squeakygenius
New member
ComboFix Report
FILE
C:\Documents and Settings\Travis\Desktop\Microsoft Office 2007 .rar
C:\Program Files\McAfee\SpamKiller\MSKAGE~1 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~2 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~3 .EXE
C:\WINDOWS\system32\ddayv.dll
C:\WINDOWS\system32\ddayv.exe
C:\WINDOWS\system32\vyadd.ini
C:\WINDOWS\system32\vyadd.ini2
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\hiftycxe.dll
C:\Install\
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAGE~2 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~1 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~2 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~3 .EXE
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\crfbxdrr.ini
C:\WINDOWS\system32\ddayv.exe
C:\WINDOWS\system32\gdlyjejq.ini
C:\WINDOWS\system32\gibmbend.dll
C:\WINDOWS\system32\gptsfqcg.dll
C:\WINDOWS\system32\hiftycxe.dll
C:\WINDOWS\system32\hiftycxe.dllbox
C:\WINDOWS\system32\igujkvda.dll
C:\WINDOWS\system32\kvuipeib.dll
C:\WINDOWS\system32\kwvcvcib.dll
C:\WINDOWS\system32\lvyocdgq.dll
C:\WINDOWS\system32\pbbwdawi.ini
C:\WINDOWS\system32\pqmonbdq.ini
C:\WINDOWS\system32\qchqguqx.ini
C:\WINDOWS\system32\qtxjfjkx.ini
C:\WINDOWS\system32\raqhuskb.dll
C:\WINDOWS\system32\rrdxbfrc.dll
C:\WINDOWS\system32\utedjhuj.dll
C:\WINDOWS\system32\vhgphidm.ini
C:\WINDOWS\system32\vyadd.ini
C:\WINDOWS\system32\vyadd.ini2
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wncnabkj
C:\WINDOWS\system32\wncnabkj\bg1.gif
C:\WINDOWS\system32\wncnabkj\bgtop.gif
C:\WINDOWS\system32\wncnabkj\bottom1.gif
C:\WINDOWS\system32\wncnabkj\essentials.gif
C:\WINDOWS\system32\wncnabkj\icon1.ico
C:\WINDOWS\system32\wncnabkj\install1.gif
C:\WINDOWS\system32\wncnabkj\left1.gif
C:\WINDOWS\system32\wncnabkj\li.gif
C:\WINDOWS\system32\wncnabkj\logo.gif
C:\WINDOWS\system32\wncnabkj\main.htm
C:\WINDOWS\system32\wncnabkj\mainframe.htm
C:\WINDOWS\system32\wncnabkj\reinstall1.gif
C:\WINDOWS\system32\wncnabkj\right1.gif
C:\WINDOWS\system32\wncnabkj\s1.htm
C:\WINDOWS\system32\wncnabkj\s2.htm
C:\WINDOWS\system32\wncnabkj\s3.htm
C:\WINDOWS\system32\wncnabkj\SMTop1.gif
C:\WINDOWS\system32\wncnabkj\SMTop2.gif
C:\WINDOWS\system32\wncnabkj\SMTop3.gif
C:\WINDOWS\system32\wncnabkj\SMTop4.gif
C:\WINDOWS\system32\wncnabkj\soft1_off.gif
C:\WINDOWS\system32\wncnabkj\soft1_off_ext.gif
C:\WINDOWS\system32\wncnabkj\soft1_on.gif
C:\WINDOWS\system32\wncnabkj\soft1_on_ext.gif
C:\WINDOWS\system32\wncnabkj\soft2_off.gif
C:\WINDOWS\system32\wncnabkj\soft2_off_ext.gif
C:\WINDOWS\system32\wncnabkj\soft2_on.gif
C:\WINDOWS\system32\wncnabkj\soft2_on_ext.gif
C:\WINDOWS\system32\wncnabkj\soft3_off.gif
C:\WINDOWS\system32\wncnabkj\soft3_off_ext.gif
C:\WINDOWS\system32\wncnabkj\soft3_on.gif
C:\WINDOWS\system32\wncnabkj\soft3_on_ext.gif
C:\WINDOWS\system32\wncnabkj\softbottom_off.gif
C:\WINDOWS\system32\wncnabkj\softbottom_on.gif
C:\WINDOWS\system32\wncnabkj\softleft_off.gif
C:\WINDOWS\system32\wncnabkj\softleft_on.gif
C:\WINDOWS\system32\wncnabkj\top1.gif
C:\WINDOWS\system32\wncnabkj\top2.gif
C:\WINDOWS\system32\wncnabkj\turnoff1.gif
C:\WINDOWS\system32\wncnabkj\turnon1.gif
.
