katoquinn
Topic Starter
After battling spyware/malware for a week, I still have traces of Storage Protector on my desktop, and my overall performance is extremely slow. Here are my two log files. Any help would be GREATLY appreciated!
ComboFix 08-01-30.6 - Kate Quinn 2008-01-30 11:26:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.141 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\rphnhdvh.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Temporary
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\system32\ajabedwx.dll
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\dpafaqlb.dll
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini2
C:\WINDOWS\system32\gvqudbuz.dllbox
C:\WINDOWS\system32\gwfdhfdc(2).dll
C:\WINDOWS\system32\gwfdhfdc.dll
C:\WINDOWS\system32\gwfdhfdc.dllbox
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mljgf(2).dll
C:\WINDOWS\system32\mljgf(3).dll
C:\WINDOWS\system32\mljgf(4).dll
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.exe
C:\WINDOWS\system32\ncbpuxvj.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rphnhdvh.dll
C:\WINDOWS\system32\rphnhdvh.dllbox
C:\WINDOWS\system32\xwdebaja.ini
C:\WINDOWS\Fonts\'
—– BITS: Possible infected sites —–
hxxp://origin.onecare.live.com
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.
2008-01-30 11:18 . 2008-01-30 11:18 d——– C:\Program Files\Trend Micro
2008-01-30 10:37 . 2008-01-30 10:37 338,432 –a—— C:\WINDOWS\system32\RCXF2E.tmp
2008-01-30 09:28 . 2008-01-30 10:21 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-01-29 22:02 . 2005-07-04 16:03 1,650,688 –a—— C:\WINDOWS\system32\qdiagdwc.ocx
2008-01-29 22:02 . 2005-02-09 13:08 7,168 –a—— C:\WINDOWS\system32\DLPT64.sys
2008-01-29 22:02 . 2005-02-08 13:04 5,632 –a—— C:\WINDOWS\system32\GPCIEn64.sys
2008-01-29 22:02 . 2005-02-08 15:46 5,120 –a—— C:\WINDOWS\system32\GTKCMO64.sys
2008-01-29 22:02 . 2005-02-07 19:07 4,608 –a—— C:\WINDOWS\system32\DDMI64.sys
2008-01-29 08:46 . 2008-01-29 21:51 654 –ahs—- C:\WINDOWS\system32\mahrhwdf.ini
2008-01-28 09:08 . 2008-01-28 09:08 1,374 –a—— C:\WINDOWS\imsins.BAK
2008-01-27 20:31 . 2008-01-27 20:32 d——– C:\WINSSLog
2008-01-27 20:13 . 2008-01-27 20:13 d——– C:\Program Files\MSBuild
2008-01-27 20:05 . 2008-01-27 20:05 d——– C:\WINDOWS\system32\XPSViewer
2008-01-27 20:04 . 2008-01-27 20:04 d——– C:\Program Files\Reference Assemblies
2008-01-27 13:43 . 2008-01-30 11:01 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-27 13:43 . 2008-01-27 13:43 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-26 13:35 . 2008-01-04 20:56 1,526,640 –a—— C:\WINDOWS\WRSetup.dll
2008-01-26 13:34 . 2008-01-26 13:34 164 –a—— C:\install.dat
2008-01-26 10:44 . 2008-01-30 09:10 d——– C:\Documents and Settings\Kate Quinn\.housecall6.6
2008-01-25 23:58 . 2008-01-30 08:36 174,592 –a—— C:\WINDOWS\system32\LEXPPS .EXE
2008-01-25 23:39 . 2008-01-30 11:01 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-25 16:43 . 2006-06-29 13:07 14,048 –a—— C:\WINDOWS\system32\spmsg2.dll
2008-01-25 16:41 . 2008-01-25 16:41 d——– C:\Program Files\MSXML 6.0
2008-01-25 14:27 . 2008-01-25 14:27 d——– C:\WINDOWS\system32\nGpxx18
2008-01-25 14:27 . 2008-01-25 14:27 d——– C:\Temp\gTiis19
2008-01-25 14:27 . 2008-01-25 14:27 d——– C:\Temp\cXzz9
2008-01-24 22:53 . 2008-01-24 22:53 d——– C:\WINDOWS\system32\bits
2008-01-24 22:52 . 2007-03-29 07:56 409,600 ——— C:\WINDOWS\system32\dllcache\qmgr.dll
2008-01-24 22:52 . 2007-03-29 07:56 18,944 ——— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-01-24 22:52 . 2007-03-29 07:56 7,168 ——— C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-01-24 22:52 . 2007-03-29 07:56 7,168 –a—— C:\WINDOWS\system32\bitsprx4.dll
2008-01-24 22:34 . 2008-01-24 22:34 18,944 –a—— C:\services.exe
2008-01-24 22:32 . 2008-01-24 22:32 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\Weight Commander
2008-01-24 22:27 . 2008-01-24 22:27 d–h—– C:\Program Files\Uninstall Information
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\MUSICMATCH
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\illiminable
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\Fujifilm e-Systems
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\Digital Line Detect
2008-01-24 22:27 . 2008-01-25 23:45 d——– C:\Program Files\Apoint
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-24 22:26 . 2008-01-24 22:26 d——– C:\Program Files\MSXML 4.0
2008-01-24 22:23 . 2008-01-25 14:17 d——– C:\Documents and Settings\Kate Quinn\Application Data\Viewpoint
2008-01-24 22:21 . 2008-01-24 22:21 d——– C:\Program Files\Your Company Name
2008-01-20 16:38 . 2008-01-20 16:38 334,848 –a—— C:\WINDOWS\system32\mljgf(2).dll_old
2008-01-17 19:32 . 2008-01-26 16:01 d——– C:\WINDOWS\system32\kt8
2008-01-17 19:32 . 2008-01-24 22:29 d——– C:\WINDOWS\system32\gz4
2008-01-17 19:32 . 2008-01-26 13:28 d——– C:\WINDOWS\system32\dp2
2008-01-17 19:31 . 2008-01-17 19:31 d——– C:\WINDOWS\system32\edcA18
2008-01-17 19:31 . 2008-01-30 11:32 d——– C:\Temp
2008-01-16 10:31 . 2008-01-16 10:31 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2008-01-16 09:57 . 2008-01-16 09:57 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-16 09:57 . 2008-01-16 09:57 356,352 –a—— C:\WINDOWS\eSellerateEngine.dll
2008-01-16 08:23 . 2008-01-30 11:32 d——– C:\Program Files\iTunes
2008-01-16 08:19 . 2008-01-25 23:45 d——– C:\Program Files\QuickTime
2008-01-16 08:17 . 2008-01-16 08:17 d——– C:\Program Files\Common Files\Apple
2008-01-10 15:27 . 2008-01-10 15:27 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-01-03 11:14 . 2008-01-03 11:15 d——– C:\Documents and Settings\Kate Quinn\My Music
2007-12-27 23:06 . 2007-12-27 23:06 dr-h—– C:\Documents and Settings\Kate Quinn\Application Data\SecuROM
2007-12-27 22:07 . 2007-12-27 22:07 d——– C:\Program Files\Electronic Arts
2007-12-27 21:52 . 2006-11-13 01:02 288,768 –a—— C:\WINDOWS\system32\rhttpaa.dll
2007-12-27 21:52 . 2006-11-13 01:02 116,736 –a—— C:\WINDOWS\system32\aaclient.dll
2007-12-27 21:52 . 2006-11-13 01:02 36,352 –a—— C:\WINDOWS\system32\tsgqec.dll
2007-12-27 21:48 . 2007-12-27 21:48 41,472 –ahs—- C:\WINDOWS\Thumbs.db
2007-12-27 21:48 . 2008-01-22 18:10 6,656 –ahs—- C:\WINDOWS\system32\Thumbs.db
2007-12-27 14:03 . 2007-12-27 14:03 d——– C:\Program Files\Western Digital
2007-12-27 14:01 . 2007-12-27 14:01 d——– C:\Program Files\Western Digital Technologies
2007-12-27 09:31 . 2007-12-27 09:31 d——– C:\Program Files\Smilebox
2007-12-27 09:30 . 2008-01-25 23:45 d——– C:\Documents and Settings\Kate Quinn\Application Data\Smilebox
2007-12-25 14:22 . 2007-12-25 14:22 0 –a—— C:\WINDOWS\iplayer.INI
2007-12-25 12:43 . 2007-12-27 17:26 d——– C:\WINDOWS\SxsCaPendDel
2007-12-04 00:18 . 2007-12-04 00:18 d——– C:\WINDOWS\McAfee.com
2007-12-03 23:48 . 2007-12-03 23:48 d——– C:\Documents and Settings\All Users\Application Data\Dell
2007-12-03 07:08 . 2007-12-03 07:08 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2007-12-03 07:07 . 2007-12-03 07:07 d——– C:\Program Files\Dell Support Center
2007-12-03 07:07 . 2007-12-03 07:07 d——– C:\Program Files\Common Files\supportsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-30 13:52 ——— d—–w C:\Program Files\Google
2008-01-26 18:26 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-26 18:26 ——— d—–w C:\Program Files\DellSupport
2008-01-26 18:26 ——— d—–w C:\Program Files\Dell AIO Printer A920
2008-01-26 04:45 ——— d—–w C:\Program Files\AIM6
2008-01-25 19:30 ——— d—–w C:\Documents and Settings\Kate Quinn\Application Data\LimeWire
2008-01-25 19:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-25 03:23 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-16 13:23 ——— d—–w C:\Program Files\iPod
2007-12-25 17:54 ——— d—–w C:\Program Files\Yahoo!
2007-12-25 17:37 ——— d–h–w C:\Documents and Settings\Kate Quinn\Application Data\Move Networks
2007-12-25 17:36 ——— d—–w C:\Program Files\Kodak
2007-12-25 17:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2007-12-25 17:29 ——— d—–w C:\Program Files\Java
2007-12-25 17:29 ——— d—–w C:\Program Files\ABBYY FineReader 5.0 Sprint
2007-10-22 08:31 76,808 -c–a-w C:\WINDOWS\DSETUP.dll
2007-10-22 08:31 502,792 -c–a-w C:\WINDOWS\DXSETUP.exe
2007-10-22 08:31 1,673,224 -c–a-w C:\WINDOWS\dsetup32.dll
2007-01-08 04:55 13,012 -c–a-w C:\Documents and Settings\Kate Quinn\Bubblets.dat
2006-11-04 22:46 88 -csha-r C:\WINDOWS\system32\7F4E96D5B5.sys
2006-11-04 22:49 3,558 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83F6B9E6-3F73-4F0C-F480-C4A0240919D8}]
C:\Program Files\MSN\lacusy.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-11-21 00:56:44 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljgfff]
mljgfff.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R3 WCDV_Aud;WevCamDV WDM Virtual Audio Device;C:\WINDOWS\system32\drivers\wcdvaud.sys [2004-01-30 12:08]
S2 FreezeScreenSaver;FreezeScreenSaver;C:\WINDOWS\system32\FreezeScreenSaver.exe [2005-09-29 14:55]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-23 04:07:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-30 08:41:32 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EEC30FFE-2FA2-46D1-8CC5-2B99AE93A90A}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 11:36:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2008-01-30 11:40:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-30 16:40:35
.
2008-01-30 08:22:51 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:41:18 AM, on 1/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://wwwp.musicmatch.com/aod2/dmx/update/dmx100d.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: 0 - {83F6B9E6-3F73-4F0C-F480-C4A0240919D8} - C:\Program Files\MSN\lacusy.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (file missing)
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {C6D25826-96AE-462F-A852-BB33B882B723} (SFImageUpload1_4.ImageUpload) - http://duanereade.storefront.com/images/gl…geUpload1_4.CAB
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) - http://entriq.vo.llnwd.net/o1/NBCUniversal…eck_1_0_0_5.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - http://entriq.vo.llnwd.net/o1/NBCUniversal…_2_2_Silent.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - http://entriq.vo.llnwd.net/o1/NBCUniversal…sal_1_0_0_7.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…176/mcfscan.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab?
O20 - Winlogon Notify: mljgfff - mljgfff.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: (no name) - http://www.facebook.com/
–
End of file - 8623 bytes
ComboFix 08-01-30.6 - Kate Quinn 2008-01-30 11:26:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.141 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\rphnhdvh.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Temporary
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\system32\ajabedwx.dll
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\dpafaqlb.dll
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini2
C:\WINDOWS\system32\gvqudbuz.dllbox
C:\WINDOWS\system32\gwfdhfdc(2).dll
C:\WINDOWS\system32\gwfdhfdc.dll
C:\WINDOWS\system32\gwfdhfdc.dllbox
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mljgf(2).dll
C:\WINDOWS\system32\mljgf(3).dll
C:\WINDOWS\system32\mljgf(4).dll
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.exe
C:\WINDOWS\system32\ncbpuxvj.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rphnhdvh.dll
C:\WINDOWS\system32\rphnhdvh.dllbox
C:\WINDOWS\system32\xwdebaja.ini
C:\WINDOWS\Fonts\'
—– BITS: Possible infected sites —–
hxxp://origin.onecare.live.com
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.
2008-01-30 11:18 . 2008-01-30 11:18 d——– C:\Program Files\Trend Micro
2008-01-30 10:37 . 2008-01-30 10:37 338,432 –a—— C:\WINDOWS\system32\RCXF2E.tmp
2008-01-30 09:28 . 2008-01-30 10:21 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-01-29 22:02 . 2005-07-04 16:03 1,650,688 –a—— C:\WINDOWS\system32\qdiagdwc.ocx
2008-01-29 22:02 . 2005-02-09 13:08 7,168 –a—— C:\WINDOWS\system32\DLPT64.sys
2008-01-29 22:02 . 2005-02-08 13:04 5,632 –a—— C:\WINDOWS\system32\GPCIEn64.sys
2008-01-29 22:02 . 2005-02-08 15:46 5,120 –a—— C:\WINDOWS\system32\GTKCMO64.sys
2008-01-29 22:02 . 2005-02-07 19:07 4,608 –a—— C:\WINDOWS\system32\DDMI64.sys
2008-01-29 08:46 . 2008-01-29 21:51 654 –ahs—- C:\WINDOWS\system32\mahrhwdf.ini
2008-01-28 09:08 . 2008-01-28 09:08 1,374 –a—— C:\WINDOWS\imsins.BAK
2008-01-27 20:31 . 2008-01-27 20:32 d——– C:\WINSSLog
2008-01-27 20:13 . 2008-01-27 20:13 d——– C:\Program Files\MSBuild
2008-01-27 20:05 . 2008-01-27 20:05 d——– C:\WINDOWS\system32\XPSViewer
2008-01-27 20:04 . 2008-01-27 20:04 d——– C:\Program Files\Reference Assemblies
2008-01-27 13:43 . 2008-01-30 11:01 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-27 13:43 . 2008-01-27 13:43 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-26 13:35 . 2008-01-04 20:56 1,526,640 –a—— C:\WINDOWS\WRSetup.dll
2008-01-26 13:34 . 2008-01-26 13:34 164 –a—— C:\install.dat
2008-01-26 10:44 . 2008-01-30 09:10 d——– C:\Documents and Settings\Kate Quinn\.housecall6.6
2008-01-25 23:58 . 2008-01-30 08:36 174,592 –a—— C:\WINDOWS\system32\LEXPPS .EXE
2008-01-25 23:39 . 2008-01-30 11:01 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-25 16:43 . 2006-06-29 13:07 14,048 –a—— C:\WINDOWS\system32\spmsg2.dll
2008-01-25 16:41 . 2008-01-25 16:41 d——– C:\Program Files\MSXML 6.0
2008-01-25 14:27 . 2008-01-25 14:27 d——– C:\WINDOWS\system32\nGpxx18
2008-01-25 14:27 . 2008-01-25 14:27 d——– C:\Temp\gTiis19
2008-01-25 14:27 . 2008-01-25 14:27 d——– C:\Temp\cXzz9
2008-01-24 22:53 . 2008-01-24 22:53 d——– C:\WINDOWS\system32\bits
2008-01-24 22:52 . 2007-03-29 07:56 409,600 ——— C:\WINDOWS\system32\dllcache\qmgr.dll
2008-01-24 22:52 . 2007-03-29 07:56 18,944 ——— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-01-24 22:52 . 2007-03-29 07:56 7,168 ——— C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-01-24 22:52 . 2007-03-29 07:56 7,168 –a—— C:\WINDOWS\system32\bitsprx4.dll
2008-01-24 22:34 . 2008-01-24 22:34 18,944 –a—— C:\services.exe
2008-01-24 22:32 . 2008-01-24 22:32 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\Weight Commander
2008-01-24 22:27 . 2008-01-24 22:27 d–h—– C:\Program Files\Uninstall Information
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\MUSICMATCH
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\illiminable
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\Fujifilm e-Systems
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Program Files\Digital Line Detect
2008-01-24 22:27 . 2008-01-25 23:45 d——– C:\Program Files\Apoint
2008-01-24 22:27 . 2008-01-24 22:27 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-24 22:26 . 2008-01-24 22:26 d——– C:\Program Files\MSXML 4.0
2008-01-24 22:23 . 2008-01-25 14:17 d——– C:\Documents and Settings\Kate Quinn\Application Data\Viewpoint
2008-01-24 22:21 . 2008-01-24 22:21 d——– C:\Program Files\Your Company Name
2008-01-20 16:38 . 2008-01-20 16:38 334,848 –a—— C:\WINDOWS\system32\mljgf(2).dll_old
2008-01-17 19:32 . 2008-01-26 16:01 d——– C:\WINDOWS\system32\kt8
2008-01-17 19:32 . 2008-01-24 22:29 d——– C:\WINDOWS\system32\gz4
2008-01-17 19:32 . 2008-01-26 13:28 d——– C:\WINDOWS\system32\dp2
2008-01-17 19:31 . 2008-01-17 19:31 d——– C:\WINDOWS\system32\edcA18
2008-01-17 19:31 . 2008-01-30 11:32 d——– C:\Temp
2008-01-16 10:31 . 2008-01-16 10:31 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2008-01-16 09:57 . 2008-01-16 09:57 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-16 09:57 . 2008-01-16 09:57 356,352 –a—— C:\WINDOWS\eSellerateEngine.dll
2008-01-16 08:23 . 2008-01-30 11:32 d——– C:\Program Files\iTunes
2008-01-16 08:19 . 2008-01-25 23:45 d——– C:\Program Files\QuickTime
2008-01-16 08:17 . 2008-01-16 08:17 d——– C:\Program Files\Common Files\Apple
2008-01-10 15:27 . 2008-01-10 15:27 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts
2008-01-03 11:14 . 2008-01-03 11:15 d——– C:\Documents and Settings\Kate Quinn\My Music
2007-12-27 23:06 . 2007-12-27 23:06 dr-h—– C:\Documents and Settings\Kate Quinn\Application Data\SecuROM
2007-12-27 22:07 . 2007-12-27 22:07 d——– C:\Program Files\Electronic Arts
2007-12-27 21:52 . 2006-11-13 01:02 288,768 –a—— C:\WINDOWS\system32\rhttpaa.dll
2007-12-27 21:52 . 2006-11-13 01:02 116,736 –a—— C:\WINDOWS\system32\aaclient.dll
2007-12-27 21:52 . 2006-11-13 01:02 36,352 –a—— C:\WINDOWS\system32\tsgqec.dll
2007-12-27 21:48 . 2007-12-27 21:48 41,472 –ahs—- C:\WINDOWS\Thumbs.db
2007-12-27 21:48 . 2008-01-22 18:10 6,656 –ahs—- C:\WINDOWS\system32\Thumbs.db
2007-12-27 14:03 . 2007-12-27 14:03 d——– C:\Program Files\Western Digital
2007-12-27 14:01 . 2007-12-27 14:01 d——– C:\Program Files\Western Digital Technologies
2007-12-27 09:31 . 2007-12-27 09:31 d——– C:\Program Files\Smilebox
2007-12-27 09:30 . 2008-01-25 23:45 d——– C:\Documents and Settings\Kate Quinn\Application Data\Smilebox
2007-12-25 14:22 . 2007-12-25 14:22 0 –a—— C:\WINDOWS\iplayer.INI
2007-12-25 12:43 . 2007-12-27 17:26 d——– C:\WINDOWS\SxsCaPendDel
2007-12-04 00:18 . 2007-12-04 00:18 d——– C:\WINDOWS\McAfee.com
2007-12-03 23:48 . 2007-12-03 23:48 d——– C:\Documents and Settings\All Users\Application Data\Dell
2007-12-03 07:08 . 2007-12-03 07:08 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2007-12-03 07:07 . 2007-12-03 07:07 d——– C:\Program Files\Dell Support Center
2007-12-03 07:07 . 2007-12-03 07:07 d——– C:\Program Files\Common Files\supportsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-30 13:52 ——— d—–w C:\Program Files\Google
2008-01-26 18:26 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-26 18:26 ——— d—–w C:\Program Files\DellSupport
2008-01-26 18:26 ——— d—–w C:\Program Files\Dell AIO Printer A920
2008-01-26 04:45 ——— d—–w C:\Program Files\AIM6
2008-01-25 19:30 ——— d—–w C:\Documents and Settings\Kate Quinn\Application Data\LimeWire
2008-01-25 19:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-25 03:23 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-16 13:23 ——— d—–w C:\Program Files\iPod
2007-12-25 17:54 ——— d—–w C:\Program Files\Yahoo!
2007-12-25 17:37 ——— d–h–w C:\Documents and Settings\Kate Quinn\Application Data\Move Networks
2007-12-25 17:36 ——— d—–w C:\Program Files\Kodak
2007-12-25 17:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2007-12-25 17:29 ——— d—–w C:\Program Files\Java
2007-12-25 17:29 ——— d—–w C:\Program Files\ABBYY FineReader 5.0 Sprint
2007-10-22 08:31 76,808 -c–a-w C:\WINDOWS\DSETUP.dll
2007-10-22 08:31 502,792 -c–a-w C:\WINDOWS\DXSETUP.exe
2007-10-22 08:31 1,673,224 -c–a-w C:\WINDOWS\dsetup32.dll
2007-01-08 04:55 13,012 -c–a-w C:\Documents and Settings\Kate Quinn\Bubblets.dat
2006-11-04 22:46 88 -csha-r C:\WINDOWS\system32\7F4E96D5B5.sys
2006-11-04 22:49 3,558 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
—-a-w 201,352 2008-01-25 19:25:50 C:\Documents and Settings\Kate Quinn\Application Data\Smilebox\SmileboxTray .exe —-a-w 50,528 2008-01-25 19:25:13 C:\Program Files\AIM6\aim6 .exe —-a-w 155,648 2008-01-25 03:32:02 C:\Program Files\Apoint\Apoint .exe —-a-w 344,064 2008-01-25 03:32:03 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe —-a-w 50,760 2008-01-25 03:32:47 C:\Program Files\Common Files\AOL\1147261090\ee\AOLSoftware .exe —-a-w 81,920 2008-01-25 03:32:11 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe —-a-w 28,672 2008-01-25 03:32:32 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind .exe —-a-w 53,248 2008-01-25 03:32:06 C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe —-a-w 290,816 2008-01-25 03:32:03 C:\Program Files\Dell\Media Experience\PCMService .exe —-a-w 684,032 2008-01-25 03:32:04 C:\Program Files\Dell\QuickSet\Quickset .exe —-a-w 270,336 2008-01-25 03:32:13 C:\Program Files\Dell AIO Printer A920\dlbkbmgr .exe —-a-w 202,544 2008-01-25 19:25:42 C:\Program Files\Dell Support Center\bin\sprtcmd .exe —-a-w 16,384 2008-01-25 03:32:52 C:\Program Files\Dell Support Center\gs_agent\custom\dsca .exe —-a-w 460,784 2008-01-25 19:25:33 C:\Program Files\DellSupport\DSAgnt .exe —-a-w 68,856 2008-01-30 13:51:53 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe —-a-w 385,024 2008-01-25 03:32:03 C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe —-a-w 267,048 2008-01-30 16:00:48 C:\Program Files\iTunes\iTunesHelper .exe —-a-w 132,496 2008-01-25 03:32:55 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe —-a-w 1,694,208 2008-01-28 01:35:35 C:\Program Files\Messenger\msmsgs .exe —-a-w 1,200,128 2008-01-26 18:26:58 C:\Program Files\Microsoft ActiveSync\wcescomm .exe —-a-w 385,024 2008-01-26 18:26:59 C:\Program Files\QuickTime\QTTask .exe —-a-w 204,288 2008-01-25 19:25:42 C:\Program Files\Windows Media Player\WMPNSCFG .exe —-a-w 15,360 2008-01-30 16:01:10 C:\WINDOWS\system32\ctfmon .exe —-a-w 174,592 2008-01-30 13:36:27 C:\WINDOWS\system32\LEXPPS .EXE —-a-w 155,648 2008-01-25 03:32:34 C:\WINDOWS\system32\NeroCheck .exe —-a-w 122,941 2008-01-25 03:32:26 C:\WINDOWS\system32\dla\tfswctrl .exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83F6B9E6-3F73-4F0C-F480-C4A0240919D8}]
C:\Program Files\MSN\lacusy.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-11-21 00:56:44 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljgfff]
mljgfff.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R3 WCDV_Aud;WevCamDV WDM Virtual Audio Device;C:\WINDOWS\system32\drivers\wcdvaud.sys [2004-01-30 12:08]
S2 FreezeScreenSaver;FreezeScreenSaver;C:\WINDOWS\system32\FreezeScreenSaver.exe [2005-09-29 14:55]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-23 04:07:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-30 08:41:32 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EEC30FFE-2FA2-46D1-8CC5-2B99AE93A90A}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 11:36:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2008-01-30 11:40:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-30 16:40:35
.
2008-01-30 08:22:51 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:41:18 AM, on 1/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://wwwp.musicmatch.com/aod2/dmx/update/dmx100d.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: 0 - {83F6B9E6-3F73-4F0C-F480-C4A0240919D8} - C:\Program Files\MSN\lacusy.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (file missing)
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {C6D25826-96AE-462F-A852-BB33B882B723} (SFImageUpload1_4.ImageUpload) - http://duanereade.storefront.com/images/gl…geUpload1_4.CAB
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) - http://entriq.vo.llnwd.net/o1/NBCUniversal…eck_1_0_0_5.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - http://entriq.vo.llnwd.net/o1/NBCUniversal…_2_2_Silent.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - http://entriq.vo.llnwd.net/o1/NBCUniversal…sal_1_0_0_7.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…176/mcfscan.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab?
O20 - Winlogon Notify: mljgfff - mljgfff.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: (no name) - http://www.facebook.com/
–
End of file - 8623 bytes