Romeo
Done….Incoming logs…
ComboFix 07-11-19.4 - Leonard's 2007-12-04 8:08:53.5 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.69 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Leonard's\Desktop\CFSCRIPT.txt
* Created a new restore point
FILE
C:\pora.exe
C:\WINDOWS\SYSTEM32\ace16win.dll
C:\WINDOWS\system32\algs.exe
C:\WINDOWS\SYSTEM32\din.ip
C:\WINDOWS\SYSTEM32\dpqaqlqx.bin
C:\WINDOWS\system32\firewall.exe
C:\WINDOWS\system32\Isass.exe
C:\WINDOWS\SYSTEM32\jpewocmz.ini
C:\WINDOWS\SYSTEM32\mljklml.dll
C:\WINDOWS\SYSTEM32\qommmll.dll
C:\WINDOWS\SYSTEM32\stfv.bin
C:\WINDOWS\SYSTEM32\systemo2.exe
C:\WINDOWS\SYSTEM32\sznf.ascii
C:\WINDOWS\SYSTEM32\unpr.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\b3b6dfa3928d2fccb3f736a9
C:\b3b6dfa3928d2fccb3f736a9\mrt.exe._p
C:\b3b6dfa3928d2fccb3f736a9\mrtstub.exe
C:\pora.exe
C:\WINDOWS\SYSTEM32\ace16win.dll
C:\WINDOWS\SYSTEM32\acespy
C:\WINDOWS\SYSTEM32\acespy\__acelog.ndx
C:\WINDOWS\SYSTEM32\acespy\systune.exe
C:\WINDOWS\system32\algs.exe
C:\WINDOWS\SYSTEM32\din.ip
C:\WINDOWS\SYSTEM32\dpqaqlqx.bin
C:\WINDOWS\SYSTEM32\jpewocmz.ini
C:\WINDOWS\SYSTEM32\mljklml.dll
C:\WINDOWS\SYSTEM32\qommmll.dll
C:\WINDOWS\SYSTEM32\stfv.bin
C:\WINDOWS\SYSTEM32\systemo2.exe
C:\WINDOWS\SYSTEM32\sznf.ascii
C:\WINDOWS\SYSTEM32\unpr.sys
.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-11-26 16:58 d——– C:\Documents and Settings\Leonard's\DoctorWeb
2007-11-10 13:10 d——– C:\Program Files\uTorrent
2007-11-10 13:10 d——– C:\Documents and Settings\Leonard's\Application Data\uTorrent
2007-11-05 07:50 9,728 –a—— C:\WINDOWS\_MSRSTRT.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 15:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-03 15:28 68,830,616 —-a-w C:\Documents and Settings\Leonard's\jdk-6u3-windows-i586-p.exe
2007-11-03 15:19 382,352 —-a-w C:\Documents and Settings\Leonard's\jdk-6u3-windows-i586-p-iftw.exe
2007-11-02 18:03 ——— d—–w C:\Documents and Settings\Leonard's\Application Data\Grisoft
2007-11-02 17:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-14 20:23 ——— d–h–w C:\Program Files\Ss-Tools
2007-08-14 01:14 649,921 —-a-w C:\Documents and Settings\My Programs\data_eraser_setup.exe
2006-08-24 17:47 1,704,069 —-a-w C:\Documents and Settings\My Programs\PHOTOFILTRE SETUP.exe
2006-04-19 15:31 5,037,072 —-a-w C:\Documents and Settings\My Programs\spybotsd14.exe
2006-04-19 15:29 2,855,080 —-a-w C:\Documents and Settings\My Programs\aawsepersonal.exe
2006-03-01 14:14 5,640,784 —-a-w C:\Documents and Settings\My Programs\winamp52_full_emusic-7plus.exe
2006-02-28 14:28 2,167,119 —-a-w C:\Documents and Settings\My Programs\DBPOWER AMP-r11[1].5.exe
2006-02-28 13:48 1,665,325 —-a-w C:\Documents and Settings\My Programs\AUDIOGRABBER (setup).exe
2006-01-03 14:29 32,835 —-a-w C:\Documents and Settings\My Programs\HotKeyplus100.zip
2005-12-29 13:32 5,225,384 —-a-w C:\Documents and Settings\My Programs\Firefox Setup 1.5.exe
2005-12-23 22:19 189,764 —-a-w C:\Documents and Settings\My Programs\Mp3DC139.exe
2005-12-02 15:53 865,846 —-a-w C:\Documents and Settings\My Programs\srwa5-1.61.17.exe
2005-10-29 11:10 70,315 —-a-w C:\Documents and Settings\My Programs\Auto Close Winamp V.1.4 (5 star).exe
2005-10-17 01:49 816,782 —ha-w C:\Documents and Settings\My Programs\oggcodecs_0.69.8924 (for wmp).exe
2005-10-15 11:15 1,978,007 —ha-w C:\Documents and Settings\My Programs\mp3gain-win-full-1_2_5.exe
2005-09-29 20:29 1,207,074 —ha-w C:\Documents and Settings\My Programs\eac-0.95b3.exe
2005-09-25 20:34 4,878,136 —ha-w C:\Documents and Settings\My Programs\Firefox Setup 1.0.7.exe
2005-09-13 20:30 1,934,096 —ha-w C:\Documents and Settings\My Programs\DBPowerAmp-r11.exe
2005-08-18 17:48 79 —-a-w C:\Program Files\Show Desktop.scf
2005-07-09 14:59 1,585,777 —ha-w C:\Documents and Settings\My Programs\PhotoFiltre.exe
2002-11-26 05:10 40,012 —-a-w C:\Documents and Settings\My Programs\DBPower Amp Reset.exe
.
