My first thread was closed because I'm a newbie/dope who didn't understand how to properly check this forum for a reply. I wasted someone's time and I'm sorry! I posted the hjt log and I think Peku (?) was helping me and requested that I run COMBOFIX.
Again, I'm sorry that I didn't realize that my first post was responded to (I can't even find the original post now) but I really do need help and will not make the same mistake twice!!
Here is the combofix log, please let me know if you need me to post another hjtlog:
ComboFix 09-01-21.04 - Michael McPartland 2009-01-24 12:34:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.723 [GMT -5:00]
Running from: c:\documents and settings\Michael McPartland\Desktop\ComboFix.exe
AV: *On-access scanning disabled* (Outdated)
FW: *disabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\cbXPjKAR.dll
c:\windows\system32\clhzyt.dll
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekaoqlrvmlq.sys
c:\windows\system32\eitcey.dll
c:\windows\system32\ffehPXbc.ini
c:\windows\system32\ffehPXbc.ini2
c:\windows\system32\grcghkng.dll
c:\windows\system32\hevjdy.dll
c:\windows\system32\iesbtsth.dll
c:\windows\system32\ijvesdmg.dll
c:\windows\system32\kbyjsnqc.dll
c:\windows\system32\ljJBusQh.dll
c:\windows\system32\ljyqdemh.dll
c:\windows\system32\lootxnat.dll
c:\windows\system32\prunnet.exe
c:\windows\system32\qstkad.dll
c:\windows\system32\rewmkadt.dll
c:\windows\system32\rwuxvu.dll
c:\windows\system32\seneka.dat
c:\windows\system32\senekadf.dat
c:\windows\system32\senekajdsboykv.dll
c:\windows\system32\senekalog.dat
c:\windows\system32\tfvvzq.dll
c:\windows\system32\trdpbnof.dll
c:\windows\system32\txtmbkhi.dll
c:\windows\system32\vtUkiHwW.dll
c:\windows\system32\wfhmrc.dll
c:\windows\system32\wvUnMCUl.dll
c:\windows\system32\xbpffkhk.dll
c:\windows\system32\xsuemdng.dll
c:\windows\system32\yvqgff.dll
c:\windows\system32\yxowom.dll
c:\windows\Tasks\lmtklube.job
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
((((((((((((((((((((((((( Files Created from 2008-12-24 to 2009-01-24 )))))))))))))))))))))))))))))))
.
2009-01-23 20:48 . 2009-01-23 20:48 1,435,294 ---hs---- c:\windows\system32\gmdsevji.ini
2009-01-22 20:46 . 2009-01-22 20:46 1,435,294 ---hs---- c:\windows\system32\fxjnxgsh.ini
2009-01-21 20:46 . 2009-01-21 20:46 1,435,294 ---hs---- c:\windows\system32\mugqawsp.ini
2009-01-20 20:44 . 2009-01-20 20:44 1,432,799 ---hs---- c:\windows\system32\uhulpugs.ini
2009-01-20 20:32 . 2009-01-20 20:32 1,432,799 ---hs---- c:\windows\system32\htpcgwss.ini
2009-01-18 20:29 . 2009-01-20 20:31 1,432,799 ---hs---- c:\windows\system32\unynljyo.ini
2009-01-17 18:20 . 2009-01-17 18:20 1,403,021 ---hs---- c:\windows\system32\ksnumpmg.ini
2009-01-17 11:44 . 2009-01-17 11:44 <DIR> d-------- c:\documents and settings\Michael McPartland\Application Data\ZoomBrowser EX
2009-01-17 11:40 . 2009-01-17 11:40 2 --a------ c:\windows\msoffice.ini
2009-01-17 11:39 . 2009-01-17 11:39 347 --a------ c:\windows\CTWave32.INI
2009-01-17 11:39 . 2009-01-17 11:39 29 --a------ c:\windows\sfbm.INI
2009-01-17 11:33 . 2009-01-17 11:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-01-17 11:32 . 2009-01-17 11:33 <DIR> d-------- c:\program files\Canon
2009-01-17 11:31 . 2009-01-17 11:31 <DIR> d-------- c:\program files\Common Files\Canon
2009-01-16 17:16 . 2009-01-17 18:19 1,403,021 ---hs---- c:\windows\system32\aypsboan.ini
2009-01-15 18:02 . 2009-01-15 18:02 <DIR> d-------- c:\program files\Trend Micro
2009-01-15 14:24 . 2009-01-15 14:24 1,375,225 --ahs---- c:\windows\system32\cqnsjybk.ini
2009-01-15 14:19 . 2009-01-15 14:19 40,960 --a------ c:\windows\system32\kmcuklec.dll
