ComboFix 08-12-05.02 - markw 2008-12-05 19:37:59.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.513 [GMT -7:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat c:\windows\IE4 Error Log.txt c:\windows\system32\~.exe c:\windows\system32\abuwedeb.ini c:\windows\system32\azagurof.ini c:\windows\system32\bedewuba.dll c:\windows\system32\bigitita.dll c:\windows\system32\bozahuvo.dll c:\windows\system32\digolefo.dll c:\windows\system32\drivers\fad.sys c:\windows\system32\ehutonuf.ini c:\windows\system32\ejegepum.ini c:\windows\system32\epefuhoh.ini c:\windows\system32\fewiboje.dll c:\windows\system32\fihonabe.dll c:\windows\system32\forugaza.dll c:\windows\system32\funotuhe.dll c:\windows\system32\getazete.dll c:\windows\system32\gobogizu.dll c:\windows\system32\gumejisi.dll c:\windows\system32\hohufepe.dll c:\windows\system32\ikuduhom.ini c:\windows\system32\inajotum.ini c:\windows\system32\isijemug.ini c:\windows\system32\jonefede.dll c:\windows\system32\kopohoyo.dll c:\windows\system32\kufomahi.dll c:\windows\system32\letuyami.dll c:\windows\system32\lojonuda.dll c:\windows\system32\modisemi.dll c:\windows\system32\mohuduki.dll c:\windows\system32\mupegeje.dll c:\windows\system32\mutojani.dll c:\windows\system32\nawiwodu.dll c:\windows\system32\nijapuzu.dll c:\windows\system32\odusozej.ini c:\windows\system32\polugise.dll c:\windows\system32\retotiwe.dll c:\windows\system32\revemivu.dll c:\windows\system32\tamewoli.dll c:\windows\system32\tayudupi.dll c:\windows\system32\tolerabi.dll c:\windows\system32\tubigure.dll c:\windows\system32\uvimunew.ini c:\windows\system32\uzupajin.ini c:\windows\system32\vekajipi.dll c:\windows\system32\wenumivu.dll c:\windows\system32\wutiporu.dll c:\windows\system32\yodivuwo.dll c:\windows\system32\yokuwalu.dll c:\windows\system32\yorejego.dll c:\windows\system32\zaleluna.dll c:\windows\system32\zobekota.dll ----- BITS: Possible infected sites ----- hxxp://77.74.48.105 . ((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 ))))))))))))))))))))))))))))))) . 2008-12-05 19:08 . 2008-12-05 19:08 d-------- C:\Temp 2008-12-05 19:00 . 2008-12-05 19:00 268 --ah----- C:\sqmdata17.sqm 2008-12-05 19:00 . 2008-12-05 19:00 244 --ah----- C:\sqmnoopt17.sqm 2008-11-30 17:36 . 2008-11-30 17:36 268 --ah----- C:\sqmdata16.sqm 2008-11-30 17:36 . 2008-11-30 17:36 244 --ah----- C:\sqmnoopt16.sqm 2008-11-30 14:43 . 2008-11-30 14:43 0 --a------ c:\windows\nsreg.dat 2008-11-26 08:16 . 2008-11-26 08:16 d-------- c:\windows\system32\config\systemprofile\Application Data\alot 2008-11-24 12:54 . 2008-11-24 12:54 268 --ah----- C:\sqmdata15.sqm 2008-11-24 12:54 . 2008-11-24 12:54 244 --ah----- C:\sqmnoopt15.sqm 2008-11-15 19:16 . 2008-11-15 19:16 268 --ah----- C:\sqmdata14.sqm 2008-11-15 19:16 . 2008-11-15 19:16 244 --ah----- C:\sqmnoopt14.sqm 2008-11-15 18:29 . 2008-11-15 18:29 268 --ah----- C:\sqmdata13.sqm 2008-11-15 18:29 . 2008-11-15 18:29 244 --ah----- C:\sqmnoopt13.sqm 2008-11-15 17:26 . 2008-11-15 17:26 268 --ah----- C:\sqmdata12.sqm 2008-11-15 17:26 . 2008-11-15 17:26 244 --ah----- C:\sqmnoopt12.sqm 2008-11-15 16:58 . 2008-11-15 16:58 268 --ah----- C:\sqmdata11.sqm 2008-11-15 16:58 . 2008-11-15 16:58 244 --ah----- C:\sqmnoopt11.sqm 2008-11-13 12:47 . 2008-11-13 12:47 268 --ah----- C:\sqmdata10.sqm 2008-11-13 12:47 . 2008-11-13 12:47 244 --ah----- C:\sqmnoopt10.sqm 2008-11-08 21:14 . 2008-11-08 21:14 268 --ah----- C:\sqmdata09.sqm 2008-11-08 21:14 . 2008-11-08 21:14 244 --ah----- C:\sqmnoopt09.sqm 2008-11-08 15:02 . 2008-11-30 15:27 238 --a------ c:\windows\mafosav.INI 2008-11-08 15:00 . 2008-11-08 15:00 d-------- c:\program files\GameTop.com . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-06 02:06 --------- d-----w c:\program files\AIM 2008-12-06 02:06 --------- d-----w c:\documents and settings\markw\Application Data\Aim 2008-12-01 01:14 --------- d-----w c:\documents and settings\Sarah\Application Data\Smilebox 2008-12-01 01:05 --------- d-----w c:\program files\Java 2008-12-01 00:55 --------- d-----w c:\program files\CoCreate 2008-12-01 00:36 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2008-12-01 00:10 --------- d-----w c:\program files\Trend Micro 2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-20 22:18 --------- d-----w c:\program files\Microsoft Silverlight 2008-10-11 02:27 0 ---ha-w c:\windows\system32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf 2008-10-11 02:27 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf 2008-10-11 02:25 0 ---ha-w c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf 2008-10-06 02:48 --------- d-----w c:\program files\Zune 2008-01-05 10:59 724,984 ----a-w c:\documents and settings\markw\gotomypc_437.