((((((((((((((((((((((((((((( snapshot@2007-11-27_11.56.46.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 16:57:12 174,080 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
- 2007-11-27 12:47:12 16,384 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2007-12-04 12:49:58 16,384 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2007-11-27 12:47:12 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2007-12-04 12:49:58 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2007-11-27 12:47:12 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
+ 2007-12-04 12:49:58 32,768 –sha-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPP Auto Loader"="C:\WINDOWS\tppaldr.exe" [2002-06-24 10:20]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 16:48]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 16:44]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-24 18:15]
"HotKeyz.exe"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
C:\Documents and Settings\Leonard's\Start Menu\Programs\Startup\
Eagle Listener.lnk - C:\3apps\Catapult\3listen.exe [2005-08-18 11:54:07]
Eagle Scheduler.lnk - C:\3apps\Catapult\Sched.exe [2005-08-18 11:54:22]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
"NoToolbarsOnTaskbar"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!ewido]
C:\Program Files\ewido anti-spyware 4.0\ewido.exe /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Managed Services Tray]
2006-05-02 14:11 147456 –a—— C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MVS Splash]
2006-05-02 14:27 417792 –a—— C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuikShield]
qkshield.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"McShield"=3 (0x3)
R1 mfetdik;McAfee Inc.;C:\WINDOWS\system32\drivers\mfetdik.sys
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 myAgtSvc;McAfee Total Protection Agent Service;C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe /ServiceStart
R2 NetAlrt;NetAlrt;\??\C:\WINDOWS\System32\drivers\NetAlrt.sys
R2 PlatAlrt;PlatAlrt;\??\C:\WINDOWS\System32\drivers\PlatAlrt.sys
R2 SWAGENT;SonicWALL Agent Service;C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
S0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys
S3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINDOWS\system32\drivers\NMSCFG.SYS
S3 NMSSvc;Intel® NMS;C:\WINDOWS\System32\NMSSvc.exe
S3 TPP200;USB Storage Adapter V2 (TPP);C:\WINDOWS\system32\DRIVERS\TPP200.SYS
.
Contents of the 'Scheduled Tasks' folder
"2007-12-04 14:12:54 C:\WINDOWS\Tasks\HotKeyPlus.job"
- C:\Program Files\HotKeyplus100\HotKeyPlus.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-04 08:14:09
Windows 5.1.2600 Service Pack 2 FAT NTAPI
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-04 8:15:32 - machine was rebooted
C:\ComboFix2.txt … 2007-11-27 11:57
.