((((((((((((((((((((((((( Files Created from 2008-01-06 to 2008-02-06 )))))))))))))))))))))))))))))))
.
2008-02-06 18:23 . 2008-02-06 18:23 294 ---hs---- C:\WINDOWS\system32\qtxjfjkx.ini
2008-02-06 02:00 . 2008-02-06 02:00 90,688 --a------ C:\WINDOWS\system32\xkjfjxtq.dll
2008-02-01 15:43 . 2008-02-06 13:23 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-01-31 18:38 . 2008-01-31 18:38 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-31 18:38 . 2008-01-31 18:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-28 16:54 . 2008-01-28 16:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Dell
2008-01-23 18:32 . 2008-01-23 18:32 <DIR> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-06 23:17 --------- d-----w C:\Documents and Settings\Travis\Application Data\Skype
2008-02-01 21:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-01 21:26 --------- d-----w C:\Program Files\Sonic
2008-02-01 20:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-01 20:45 --------- d-----r C:\Documents and Settings\Travis\Application Data\yahoo!
2008-02-01 20:20 --------- d-----w C:\Program Files\Jasc Software Inc
2008-02-01 06:17 --------- d-----w C:\Program Files\iTunes
2008-01-31 23:08 --------- d-----w C:\Program Files\DellSupport
2008-01-31 23:07 --------- d-----w C:\Program Files\Apoint
2008-01-30 22:56 --------- d-----w C:\Program Files\QuickTime
2008-01-22 07:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-23 07:34 --------- d-----w C:\Documents and Settings\Travis\Application Data\Ventrilo
2007-12-23 07:23 --------- d-----w C:\Program Files\Ventrilo
2007-12-23 07:07 --------- d-----w C:\Program Files\Xilisoft
2007-12-23 06:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-17 12:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-17 02:52 --------- d-----w C:\Program Files\Common Files\Adobe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"MSKAGENTEXE"="c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [ ]
"DellTransferAgent"="C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_09\bin\jusched.exe" [ ]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [ ]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset .exe" [2008-02-06 18:23 606208]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [ ]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [ ]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [ ]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [ ]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [ ]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [ ]
"MSKAGENTEXE"="C:\PROGRA~1\mcafee\SPAMKI~1\MSKAGE~2.EXE" [ ]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [ ]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [ ]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-02 15:24 257088]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [ ]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [ ]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"1cb2ae18"="C:\WINDOWS\system32\xkjfjxtq.dll" [2008-02-06 02:00 90688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WMC_WMPDBExport"="C:\Program Files\Windows Media Player\wmdbexport.exe" [2006-10-18 19:04 493568]
"TSClientMSIUninstaller"="cmd.exe" [2004-08-04 05:00 388608 C:\WINDOWS\system32\cmd.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-07-29 23:17:47 113664]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2005-03-05 20:18:22 10872]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 18:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 18:50:52 53248]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-05-08 14:41:37 450560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
C:\Program Files\Common Files\Stardock\mcpstub.dll 2003-08-25 09:25 139264 C:\Program Files\Common Files\Stardock\MCPStub.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-07-27 16:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
S2 TICalc;TICalc;C:\WINDOWS\system32\drivers\TICalc.sys [2000-02-22 15:46]
S3 LTower;LEGO USB Tower Driver;C:\WINDOWS\system32\Drivers\LTower.sys [2004-01-22 16:15]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e728d8b5-aae5-11dc-a1ca-00038a000015}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-16 15:41:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-01 23:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (D513DT71-Travis).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-06 18:23:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\xkjfjxtq.dll
-> C:\Program Files\Dell\QuickSet\dadkeyb.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell\QuickSet\quickset .exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Travis\Instant Messenger\aim.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-02-06 18:32:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-06 23:32:53
ComboFix2.txt 2008-01-31 23:22:34
ComboFix3.txt 2008-01-30 23:16:59
.
2008-01-11 01:07:39 --- E O F ---
FILE
C:\Documents and Settings\Travis\Desktop\Microsoft Office 2007 .rar
C:\Program Files\McAfee\SpamKiller\MSKAGE~1 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~2 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~3 .EXE
C:\WINDOWS\system32\ddayv.dll
C:\WINDOWS\system32\ddayv.exe
C:\WINDOWS\system32\vyadd.ini
C:\WINDOWS\system32\vyadd.ini2
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\hiftycxe.dll
C:\Install\
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAGE~2 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~1 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~2 .EXE
C:\Program Files\McAfee\SpamKiller\MSKAGE~3 .EXE
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\crfbxdrr.ini
C:\WINDOWS\system32\ddayv.exe
C:\WINDOWS\system32\gdlyjejq.ini
C:\WINDOWS\system32\gibmbend.dll
C:\WINDOWS\system32\gptsfqcg.dll
C:\WINDOWS\system32\hiftycxe.dll
C:\WINDOWS\system32\hiftycxe.dllbox
C:\WINDOWS\system32\igujkvda.dll
C:\WINDOWS\system32\kvuipeib.dll
C:\WINDOWS\system32\kwvcvcib.dll
C:\WINDOWS\system32\lvyocdgq.dll
C:\WINDOWS\system32\pbbwdawi.ini
C:\WINDOWS\system32\pqmonbdq.ini
C:\WINDOWS\system32\qchqguqx.ini
C:\WINDOWS\system32\qtxjfjkx.ini
C:\WINDOWS\system32\raqhuskb.dll
C:\WINDOWS\system32\rrdxbfrc.dll
C:\WINDOWS\system32\utedjhuj.dll
C:\WINDOWS\system32\vhgphidm.ini
C:\WINDOWS\system32\vyadd.ini
C:\WINDOWS\system32\vyadd.ini2
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wncnabkj
C:\WINDOWS\system32\wncnabkj\bg1.gif
C:\WINDOWS\system32\wncnabkj\bgtop.gif
C:\WINDOWS\system32\wncnabkj\bottom1.gif
C:\WINDOWS\system32\wncnabkj\essentials.gif
C:\WINDOWS\system32\wncnabkj\icon1.ico
C:\WINDOWS\system32\wncnabkj\install1.gif
C:\WINDOWS\system32\wncnabkj\left1.gif
C:\WINDOWS\system32\wncnabkj\li.gif
C:\WINDOWS\system32\wncnabkj\logo.gif
C:\WINDOWS\system32\wncnabkj\main.htm
C:\WINDOWS\system32\wncnabkj\mainframe.htm
C:\WINDOWS\system32\wncnabkj\reinstall1.gif
C:\WINDOWS\system32\wncnabkj\right1.gif
C:\WINDOWS\system32\wncnabkj\s1.htm
C:\WINDOWS\system32\wncnabkj\s2.htm
C:\WINDOWS\system32\wncnabkj\s3.htm
C:\WINDOWS\system32\wncnabkj\SMTop1.gif
C:\WINDOWS\system32\wncnabkj\SMTop2.gif
C:\WINDOWS\system32\wncnabkj\SMTop3.gif
C:\WINDOWS\system32\wncnabkj\SMTop4.gif
C:\WINDOWS\system32\wncnabkj\soft1_off.gif
C:\WINDOWS\system32\wncnabkj\soft1_off_ext.gif
C:\WINDOWS\system32\wncnabkj\soft1_on.gif
C:\WINDOWS\system32\wncnabkj\soft1_on_ext.gif
C:\WINDOWS\system32\wncnabkj\soft2_off.gif
C:\WINDOWS\system32\wncnabkj\soft2_off_ext.gif
C:\WINDOWS\system32\wncnabkj\soft2_on.gif
C:\WINDOWS\system32\wncnabkj\soft2_on_ext.gif
C:\WINDOWS\system32\wncnabkj\soft3_off.gif
C:\WINDOWS\system32\wncnabkj\soft3_off_ext.gif
C:\WINDOWS\system32\wncnabkj\soft3_on.gif
C:\WINDOWS\system32\wncnabkj\soft3_on_ext.gif
C:\WINDOWS\system32\wncnabkj\softbottom_off.gif
C:\WINDOWS\system32\wncnabkj\softbottom_on.gif
C:\WINDOWS\system32\wncnabkj\softleft_off.gif
C:\WINDOWS\system32\wncnabkj\softleft_on.gif
C:\WINDOWS\system32\wncnabkj\top1.gif
C:\WINDOWS\system32\wncnabkj\top2.gif
C:\WINDOWS\system32\wncnabkj\turnoff1.gif
C:\WINDOWS\system32\wncnabkj\turnon1.gif
.
((((((((((((((((((((((((( Files Created from 2008-01-06 to 2008-02-06 )))))))))))))))))))))))))))))))
.
2008-02-06 18:23 . 2008-02-06 18:23 294 ---hs---- C:\WINDOWS\system32\qtxjfjkx.ini
2008-02-06 02:00 . 2008-02-06 02:00 90,688 --a------ C:\WINDOWS\system32\xkjfjxtq.dll
2008-02-01 15:43 . 2008-02-06 13:23 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-01-31 18:38 . 2008-01-31 18:38 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-31 18:38 . 2008-01-31 18:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-28 16:54 . 2008-01-28 16:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Dell
2008-01-23 18:32 . 2008-01-23 18:32 <DIR> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-06 23:17 --------- d-----w C:\Documents and Settings\Travis\Application Data\Skype
2008-02-01 21:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-01 21:26 --------- d-----w C:\Program Files\Sonic
2008-02-01 20:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-01 20:45 --------- d-----r C:\Documents and Settings\Travis\Application Data\yahoo!
2008-02-01 20:20 --------- d-----w C:\Program Files\Jasc Software Inc
2008-02-01 06:17 --------- d-----w C:\Program Files\iTunes
2008-01-31 23:08 --------- d-----w C:\Program Files\DellSupport
2008-01-31 23:07 --------- d-----w C:\Program Files\Apoint
2008-01-30 22:56 --------- d-----w C:\Program Files\QuickTime
2008-01-22 07:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-23 07:34 --------- d-----w C:\Documents and Settings\Travis\Application Data\Ventrilo
2007-12-23 07:23 --------- d-----w C:\Program Files\Ventrilo
2007-12-23 07:07 --------- d-----w C:\Program Files\Xilisoft
2007-12-23 06:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-17 12:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-17 02:52 --------- d-----w C:\Program Files\Common Files\Adobe
.
Code:
<pre>
----a-w 606,208 2008-02-06 23:23:38 C:\Program Files\Dell\QuickSet\quickset .exe
----a-w 23,423,528 2008-01-29 00:42:34 C:\Program Files\Skype\Phone\Skype .exe
----a-w 15,360 2008-01-30 23:05:57 C:\WINDOWS\system32\ctfmon .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"MSKAGENTEXE"="c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [ ]
"DellTransferAgent"="C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_09\bin\jusched.exe" [ ]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [ ]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset .exe" [2008-02-06 18:23 606208]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [ ]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [ ]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [ ]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [ ]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [ ]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [ ]
"MSKAGENTEXE"="C:\PROGRA~1\mcafee\SPAMKI~1\MSKAGE~2.EXE" [ ]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [ ]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [ ]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-02 15:24 257088]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [ ]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [ ]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"1cb2ae18"="C:\WINDOWS\system32\xkjfjxtq.dll" [2008-02-06 02:00 90688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WMC_WMPDBExport"="C:\Program Files\Windows Media Player\wmdbexport.exe" [2006-10-18 19:04 493568]
"TSClientMSIUninstaller"="cmd.exe" [2004-08-04 05:00 388608 C:\WINDOWS\system32\cmd.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-07-29 23:17:47 113664]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2005-03-05 20:18:22 10872]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 18:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 18:50:52 53248]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-05-08 14:41:37 450560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
C:\Program Files\Common Files\Stardock\mcpstub.dll 2003-08-25 09:25 139264 C:\Program Files\Common Files\Stardock\MCPStub.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-07-27 16:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
S2 TICalc;TICalc;C:\WINDOWS\system32\drivers\TICalc.sys [2000-02-22 15:46]
S3 LTower;LEGO USB Tower Driver;C:\WINDOWS\system32\Drivers\LTower.sys [2004-01-22 16:15]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e728d8b5-aae5-11dc-a1ca-00038a000015}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-16 15:41:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-01 23:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (D513DT71-Travis).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-06 18:23:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\xkjfjxtq.dll
-> C:\Program Files\Dell\QuickSet\dadkeyb.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell\QuickSet\quickset .exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Travis\Instant Messenger\aim.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-02-06 18:32:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-06 23:32:53
ComboFix2.txt 2008-01-31 23:22:34
ComboFix3.txt 2008-01-30 23:16:59
.
2008-01-11 01:07:39 --- E O F ---