ComboFix Results
ComboFix 08-03-18.1 - Russell 2008-03-20 12:29:23.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1515 [GMT -4:00]
Running from: C:\Documents and Settings\Russell\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\kmd.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aixueqle.dll
C:\WINDOWS\system32\bdgylfts.dll
C:\WINDOWS\system32\bfmitpyr.dll
C:\WINDOWS\system32\bkmoopob.exe
C:\WINDOWS\system32\dqsxawat.ini
C:\WINDOWS\system32\fcamplqu.dll
C:\WINDOWS\system32\fikthhje.dll
C:\WINDOWS\system32\hhlqmoxl.dll
C:\WINDOWS\system32\jokrthiw.ini
C:\WINDOWS\system32\jowfcgbd.dll
C:\WINDOWS\system32\lxomqlhh.ini
C:\WINDOWS\system32\nlgvjvql.dll
C:\WINDOWS\system32\nnentlgr.ini
C:\WINDOWS\system32\odhnglwy.dll
C:\WINDOWS\system32\rgltnenn.dll
C:\WINDOWS\system32\skkxhnfk.dll
C:\WINDOWS\system32\tawaxsqd.dll
C:\WINDOWS\system32\thscdmeg.dll
C:\WINDOWS\system32\tvoidsnx.dll
C:\WINDOWS\system32\tynlodcl.dll
C:\WINDOWS\system32\ujxfvwux.dll
C:\WINDOWS\system32\ursvftho.dll
C:\WINDOWS\system32\voemesaw.dll
C:\WINDOWS\system32\vqovodfb.dll
C:\WINDOWS\system32\wihtrkoj.dll
C:\WINDOWS\system32\wrggihrq.dll
C:\WINDOWS\system32\wycdd.ini
C:\WINDOWS\system32\wycdd.ini2
C:\WINDOWS\system32\xoamswde.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-20 to 2008-03-20 )))))))))))))))))))))))))))))))
.
2008-03-20 11:54 . 2008-03-20 12:15 <DIR> d-------- C:\VundoFix Backups
2008-03-19 01:24 . 2008-03-19 01:24 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-19 01:24 . 2008-03-19 01:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-19 00:53 . 2008-03-19 00:52 691,545 --a------ C:\WINDOWS\unins000.exe
2008-03-19 00:53 . 2008-03-19 00:53 2,548 --a------ C:\WINDOWS\unins000.dat
2008-03-18 23:17 . 2008-03-19 21:18 2,389,938 --ahs---- C:\WINDOWS\system32\jtfhxjcv.ini
2008-03-16 21:48 . 2008-03-17 23:05 1,359,787 --ahs---- C:\WINDOWS\system32\bbhddbav.ini
2008-03-15 20:21 . 2008-03-16 21:43 1,367,163 --ahs---- C:\WINDOWS\system32\tcwtvqul.ini
2008-03-15 20:17 . 2008-03-15 20:17 98,368 --a------ C:\WINDOWS\system32\kavpvluq.dll
2008-03-13 20:21 . 2008-03-14 11:19 1,346,750 --ahs---- C:\WINDOWS\system32\jduyossy.ini
2008-03-13 13:28 . 2008-03-16 00:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-13 13:28 . 2008-03-13 13:28 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-13 01:16 . 2008-03-13 01:16 36,352 --a------ C:\WINDOWS\system32\wvuspnm.V23dll
2008-03-12 21:49 . 2008-03-12 21:49 36,352 --a------ C:\WINDOWS\system32\wvuspnm.V22dll
2008-03-12 21:38 . 2008-03-12 21:38 36,352 --a------ C:\WINDOWS\system32\wvuspnm.V21dll
2008-03-12 21:36 . 2008-03-12 21:36 36,352 --a------ C:\WINDOWS\system32\wvuspnm.Vdll
2008-03-11 23:01 . 2008-03-11 23:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-11 17:38 . 2008-03-13 11:36 1,321,480 --ahs---- C:\WINDOWS\system32\emxinmtw.ini
2008-03-11 17:38 . 2008-03-11 17:38 86,592 --a------ C:\WINDOWS\system32\wtmnixme.dll
2008-03-11 17:35 . 2008-03-11 17:35 93,248 --a------ C:\WINDOWS\system32\jqjsbhho.dll
2008-03-11 17:32 . 2008-03-11 17:32 90,688 --a------ C:\WINDOWS\system32\gxlmaalg.dll
2008-03-10 17:35 . 2008-03-11 17:06 1,315,590 --ahs---- C:\WINDOWS\system32\xivpadaw.ini
2008-03-07 12:15 . 2008-03-07 12:15 1,307,561 --ahs---- C:\WINDOWS\system32\ocvyqjej.ini
2008-03-07 02:11 . 2008-03-07 02:11 32,764 --a------ C:\WINDOWS\17PHolmes572.exe
2008-03-07 02:10 . 2008-03-07 02:10 36,352 --a------ C:\WINDOWS\system32\wvuspnm.dll
2008-02-23 16:17 . 2007-08-21 10:58 146,944 --a------ C:\WINDOWS\system32\st325602.dll
2008-02-23 14:08 . 2008-03-18 23:35 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-23 13:12 . 2000-12-05 10:11 4,174,814 --a------ C:\WINDOWS\system32\ct4mgm.sf2
2008-02-23 13:12 . 2005-05-25 18:34 158,464 --a------ C:\WINDOWS\system32\drivers\ctusfsyn.sys
2008-02-23 13:12 . 2005-01-10 19:15 138,752 --a------ C:\WINDOWS\system32\drivers\ctsfm2k.sys
2008-02-23 13:12 . 2005-01-10 19:15 115,200 --a------ C:\WINDOWS\system32\sfms32.dll
2008-02-23 13:12 . 2005-01-10 19:15 106,496 --a------ C:\WINDOWS\system32\drivers\ctoss2k.sys
2008-02-23 13:12 . 2005-01-10 19:15 20,992 --a------ C:\WINDOWS\system32\sfman32.dll
2008-02-23 13:12 . 2002-01-03 00:44 59 --a------ C:\WINDOWS\system32\default4.sfm
2008-02-23 13:11 . 2006-01-18 23:07 160,768 --a------ C:\WINDOWS\system32\cifilter.dll
2008-02-23 13:11 . 2005-12-07 12:34 40,448 --a------ C:\WINDOWS\system32\CiEcho.dll
2008-02-23 13:11 . 2005-10-29 20:42 11,776 --a------ C:\WINDOWS\inres.dll
2008-02-23 01:13 . 2008-02-23 01:13 <DIR> d-------- C:\Program Files\Creative
2008-02-23 01:13 . 2006-01-04 16:41 1,389,056 --a------ C:\WINDOWS\system32\drivers\monfilt.sys
2008-02-23 01:13 . 2006-01-19 10:49 22,629 --a------ C:\WINDOWS\system32\CiFilter.ini
2008-02-23 01:13 . 2008-02-23 13:12 424 -rah----- C:\WINDOWS\ctfile.rfc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 04:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-19 04:55 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-19 03:20 --------- d-----w C:\Program Files\ESET
2008-03-12 03:57 --------- d-----w C:\Program Files\Common Files\Real
2008-02-23 20:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-23 18:06 --------- d-----w C:\Program Files\Ace Utilities
2008-02-14 20:06 --------- d-----w C:\Documents and Settings\Russell\Application Data\ArcSoft
2008-02-14 19:54 --------- d-----w C:\Documents and Settings\Russell\Application Data\Canon
2008-02-14 19:46 --------- d-----w C:\Program Files\Canon
2008-02-14 19:45 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2008-02-14 19:45 --------- d-----w C:\Documents and Settings\Russell\Application Data\ScanSoft
2008-02-14 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-02-14 19:44 --------- d-----w C:\Program Files\ScanSoft
2008-02-14 19:42 --------- d-----w C:\Program Files\ArcSoft
2008-02-14 19:39 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ
2008-02-14 19:38 --------- d--h--w C:\Program Files\CanonBJ
2008-02-12 06:09 --------- d-----w C:\Program Files\Google
2008-02-09 02:41 --------- d-----w C:\Program Files\XP Smoker
2008-01-20 07:12 --------- d-----w C:\Documents and Settings\Russell\Application Data\InstallShield
2008-01-14 21:48 681,984 ----a-w C:\WINDOWS\is-E4S7I.exe
2008-01-14 03:00 246 ----a-w C:\Program Files\Common Files\lacu
2007-02-03 02:01 56 --sha-r C:\WINDOWS\system32\388022A7CC.sys
2007-02-27 07:15 88 --sha-r C:\WINDOWS\system32\CCA7228038.sys
2007-02-27 07:15 6,216 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
Code:
<pre>
----a-w 313,472 2008-01-14 06:47:25 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
----a-w 61,440 2008-01-14 06:47:16 C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy .exe
----a-w 45,056 2008-01-14 06:47:12 C:\Program Files\ATI Technologies\ATI.ACE\cli .exe
----a-w 81,920 2008-01-14 06:47:16 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
----a-w 49,152 2008-01-14 06:47:12 C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
----a-w 460,784 2008-01-14 06:47:27 C:\Program Files\DellSupport\DSAgnt .exe
----a-w 696,320 2008-01-14 06:47:20 C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
----a-w 802,816 2008-01-14 06:47:21 C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
----a-w 267,064 2008-01-14 06:47:20 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 1,694,208 2008-01-14 04:32:16 C:\Program Files\Messenger\msmsgs .exe
----a-w 761,947 2008-01-14 06:47:14 C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
----a-w 67,584 2008-01-14 06:47:10 C:\WINDOWS\ehome\ehtray .exe
----a-w 122,941 2008-01-14 06:47:17 C:\WINDOWS\system32\dla\tfswctrl .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{014f5f82-2d71-45ac-98c9-d78976fa1812}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{16F1EFD4-D9EE-47CE-AD44-5A97D0063803}]
C:\WINDOWS\system32\mlljk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1B2A5AA0-7BE2-4612-83E9-425D05F079E4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{22342B44-5B98-4B30-9D53-C182AD8DF217}]
2008-03-07 02:10 36352 --a------ C:\WINDOWS\system32\wvuspnm.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 06:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-01-16 22:52 949376]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-16 21:40 1197648]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.exe" [2007-05-14 15:23 1191936]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 11:22 405504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{22342B44-5B98-4B30-9D53-C182AD8DF217}"= C:\WINDOWS\system32\wvuspnm.dll [2008-03-07 02:10 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuspnm]
wvuspnm.dll 2008-03-07 02:10 36352 C:\WINDOWS\system32\wvuspnm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\iTunes\\iTunes.exe"=
S3 AngelUsb;Angel USB MPEG Device;C:\WINDOWS\system32\DRIVERS\AngelUsb.sys [2005-02-17 10:06]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ffdf6fc-c474-11dc-9d80-0015c50f5836}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ffdf6fd-c474-11dc-9d80-0015c50f5836}]
\Shell\AutoRun\command - setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-11 18:37:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-20 12:35:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\wvuspnm.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
.
**************************************************************************
.
Completion time: 2008-03-20 12:38:01 - machine was rebooted [Russell]
ComboFix-quarantined-files.txt 2008-03-20 16:37:55
ComboFix2.txt 2008-02-09 02:13:32
ComboFix3.txt 2008-01-17 00:16:56
.
2008-03-18 00:09:15 --- E O F ---