— E O F —
AND
Logfile of HijackThis v1.99.1
Scan saved at 8:16:42 AM, on 12/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\tppaldr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\3apps\Catapult\3listen.exe
C:\3apps\Catapult\Sched.exe
C:\3apps\CATAPULT\APPIPC.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\program files\plethora\hijackthis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9000
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeyz.exe Startup] C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC039A07-7AFA-4AAC-95A9-D7FA4F6BA664}: NameServer = 68.1.208.30,68.1.208.25
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
ComboFix 07-11-19.4 - Leonard's 2007-12-04 8:08:53.5 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.69 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Leonard's\Desktop\CFSCRIPT.txt
* Created a new restore point
FILE
C:\pora.exe
C:\WINDOWS\SYSTEM32\ace16win.dll
C:\WINDOWS\system32\algs.exe
C:\WINDOWS\SYSTEM32\din.ip
C:\WINDOWS\SYSTEM32\dpqaqlqx.bin
C:\WINDOWS\system32\firewall.exe
C:\WINDOWS\system32\Isass.exe
C:\WINDOWS\SYSTEM32\jpewocmz.ini
C:\WINDOWS\SYSTEM32\mljklml.dll
C:\WINDOWS\SYSTEM32\qommmll.dll
C:\WINDOWS\SYSTEM32\stfv.bin
C:\WINDOWS\SYSTEM32\systemo2.exe
C:\WINDOWS\SYSTEM32\sznf.ascii
C:\WINDOWS\SYSTEM32\unpr.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\b3b6dfa3928d2fccb3f736a9
C:\b3b6dfa3928d2fccb3f736a9\mrt.exe._p
C:\b3b6dfa3928d2fccb3f736a9\mrtstub.exe
C:\pora.exe
C:\WINDOWS\SYSTEM32\ace16win.dll
C:\WINDOWS\SYSTEM32\acespy
C:\WINDOWS\SYSTEM32\acespy\__acelog.ndx
C:\WINDOWS\SYSTEM32\acespy\systune.exe
C:\WINDOWS\system32\algs.exe
C:\WINDOWS\SYSTEM32\din.ip
C:\WINDOWS\SYSTEM32\dpqaqlqx.bin
C:\WINDOWS\SYSTEM32\jpewocmz.ini
C:\WINDOWS\SYSTEM32\mljklml.dll
C:\WINDOWS\SYSTEM32\qommmll.dll
C:\WINDOWS\SYSTEM32\stfv.bin
C:\WINDOWS\SYSTEM32\systemo2.exe
C:\WINDOWS\SYSTEM32\sznf.ascii
C:\WINDOWS\SYSTEM32\unpr.sys
.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-11-26 16:58 d——– C:\Documents and Settings\Leonard's\DoctorWeb
2007-11-10 13:10 d——– C:\Program Files\uTorrent
2007-11-10 13:10 d——– C:\Documents and Settings\Leonard's\Application Data\uTorrent
2007-11-05 07:50 9,728 –a—— C:\WINDOWS\_MSRSTRT.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 15:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-03 15:28 68,830,616 —-a-w C:\Documents and Settings\Leonard's\jdk-6u3-windows-i586-p.exe
2007-11-03 15:19 382,352 —-a-w C:\Documents and Settings\Leonard's\jdk-6u3-windows-i586-p-iftw.exe
2007-11-02 18:03 ——— d—–w C:\Documents and Settings\Leonard's\Application Data\Grisoft
2007-11-02 17:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-14 20:23 ——— d–h–w C:\Program Files\Ss-Tools
2007-08-14 01:14 649,921 —-a-w C:\Documents and Settings\My Programs\data_eraser_setup.exe
2006-08-24 17:47 1,704,069 —-a-w C:\Documents and Settings\My Programs\PHOTOFILTRE SETUP.exe
2006-04-19 15:31 5,037,072 —-a-w C:\Documents and Settings\My Programs\spybotsd14.exe
2006-04-19 15:29 2,855,080 —-a-w C:\Documents and Settings\My Programs\aawsepersonal.exe
2006-03-01 14:14 5,640,784 —-a-w C:\Documents and Settings\My Programs\winamp52_full_emusic-7plus.exe
2006-02-28 14:28 2,167,119 —-a-w C:\Documents and Settings\My Programs\DBPOWER AMP-r11[1].5.exe
2006-02-28 13:48 1,665,325 —-a-w C:\Documents and Settings\My Programs\AUDIOGRABBER (setup).exe
2006-01-03 14:29 32,835 —-a-w C:\Documents and Settings\My Programs\HotKeyplus100.zip
2005-12-29 13:32 5,225,384 —-a-w C:\Documents and Settings\My Programs\Firefox Setup 1.5.exe
2005-12-23 22:19 189,764 —-a-w C:\Documents and Settings\My Programs\Mp3DC139.exe
2005-12-02 15:53 865,846 —-a-w C:\Documents and Settings\My Programs\srwa5-1.61.17.exe
2005-10-29 11:10 70,315 —-a-w C:\Documents and Settings\My Programs\Auto Close Winamp V.1.4 (5 star).exe
2005-10-17 01:49 816,782 —ha-w C:\Documents and Settings\My Programs\oggcodecs_0.69.8924 (for wmp).exe
2005-10-15 11:15 1,978,007 —ha-w C:\Documents and Settings\My Programs\mp3gain-win-full-1_2_5.exe
2005-09-29 20:29 1,207,074 —ha-w C:\Documents and Settings\My Programs\eac-0.95b3.exe
2005-09-25 20:34 4,878,136 —ha-w C:\Documents and Settings\My Programs\Firefox Setup 1.0.7.exe
2005-09-13 20:30 1,934,096 —ha-w C:\Documents and Settings\My Programs\DBPowerAmp-r11.exe
2005-08-18 17:48 79 —-a-w C:\Program Files\Show Desktop.scf
2005-07-09 14:59 1,585,777 —ha-w C:\Documents and Settings\My Programs\PhotoFiltre.exe
2002-11-26 05:10 40,012 —-a-w C:\Documents and Settings\My Programs\DBPower Amp Reset.exe
.