2009-01-15 14:18 . 2009-01-24 12:37 2,204 --a------ c:\windows\zifjxuoo
2009-01-02 16:34 . 2009-01-02 16:34 <DIR> d-------- c:\windows\system32\IOSUBSYS
2009-01-02 15:47 . 2008-12-23 11:35 <DIR> d-------- C:\Converted Audio Files
2009-01-02 15:45 . 2009-01-02 15:46 <DIR> d-------- c:\program files\Acoustica MP3 To Wave Converter PLUS
2009-01-02 15:32 . 2009-01-02 15:32 <DIR> d-------- c:\program files\WAV to MP3 Encoder
2009-01-02 15:32 . 2001-12-12 11:35 348,160 --a------ c:\windows\system32\MEnc.ocx
2009-01-02 15:32 . 2002-08-22 23:27 348,160 --a------ c:\windows\system32\FlatBtn6.ocx
2009-01-02 15:32 . 1998-06-24 01:00 140,096 --a------ c:\windows\system32\Comdlg32.ocx
2008-12-29 13:33 . 2008-12-29 13:33 <DIR> d-------- c:\documents and settings\Michael McPartland\Application Data\SlySoft
2008-12-29 12:47 . 2008-12-29 12:47 <DIR> d-------- c:\program files\SlySoft
2008-12-24 23:30 . 2008-12-24 23:31 <DIR> d-------- c:\program files\iTunes
2008-12-24 23:30 . 2008-12-24 23:30 <DIR> d-------- c:\program files\iPod
2008-12-24 23:30 . 2008-12-24 23:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-24 23:28 . 2008-12-24 23:29 <DIR> d-------- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-24 05:29 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-17 16:43 --------- d-----w c:\program files\Dell
2009-01-17 16:41 --------- d-----w c:\program files\Common Files\AOL
2009-01-17 16:41 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-01-17 16:39 --------- d-----w c:\program files\Creative
2009-01-10 02:04 --------- d-----w c:\documents and settings\Michael McPartland\Application Data\AdobeUM
2009-01-02 21:34 --------- d-----w c:\program files\Google
2008-12-25 04:28 --------- d-----w c:\program files\Common Files\Apple
2008-07-31 20:05 88 --sh--r c:\windows\system32\2179C14E34.sys
2008-07-31 20:05 3,350 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-23 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 1159168]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-06-15 169472]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-06-15 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
S0 zifjxuoo;zifjxuoo;c:\windows\system32\drivers\sczphrtq.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{379cb646-d82f-11dd-84da-00038a000015}]
\Shell\AutoRun\command - f:\system\viewer\FlipVideoforPC.exe
\Shell\Flip Video for PC\command - f:\system\viewer\FlipVideoforPC.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{0344C053-68F1-4D54-9D7E-CD65B0B9B411} - c:\windows\system32\cbXPheff.dll
BHO-{3dc85106-99a2-4057-8ea8-6d57ddbf4652} - c:\windows\system32\wfhmrc.dll
HKCU-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
HKCU-Run-SetDefaultMIDI - MIDIDef.exe
HKLM-Run-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
HKLM-Run-f47c4660 - c:\windows\system32\ijvesdmg.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.nytimes.com/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Michael McPartland\Application Data\Mozilla\Firefox\Profiles\j7w9mdtu.default\
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-24 12:38:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\drivers\sczphrtq.sys 25088 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-01-24 12:39:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-24 17:39:38
Pre-Run: 29,832,245,248 bytes free
Post-Run: 29,816,799,232 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
224
Again, I'm sorry that I didn't realize that my first post was responded to (I can't even find the original post now) but I really do need help and will not make the same mistake twice!!
