ComboFix 08-02-17.2 - Owner 2008-02-17 12:56:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.463 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\jkkji.dll
C:\Documents and Settings\Owner\Local Settings\Temp\sdexe.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\mcroso~1.net
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\wininstall.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\aatbbxmj.ini
C:\WINDOWS\system32\amwauxrw.ini
C:\WINDOWS\system32\axkklufo.dll
C:\WINDOWS\system32\axqmbvhe.dll
C:\WINDOWS\system32\barmhjfr.dll
C:\WINDOWS\system32\bfaqineu.dll
C:\WINDOWS\system32\brdcjkcm.dll
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\cvmingbw.dll
C:\WINDOWS\system32\djpsokgx.ini
C:\WINDOWS\system32\ecxjkdyw.ini
C:\WINDOWS\system32\erfcanym.dll
C:\WINDOWS\system32\fdesaggl.dll
C:\WINDOWS\system32\ftsbdwpj.ini
C:\WINDOWS\system32\fuyfqurl.ini
C:\WINDOWS\system32\gbbpjgtm.ini
C:\WINDOWS\system32\gdxjihut.dll
C:\WINDOWS\system32\hhgxkxeh.dll
C:\WINDOWS\system32\hhjlunnq.dll
C:\WINDOWS\system32\ijkkj.ini
C:\WINDOWS\system32\ijkkj.ini2
C:\WINDOWS\system32\jkbccgxt.ini
C:\WINDOWS\system32\jkkji.dll
C:\WINDOWS\system32\jkkji.exe
C:\WINDOWS\system32\lbifqeeq.ini
C:\WINDOWS\system32\ludeblni.ini
C:\WINDOWS\system32\mdhdavnh.dll
C:\WINDOWS\system32\nueeptlt.ini
C:\WINDOWS\system32\oqxkqman.dll
C:\WINDOWS\system32\paujqpfv.dll
C:\WINDOWS\system32\pbbkmryh.ini
C:\WINDOWS\system32\pjrtagax.dll
C:\WINDOWS\system32\qbskcsfw.dll
C:\WINDOWS\system32\qclfjoep.dll
C:\WINDOWS\system32\qmpoccmj.dll
C:\WINDOWS\system32\qydyntco.dll
C:\WINDOWS\system32\RCX15.tmp
C:\WINDOWS\system32\RCX16.tmp
C:\WINDOWS\system32\RCX1B.tmp
C:\WINDOWS\system32\RCX1C.tmp
C:\WINDOWS\system32\RCX1D.tmp
C:\WINDOWS\system32\RCX1E.tmp
C:\WINDOWS\system32\RCX1F.tmp
C:\WINDOWS\system32\RCX20.tmp
C:\WINDOWS\system32\RCX21.tmp
C:\WINDOWS\system32\RCX22.tmp
C:\WINDOWS\system32\RCX23.tmp
C:\WINDOWS\system32\RCX24.tmp
C:\WINDOWS\system32\RCX26.tmp
C:\WINDOWS\system32\RCX27.tmp
C:\WINDOWS\system32\RCX28.tmp
C:\WINDOWS\system32\RCX29.tmp
C:\WINDOWS\system32\RCX2A.tmp
C:\WINDOWS\system32\RCX2B.tmp
C:\WINDOWS\system32\RCX2C.tmp
C:\WINDOWS\system32\RCX2D.tmp
C:\WINDOWS\system32\RCX2E.tmp
C:\WINDOWS\system32\RCX2F.tmp
C:\WINDOWS\system32\RCX30.tmp
C:\WINDOWS\system32\RCX31.tmp
C:\WINDOWS\system32\RCX3F.tmp
C:\WINDOWS\system32\RCX9.tmp
C:\WINDOWS\system32\RCXA.tmp
C:\WINDOWS\system32\RCXF.tmp
C:\WINDOWS\system32\suyhnejw.dll
C:\WINDOWS\system32\sxcpsacd.ini
C:\WINDOWS\system32\tqvmcshd.dll
C:\WINDOWS\system32\ueniqafb.ini
C:\WINDOWS\system32\uvintcke.dll
C:\WINDOWS\system32\uxvutevp.dll
C:\WINDOWS\system32\vfpqjuap.ini
C:\WINDOWS\system32\vwknqmpc.ini
C:\WINDOWS\system32\wfbrfnlu.ini
C:\WINDOWS\system32\wfscksbq.ini
C:\WINDOWS\system32\wnstsicom32.exe
C:\WINDOWS\system32\wywircbp.ini
C:\WINDOWS\system32\yllwvorn.ini
C:\WINDOWS\system32\yucpgiok.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-01-17 to 2008-02-17 )))))))))))))))))))))))))))))))
.
2008-02-16 21:04 . 2008-02-16 21:05 <DIR> d-------- C:\ininstall_list
2008-02-15 19:51 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-02-15 19:32 . 2008-02-15 19:32 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-15 19:32 . 2008-02-15 19:32 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-14 21:08 . 2008-02-17 12:51 13,243 --a------ C:\WINDOWS\BMb74ae4e1.xml
2008-02-14 21:08 . 2008-02-17 12:48 22 --a------ C:\WINDOWS\pskt.ini
2008-02-13 21:14 . 2008-02-14 18:44 474 --ahs---- C:\WINDOWS\system32\byrxrgcg.ini
2008-02-08 22:28 . 2008-02-09 23:57 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-08 22:28 . 2008-02-08 22:28 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-19 22:40 . 2008-01-19 22:40 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-01-19 22:33 . 2008-01-19 22:33 <DIR> d-------- C:\Documents and Settings\Owner\.SunDownloadManager
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-17 17:59 --------- d-----w C:\Program Files\QuickTime
2008-02-16 04:57 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-02-16 02:57 --------- d-----w C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-02-12 01:47 --------- d-----w C:\Documents and Settings\Guest\Application Data\OpenOffice.org2
2008-02-12 01:45 --------- d-----w C:\Program Files\Digital Media Reader
2008-02-10 02:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-09 03:00 --------- d-----w C:\Program Files\LimeWire
2008-01-20 03:39 --------- d-----w C:\Program Files\Real
2008-01-20 03:39 --------- d-----w C:\Program Files\Common Files\Real
2008-01-12 03:52 --------- d-----w C:\Documents and Settings\Guest\Application Data\Talkback
2008-01-05 04:14 --------- d-----w C:\Documents and Settings\Owner\Application Data\Talkback
2007-12-31 04:51 380,416 ----a-w C:\WINDOWS\mrofinu11.exe.tmp
2007-12-30 16:42 --------- d-----w C:\Program Files\DB2000V3
2007-12-30 16:19 --------- d-----w C:\Program Files\Trend Micro
2007-12-30 16:03 --------- d-----w C:\Program Files\Lavasoft
2007-12-30 16:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
.
- Code: Select all
<pre>
----a-w 313,472 2008-02-17 17:48:43 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
----a-w 339,968 2008-02-17 17:48:35 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w 185,896 2008-02-17 17:48:40 C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w 32,768 2008-01-03 02:54:11 C:\Program Files\CyberLink\PowerDVD\PDVDServ .exe
----a-w 135,168 2008-02-10 22:36:25 C:\Program Files\Digital Media Reader\shwiconem .exe
----a-w 98,304 2008-01-04 22:18:25 C:\Program Files\QuickTime\qttask .exe
----a-w 15,360 2007-12-31 04:51:35 C:\WINDOWS\system32\ctfmon .exe
----a-w 155,648 2007-12-31 02:47:59 C:\WINDOWS\system32\NeroCheck .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-01-25 21:42:22 61440]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2006-04-14 09:39:27 729088]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
"2006-07-30 23:59:34 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2006-07-30 23:59:35 C:\WINDOWS\Tasks\ISP signup reminder 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2006-07-30 23:59:35 C:\WINDOWS\Tasks\ISP signup reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-17 13:11:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\Ati2evxx.exe
.
**************************************************************************
.
Completion time: 2008-02-17 13:13:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-17 18:12:52
.
2008-02-13 21:08:50 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:15, on 2008-02-17
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
--
End of file - 2667 bytes