ComboFix 08-03-25.4 - Todd 2008-03-26 23:58:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511 [GMT -5:00]
Running from: C:\Documents and Settings\Todd\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM7b128375.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\abgmalqs.ini
C:\WINDOWS\system32\auykxntd.dll
C:\WINDOWS\system32\awhfoljp.dll
C:\WINDOWS\system32\bsmrfdan.dll
C:\WINDOWS\system32\cldeodks.dll
C:\WINDOWS\system32\ddlyyyog.ini
C:\WINDOWS\system32\dgisalxi.dll
C:\WINDOWS\system32\dxwnlexh.dll
C:\WINDOWS\system32\ealnuhjx.ini
C:\WINDOWS\system32\efcccab.dll
C:\WINDOWS\system32\ewairjej.ini
C:\WINDOWS\system32\fxffevod.dll
C:\WINDOWS\system32\gjllm.ini
C:\WINDOWS\system32\gjllm.ini2
C:\WINDOWS\system32\gttwutnh.ini
C:\WINDOWS\system32\hgvpcmnl.dll
C:\WINDOWS\system32\hhcdkbvf.ini
C:\WINDOWS\system32\hntuwttg.dll
C:\WINDOWS\system32\ikknxueg.dll
C:\WINDOWS\system32\kepsifus.dll
C:\WINDOWS\system32\lwnkpnfm.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlljg.dll
C:\WINDOWS\system32\npnixpsm.dll
C:\WINDOWS\system32\ofphqoeb.dll
C:\WINDOWS\system32\oluirxoe.dll
C:\WINDOWS\system32\opnmlkl.dll
C:\WINDOWS\system32\ppwttisq.dll
C:\WINDOWS\system32\psqcfjod.dll
C:\WINDOWS\system32\qaxhfdkn.dll
C:\WINDOWS\system32\spsfupyl.ini
.
((((((((((((((((((((((((( Files Created from 2008-02-27 to 2008-03-27 )))))))))))))))))))))))))))))))
.
2008-03-26 16:38 . 2008-03-26 16:38 <DIR> d-------- C:\ComboFix(2)
2008-03-21 11:24 . 2008-03-21 11:29 <DIR> d-------- C:\Program Files\QuickTime
2008-03-21 11:24 . 2008-03-21 11:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-21 11:23 . 2008-03-21 11:23 <DIR> d-------- C:\Program Files\Apple Software Update
2008-03-21 11:23 . 2008-03-21 11:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-03-21 10:28 . 2007-03-07 18:51 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2008-03-20 23:43 . 2008-03-20 23:43 <DIR> d-------- C:\WINDOWS\Sun
2008-03-20 22:36 . 2008-03-20 23:14 <DIR> d-------- C:\VundoFix Backups
2008-03-20 21:52 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-20 21:51 . 2008-03-20 21:52 <DIR> d-------- C:\Program Files\Java
2008-03-20 21:51 . 2008-03-20 21:51 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-20 10:17 . 2008-03-20 10:17 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Thunderbird
2008-03-20 10:17 . 2008-03-20 10:17 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-03-19 22:50 . 2008-03-19 22:50 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-19 22:50 . 2008-03-20 11:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-19 22:47 . 2008-03-19 22:52 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-03-18 09:47 . 2008-03-19 14:16 1,332,161 --ahs---- C:\WINDOWS\system32\qfrisbvc.ini
2008-03-17 09:47 . 2008-03-17 20:31 1,371,464 --ahs---- C:\WINDOWS\system32\csaakrte.ini
2008-03-16 09:41 . 2008-03-17 09:42 1,371,042 --ahs---- C:\WINDOWS\system32\dgjbtlxk.ini
2008-03-16 09:40 . 2008-03-16 09:40 63 --a------ C:\WINDOWS\system32\7821a267
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-27 02:07 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-03-21 23:55 --------- d-----w C:\Program Files\Winamp
2008-03-21 21:50 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-21 02:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-18 00:24 --------- d-----w C:\Program Files\Acceleron
2008-02-21 01:26 --------- d-----w C:\Program Files\TrapManager
2008-02-14 16:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-06 15:36 --------- d-----w C:\Documents and Settings\Todd\Application Data\Macrovision
2008-02-06 15:36 --------- d-----w C:\Documents and Settings\Todd\Application Data\Business Objects
2008-02-06 15:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-02-06 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Macrovision
2008-01-31 19:13 --------- d-----w C:\Documents and Settings\Todd\Application Data\Talkback
2007-04-26 17:47 28,848 ----a-w C:\Documents and Settings\Todd\Application Data\GDIPFONTCACHEV1.DAT
2004-02-22 22:19 217,377 ----a-w C:\Documents and Settings\Todd\setup.exe
2003-12-13 04:34 808 ----a-w C:\Program Files\INSTALL.LOG
1999-07-19 02:05 15,716 ----a-w C:\WINDOWS\inf\i386\Pmxscan.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9353DBD2-1261-4D55-9F93-46448B7BB70B}]
C:\WINDOWS\system32\mllmn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-18 20:51 68856]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"PinnacleDriverCheck"="C:\WINDOWS\System32\PSDrvCheck.exe" [2003-02-28 16:46 393216]
