ComboFix 08-12-05.02 - markw 2008-12-05 19:37:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.513 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\~.exe
c:\windows\system32\abuwedeb.ini
c:\windows\system32\azagurof.ini
c:\windows\system32\bedewuba.dll
c:\windows\system32\bigitita.dll
c:\windows\system32\bozahuvo.dll
c:\windows\system32\digolefo.dll
c:\windows\system32\drivers\fad.sys
c:\windows\system32\ehutonuf.ini
c:\windows\system32\ejegepum.ini
c:\windows\system32\epefuhoh.ini
c:\windows\system32\fewiboje.dll
c:\windows\system32\fihonabe.dll
c:\windows\system32\forugaza.dll
c:\windows\system32\funotuhe.dll
c:\windows\system32\getazete.dll
c:\windows\system32\gobogizu.dll
c:\windows\system32\gumejisi.dll
c:\windows\system32\hohufepe.dll
c:\windows\system32\ikuduhom.ini
c:\windows\system32\inajotum.ini
c:\windows\system32\isijemug.ini
c:\windows\system32\jonefede.dll
c:\windows\system32\kopohoyo.dll
c:\windows\system32\kufomahi.dll
c:\windows\system32\letuyami.dll
c:\windows\system32\lojonuda.dll
c:\windows\system32\modisemi.dll
c:\windows\system32\mohuduki.dll
c:\windows\system32\mupegeje.dll
c:\windows\system32\mutojani.dll
c:\windows\system32\nawiwodu.dll
c:\windows\system32\nijapuzu.dll
c:\windows\system32\odusozej.ini
c:\windows\system32\polugise.dll
c:\windows\system32\retotiwe.dll
c:\windows\system32\revemivu.dll
c:\windows\system32\tamewoli.dll
c:\windows\system32\tayudupi.dll
c:\windows\system32\tolerabi.dll
c:\windows\system32\tubigure.dll
c:\windows\system32\uvimunew.ini
c:\windows\system32\uzupajin.ini
c:\windows\system32\vekajipi.dll
c:\windows\system32\wenumivu.dll
c:\windows\system32\wutiporu.dll
c:\windows\system32\yodivuwo.dll
c:\windows\system32\yokuwalu.dll
c:\windows\system32\yorejego.dll
c:\windows\system32\zaleluna.dll
c:\windows\system32\zobekota.dll
----- BITS: Possible infected sites -----
hxxp://77.74.48.105
.
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.
2008-12-05 19:08 . 2008-12-05 19:08
d-------- C:\Temp
2008-12-05 19:00 . 2008-12-05 19:00 268 --ah----- C:\sqmdata17.sqm
2008-12-05 19:00 . 2008-12-05 19:00 244 --ah----- C:\sqmnoopt17.sqm
2008-11-30 17:36 . 2008-11-30 17:36 268 --ah----- C:\sqmdata16.sqm
2008-11-30 17:36 . 2008-11-30 17:36 244 --ah----- C:\sqmnoopt16.sqm
2008-11-30 14:43 . 2008-11-30 14:43 0 --a------ c:\windows\nsreg.dat
2008-11-26 08:16 . 2008-11-26 08:16 d-------- c:\windows\system32\config\systemprofile\Application Data\alot
2008-11-24 12:54 . 2008-11-24 12:54 268 --ah----- C:\sqmdata15.sqm
2008-11-24 12:54 . 2008-11-24 12:54 244 --ah----- C:\sqmnoopt15.sqm
2008-11-15 19:16 . 2008-11-15 19:16 268 --ah----- C:\sqmdata14.sqm
2008-11-15 19:16 . 2008-11-15 19:16 244 --ah----- C:\sqmnoopt14.sqm
2008-11-15 18:29 . 2008-11-15 18:29 268 --ah----- C:\sqmdata13.sqm
2008-11-15 18:29 . 2008-11-15 18:29 244 --ah----- C:\sqmnoopt13.sqm
2008-11-15 17:26 . 2008-11-15 17:26 268 --ah----- C:\sqmdata12.sqm
2008-11-15 17:26 . 2008-11-15 17:26 244 --ah----- C:\sqmnoopt12.sqm
2008-11-15 16:58 . 2008-11-15 16:58 268 --ah----- C:\sqmdata11.sqm
2008-11-15 16:58 . 2008-11-15 16:58 244 --ah----- C:\sqmnoopt11.sqm
2008-11-13 12:47 . 2008-11-13 12:47 268 --ah----- C:\sqmdata10.sqm
2008-11-13 12:47 . 2008-11-13 12:47 244 --ah----- C:\sqmnoopt10.sqm
2008-11-08 21:14 . 2008-11-08 21:14 268 --ah----- C:\sqmdata09.sqm
2008-11-08 21:14 . 2008-11-08 21:14 244 --ah----- C:\sqmnoopt09.sqm
2008-11-08 15:02 . 2008-11-30 15:27 238 --a------ c:\windows\mafosav.INI
2008-11-08 15:00 . 2008-11-08 15:00 d-------- c:\program files\GameTop.com
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-06 02:06 --------- d-----w c:\program files\AIM
2008-12-06 02:06 --------- d-----w c:\documents and settings\markw\Application Data\Aim
