combofix log
ComboFix 07-08-04.3 - "Administrator" 2007-08-05 16:48:47.1 [GMT -5:00] - NTFS [SAFE MODE]
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\LOCALS~1\APPLIC~1\install.dat
C:\DOCUME~1\NETWOR~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\NETWOR~1\APPLIC~1\install.dat
C:\DOCUME~1\SaraS\APPLIC~1\..\err.log>>d-delA.cf
C:\DOCUME~1\SaraS\APPLIC~1\.rdr.ini
C:\DOCUME~1\SaraS\APPLIC~1\install.dat
C:\DOCUME~1\SaraS\APPLIC~1\Starware
C:\DOCUME~1\SaraS\APPLIC~1\Starware\Manager\ManagerOptions.xml
C:\DOCUME~1\SaraS\APPLIC~1\Starware\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\ppatch~1\m?iexec.exe
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\MSN\vixyl83122.dll
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\WINDOWS\83122.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\crosof~1.net
C:\WINDOWS\csrss.exe
C:\WINDOWS\desktop.html
C:\WINDOWS\mgrs.exe
C:\WINDOWS\offun.exe
C:\WINDOWS\rau001978.exe
C:\WINDOWS\retadpu27.exe
C:\WINDOWS\retadpu572.exe
C:\WINDOWS\spooldr.exe
C:\WINDOWS\system32\awtqrqn.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b02FdUe\b02FdUe1065.exe
C:\WINDOWS\system32\b06FdUe
C:\WINDOWS\system32\b06FdUe\b06FdUe1083.exe
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\dllh8jkd1q1.exe
C:\WINDOWS\system32\dllh8jkd1q2.exe
C:\WINDOWS\system32\dllh8jkd1q5.exe
C:\WINDOWS\system32\dllh8jkd1q6.exe
C:\WINDOWS\system32\dllh8jkd1q7.exe
C:\WINDOWS\system32\dllh8jkd1q8.exe
C:\WINDOWS\system32\dnsersnd.dll
C:\WINDOWS\system32\drivers\asc3550u.sys
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\exahqsno.exe
C:\WINDOWS\system32\hlpsrv.exe
C:\WINDOWS\system32\jkkjkig.dll
C:\WINDOWS\system32\khfghif.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\loftketd.dll
C:\WINDOWS\system32\mjejyysf.exe
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\spooldr.sys
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\urqonnn.dll
C:\WINDOWS\system32\vedxga1me4t1.exe
C:\WINDOWS\system32\vedxga3me2.exe
C:\WINDOWS\system32\vedxga4me1.exe
C:\WINDOWS\system32\vx.tll
C:\WINDOWS\system32\win
C:\WINDOWS\system32\winfqk32.dll
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\wuulyhu.dll
C:\WINDOWS\system32\wvuvssp.dll
C:\WINDOWS\system32\X1
C:\WINDOWS\system32\X1\kmhp83122.exe
C:\WINDOWS\system32\X11
C:\WINDOWS\system32\X11\z553.exe
C:\WINDOWS\system32\X3
C:\WINDOWS\system32\X3\wr731.exe
C:\WINDOWS\system32\X7
C:\WINDOWS\system32\X9
C:\WINDOWS\system32\yabxy.dll
C:\WINDOWS\system32\yxbay.bak1
C:\WINDOWS\system32\yxbay.bak2
C:\WINDOWS\system32\yxbay.ini
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\uninst2.htm
C:\WINDOWS\unist1.htm
C:\WINDOWS\wr.txt
C:\windows\xpupdate.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_APIMON
-------\LEGACY_FOPN
-------\LEGACY_NET_AGENT
-------\LEGACY_QIE28
-------\LEGACY_WINDOWS_OVERLAY_COMPONENTS
-------\ApiMon
-------\Net Agent
-------\Windows Overlay Components
((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))
2007-08-05 16:47 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-05 16:46 1,408,582 --a------ C:\ComboFix.exe
2007-08-04 18:08 <DIR> d-------- C:\WINDOWS\system32\drivers\bak
2007-08-04 17:58 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-07-31 22:45 93,696 --a------ C:\WINDOWS\system32\drvsat.dll
2007-07-31 22:45 <DIR> d-------- C:\DOCUME~1\SaraS\APPLIC~1\?ymbols
2007-07-31 22:30 125,504 --a--c--- C:\WINDOWS\system32\bhipvpus.dll
2007-07-31 19:44 70,312 --a------ C:\Program Files\codec_setup.exe
2007-07-31 16:30 168,960 --a------ C:\WINDOWS\system32\drivers\Qie28.sys
2007-07-31 16:17 168,960 --a------ C:\WINDOWS\system32\drivers\Xrx49.sys
2007-07-31 16:17 168,960 --a------ C:\WINDOWS\system32\drivers\symavc32.sys
2007-07-31 16:11 9,769 --a------ C:\WINDOWS\gsvjy0578.exe