((((((((((((((((((((((((((((( snapshot@2007-11-27_11.56.46.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 16:57:12 174,080 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
- 2007-11-27 12:47:12 16,384 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2007-12-04 12:49:58 16,384 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2007-11-27 12:47:12 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2007-12-04 12:49:58 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2007-11-27 12:47:12 32,768 ——w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
+ 2007-12-04 12:49:58 32,768 –sha-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPP Auto Loader"="C:\WINDOWS\tppaldr.exe" [2002-06-24 10:20]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 16:48]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 16:44]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-24 18:15]
"HotKeyz.exe"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
C:\Documents and Settings\Leonard's\Start Menu\Programs\Startup\
Eagle Listener.lnk - C:\3apps\Catapult\3listen.exe [2005-08-18 11:54:07]
Eagle Scheduler.lnk - C:\3apps\Catapult\Sched.exe [2005-08-18 11:54:22]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
"NoToolbarsOnTaskbar"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!ewido]
C:\Program Files\ewido anti-spyware 4.0\ewido.exe /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Managed Services Tray]
2006-05-02 14:11 147456 –a—— C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MVS Splash]
2006-05-02 14:27 417792 –a—— C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuikShield]
qkshield.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"McShield"=3 (0x3)
R1 mfetdik;McAfee Inc.;C:\WINDOWS\system32\drivers\mfetdik.sys
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 myAgtSvc;McAfee Total Protection Agent Service;C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe /ServiceStart
R2 NetAlrt;NetAlrt;\??\C:\WINDOWS\System32\drivers\NetAlrt.sys
R2 PlatAlrt;PlatAlrt;\??\C:\WINDOWS\System32\drivers\PlatAlrt.sys
R2 SWAGENT;SonicWALL Agent Service;C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
S0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys
S3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINDOWS\system32\drivers\NMSCFG.SYS
S3 NMSSvc;Intel® NMS;C:\WINDOWS\System32\NMSSvc.exe
S3 TPP200;USB Storage Adapter V2 (TPP);C:\WINDOWS\system32\DRIVERS\TPP200.SYS
.
Contents of the 'Scheduled Tasks' folder
"2007-12-04 14:12:54 C:\WINDOWS\Tasks\HotKeyPlus.job"
- C:\Program Files\HotKeyplus100\HotKeyPlus.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-04 08:14:09
Windows 5.1.2600 Service Pack 2 FAT NTAPI
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-04 8:15:32 - machine was rebooted
C:\ComboFix2.txt … 2007-11-27 11:57
.
— E O F —
AND
Logfile of HijackThis v1.99.1
Scan saved at 8:16:42 AM, on 12/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\tppaldr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\3apps\Catapult\3listen.exe
C:\3apps\Catapult\Sched.exe
C:\3apps\CATAPULT\APPIPC.exe
C:\WINDOWS\system32\P32HELP.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\program files\plethora\hijackthis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9000
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeyz.exe Startup] C:\Program Files\Skynergy\HotKeyz\HotKeyz.exe Startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Eagle Listener.lnk = C:\3apps\Catapult\3listen.exe
O4 - Startup: Eagle Scheduler.lnk = C:\3apps\Catapult\Sched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AC039A07-7AFA-4AAC-95A9-D7FA4F6BA664}: NameServer = 68.1.208.30,68.1.208.25
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe