ComboFix 08-02-15.1 - Bob 2008-02-24 12:31:49.1 - NTFSx86 Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\wfuwscsr.dll C:\check_LSA7.txt C:\Documents and Settings\All Users\Application Data\salesmonitor C:\Documents and Settings\Bob\Start Menu\Programs\Startup\TA_Start.lnk C:\Documents and Settings\Brad\Start Menu\Programs\Startup\TA_Start.lnk C:\Documents and Settings\Brian\Start Menu\Programs\Startup\ta_start.lnk C:\Documents and Settings\Cindy.KIDS-W04GTXLD67\Start Menu\Programs\Startup\ta_start.lnk C:\Documents and Settings\Elizabeth\Start Menu\Programs\Startup\TA_Start.lnk C:\Documents and Settings\FixedElizabeth\Start Menu\Programs\Startup\ta_start.lnk C:\Temp\fse C:\WINDOWS\cookies.ini C:\WINDOWS\system32\accdd.bak1 C:\WINDOWS\system32\accdd.ini C:\WINDOWS\system32\afetwhrq.dll C:\WINDOWS\system32\ccbeg.bak2 C:\WINDOWS\system32\ccbeg.ini C:\WINDOWS\system32\ccbeg.ini2 C:\WINDOWS\system32\ccbeg.tmp C:\WINDOWS\system32\dgcqdghm.ini C:\WINDOWS\system32\dtcumrqt.ini C:\WINDOWS\system32\edeeg.bak1 C:\WINDOWS\system32\edeeg.ini C:\WINDOWS\system32\eevnmddl.ini C:\WINDOWS\system32\f02WtR C:\WINDOWS\system32\faeiefau.dll C:\WINDOWS\system32\fbmtrjpf.dll C:\WINDOWS\system32\fpjrtmbf.ini C:\WINDOWS\system32\fpnghovx.ini C:\WINDOWS\system32\fynjtrkh.dll C:\WINDOWS\system32\gqjwuwts.ini C:\WINDOWS\system32\jjjlm.bak1 C:\WINDOWS\system32\jjjlm.bak2 C:\WINDOWS\system32\jjjlm.ini C:\WINDOWS\system32\jyvlxgyr.dll C:\WINDOWS\system32\lrcldycn.ini C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\myqnotiq.dll C:\WINDOWS\system32\nycuikle.dll C:\WINDOWS\system32\oqstv.bak1 C:\WINDOWS\system32\oqstv.ini C:\WINDOWS\system32\qytmitjt.ini C:\WINDOWS\system32\rqstv.bak1 C:\WINDOWS\system32\rqstv.ini C:\WINDOWS\system32\rtodkley.dll C:\WINDOWS\system32\rygxlvyj.ini C:\WINDOWS\system32\sehgsnlx.dll C:\WINDOWS\system32\stwuwjqg.dll C:\WINDOWS\system32\tqrmuctd.dll C:\WINDOWS\system32\txlmjqld.dll C:\WINDOWS\system32\uafeieaf.ini C:\WINDOWS\system32\uninstall.exe C:\WINDOWS\system32\utvwa.bak1 C:\WINDOWS\system32\utvwa.ini C:\WINDOWS\system32\wfuwscsr.dll C:\WINDOWS\system32\wfuwscsr.dllbox C:\WINDOWS\system32\windows C:\WINDOWS\system32\xbeeg.bak1 C:\WINDOWS\system32\xbeeg.ini C:\WINDOWS\system32\xhpcmwdy.dll C:\WINDOWS\system32\xvohgnpf.dll C:\WINDOWS\system32\ydwmcphx.ini C:\WINDOWS\system32\yelkdotr.ini C:\WINDOWS\system32\yycdd.bak1 C:\WINDOWS\system32\yycdd.ini . ((((((((((((((((((((((((( Files Created from 2008-01-24 to 2008-02-24 ))))))))))))))))))))))))))))))) . 2008-02-23 01:27 . 2008-02-23 01:27 d-------- C:\Program Files\CCleaner 2008-02-19 21:10 . 2007-08-01 16:47 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-02-19 20:56 . 2008-02-21 00:26 d-------- C:\Documents and Settings\Bob\Application Data\HouseCall 6.6 2008-02-17 12:33 . 2008-02-17 12:33 d-------- C:\Program Files\Lavasoft 2008-02-17 12:33 . 2008-02-17 12:34 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-02-17 12:32 . 2008-02-17 12:32 d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-02-17 09:28 . 2008-02-17 23:25 453 ---hs---- C:\WINDOWS\system32\ycbeg.ini 2008-02-16 20:04 . 2008-02-16 21:10 414 ---hs---- C:\WINDOWS\system32\xyadd.ini 2008-02-16 15:39 . 2008-02-17 04:05 d-------- C:\Program Files\a-squared Free 2008-02-16 00:44 . 