ComboFix 08-02-18.1 - Barry Kunz 2008-02-19 20:38:43.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\jkklk.dll
C:\WINDOWS\system32\awtqpmm.dll
C:\WINDOWS\system32\ewjkevwv.dll
C:\WINDOWS\system32\jkklk.dll
C:\WINDOWS\SYSTEM32\kjllm.ini
C:\WINDOWS\SYSTEM32\kjllm.ini2
C:\WINDOWS\SYSTEM32\klkkj.ini
C:\WINDOWS\SYSTEM32\klkkj.ini2
C:\WINDOWS\SYSTEM32\vwvekjwe.ini
C:\WINDOWS\system32\xppsjbln.dll
.
—- Previous Run ——-
.
C:\WINDOWS\system32\awtqpmm.dll
C:\WINDOWS\system32\ewjkevwv.dll
C:\WINDOWS\system32\jkklk.dll
C:\WINDOWS\SYSTEM32\kjllm.ini
C:\WINDOWS\SYSTEM32\kjllm.ini2
C:\WINDOWS\SYSTEM32\klkkj.ini
C:\WINDOWS\SYSTEM32\klkkj.ini2
C:\WINDOWS\SYSTEM32\vwvekjwe.ini
C:\WINDOWS\system32\xppsjbln.dll
C:\Program Files\Real
.
((((((((((((((((((((((((( Files Created from 2008-01-20 to 2008-02-20 )))))))))))))))))))))))))))))))
.
2008-02-18 13:07 . 2008-02-18 15:28 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-18 13:07 . 2008-02-18 13:07 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-02 15:56 . 2008-02-18 14:00 d——– C:\VundoFix Backups
2008-02-02 10:22 . 2008-02-02 10:30 d——– C:\sdat
2008-02-02 10:05 . 2008-02-02 10:10 33,260,764 –a—— C:\sdat5221.exe
2008-02-02 03:52 . 2008-02-02 11:14 d——– C:\Documents and Settings\Barry Kunz\smitRem
2008-02-02 03:32 . 2004-01-08 00:11 d——– C:\Documents and Settings\Administrator.ELLIE\Application Data\Sonic
2008-02-02 03:32 . 2004-01-08 00:13 d——– C:\Documents and Settings\Administrator.ELLIE\Application Data\Jasc Software Inc
2008-02-02 03:14 . 2008-02-02 03:14 3,470 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2008-02-02 03:13 . 2008-02-02 11:14 d——– C:\Documents and Settings\Barry Kunz\SmitfraudFix
2008-02-02 03:13 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\SYSTEM32\VCCLSID.exe
2008-02-02 03:13 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\SYSTEM32\SrchSTS.exe
2008-02-02 03:13 . 2008-02-02 00:55 83,456 –a—— C:\WINDOWS\SYSTEM32\VACFix.exe
2008-02-02 03:13 . 2008-01-27 14:37 81,920 –a—— C:\WINDOWS\SYSTEM32\IEDFix.exe
2008-02-02 03:13 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\SYSTEM32\dumphive.exe
2008-02-02 03:13 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\SYSTEM32\WS2Fix.exe
2008-02-02 03:06 . 2008-02-02 03:06 1,212,030 –a—— C:\SmitfraudFix.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 14:15 ——— d—–w C:\Documents and Settings\Barry Kunz\Application Data\SiteAdvisor
2008-02-16 15:26 ——— d—–w C:\Program Files\McAfee
2008-02-12 03:27 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-09 18:24 ——— d—–w C:\Documents and Settings\Barry Kunz\Application Data\Intuit
2008-02-09 18:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-09 18:09 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-02-09 17:57 ——— d—–w C:\Program Files\TurboTax
2008-02-09 16:19 ——— d—–w C:\Program Files\ABC
2008-02-02 21:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-02 20:06 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-01-28 06:39 ——— d—–w C:\Program Files\iTunes
2008-01-28 06:39 ——— d—–w C:\Program Files\iPod
2008-01-28 06:37 ——— d—–w C:\Program Files\QuickTime
2008-01-15 04:36 ——— d—–w C:\Program Files\mIRC
2008-01-04 02:11 ——— d—–w C:\Program Files\MagicISO
2007-12-30 06:21 ——— d—–w C:\Program Files\Alcohol Soft
2007-12-30 06:15 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-23 13:37 ——— d—–w C:\Program Files\SiteAdvisor
2007-10-12 01:49 95,544 —-a-w C:\Documents and Settings\Barry Kunz\Application Data\GDIPFONTCACHEV1.DAT
2007-04-19 04:06 439,296 —-a-w C:\Documents and Settings\Barry Kunz\GoToAssist_phone__317_en.exe
2007-02-16 14:20 3,518 —-a-w C:\Documents and Settings\Barry Kunz\Application Data\wklnhst.dat
2006-09-24 17:41 483,401 —-a-w C:\Documents and Settings\Barry Kunz\gotomypc_314.exe
2006-08-20 23:06 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2006-01-22 05:17 9,692,886 —-a-w C:\Program Files\vlc-0.8.4a-win32.exe
2006-01-22 02:37 4,222,516 —-a-w C:\Program Files\ABC-win32-v3.1.exe
2005-10-06 22:41 483,401 —-a-w C:\Documents and Settings\Barry Kunz\314_gotomypc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A7ED57BC-5C26-4348-9E08-52174949DAC2}]
C:\WINDOWS\system32\ssqpm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F4EDFEA7-289F-4996-BE11-6712DF56C6ED}]
C:\WINDOWS\system32\mlljk.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"RemoteCenter"="C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE" [2004-06-25 09:21 147456]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54 5674352]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-12-22 02:20 222080]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 02:04 114741]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 20:47 204800]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01 110592]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36 114688]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2006-12-19 21:37 36952]
"EPSON Stylus CX7800 Series (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAFA.exe" [2005-04-06 16:00 98304]
"Microsoft Help"="C:\LOL\jah.exe" [2007-12-01 20:26 45056]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54 5674352]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Media Card Companion Monitor.lnk - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe [2005-06-04 15:32:26 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"Image"= rundll32 C:\WINDOWS\sdkqh32.dll,Install
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gclfladm]
R2 ONSIO;ONSIO;C:\WINDOWS\SYSTEM32\DRIVERS\ONSIO.SYS [1998-09-14 08:41]
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [2006-11-07 00:20]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
S0 SMPLSCSI;SMPLSCSI;C:\WINDOWS\system32\drivers\SMPLSCSI.SYS [1998-08-01 12:00]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 08:05]
S3 PortlUSB;PortlUSB;C:\WINDOWS\system32\DRIVERS\SiriusUSB.sys [2005-09-03 00:58]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 01:46:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-15 06:00:04 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-02-01 06:00:11 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-19 20:52:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\program files\mcafee\msc\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-02-19 21:01:55 - machine was rebooted [Barry Kunz]
ComboFix-quarantined-files.txt 2008-02-20 02:01:52
ComboFix2.txt 2008-02-02 22:30:42
.
2008-02-13 08:05:17 — E O F —