ComboFix 08-09-12.03 - Mom 2008-09-12 19:51:33.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.567 [GMT -4:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Mom\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Dad\Cookies\[removed][1].txt C:\Documents and Settings\Family\Cookies\[removed][1].txt C:\Documents and Settings\Family\Cookies\[removed][2].txt C:\Documents and Settings\Family\Cookies\[removed][4].txt C:\Documents and Settings\Family\Cookies\family@advertising[2].txt C:\Documents and Settings\Family\Cookies\[removed][1].txt C:\Documents and Settings\Family\Cookies\family@insightexpressai[2].txt C:\Documents and Settings\Family\Cookies\family@trafficmp[2].txt C:\WINDOWS\Install.txt C:\WINDOWS\system32\90.exe C:\WINDOWS\system32\afisicx.exe C:\WINDOWS\system32\atsxyzd.sys C:\WINDOWS\system32\comsa32.sys C:\WINDOWS\system32\inf\svchoct.exe C:\WINDOWS\system32\inf\svchosd.exe C:\WINDOWS\system32\mabidwe.exe C:\WINDOWS\system32\mmchost.dll C:\WINDOWS\system32\mywfhit.ini C:\WINDOWS\system32\mywfhit.ini.tmp C:\WINDOWS\system32\noytcyr.exe C:\WINDOWS\system32\roytctm.exe C:\WINDOWS\system32\rtl60.bpl C:\WINDOWS\system32\soxpeca.exe C:\WINDOWS\system32\syspilog.pil C:\WINDOWS\system32\tdydowkc.exe C:\WINDOWS\system32\tmpacj0.exe C:\WINDOWS\system32\tpszxyd.sys C:\WINDOWS\system32\wsldoekd.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_AFISICX -------\Legacy_MABIDWE -------\Legacy_NOYTCYR -------\Legacy_PACKET -------\Legacy_PANDRV -------\Legacy_ROYTCTM -------\Legacy_SEUICTOL -------\Legacy_SOXPECA -------\Legacy_TDYDOWKC -------\Legacy_WSLDOEKD -------\Service_afisicx -------\Service_mabidwe -------\Service_noytcyr -------\Service_Packet -------\Service_roytctm -------\Service_seuictol -------\Service_soxpeca -------\Service_tdydowkc -------\Service_wsldoekd ((((((((((((((((((((((((( Files Created from 2008-08-13 to 2008-09-13 ))))))))))))))))))))))))))))))) . 2008-09-12 20:02 . 2008-09-12 20:02 244,224 --a------ C:\WINDOWS\dcbdcatys32_080913a.dll 2008-09-12 20:02 . 2008-09-12 20:02 36,352 --a------ C:\WINDOWS\wftadfi16_080913a.dll 2008-09-12 17:29 . 2008-09-12 17:29 61,224 --a------ C:\Documents and Settings\Mom\GoToAssistDownloadHelper.exe 2008-09-12 17:04 . 2008-09-12 17:04 d-------- C:\lspfix 2008-09-12 16:56 . 2008-09-12 16:56 d-------- C:\Program Files\Common Files\Adobe AIR 2008-09-12 16:54 . 2008-09-12 16:54 d-------- C:\Program Files\NOS 2008-09-12 16:54 . 2008-09-12 16:55 d-------- C:\Documents and Settings\All Users\Application Data\NOS 2008-09-10 00:02 . 2008-09-10 00:21 d-------- C:\Program Files\e-texaspoker client 2008-09-03 19:31 . 2008-09-03 19:31 d-------- C:\Documents and Settings\Mom\Application Data\McAfee 2008-09-03 19:27 . 2006-03-03 08:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll 2008-09-03 19:27 . 2008-09-12 20:03 15,327 --a------ C:\WINDOWS\system32\Config.MPF 2008-09-03 19:25 . 2008-09-03 19:25 d-------- C:\Program Files\McAfee.com 2008-09-03 19:25 . 2008-09-12 10:51 d-------- C:\Program Files\McAfee 2008-09-03 19:25 . 2008-09-03 19:25 d-------- C:\Program Files\Common Files\McAfee 2008-09-03 19:25 . 2007-11-22 06:44 201,320 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys 2008-09-03 19:25 . 2007-07-13 06:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys 2008-09-03 19:25 . 2007-11-22 06:44 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys 2008-09-03 19:25 . 2007-12-02 12:51 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys 2008-09-03 19:25 . 2007-11-22 06:44 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys 2008-09-03 19:25 . 