2008-02-16 00:44 d-------- C:\Temp\pnet 2008-02-15 00:14 . 2008-02-21 00:47 d-------- C:\HighjackThis 2008-02-14 21:12 . 2008-02-14 21:12 d-------- C:\Documents and Settings\Bob\Application Data\Seven Zip 2008-02-14 21:12 . 2008-02-14 21:13 d-------- C:\Documents and Settings\All Users\Application Data\{B192D4FB-BECF-4AA5-92DC-DA82DABF79FA} 2008-02-14 21:09 . 2008-02-14 21:09 d-------- C:\Program Files\NZCSM 2008-02-14 21:01 . 2008-02-14 21:12 d-------- C:\Program Files\Cosmi 2008-02-13 06:18 . 2008-02-23 01:19 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-02-13 06:18 . 2008-02-13 06:18 1,409 --a------ C:\WINDOWS\QTFont.for 2008-02-13 06:16 . 2008-02-13 06:17 d-------- C:\Program Files\iTunes 2008-02-13 06:14 . 2008-02-13 06:14 d-------- C:\Program Files\Bonjour 2008-02-13 06:09 . 2008-02-13 06:09 d-------- C:\Program Files\Apple Software Update 2008-02-13 06:08 . 2008-02-13 06:08 d-------- C:\Program Files\Common Files\Apple 2008-02-13 06:08 . 2008-02-13 06:08 d-------- C:\Documents and Settings\All Users\Application Data\Apple 2008-02-11 16:21 . 2008-02-11 16:21 d-------- C:\WINDOWS\LHSP 2008-02-11 16:21 . 2008-02-11 16:21 d-------- C:\Program Files\eLanguage 2008-02-11 16:21 . 2008-02-11 16:21 d-------- C:\HGASRAPI 2008-02-11 16:21 . 2008-02-13 17:27 153,200 --a------ C:\WINDOWS\PSPRT.INI 2008-02-11 16:21 . 1997-04-14 20:27 81,920 --a------ C:\WINDOWS\ASR32311.DLL 2008-02-11 16:21 . 2008-02-13 17:27 82 --a------ C:\WINDOWS\PSPRTGEN.INI 2008-02-11 16:21 . 2008-02-11 16:21 70 --a------ C:\WINDOWS\HGSpeech.ini 2008-02-03 11:00 . 2008-02-03 11:00 1,630,840 --ahs---- C:\WINDOWS\system32\xpjbgdue.ini 2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx 2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts 2008-01-30 22:26 . 2008-02-03 11:00 1,651,353 --ahs---- C:\WINDOWS\system32\hjoexhtj.ini 2008-01-30 21:44 . 2008-01-30 22:03 249,133 --a------ C:\WINDOWS\system32\qstwa.tmp 2008-01-30 20:07 . 2008-01-30 22:13 1,931,276 --ahs---- C:\WINDOWS\system32\uhynkhvv.ini 2008-01-30 19:50 . 2008-01-30 19:50 13,942 --a------ C:\WINDOWS\system32\iphone-012.ico 2008-01-30 19:35 . 2008-01-30 19:35 4,286 --a------ C:\WINDOWS\system32\cruise-006.ico 2008-01-30 19:34 . 2008-01-30 19:34 13,942 --a------ C:\WINDOWS\system32\iphone-011.ico 2008-01-28 22:13 . 2008-01-30 20:04 1,930,704 --ahs---- C:\WINDOWS\system32\rvlbjeqs.ini . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-23 07:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-02-15 12:26 --------- d-----w C:\Program Files\Spybot - Search & Destroy 2008-02-13 12:17 --------- d-----w C:\Program Files\iPod 2008-02-13 12:14 --------- d-----w C:\Program Files\QuickTime 2008-02-02 03:50 28,256 ----a-w C:\WINDOWS\system32\drivers\MxlW2k.sys 2008-01-29 06:01 --------- d-----w C:\Program Files\Dictionary 2008-01-13 21:51 --------- d-----w C:\Program Files\Common Files\AOL 2008-01-13 21:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL 2007-06-05 02:12 32 --sha-w C:\WINDOWS\{28F43F3B-6994-41A6-A4A7-7B3CD06C896C}.dat 2004-02-16 01:20 0 --sha-w C:\WINDOWS\SMINST\HPCD.sys 2007-11-14 05:16 645,577 --sha-w C:\WINDOWS\system32\ehhkj.bak1 2007-11-14 04:08 645,577 --sha-w C:\WINDOWS\system32\utstv.bak1 2007-06-05 02:12 32 --sha-w C:\WINDOWS\system32\{AE227DC5-2D19-4810-B93C-3FC9C8166D9E}.