eyecandyman
Topic Starter
hi,
there is an iexplore.exe file in my C:/doc & set/user/locset/temp that ont remove. When i stop explorer.exe from the task manager and restart it a window pos up and says setting up personalized settings for : [blank] with target C:/doc&set/user/locset/temp/iexplore.exe.
I read some of your other threads and found a similar one and followed the first instructions you gave and ran atf cleaner and combofix and checked to see if the file was removed but it was the only one that was still residing in the folder……
So i will post the combofix log here to see if you have any idea would i should do. Obviously i allready ran anti spyware programs.
thanks in advance
ComboFix 07-12-18.1 - Jeff 2007-12-18 21:04:17.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.733 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\d.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\taskmgr.exe
C:\Documents and Settings\Jeff\Application Data\macromedia\Flash Player\#SharedObjects\WPYE9VA3\iforex.com
C:\Documents and Settings\Jeff\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\install.exe
C:\Program Files\ComPlus Applications\wuoryro.html
C:\setup.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\b122.exe
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu1000137.exe
C:\WINDOWS\mrofinu1000140.exe
C:\WINDOWS\system32\f.exe
C:\WINDOWS\system32\ilnmp.ini
C:\WINDOWS\system32\ilnmp.ini2
C:\WINDOWS\system32\p2pnetworking.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\winlogo.exe
C:\WINDOWS\WINDOWS
C:\WINDOWS\WINDOWS\svhost.exe
C:\WINDOWS\WINDOWS\svhost.sys
C:\winlogon.exe
C:\x.dat
C:\z.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2007-11-18 to 2007-12-18 )))))))))))))))))))))))))))))))
.
2007-12-18 18:46 . 2007-12-18 18:46 d–hs—- C:\FOUND.001
2007-12-18 18:34 . 2007-12-18 18:34 167 –a—— C:\Documents and Settings\Jeff\1986.bat
2007-12-18 18:33 . 2007-12-18 18:33 36,864 –a—— C:\Documents and Settings\Jeff\winlogo.exe
2007-12-18 17:55 . 2007-12-18 17:56 d——– C:\Program Files\Windows Defender
2007-12-18 17:31 . 2007-12-18 17:31 d–hs—- C:\FOUND.000
2007-12-18 17:17 . 2007-12-18 17:17 39,936 –a—— C:\WINDOWS\mrofinu1000137.exe.tmp
2007-12-18 17:17 . 2007-12-18 17:17 167 –a—— C:\WINDOWS\system32\2010.bat
2007-12-18 17:16 . 2007-12-18 17:16 d——– C:\WINDOWS\system32\twdr
2007-12-18 17:16 . 2007-12-18 17:16 d——– C:\WINDOWS\system32\rey2
2007-12-18 17:16 . 2007-12-18 17:16 d——– C:\WINDOWS\system32\ref1
2007-12-18 17:16 . 2007-12-18 17:16 d–hs—- C:\WINDOWS\SmVmZg
2007-12-18 17:16 . 2007-12-18 17:16 40,448 –a—— C:\WINDOWS\system32\qomjhed.dll
2007-12-18 17:16 . 2007-12-18 17:16 610 –a—— C:\WINDOWS\system32\x.dat
2007-12-18 17:16 . 2007-12-18 17:16 287 –a—— C:\WINDOWS\system32\z.dat
2007-12-18 17:16 . 2007-12-18 17:16 134 –a—— C:\n.bat
2007-12-18 17:15 . 2007-12-18 17:15 d——– C:\WINDOWS\system32\ineWc07
2007-12-18 17:15 . 2007-12-18 17:15 d——– C:\Temp\tpBe12
2007-12-18 17:15 . 2007-12-18 17:15 d——– C:\Temp
2007-12-18 17:15 . 2007-12-18 17:15 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-18 17:15 . 2007-12-18 17:15 0 –a—— C:\WINDOWS\system32\taskkill.exe
2007-12-18 16:14 . 2003-06-26 13:52 464,128 –a—— C:\WINDOWS\system32\csimxctl.ocx
2007-12-18 16:14 . 2003-06-17 13:54 87,280 –a—— C:\WINDOWS\system32\wsatrace.dll
2007-12-18 16:02 . 2007-12-18 16:02 d——– C:\Program Files\Poker Tracker V2
2007-12-18 00:01 . 2007-12-18 00:01 d——– C:\Program Files\HoldemInspector2
2007-12-17 00:14 . 2007-12-17 00:22 5,742 –a—— C:\PokerStars.log.0
2007-12-16 20:48 . 2004-08-04 00:56 249,856 –a—— C:\WINDOWS\system32\dllcache\ctmasetp.dll
2007-12-16 20:47 . 2004-08-04 05:00 1,677,824 –a—— C:\WINDOWS\system32\dllcache\chsbrkr.dll