Here is the combofix log, please let me know if you need me to post another hjtlog:
ComboFix 09-01-21.04 - Michael McPartland 2009-01-24 12:34:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.723 [GMT -5:00]
Running from: c:\documents and settings\Michael McPartland\Desktop\ComboFix.exe
AV: *On-access scanning disabled* (Outdated)
FW: *disabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\cbXPjKAR.dll
c:\windows\system32\clhzyt.dll
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekaoqlrvmlq.sys
c:\windows\system32\eitcey.dll
c:\windows\system32\ffehPXbc.ini
c:\windows\system32\ffehPXbc.ini2
c:\windows\system32\grcghkng.dll
c:\windows\system32\hevjdy.dll
c:\windows\system32\iesbtsth.dll
c:\windows\system32\ijvesdmg.dll
c:\windows\system32\kbyjsnqc.dll
c:\windows\system32\ljJBusQh.dll
c:\windows\system32\ljyqdemh.dll
c:\windows\system32\lootxnat.dll
c:\windows\system32\prunnet.exe
c:\windows\system32\qstkad.dll
c:\windows\system32\rewmkadt.dll
c:\windows\system32\rwuxvu.dll
c:\windows\system32\seneka.dat
c:\windows\system32\senekadf.dat
c:\windows\system32\senekajdsboykv.dll
c:\windows\system32\senekalog.dat
c:\windows\system32\tfvvzq.dll
c:\windows\system32\trdpbnof.dll
c:\windows\system32\txtmbkhi.dll
c:\windows\system32\vtUkiHwW.dll
c:\windows\system32\wfhmrc.dll
c:\windows\system32\wvUnMCUl.dll
c:\windows\system32\xbpffkhk.dll
c:\windows\system32\xsuemdng.dll
c:\windows\system32\yvqgff.dll
c:\windows\system32\yxowom.dll
c:\windows\Tasks\lmtklube.job
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
((((((((((((((((((((((((( Files Created from 2008-12-24 to 2009-01-24 )))))))))))))))))))))))))))))))
.
2009-01-23 20:48 . 2009-01-23 20:48 1,435,294 ---hs---- c:\windows\system32\gmdsevji.ini
2009-01-22 20:46 . 2009-01-22 20:46 1,435,294 ---hs---- c:\windows\system32\fxjnxgsh.ini
2009-01-21 20:46 . 2009-01-21 20:46 1,435,294 ---hs---- c:\windows\system32\mugqawsp.ini
2009-01-20 20:44 . 2009-01-20 20:44 1,432,799 ---hs---- c:\windows\system32\uhulpugs.ini
2009-01-20 20:32 . 2009-01-20 20:32 1,432,799 ---hs---- c:\windows\system32\htpcgwss.ini
2009-01-18 20:29 . 2009-01-20 20:31 1,432,799 ---hs---- c:\windows\system32\unynljyo.ini
2009-01-17 18:20 . 2009-01-17 18:20 1,403,021 ---hs---- c:\windows\system32\ksnumpmg.ini
2009-01-17 11:44 . 2009-01-17 11:44 <DIR> d-------- c:\documents and settings\Michael McPartland\Application Data\ZoomBrowser EX
2009-01-17 11:40 . 2009-01-17 11:40 2 --a------ c:\windows\msoffice.ini
2009-01-17 11:39 . 2009-01-17 11:39 347 --a------ c:\windows\CTWave32.INI
2009-01-17 11:39 . 2009-01-17 11:39 29 --a------ c:\windows\sfbm.INI
2009-01-17 11:33 . 2009-01-17 11:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-01-17 11:32 . 2009-01-17 11:33 <DIR> d-------- c:\program files\Canon
2009-01-17 11:31 . 2009-01-17 11:31 <DIR> d-------- c:\program files\Common Files\Canon
2009-01-16 17:16 . 2009-01-17 18:19 1,403,021 ---hs---- c:\windows\system32\aypsboan.ini
2009-01-15 18:02 . 2009-01-15 18:02 <DIR> d-------- c:\program files\Trend Micro
2009-01-15 14:24 . 2009-01-15 14:24 1,375,225 --ahs---- c:\windows\system32\cqnsjybk.ini
2009-01-15 14:19 . 2009-01-15 14:19 40,960 --a------ c:\windows\system32\kmcuklec.dll
2009-01-15 14:18 . 2009-01-24 12:37 2,204 --a------ c:\windows\zifjxuoo