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496] "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 53248] "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-06 110592] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-05 127035] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-01 98304] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152] "tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2007-03-07 1773568] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2006-10-23 40048] "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-09-12 160160] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-14 217193] Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-07-19 113664] Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048] Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2007-05-11 738968] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624] HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-11 73728] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless] 2004-09-07 14:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Diet Analysis Plus 7.0.1\\jre1.5.0_01\\bin\\javaw.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\WINDOWS\\system32\\ftp.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= R2 tmevtmgr;tmevtmgr;\??\c:\windows\system32\drivers\tmevtmgr.sys [2008-04-26 52240] R2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2008-02-15 36368] R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-01-09 24652] R3 GTIPCI21;GTIPCI21;c:\windows\system32\DRIVERS\gtipci21.sys [2005-08-11 80384] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2008-02-15 333328] R3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~3\TmPfw.exe [2008-04-26 488768] R3 tmproxy;Trend Micro Proxy Service;"c:\program files\Trend Micro\Internet Security\TmProxy.exe" [2008-04-26 648456] S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\DRIVERS\OVCE.sys [2006-06-20 31872] . - - - - ORPHANS REMOVED - - - - BHO-{4209c1f6-b9da-45d7-993b-04204da36f26} - c:\windows\system32\gobogizu.dll HKCU-Run-Yahoo! Pager - c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mStart Page = hxxp://www.yahoo.com/ mWindow Title = Windows Internet Explorer provided by Comcast mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 c:\windows\Downloaded Program Files\SbCIe02a.dll - O16 -: {640B39C1-D713-464F-92C3-75BD972B95EE} hxxp://www.sidestep.com/get/k42037/sb02a.cab c:\windows\Downloaded Program Files\SbCIe02a.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-05 19:44:22 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1500) c:\program files\Intel\Wireless\Bin\LgNotify.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Intel\Wireless\Bin\WLKEEPER.exe c:\windows\system32\scardsvr.exe c:\windows\system32\BAsfIpM.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe c:\windows\system32\HPZipm12.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\program files\Trend Micro\Internet Security\SfCtlCom.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\windows\system32\ZuneBusEnum.exe c:\program files\Trend Micro\BM\TMBMSRV.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\progra~1\Intel\Wireless\Bin\1XConfig.exe c:\program files\Zune\ZuneNss.exe c:\windows\system32\igfxsrvc.exe c:\program files\Apoint\ApntEx.exe c:\program files\HP\Digital Imaging\bin\hpqimzone.exe . ************************************************************************** . Completion time: 2008-12-05 19:51:35 - machine was rebooted [markw] ComboFix-quarantined-files.txt 2008-12-06 02:51:30 Pre-Run: 15,728,119,808 bytes free Post-Run: 17,004,797,952 bytes free 236 --- E O F --- 2008-11-13 19:15:21