2007-12-16 20:46 . 2004-08-04 00:56 1,888,992 –a—— C:\WINDOWS\system32\dllcache\ati3duag.dll
2007-12-16 20:45 . 2001-08-17 13:28 762,780 –a—— C:\WINDOWS\system32\dllcache\3cwmcru.sys
2007-12-16 20:44 . 2001-08-17 14:56 66,048 –a—— C:\WINDOWS\system32\dllcache\s3legacy.dll
2007-12-16 15:58 . 2007-12-16 15:58 d——– C:\Program Files\Sharp World Clock
2007-12-16 15:58 . 2007-12-16 15:58 d——– C:\Documents and Settings\Jeff\Application Data\Sharp World Clock
2007-12-16 05:51 . 2007-12-16 05:51 59 –a—— C:\WINDOWS\pp.enc
2007-12-16 05:41 . 2007-12-16 05:41 d——– C:\WINDOWS\system32\FlashAX
2007-12-16 05:40 . 2007-12-16 05:40 d——– C:\Microgaming
2007-12-16 05:40 . 2007-12-16 05:40 d——– C:\Documents and Settings\Jeff\Application Data\Microgaming
2007-12-15 23:42 . 2007-12-15 23:42 d——– C:\Program Files\NewDigitalSoft
2007-12-15 23:19 . 2007-12-15 23:20 d——– C:\Program Files\AutoIt3
2007-12-14 23:07 . 2007-12-14 23:07 d——– C:\Program Files\InterPoker
2007-12-14 23:07 . 2007-08-01 10:03 93,184 –a—— C:\WINDOWS\system32\UnPoker.exe
2007-12-14 19:47 . 2007-12-14 19:47 d——– C:\Program Files\HollywoodPoker
2007-12-14 18:18 . 2007-12-14 18:18 d——– C:\Program Files\CarbonPoker
2007-12-14 17:56 . 2007-12-14 17:56 d——– C:\Program Files\PokerStars
2007-12-14 15:26 . 2007-12-14 15:26 d——– C:\Poker
2007-12-14 15:25 . 2007-12-14 15:25 d——– C:\Documents and Settings\All Users\Application Data\RoboForm
2007-12-14 15:24 . 2007-12-14 15:24 d——– C:\Program Files\Siber Systems
2007-12-14 14:44 . 2007-12-14 14:44 d——– C:\Program Files\Everest Poker
2007-12-14 14:34 . 2007-12-14 14:34 d——– C:\Program Files\PacificPoker4
2007-12-14 01:53 . 2007-12-14 01:53 d——– C:\Program Files\PartyGaming
2007-12-14 01:16 . 2007-12-17 00:23 248 –a—— C:\WINDOWS\system32\systemdrv32.aso
2007-12-14 01:08 . 2007-12-14 01:08 d——– C:\Program Files\Absolute Poker
2007-12-14 01:08 . 2007-12-14 01:08 d——– C:\Program Files\_uninstallation_info
2007-12-13 23:33 . 2007-12-13 23:33 d——– C:\Program Files\EuroPoker
2007-12-13 22:33 . 2007-12-13 22:33 d——– C:\Program Files\PokerRoom.com
2007-12-08 01:30 . 2007-12-08 01:30 d——– C:\Program Files\PartyGaming.Net
2007-12-04 03:54 . 2007-12-04 03:54 d——– C:\Documents and Settings\Jeff\Application Data\Ahead
2007-12-04 01:08 . 2007-12-04 01:08 d——– C:\Documents and Settings\Jeff\Application Data\skypePM
2007-12-04 01:08 . 2007-12-04 01:08 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-12-04 01:07 . 2007-12-04 01:07 d——– C:\Program Files\Skype
2007-12-04 01:07 . 2007-12-04 01:07 d——– C:\Program Files\Common Files\Skype
2007-12-04 01:07 . 2007-12-04 01:07 d——– C:\Documents and Settings\Jeff\Application Data\Skype
2007-12-04 01:07 . 2007-12-04 01:07 d——– C:\Documents and Settings\All Users\Application Data\Skype
2007-12-03 23:36 . 2007-12-03 23:36 d——– C:\Program Files\YouSendIt
2007-12-03 23:36 . 2007-12-03 23:36 d——– C:\Documents and Settings\Jeff\Application Data\YouSendIt
2007-12-01 16:11 . 2007-12-01 16:11 d——– C:\Program Files\Audacity
2007-12-01 15:48 . 2007-12-01 15:48 187 –a—— C:\Shortcut to ACER ©.lnk
2007-12-01 13:19 . 2007-12-01 13:19 d——– C:\WINDOWS\WLTB Custom Button Feeds
2007-12-01 13:18 . 2007-12-01 13:18 d—s—- C:\WINDOWS\system32\%SystemDrive%
2007-12-01 13:18 . 2007-12-01 13:18 d——– C:\WINDOWS\Google Toolbar
2007-11-30 03:01 . 2007-11-30 03:01 d——– C:\Program Files\Windows Live Favorites
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-05 02:52 ——— d—–w C:\Documents and Settings\Jeff\Application Data\U3
2007-11-02 22:27 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Intermedia Design
2007-11-02 22:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intermedia Design
2007-11-02 22:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Data
2007-11-02 22:26 ——— d—–w C:\Program Files\Intermedia Design
2007-11-02 22:18 ——— d—–w C:\Program Files\Reasonable NoClone 4 Home
2007-11-02 22:18 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Reasonable Software
2007-11-02 21:50 ——— d—–w C:\Program Files\GizmoPlugin
2007-11-02 19:52 ——— d—–w C:\Program Files\mp3Tag 5
2007-11-02 19:17 ——— d—–w C:\Program Files\RapidSolution
2007-11-02 19:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\RapidSolution
2007-11-02 18:59 ——— d—–w C:\Program Files\Moleskinsoft Clone Remover 2.6
2007-10-31 04:12 3,590,656 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 16:53 ——— d—–w C:\Program Files\Microsoft.NET
2007-10-28 12:39 ——— d—–w C:\Program Files\Microsoft Voice Command
2007-10-28 11:36 ——— d—–w C:\Program Files\Windows Mobile-hulpbronnen
2007-10-28 11:23 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Sprite Software
2007-10-28 11:23 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Sprite Setup Wizard
2007-10-28 11:23 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Sprite PC Agent
2007-10-28 11:20 ——— d—–w C:\Program Files\Sprite Software
2007-10-28 01:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-28 01:12 ——— d—–w C:\Program Files\Zortam Mp3 Media Studio
2007-10-27 16:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 16:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 10:33 ——— d—–w C:\Program Files\iPod
2007-10-25 10:32 ——— d—–w C:\Program Files\iTunes
2007-10-25 10:31 ——— d—–w C:\Program Files\QuickTime
2007-10-25 10:29 ——— d—–w C:\Program Files\Common Files\Apple
2007-10-25 10:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-22 01:15 ——— d—–w C:\Program Files\Peretek
2007-10-19 23:54 ——— d—–w C:\Documents and Settings\Jeff\Application Data\NewsLeecher
2007-10-10 23:56 824,832 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 671,232 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:56 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 23:56 1,159,680 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-09-10 12:51 20 —h–w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-04-28 17:12 1,771,191 —-a-w C:\Program Files\kwekker-1.1b-setup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DB0B918E-A0A8-482B-8D75-A682816B0C7B}]
2007-12-18 17:16 40448 –a—— C:\WINDOWS\system32\qomjhed.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 18:34]
"svhost"="C:\WINDOWS\WINDOWS\svhost.exe" []
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-12-14 15:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 20:27]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 10:49]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 10:49]
"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2004-08-06 14:04]
"PowerKey"="C:\Program Files\Launch Manager\PowerKey.exe" [2002-08-30 15:02]
"LManager"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2004-07-15 17:24]
"CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [2004-01-28 17:48]
"LMgrOSD"="C:\Program Files\Launch Manager\OSDCtrl.exe" [2004-09-08 11:28]
"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2004-08-13 22:40]
"VTTrayp"="VTtrayp.exe" [2004-06-22 02:57 C:\WINDOWS\system32\VTTrayp.exe]
"VTTimer"="VTTimer.exe" [2004-09-01 16:28 C:\WINDOWS\system32\VTTimer.exe]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2004-07-13 14:48 C:\WINDOWS\system32\nwiz.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-03 12:21 C:\WINDOWS\AGRSMMSG.exe]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2004-04-19 17:44]
"svhost"="C:\WINDOWS\WINDOWS\svhost.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-16 15:49]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-14 02:04]
"Spyware Doctor"="" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Alice Agent voor automatische updates.lnk - C:\Program Files\T-Mobile\Communication Center\AutoUpdateSrv.exe [2007-05-14 00:33:56]
svhost.exe.lnk - C:\WINDOWS\twunk_16.exe [1980-01-01]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{DB0B918E-A0A8-482B-8D75-A682816B0C7B}"= C:\WINDOWS\system32\qomjhed.dll [2007-12-18 17:16 40448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomjhed]
qomjhed.dll 2007-12-18 17:16 40448 C:\WINDOWS\system32\qomjhed.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jeff^Start Menu^Programs^Startup^WorldClock.lnk]
path=C:\Documents and Settings\Jeff\Start Menu\Programs\Startup\WorldClock.lnk
backup=C:\WINDOWS\pss\WorldClock.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bpk]
C:\Program Files\BPK\bpk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXDllRegExe]
dxdllreg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2007-05-11 02:08 2512392 –a—— C:\WINDOWS\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\p2p networking]
p2pnetworking.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
C:\Program Files\Registry Mechanic\RegMech.exe /QS
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1000140.exe 61A847B5BBF72813329B385776F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpriteService]
2006-11-03 11:19 544768 –a—— C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-19 20:27 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys [2003-04-28 11:27]
R2 Gizmo Plugin;Gizmo VoIP Service;"C:\Program Files\GizmoPlugin\GizmoPlugin.exe" [2007-11-02 22:50]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;C:\WINDOWS\system32\DRIVERS\i2220ntx.sys [2004-03-29 17:23]
R3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys [2005-06-10 06:55]
R3 POWERKEY;POWERKEY;C:\Program Files\Launch Manager\POWERKEY.sys [2000-12-19 18:29]
S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys []
S2 freenet-darknet-8888;Freenet 0.7 darknet-8888;"C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe" -s "C:\Program Files\Freenet\wrapper.conf" []
S3 fwb;fwb;C:\DOCUME~1\Jeff\LOCALS~1\Temp\a.dll []
S3 GoogleDesktopManager-091907-194040;Google Desktop Manager 5.1.709.19590;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-16 15:49]
S3 GTF32BUS;GT F32 BUS;C:\WINDOWS\system32\DRIVERS\gtf32bus.sys [2005-09-01 18:54]
S3 GTPTSER;GT PT SER;C:\WINDOWS\system32\DRIVERS\gtptser.sys [2005-09-01 18:54]
S3 GTSCSER;GT SC SER;C:\WINDOWS\system32\DRIVERS\gtscser.sys [2005-08-29 16:45]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial;C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2007-03-03 18:47]
S3 IpHook;IpHook;C:\Program Files\Network Traffic Monitor\IpHook.sys []
S3 W8335XP;Marvell Libertas 802.11b/g Driver for Windows XP (8335);C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-09-09 22:14]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c000bb6-1f4b-11dc-b280-000ae4a7dfb6}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9196fd06-5091-11dc-b296-000ae4a7dfb6}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8d03950-660f-11dc-b27b-000ae4a7dfb6}]
\Shell\AutoRun\command - I:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6cfbe22-1f75-11dc-b281-000ae4a7dfb6}]
\Shell\AutoRun\command - H:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-05 09:02:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-18 18:34:04 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-12-18 20:15:28 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-18 21:14:55
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\qomjhed.dll
.
Completion time: 2007-12-18 21:17:51 - machine was rebooted
.
2007-12-18 02:01:22 — E O F —
there is an iexplore.exe file in my C:/doc & set/user/locset/temp that ont remove. When i stop explorer.exe from the task manager and restart it a window pos up and says setting up personalized settings for : [blank] with target C:/doc&set/user/locset/temp/iexplore.exe.
I read some of your other threads and found a similar one and followed the first instructions you gave and ran atf cleaner and combofix and checked to see if the file was removed but it was the only one that was still residing in the folder……
So i will post the combofix log here to see if you have any idea would i should do. Obviously i allready ran anti spyware programs.
thanks in advance
ComboFix 07-12-18.1 - Jeff 2007-12-18 21:04:17.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.733 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\d.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\taskmgr.exe
C:\Documents and Settings\Jeff\Application Data\macromedia\Flash Player\#SharedObjects\WPYE9VA3\iforex.com
C:\Documents and Settings\Jeff\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\install.exe
C:\Program Files\ComPlus Applications\wuoryro.html
C:\setup.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\b122.exe
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu1000137.exe
C:\WINDOWS\mrofinu1000140.exe
C:\WINDOWS\system32\f.exe
C:\WINDOWS\system32\ilnmp.ini
C:\WINDOWS\system32\ilnmp.ini2
C:\WINDOWS\system32\p2pnetworking.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\winlogo.exe
C:\WINDOWS\WINDOWS
C:\WINDOWS\WINDOWS\svhost.exe
C:\WINDOWS\WINDOWS\svhost.sys
C:\winlogon.exe
C:\x.dat
C:\z.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2007-11-18 to 2007-12-18 )))))))))))))))))))))))))))))))
.
2007-12-18 18:46 . 2007-12-18 18:46 d–hs—- C:\FOUND.001
2007-12-18 18:34 . 2007-12-18 18:34 167 –a—— C:\Documents and Settings\Jeff\1986.bat
2007-12-18 18:33 . 2007-12-18 18:33 36,864 –a—— C:\Documents and Settings\Jeff\winlogo.exe
2007-12-18 17:55 . 2007-12-18 17:56 d——– C:\Program Files\Windows Defender
2007-12-18 17:31 . 2007-12-18 17:31 d–hs—- C:\FOUND.000
2007-12-18 17:17 . 2007-12-18 17:17 39,936 –a—— C:\WINDOWS\mrofinu1000137.exe.tmp
2007-12-18 17:17 . 2007-12-18 17:17 167 –a—— C:\WINDOWS\system32\2010.bat
2007-12-18 17:16 . 2007-12-18 17:16 d——– C:\WINDOWS\system32\twdr
2007-12-18 17:16 . 2007-12-18 17:16 d——– C:\WINDOWS\system32\rey2
2007-12-18 17:16 . 2007-12-18 17:16 d——– C:\WINDOWS\system32\ref1
2007-12-18 17:16 . 2007-12-18 17:16 d–hs—- C:\WINDOWS\SmVmZg
2007-12-18 17:16 . 2007-12-18 17:16 40,448 –a—— C:\WINDOWS\system32\qomjhed.dll
2007-12-18 17:16 . 2007-12-18 17:16 610 –a—— C:\WINDOWS\system32\x.dat
2007-12-18 17:16 . 2007-12-18 17:16 287 –a—— C:\WINDOWS\system32\z.dat
2007-12-18 17:16 . 2007-12-18 17:16 134 –a—— C:\n.bat
2007-12-18 17:15 . 2007-12-18 17:15 d——– C:\WINDOWS\system32\ineWc07
2007-12-18 17:15 . 2007-12-18 17:15 d——– C:\Temp\tpBe12
2007-12-18 17:15 . 2007-12-18 17:15 d——– C:\Temp
2007-12-18 17:15 . 2007-12-18 17:15 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-18 17:15 . 2007-12-18 17:15 0 –a—— C:\WINDOWS\system32\taskkill.exe
2007-12-18 16:14 . 2003-06-26 13:52 464,128 –a—— C:\WINDOWS\system32\csimxctl.ocx
2007-12-18 16:14 . 2003-06-17 13:54 87,280 –a—— C:\WINDOWS\system32\wsatrace.dll
2007-12-18 16:02 . 2007-12-18 16:02 d——– C:\Program Files\Poker Tracker V2
2007-12-18 00:01 . 2007-12-18 00:01 d——– C:\Program Files\HoldemInspector2
2007-12-17 00:14 . 2007-12-17 00:22 5,742 –a—— C:\PokerStars.log.0
2007-12-16 20:48 . 2004-08-04 00:56 249,856 –a—— C:\WINDOWS\system32\dllcache\ctmasetp.dll
2007-12-16 20:47 . 2004-08-04 05:00 1,677,824 –a—— C:\WINDOWS\system32\dllcache\chsbrkr.dll
2007-12-16 20:46 . 2004-08-04 00:56 1,888,992 –a—— C:\WINDOWS\system32\dllcache\ati3duag.dll
2007-12-16 20:45 . 2001-08-17 13:28 762,780 –a—— C:\WINDOWS\system32\dllcache\3cwmcru.sys
2007-12-16 20:44 . 2001-08-17 14:56 66,048 –a—— C:\WINDOWS\system32\dllcache\s3legacy.dll
2007-12-16 15:58 . 2007-12-16 15:58 d——– C:\Program Files\Sharp World Clock
2007-12-16 15:58 . 2007-12-16 15:58 d——– C:\Documents and Settings\Jeff\Application Data\Sharp World Clock
2007-12-16 05:51 . 2007-12-16 05:51 59 –a—— C:\WINDOWS\pp.enc
2007-12-16 05:41 . 2007-12-16 05:41 d——– C:\WINDOWS\system32\FlashAX
2007-12-16 05:40 . 2007-12-16 05:40 d——– C:\Microgaming
2007-12-16 05:40 . 2007-12-16 05:40 d——– C:\Documents and Settings\Jeff\Application Data\Microgaming
2007-12-15 23:42 . 2007-12-15 23:42 d——– C:\Program Files\NewDigitalSoft
2007-12-15 23:19 . 2007-12-15 23:20 d——– C:\Program Files\AutoIt3
2007-12-14 23:07 . 2007-12-14 23:07 d——– C:\Program Files\InterPoker
2007-12-14 23:07 . 2007-08-01 10:03 93,184 –a—— C:\WINDOWS\system32\UnPoker.exe
2007-12-14 19:47 . 2007-12-14 19:47 d——– C:\Program Files\HollywoodPoker
2007-12-14 18:18 . 2007-12-14 18:18 d——– C:\Program Files\CarbonPoker
2007-12-14 17:56 . 2007-12-14 17:56 d——– C:\Program Files\PokerStars
2007-12-14 15:26 . 2007-12-14 15:26 d——– C:\Poker
2007-12-14 15:25 . 2007-12-14 15:25 d——– C:\Documents and Settings\All Users\Application Data\RoboForm
2007-12-14 15:24 . 2007-12-14 15:24 d——– C:\Program Files\Siber Systems
2007-12-14 14:44 . 2007-12-14 14:44 d——– C:\Program Files\Everest Poker
2007-12-14 14:34 . 2007-12-14 14:34 d——– C:\Program Files\PacificPoker4
2007-12-14 01:53 . 2007-12-14 01:53 d——– C:\Program Files\PartyGaming
2007-12-14 01:16 . 2007-12-17 00:23 248 –a—— C:\WINDOWS\system32\systemdrv32.aso
2007-12-14 01:08 . 2007-12-14 01:08 d——– C:\Program Files\Absolute Poker
2007-12-14 01:08 . 2007-12-14 01:08 d——– C:\Program Files\_uninstallation_info
2007-12-13 23:33 . 2007-12-13 23:33 d——– C:\Program Files\EuroPoker
2007-12-13 22:33 . 2007-12-13 22:33 d——– C:\Program Files\PokerRoom.com
2007-12-08 01:30 . 2007-12-08 01:30 d——– C:\Program Files\PartyGaming.Net
2007-12-04 03:54 . 2007-12-04 03:54 d——– C:\Documents and Settings\Jeff\Application Data\Ahead
2007-12-04 01:08 . 2007-12-04 01:08 d——– C:\Documents and Settings\Jeff\Application Data\skypePM
2007-12-04 01:08 . 2007-12-04 01:08 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-12-04 01:07 . 2007-12-04 01:07 d——– C:\Program Files\Skype
2007-12-04 01:07 . 2007-12-04 01:07 d——– C:\Program Files\Common Files\Skype
2007-12-04 01:07 . 2007-12-04 01:07 d——– C:\Documents and Settings\Jeff\Application Data\Skype
2007-12-04 01:07 . 2007-12-04 01:07 d——– C:\Documents and Settings\All Users\Application Data\Skype
2007-12-03 23:36 . 2007-12-03 23:36 d——– C:\Program Files\YouSendIt
2007-12-03 23:36 . 2007-12-03 23:36 d——– C:\Documents and Settings\Jeff\Application Data\YouSendIt
2007-12-01 16:11 . 2007-12-01 16:11 d——– C:\Program Files\Audacity
2007-12-01 15:48 . 2007-12-01 15:48 187 –a—— C:\Shortcut to ACER ©.lnk
2007-12-01 13:19 . 2007-12-01 13:19 d——– C:\WINDOWS\WLTB Custom Button Feeds
2007-12-01 13:18 . 2007-12-01 13:18 d—s—- C:\WINDOWS\system32\%SystemDrive%
2007-12-01 13:18 . 2007-12-01 13:18 d——– C:\WINDOWS\Google Toolbar
2007-11-30 03:01 . 2007-11-30 03:01 d——– C:\Program Files\Windows Live Favorites
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-05 02:52 ——— d—–w C:\Documents and Settings\Jeff\Application Data\U3
2007-11-02 22:27 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Intermedia Design
2007-11-02 22:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intermedia Design
2007-11-02 22:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Data
2007-11-02 22:26 ——— d—–w C:\Program Files\Intermedia Design
2007-11-02 22:18 ——— d—–w C:\Program Files\Reasonable NoClone 4 Home
2007-11-02 22:18 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Reasonable Software
2007-11-02 21:50 ——— d—–w C:\Program Files\GizmoPlugin
2007-11-02 19:52 ——— d—–w C:\Program Files\mp3Tag 5
2007-11-02 19:17 ——— d—–w C:\Program Files\RapidSolution
2007-11-02 19:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\RapidSolution
2007-11-02 18:59 ——— d—–w C:\Program Files\Moleskinsoft Clone Remover 2.6
2007-10-31 04:12 3,590,656 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 16:53 ——— d—–w C:\Program Files\Microsoft.NET
2007-10-28 12:39 ——— d—–w C:\Program Files\Microsoft Voice Command
2007-10-28 11:36 ——— d—–w C:\Program Files\Windows Mobile-hulpbronnen
2007-10-28 11:23 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Sprite Software
2007-10-28 11:23 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Sprite Setup Wizard
2007-10-28 11:23 ——— d—–w C:\Documents and Settings\Jeff\Application Data\Sprite PC Agent
2007-10-28 11:20 ——— d—–w C:\Program Files\Sprite Software
2007-10-28 01:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-28 01:12 ——— d—–w C:\Program Files\Zortam Mp3 Media Studio
2007-10-27 16:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 16:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 10:33 ——— d—–w C:\Program Files\iPod
2007-10-25 10:32 ——— d—–w C:\Program Files\iTunes
2007-10-25 10:31 ——— d—–w C:\Program Files\QuickTime
2007-10-25 10:29 ——— d—–w C:\Program Files\Common Files\Apple
2007-10-25 10:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-22 01:15 ——— d—–w C:\Program Files\Peretek
2007-10-19 23:54 ——— d—–w C:\Documents and Settings\Jeff\Application Data\NewsLeecher
2007-10-10 23:56 824,832 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 671,232 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:56 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 23:56 1,159,680 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-09-10 12:51 20 —h–w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2007-04-28 17:12 1,771,191 —-a-w C:\Program Files\kwekker-1.1b-setup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DB0B918E-A0A8-482B-8D75-A682816B0C7B}]
2007-12-18 17:16 40448 –a—— C:\WINDOWS\system32\qomjhed.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 18:34]
"svhost"="C:\WINDOWS\WINDOWS\svhost.exe" []
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-12-14 15:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 20:27]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 10:49]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 10:49]
"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2004-08-06 14:04]
"PowerKey"="C:\Program Files\Launch Manager\PowerKey.exe" [2002-08-30 15:02]
"LManager"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2004-07-15 17:24]
"CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [2004-01-28 17:48]
"LMgrOSD"="C:\Program Files\Launch Manager\OSDCtrl.exe" [2004-09-08 11:28]
"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2004-08-13 22:40]
"VTTrayp"="VTtrayp.exe" [2004-06-22 02:57 C:\WINDOWS\system32\VTTrayp.exe]
"VTTimer"="VTTimer.exe" [2004-09-01 16:28 C:\WINDOWS\system32\VTTimer.exe]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2004-07-13 14:48 C:\WINDOWS\system32\nwiz.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-03 12:21 C:\WINDOWS\AGRSMMSG.exe]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2004-04-19 17:44]
"svhost"="C:\WINDOWS\WINDOWS\svhost.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-16 15:49]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-14 02:04]
"Spyware Doctor"="" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Alice Agent voor automatische updates.lnk - C:\Program Files\T-Mobile\Communication Center\AutoUpdateSrv.exe [2007-05-14 00:33:56]
svhost.exe.lnk - C:\WINDOWS\twunk_16.exe [1980-01-01]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{DB0B918E-A0A8-482B-8D75-A682816B0C7B}"= C:\WINDOWS\system32\qomjhed.dll [2007-12-18 17:16 40448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomjhed]
qomjhed.dll 2007-12-18 17:16 40448 C:\WINDOWS\system32\qomjhed.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jeff^Start Menu^Programs^Startup^WorldClock.lnk]
path=C:\Documents and Settings\Jeff\Start Menu\Programs\Startup\WorldClock.lnk
backup=C:\WINDOWS\pss\WorldClock.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bpk]
C:\Program Files\BPK\bpk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXDllRegExe]
dxdllreg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2007-05-11 02:08 2512392 –a—— C:\WINDOWS\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\p2p networking]
p2pnetworking.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
C:\Program Files\Registry Mechanic\RegMech.exe /QS
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1000140.exe 61A847B5BBF72813329B385776F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpriteService]
2006-11-03 11:19 544768 –a—— C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-19 20:27 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys [2003-04-28 11:27]
R2 Gizmo Plugin;Gizmo VoIP Service;"C:\Program Files\GizmoPlugin\GizmoPlugin.exe" [2007-11-02 22:50]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;C:\WINDOWS\system32\DRIVERS\i2220ntx.sys [2004-03-29 17:23]
R3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys [2005-06-10 06:55]
R3 POWERKEY;POWERKEY;C:\Program Files\Launch Manager\POWERKEY.sys [2000-12-19 18:29]
S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys []
S2 freenet-darknet-8888;Freenet 0.7 darknet-8888;"C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe" -s "C:\Program Files\Freenet\wrapper.conf" []
S3 fwb;fwb;C:\DOCUME~1\Jeff\LOCALS~1\Temp\a.dll []
S3 GoogleDesktopManager-091907-194040;Google Desktop Manager 5.1.709.19590;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-16 15:49]
S3 GTF32BUS;GT F32 BUS;C:\WINDOWS\system32\DRIVERS\gtf32bus.sys [2005-09-01 18:54]
S3 GTPTSER;GT PT SER;C:\WINDOWS\system32\DRIVERS\gtptser.sys [2005-09-01 18:54]
S3 GTSCSER;GT SC SER;C:\WINDOWS\system32\DRIVERS\gtscser.sys [2005-08-29 16:45]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial;C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2007-03-03 18:47]
S3 IpHook;IpHook;C:\Program Files\Network Traffic Monitor\IpHook.sys []
S3 W8335XP;Marvell Libertas 802.11b/g Driver for Windows XP (8335);C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-09-09 22:14]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c000bb6-1f4b-11dc-b280-000ae4a7dfb6}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9196fd06-5091-11dc-b296-000ae4a7dfb6}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8d03950-660f-11dc-b27b-000ae4a7dfb6}]
\Shell\AutoRun\command - I:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6cfbe22-1f75-11dc-b281-000ae4a7dfb6}]
\Shell\AutoRun\command - H:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-05 09:02:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-18 18:34:04 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-12-18 20:15:28 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-18 21:14:55
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\qomjhed.dll
.
Completion time: 2007-12-18 21:17:51 - machine was rebooted
.
2007-12-18 02:01:22 — E O F —