20 --------- d-----w C:\Program Files\RGB
2008-06-05 05:47 --------- d-----w C:\Documents and Settings\Alyssa\Application Data\U3
2008-05-27 00:22 --------- d-----w C:\Program Files\Apple Software Update
2008-05-27 00:14 --------- d-----w C:\Program Files\QuickTime
2008-05-10 14:16 --------- d-----w C:\Documents and Settings\Alyssa\Application Data\Move Networks
2008-05-06 00:42 --------- d-----w C:\Documents and Settings\Alyssa\Application Data\WildTangent
2008-05-06 00:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\WildTangent
2008-05-02 20:22 205,328 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-05-02 20:21 36,368 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-05-02 20:17 1,169,240 ----a-w C:\WINDOWS\system32\drivers\vsapint.sys
2008-05-02 18:45 --------- d-----w C:\Program Files\Yahoo!
2008-04-14 00:12 69,120 ----a-w C:\WINDOWS\notepad.exe
2008-04-14 00:12 50,688 ----a-w C:\WINDOWS\twain_32.dll
2008-04-14 00:12 32,866 ------w C:\WINDOWS\slrundll.exe
2008-04-14 00:12 283,648 ----a-w C:\WINDOWS\winhlp32.exe
2008-04-14 00:12 146,432 ----a-w C:\WINDOWS\regedit.exe
2008-04-14 00:12 10,752 ----a-w C:\WINDOWS\hh.exe
2008-04-14 00:12 1,033,728 ----a-w C:\WINDOWS\explorer.exe
2007-10-16 16:53 206 ----a-w C:\Documents and Settings\All Users\Application Data\PMUSERS.DAT
2007-09-16 16:51 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-05-14 21:43 194,376 -c--a-w C:\Documents and Settings\Alyssa\Application Data\shb.dat
2007-04-11 18:25 88 --sh--r C:\WINDOWS\system32\699679CC65.sys
2007-04-11 18:25 2,516 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C081D1D-84F9-404D-964E-D60020FB1653}]
C:\WINDOWS\system32\yayxusTJ.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7B89A12A-612A-41DB-917C-1097EDBEE63F}]
C:\WINDOWS\system32\pmnkklll.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{941218AD-C2A0-475F-AE10-A41D7CBDB982}]
C:\WINDOWS\system32\nnnOGVnk.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 18:15 321040]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 23:57 395776]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01 67584]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 14:12 7630848]
"nwiz"="nwiz.exe" [2006-08-23 14:12 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 14:12 86016]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 05:12 94208]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 05:00 282624 C:\WINDOWS\stsystra.exe]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 14:02 1807960]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 18:50 81920]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 17:49 49152]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [ ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Creating Keepsakes Scrapbook Designer Event Reminder.lnk - C:\Program Files\Scrapbook Designer\scrapremind.exe [2005-01-11 12:40:48 339968]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-01-24 16:03:56 24576]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 21:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 21:50:52 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
S3 GameConsoleService;GameConsoleService;"C:\Program Files\WildTangent\Apps\Dell Game Console\GameConsoleService.exe" [2008-01-08 02:25]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-10 18:43:35 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-08 22:00:01 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2008-06-16 03:29:23 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-15 23:28:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2008-06-15 23:32:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-16 03:32:14
Pre-Run: 116,160,802,816 bytes free
Post-Run: 117,409,107,968 bytes free
215 --- E O F --- 2008-06-08 20:15:20