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07F0720A-25A2-424F-8316-AD5BA77E15D1}] C:\WINDOWS\system32\gebcc.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DBB63805-95A9-44CC-8D52-B6B83CED0C6A}] C:\WINDOWS\system32\gebcy.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E75AE316-C653-417D-9191-9ECC047B7D8A}] C:\WINDOWS\system32\ddayx.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RecordNow!"="" [] "NVIEW"="nview.dll" [2003-08-19 03:56 852038 C:\WINDOWS\system32\nview.dll] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208] "MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 20:00 200704] "Aim6"="C:\Program Files\AIM6\aim6.exe" [ ] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736] "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 08:07 114688] "CamMonitor"="c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 08:23 90112] "HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [ ] "HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 03:55 483328] "KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 21:02 61440] "UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 09:01 110592] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2003-10-11 06:07 151597] "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 22:42 212992] "VTTimer"="VTTimer.exe" [2005-03-08 03:33 53248 C:\WINDOWS\system32\VTTimer.exe] "LTMSG"="LTMSG.exe" [2003-07-14 18:52 40960 C:\WINDOWS\ltmsg.exe] "mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2003-07-23 17:37 53248] "NeroCheck"="C:\WINDOWS\System32\NeroCheck.exe" [2001-07-09 12:50 155648] "Propel Accelerator"="C:\Program Files\AT&T Worldnet Accelerator\trayctl.exe" [2004-03-01 16:37 28672] "VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 17:18 151552] "VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 11:49 163840] "OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 21:02 53248] "MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29 303104] "MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05 212992] "Atari Launcher"="C:\Program Files\Hasbro Interactive\Atari Arcade Hits 1\Atari icon.exe" [1999-06-25 15:41 49664] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 14:18 267048] C:\Documents and Settings\Brian\Start Menu\Programs\Startup\ PowerReg Scheduler V3.exe [2004-02-28 15:40:09 225280] C:\Documents and Settings\Cindy.KIDS-W04GTXLD67\Start Menu\Programs\Startup\ PowerReg Scheduler V3.exe [2004-05-02 16:05:18 225280] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2003-10-11 06:42:56 16384] HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 09:20:40 233472] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkkjgh] jkkkjgh.dll . Contents of the 'Scheduled Tasks' folder "2008-02-15 00:57:20 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2004-01-27 21:22:36 C:\WINDOWS\Tasks\Easy Internet Sign-up.job" - C:\Program Files\Easy Internet signup\HPSdpApp.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-24 12:51:30 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\a-squared Free\a2service.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\wscntfy.exe . ************************************************************************** . Completion time: 2008-02-24 12:57:28 - machine was rebooted ComboFix-quarantined-files.txt 2008-02-24 18:57:23