2007-11-22 06:44 33,832 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys 2008-09-03 19:04 . 2006-10-17 13:06 78,336 --a------ C:\WINDOWS\system32\ieencode.dll 2008-09-03 19:04 . 2006-10-17 13:06 78,336 --a------ C:\WINDOWS\system32\dllcache\ieencode.dll 2008-09-03 18:56 . 2008-09-03 19:31 d-------- C:\Documents and Settings\All Users\Application Data\McAfee 2008-09-03 18:09 . 2008-09-03 18:09 d-------- C:\Program Files\Trend Micro 2008-09-01 18:00 . 2008-09-01 18:01 d-------- C:\Program Files\iTunes 2008-09-01 18:00 . 2008-09-01 18:00 d-------- C:\Program Files\iPod 2008-09-01 17:54 . 2008-09-01 17:54 d-------- C:\Program Files\Safari 2008-08-17 21:17 . 2008-09-12 20:05 d-------- C:\WINDOWS\system32\inf 2008-08-13 19:22 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-09-13 00:05 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-09-11 02:54 1,740 ----a-w C:\Documents and Settings\Mom\Application Data\wklnhst.dat 2008-09-10 04:21 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-09-07 12:46 --------- d-----w C:\Documents and Settings\Mom\Application Data\Apple Computer 2008-09-03 22:30 --------- d-----w C:\Program Files\BAE 2008-09-02 02:44 --------- d-----w C:\Program Files\Yahoo! 2008-09-02 02:43 --------- d-----w C:\Program Files\GemMaster 2008-09-02 01:33 --------- d-----w C:\Program Files\Dl_cats 2008-09-02 01:25 --------- d-----w C:\Program Files\Picasa2 2008-09-01 22:04 --------- d-----w C:\Program Files\Apple Software Update 2008-09-01 20:37 --------- d-----w C:\Documents and Settings\Mom\Application Data\Corel 2008-07-23 00:32 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys 2007-07-05 22:19 251 ----a-w C:\Program Files\wt3d.ini 2006-12-17 20:12 0 ---ha-w C:\Documents and Settings\All Users\Application Data\gwseh.dat . ------- Sigcheck ------- 2007-07-30 19:19 53080 9f2bebcd1a03cf6ff447f756458cb8d0 C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 53080 f3e9065eb617a7e3a832a7976bfa021b C:\WINDOWS\system32\dllcache\wuauclt.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-19 68856] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 50736] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-16 7323648] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552] "DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208] "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940] "DLCFCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2005-09-08 73728] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-17 180269] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920] "itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184] "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-17 236544] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 67584] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344] "SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 C:\WINDOWS\stsystra.exe] "Mouse Suite 98 Daemon"="ICO.EXE" [2006-10-23 C:\WINDOWS\system32\ico.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160] C:\Documents and Settings\Mom\Start Menu\Programs\Startup\ V CAST Music Monitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe [2005-11-30 327680] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-12-17 7168] Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-17 24576] HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\WINDOWS\\system32\\dlcfcoms.exe"= "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlcfpswx.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "135:TCP"= 135:TCP:TCP Port 135 "5000:TCP"= 5000:TCP:TCP Port 5000 "5001:TCP"= 5001:TCP:TCP Port 5001 "5002:TCP"= 5002:TCP:TCP Port 5002 "5003:TCP"= 5003:TCP:TCP Port 5003 "5004:TCP"= 5004:TCP:TCP Port 5004 "5005:TCP"= 5005:TCP:TCP Port 5005 "5006:TCP"= 5006:TCP:TCP Port 5006 "5007:TCP"= 5007:TCP:TCP Port 5007 "5008:TCP"= 5008:TCP:TCP Port 5008 "5009:TCP"= 5009:TCP:TCP Port 5009 "5010:TCP"= 5010:TCP:TCP Port 5010 "5011:TCP"= 5011:TCP:TCP Port 5011 "5012:TCP"= 5012:TCP:TCP Port 5012 "5013:TCP"= 5013:TCP:TCP Port 5013 "5014:TCP"= 5014:TCP:TCP Port 5014 "5015:TCP"= 5015:TCP:TCP Port 5015 "5016:TCP"= 5016:TCP:TCP Port 5016 "5017:TCP"= 5017:TCP:TCP Port 5017 "5018:TCP"= 5018:TCP:TCP Port 5018 "5019:TCP"= 5019:TCP:TCP Port 5019 "5020:TCP"= 5020:TCP:TCP Port 5020 "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol "10426:UDP"= 10426:UDP:SingleClick ICC R1 NEOFLTR_550_12029;Juniper Networks TDI Filter Driver (NEOFLTR_550_12029);C:\WINDOWS\system32\Drivers\NEOFLTR_550_12029.SYS [2007-08-23 63008] R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2005-05-19 70016] R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652] R3 pelmouse;Mouse Suite Driver;C:\WINDOWS\system32\DRIVERS\pelmouse.sys [2007-04-17 18944] R3 pelusblf;USB Mouse Low Filter Driver;C:\WINDOWS\system32\DRIVERS\pelusblf.sys [2007-04-11 17920] S3 getPlus(R) Helper;getPlus(R) Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752] S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2006-06-05 24064] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}] \Shell\AutoRun\command - E:\setup.exe . Contents of the 'Scheduled Tasks' folder . - - - - ORPHANS REMOVED - - - - HKLM-Run-SDTray - C:\Program Files\Spyware Doctor\SDTrayApp.exe HKLM-Explorer_Run-minyust - C:\WINDOWS\system32\inf\svchoct.exe . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\fkxo1640.default\ FF -: plugin - C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\fkxo1640.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}\plugins\np_gp.dll FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\np_gp.dll FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPXPEE.dll FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-09-12 20:04:41 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... C:\WINDOWS\Install.txt C:\WINDOWS\system32\90.exe 53080 bytes executable C:\WINDOWS\system32\afisicx.exe 43520 bytes executable C:\WINDOWS\system32\tdydowkc.exe 44544 bytes executable C:\WINDOWS\system32\mabidwe.exe 44032 bytes executable C:\WINDOWS\system32\noytcyr.exe 44544 bytes executable scan completed successfully hidden files: 6 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\tsd32.dll . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\ehome\ehrecvr.exe C:\WINDOWS\ehome\ehSched.exe C:\Program Files\Dell Network Assistant\hnm_svc.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe C:\WINDOWS\system32\LxrSII1s.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\Qoobox\Quarantine\C\WINDOWS\system32\tpszxyd.sys.vir C:\WINDOWS\system32\PELMICED.EXE C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe C:\WINDOWS\ehome\ehmsas.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\AIM6\aolsoftware.exe C:\PROGRA~1\McAfee\MSC\mcuimgr.exe C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe C:\Program Files\McAfee\MPF\MpfSrv.exe C:\WINDOWS\system32\udxfytw.sys . ************************************************************************** . Completion time: 2008-09-12 20:14:43 - machine was rebooted [Mom] ComboFix-quarantined-files.txt 2008-09-13 00:14:34 Pre-Run: 114,644,578,304 bytes free Post-Run: 117,141,557,248 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect 307 --- E O F --- 2008-08-14 07:01:42