2007-07-28 16:03 8,704 --a--c--- C:\WINDOWS\system32\dllcache\kbdjpn.dll
2007-07-28 16:03 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll
2007-07-28 16:03 8,192 --a--c--- C:\WINDOWS\system32\dllcache\kbdkor.dll
2007-07-28 16:03 8,192 --a------ C:\WINDOWS\system32\kbdkor.dll
2007-07-28 16:03 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd106.dll
2007-07-28 16:03 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd101c.dll
2007-07-28 16:03 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd101b.dll
2007-07-28 16:03 6,144 --a------ C:\WINDOWS\system32\kbd106.dll
2007-07-28 16:03 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll
2007-07-28 16:03 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2007-07-28 16:03 5,632 --a--c--- C:\WINDOWS\system32\dllcache\kbd103.dll
2007-07-28 16:03 5,632 --a------ C:\WINDOWS\system32\kbd103.dll
2007-07-24 12:06 <DIR> d-------- C:\DOCUME~1\Tyler\APPLIC~1\MySpace
2007-07-05 00:06 294,912 --a------ C:\WINDOWS\Walgreens PhotoShow.scr
2007-07-05 00:06 <DIR> d-------- C:\DOCUME~1\SaraS\APPLIC~1\Simple Star
2007-07-05 00:06 <DIR> d-------- C:\Demo Album
2007-07-05 00:05 <DIR> d-------- C:\Program Files\Walgreens
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-05 17:04 375168 --a--c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2007-08-05 17:04 375168 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-07-31 22:26 --------- d-------- C:\Program Files\Yahoo!
2007-07-31 21:37 --------- d-------- C:\Program Files\MySpace
2007-07-31 16:16 --------- d-------- C:\Program Files\Windows NT
2007-07-31 01:54 13993410 -r-hs---- C:\AVG6DB_F.DAT
2007-07-28 21:34 --------- d-------- C:\Program Files\MSN Messenger
2007-07-28 04:06 135 --a------ C:\Program Files\page.html
2007-07-26 20:23 --------- d-------- C:\Program Files\OpenOffice.org1.1.1
2007-07-07 15:35 2983 --a------ C:\WINDOWS\mozver.dat
2007-06-25 08:54 53248 --a------ C:\WINDOWS\uni_eh44.exe
2007-06-25 08:53 53248 --a------ C:\WINDOWS\uninst1014.exe
2007-06-06 03:28 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-06-03 20:21 8326 --a------ C:\WINDOWS\extend.dat
2007-05-16 10:12 86528 -----c--- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 10:12 85504 -----c--- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 10:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 10:12 683520 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 10:12 510976 -----c--- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 10:12 1314816 -----c--- C:\WINDOWS\system32\dllcache\msoe.dll
2007-03-06 22:15 1201917 --a------ C:\Program Files\wrar37b4.exe
2007-03-06 22:14 25755448 --a------ C:\Program Files\wmp11-windowsxp-x86-enu.exe
2007-03-06 20:06 6006304 --a------ C:\Program Files\Firefox Setup 2.0.0.2.exe
2006-12-02 20:05 2522 --a------ C:\Program Files\func.js
2006-11-25 02:57 482 --a------ C:\Program Files\Del.js
2006-06-08 02:02 2048 --a------ C:\Program Files\func.exe
2006-01-22 14:25 112729 --a------ C:\Program Files\cddrv224.zip
2006-01-22 14:06 7180311 --a------ C:\Program Files\HandBrake-0.7.0-GUIAndCLI-20060115.zip
2001-09-27 18:51 44779 --a------ C:\Program Files\NLDS1XXW.INF
2001-08-27 16:40 940606 --a------ C:\Program Files\data1.cab
2001-08-27 16:40 526 --a------ C:\Program Files\layout.bin
2001-08-27 16:40 36731 --a------ C:\Program Files\data1.hdr
2001-08-27 16:40 296 --a------ C:\Program Files\Setup.ini
2001-08-27 16:40 1409627 --a------ C:\Program Files\data2.cab
2001-08-24 05:44 2632 --a------ C:\Program Files\YDSXGDK.INF
2001-06-13 09:41 142209 --a------ C:\Program Files\setup.inx
2000-11-14 02:05 131072 --a------ C:\Program Files\dsuninst.exe
2000-10-30 13:00 141 --a------ C:\Program Files\setup.inf
2000-05-16 15:36 139264 --a------ C:\Program Files\Setup.exe
2000-05-14 19:17 335626 --a------ C:\Program Files\ikernel.ex_
2000-04-01 22:00 1073 --a------ C:\Program Files\YDSXGDK.CAT
2000-04-01 22:00 1073 --a------ C:\Program Files\YDSDEV.CAT
1999-04-02 12:16 2417445 --a------ C:\Program Files\Dsxgwave.tbl
C:\WINDOWS\system32\drivers\tcpip.sys ... is infected !! (additional data below)
359,808 2005-05-25 19:04:02 C:\WINDOWS\$hf_mig$\KB893066\SP2GDR\tcpip.sys
359,936 2005-05-25 19:07:12 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
360,576 2006-04-20 12:18:35 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
339,968 2005-05-25 19:41:10 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
332,928 2002-08-29 06:58:12 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys.000
359,040 2004-08-04 06:14:40 C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
332,928 2002-08-29 06:58:12 C:\WINDOWS\$NtUninstallKB893066_0$\tcpip.sys
359,808 2005-05-25 19:04:02 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
359,040 2004-08-04 06:14:40 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
340,480 2006-01-13 01:13:17 C:\WINDOWS\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP1QFE\tcpip.sys
359,808 2006-01-13 02:28:14 C:\WINDOWS\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP2GDR\tcpip.sys
360,448 2006-01-13 17:07:08 C:\WINDOWS\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP2QFE\tcpip.sys
375,168 2007-08-05 22:05:19 C:\WINDOWS\system32\dllcache\tcpip.sys
375,168 2007-08-05 22:05:21 C:\WINDOWS\system32\drivers\tcpip.sys
375,168 2007-08-04 22:52:01 C:\WINDOWS\system32\drivers\bak\tcpip.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_CC"="C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe" [2004-05-18 06:00]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50]
"AtiPTA"="atiptaxx.exe" [2001-09-26 22:39 C:\WINDOWS\system32\atiptaxx.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-27 19:01]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 18:50]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-21 20:30]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 01:14]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 14:19]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05]
"NBInstall"="C:\DOCUME~1\SaraS\LOCALS~1\Temp\MBDownloader_876919.exe" [2007-07-31 11:32]
"vhilotgA"="C:\WINDOWS\vhilotgA.exe" []
"{CF-F4-40-02-ZN}"="C:\windows\system32\modsregq.exe" []
"g4356cbvy63"="C:\WINDOWS\g4356cbvy63" []
"SysDAFS.exe"="C:\WINDOWS\system32\SysDAFS.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [2005-11-07 16:49]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 18:51]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" []
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [2005-05-19 16:59]
"Scna"="C:\WINDOWS\CROSOF~1.NET\wowexec.exe" []
"Ownejdr"="C:\Program Files\Common Files\??pPatch\m?iexec.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"RemoveInstallPath"=cmd.exe C:\WINDOWS\system32\cmd.exe /c rmdir /S /Q "C:\PROGRA~1\WinPop" > nul
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6fc94ea-c64a-11da-9c33-005022491f7c}]
AutoRun\command- E:\JDLightning\Windows\JDLightning.exe
Contents of the 'Scheduled Tasks' folder
2007-07-30 15:57:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-05 17:04:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\WINDOWS\wdfmzrx.exe [1968] 0x82FA6C10
C:\WINDOWS\wdfmzrx.exe [336] 0x82DFFAD0
scanning hidden registry entries ...
scanning hidden files ...
C:\WINDOWS\wdfmzrx.exe
C:\WINDOWS\system32\wdfmzrx.exe
**************************************************************************
Completion time: 2007-08-05 17:08:05 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-05 17:06
--- E O F ---