"BJLaunchEXE"="C:\Program Files\Canon\BJCard\BJLaunch.exe" [2002-12-20 15:26 716800]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 18:54 127022]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 19:32 155648]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"Act.Outlook.Service"="C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe" [2007-03-28 11:43 9728]
"Act! Preloader"="C:\Program Files\ACT\ACT for Windows\ActSage.exe" [2007-03-28 11:38 1015808]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 15:16 5058560]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 20:17 443968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 02:56 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Broadband Networking.lnk - C:\WINDOWS\Installer\{8CC15633-2327-43F4-BA85-B83FDB4B59BE}\_18be6784.exe [2006-05-07 20:59:16 25214]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcccab]
efcccab.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJPD HID Control]
--a------ 2003-01-21 17:35 45056 C:\Program Files\Canon\BJPV\TVMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 02:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
--a------ 2002-04-03 01:01 135264 C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 13:39 1289000 C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 2002-11-07 11:58 1167360 C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
--a------ 2002-12-10 19:31 61440 C:\Program Files\Logitech\ImageStudio\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mozilla Quick Launch]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2003-10-06 15:16 5058560 C:\WINDOWS\System32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2003-10-06 15:16 741376 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProDsl.exe]
--a------ 2001-10-03 19:59 118784 C:\WINDOWS\PRODSL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-05-18 20:51 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 01:00 90112 C:\WINDOWS\UpdReg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebCamRT.exe]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CoffeeCup Software\\Free FTP\\FreeFTP.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe"=
"C:\\Program Files\\VoipCheap\\voipcheap.exe"=
"C:\\Program Files\\Microsoft Broadband Networking\\MSBNUtil.exe"=
"C:\\Program Files\\Microsoft Broadband Networking\\MSBNTray.exe"=
"C:\\Program Files\\Microsoft Broadband Networking\\MSBNCfg.exe"=
"C:\\Program Files\\Microsoft Broadband Networking\\MSBNUpdate.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"C:\\Program Files\\ACT\\Act for Windows\\ActSage.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2002-06-05 11:07]
R2 MSSQL$ACT7;SQL Server (ACT7);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sACT7 []
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 06:29]
R3 MSFT43XX;Microsoft Wireless Notebook Adapter Driver;C:\WINDOWS\system32\DRIVERS\mn720-50.sys [2004-06-17 00:02]
R3 PRO2100W;Intel(R) PRO/DSL 2100 Modem - PPP;C:\WINDOWS\system32\DRIVERS\p21c2kW.sys [2001-10-04 20:12]
S1 Cdrdrv;Cdrdrv;C:\WINDOWS\System32\Drivers\Cdrdrv.sys []
S1 vobiw;vobiw;C:\WINDOWS\System32\Drivers\vobIW.sys []
S3 JumpShot;Lexar Media USB Compact Flash Driver;C:\WINDOWS\system32\DRIVERS\LEXAR2K.SYS [2001-10-19 14:57]
S3 NdUsbMsn;ARESCOM USB Network Adapter;C:\WINDOWS\system32\DRIVERS\NdUsbMsn.sys [2001-10-21 03:25]
S3 PIXMCV;JVC Communication PIX-MCV Driver;C:\WINDOWS\system32\Drivers\pixmcvc.sys [2003-12-05 17:39]
S3 PIXMCVA;JVC PIX-MCV Audio Capture;C:\WINDOWS\system32\Drivers\pixmcva.sys [2003-12-05 17:39]
S3 PIXMCVV;JVC PIX-MCV Video Capture;C:\WINDOWS\system32\Drivers\pixmcvv.sys [2003-12-05 17:39]
S4 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2002-11-08 03:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{578f0128-3573-11db-bb61-000d3a6ded8b}]
\Shell\AutoRun\command - F:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-27 05:10:37 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-27 00:08:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Canon\BJCard\Bjmcmng.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
.
**************************************************************************
.
Completion time: 2008-03-27 0:15:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-27 05:15:26
.
2008-03-26 02:07:32 --- E O F ---