2009-01-02 16:34 . 2009-01-02 16:34 <DIR> d-------- c:\windows\system32\IOSUBSYS
2009-01-02 15:47 . 2008-12-23 11:35 <DIR> d-------- C:\Converted Audio Files
2009-01-02 15:45 . 2009-01-02 15:46 <DIR> d-------- c:\program files\Acoustica MP3 To Wave Converter PLUS
2009-01-02 15:32 . 2009-01-02 15:32 <DIR> d-------- c:\program files\WAV to MP3 Encoder
2009-01-02 15:32 . 2001-12-12 11:35 348,160 --a------ c:\windows\system32\MEnc.ocx
2009-01-02 15:32 . 2002-08-22 23:27 348,160 --a------ c:\windows\system32\FlatBtn6.ocx
2009-01-02 15:32 . 1998-06-24 01:00 140,096 --a------ c:\windows\system32\Comdlg32.ocx
2008-12-29 13:33 . 2008-12-29 13:33 <DIR> d-------- c:\documents and settings\Michael McPartland\Application Data\SlySoft
2008-12-29 12:47 . 2008-12-29 12:47 <DIR> d-------- c:\program files\SlySoft
2008-12-24 23:30 . 2008-12-24 23:31 <DIR> d-------- c:\program files\iTunes
2008-12-24 23:30 . 2008-12-24 23:30 <DIR> d-------- c:\program files\iPod
2008-12-24 23:30 . 2008-12-24 23:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-24 23:28 . 2008-12-24 23:29 <DIR> d-------- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-24 05:29 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-17 16:43 --------- d-----w c:\program files\Dell
2009-01-17 16:41 --------- d-----w c:\program files\Common Files\AOL
2009-01-17 16:41 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-01-17 16:39 --------- d-----w c:\program files\Creative
2009-01-10 02:04 --------- d-----w c:\documents and settings\Michael McPartland\Application Data\AdobeUM
2009-01-02 21:34 --------- d-----w c:\program files\Google
2008-12-25 04:28 --------- d-----w c:\program files\Common Files\Apple
2008-07-31 20:05 88 --sh--r c:\windows\system32\2179C14E34.sys
2008-07-31 20:05 3,350 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-23 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 1159168]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-06-15 169472]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-06-15 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
S0 zifjxuoo;zifjxuoo;c:\windows\system32\drivers\sczphrtq.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{379cb646-d82f-11dd-84da-00038a000015}]
\Shell\AutoRun\command - f:\system\viewer\FlipVideoforPC.exe
\Shell\Flip Video for PC\command - f:\system\viewer\FlipVideoforPC.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{0344C053-68F1-4D54-9D7E-CD65B0B9B411} - c:\windows\system32\cbXPheff.dll
BHO-{3dc85106-99a2-4057-8ea8-6d57ddbf4652} - c:\windows\system32\wfhmrc.dll
HKCU-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
HKCU-Run-SetDefaultMIDI - MIDIDef.exe
HKLM-Run-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
HKLM-Run-f47c4660 - c:\windows\system32\ijvesdmg.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.nytimes.com/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Michael McPartland\Application Data\Mozilla\Firefox\Profiles\j7w9mdtu.default\
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-24 12:38:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\drivers\sczphrtq.sys 25088 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-01-24 12:39:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-24 17:39:38
Pre-Run: 29,832,245,248 bytes free
Post-Run: 29,816,799,232 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
224