2008-12-01 01:14 --------- d-----w c:\documents and settings\Sarah\Application Data\Smilebox
2008-12-01 01:05 --------- d-----w c:\program files\Java
2008-12-01 00:55 --------- d-----w c:\program files\CoCreate
2008-12-01 00:36 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 00:10 --------- d-----w c:\program files\Trend Micro
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-20 22:18 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-11 02:27 0 ---ha-w c:\windows\system32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
2008-10-11 02:27 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2008-10-11 02:25 0 ---ha-w c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2008-10-06 02:48 --------- d-----w c:\program files\Zune
2008-01-05 10:59 724,984 ----a-w c:\documents and settings\markw\gotomypc_437.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 53248]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-06 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-05 127035]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-01 98304]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2007-03-07 1773568]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2006-10-23 40048]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-09-12 160160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-14 217193]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-07-19 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2007-05-11 738968]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-11 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 14:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Diet Analysis Plus 7.0.1\\jre1.5.0_01\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R2 tmevtmgr;tmevtmgr;\??\c:\windows\system32\drivers\tmevtmgr.sys [2008-04-26 52240]
R2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2008-02-15 36368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-01-09 24652]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\DRIVERS\gtipci21.sys [2005-08-11 80384]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2008-02-15 333328]
R3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~3\TmPfw.exe [2008-04-26 488768]
R3 tmproxy;Trend Micro Proxy Service;"c:\program files\Trend Micro\Internet Security\TmProxy.exe" [2008-04-26 648456]
S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\DRIVERS\OVCE.sys [2006-06-20 31872]
.
- - - - ORPHANS REMOVED - - - -
BHO-{4209c1f6-b9da-45d7-993b-04204da36f26} - c:\windows\system32\gobogizu.dll
HKCU-Run-Yahoo! Pager - c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mWindow Title = Windows Internet Explorer provided by Comcast
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\SbCIe02a.dll - O16 -: {640B39C1-D713-464F-92C3-75BD972B95EE}
hxxp://www.sidestep.com/get/k42037/sb02a.cab
c:\windows\Downloaded Program Files\SbCIe02a.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 19:44:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1500)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\system32\scardsvr.exe
c:\windows\system32\BAsfIpM.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Trend Micro\Internet Security\SfCtlCom.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Trend Micro\BM\TMBMSRV.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\program files\Zune\ZuneNss.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
.
**************************************************************************
.
Completion time: 2008-12-05 19:51:35 - machine was rebooted [markw]
ComboFix-quarantined-files.txt 2008-12-06 02:51:30
Pre-Run: 15,728,119,808 bytes free
Post-Run: 17,004,797,952 bytes free
236 --- E O F --- 2008-11-13 19:15:21