Deleted Member
Topic Starter
I've been struggling with some nasties the last couple weeks that I haven't been able to make go away. I usually use AdAware SE to take care of the problems, but it wasn't cutting it. I found information on ComboFix and installed it (along with the recovery software) and ran it this afternoon. It's made a tremendous difference already. The program prompted me to post the logs on a forum to be reviewed by someone who knew what they were doing (not me). Any assistance would be greatly appreciated. So here they are:
ComboFix Log:
ComboFix 08-02-25.3 - JPascoal 2008-02-26 13:38:01.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\JPascoal\Favorites\Online Security Guide.lnk
C:\Documents and Settings\JPascoal\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\JPascoal\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\JPascoal\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Program Files\Common Files\sstem~1
C:\Program Files\ystem3~1
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\asembl~1
C:\WINDOWS\asembl~1\l?gonui.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b148.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\mrofinu72.exe
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\adwetfwi.dll
C:\WINDOWS\system32\atacmdlo.ini
C:\WINDOWS\system32\ayqcxtvr.dll
C:\WINDOWS\system32\bbvthujo.ini
C:\WINDOWS\system32\blgogtjt.ini
C:\WINDOWS\system32\bucssgmw.dll
C:\WINDOWS\system32\bymgxrkr.dll
C:\WINDOWS\system32\c1
C:\WINDOWS\system32\ccbeg.ini
C:\WINDOWS\system32\ccbeg.ini2
C:\WINDOWS\system32\cdmsshdd.dll
C:\WINDOWS\system32\cgonptic.dll
C:\WINDOWS\system32\cmcdgdrr.dll
C:\WINDOWS\system32\d1
C:\WINDOWS\system32\d1\cby1stp.exe
C:\WINDOWS\system32\ddbpalmu.dll
C:\WINDOWS\system32\djlubfww.dll
C:\WINDOWS\system32\dkjleiko.ini
C:\WINDOWS\system32\dlhqwjre.dll
C:\WINDOWS\system32\drivers\core.cache(2).dsk
C:\WINDOWS\system32\drivers\core.cache(3).dsk
C:\WINDOWS\system32\drivers\core.cache(4).dsk
C:\WINDOWS\system32\dvdoafbq.ini
C:\WINDOWS\system32\eeyhccuc.dll
C:\WINDOWS\system32\efcbyay.dll
C:\WINDOWS\system32\ehpfputh.dll
C:\WINDOWS\system32\ekdscpnk.dll
C:\WINDOWS\system32\eosimvpn.ini
C:\windows\system32\explorer.exe
C:\WINDOWS\system32\fcnkxjgb.ini
C:\WINDOWS\system32\fgnrurbx.dll
C:\WINDOWS\system32\fuxklvyj.dll
C:\WINDOWS\system32\fvwslfad.ini
C:\WINDOWS\system32\gebcc.dll
C:\WINDOWS\system32\ginsuwqm.dll
C:\WINDOWS\system32\gsaxjtgg.ini
C:\WINDOWS\system32\gswxfypx.dll
C:\WINDOWS\system32\gumnfyci.dll
C:\WINDOWS\system32\hatnymrh.dll
C:\WINDOWS\system32\hisdnhal.dll
C:\WINDOWS\system32\hmsmuoqe.ini
C:\WINDOWS\system32\hxitjujx.ini
C:\WINDOWS\system32\iehoielp.exe
C:\WINDOWS\system32\iexplorer.dll .dbt
C:\WINDOWS\system32\ijkvsfhw.dll
C:\WINDOWS\system32\imreuyop.dll
C:\WINDOWS\system32\iqcvaolf.dll
C:\WINDOWS\system32\isrmkmls.dll
C:\WINDOWS\system32\j2
C:\WINDOWS\system32\jkvohcyu.dll
C:\WINDOWS\system32\jlksvioq.ini
C:\WINDOWS\system32\jqkeqjqt.ini
C:\WINDOWS\system32\jqrmoosj.dll
C:\WINDOWS\system32\jsoomrqj.ini
C:\WINDOWS\system32\jveqshom.ini
C:\WINDOWS\system32\jwkkpngh.ini
C:\WINDOWS\system32\jxtoixth.ini
C:\WINDOWS\system32\jxyxcwqj.ini
C:\WINDOWS\system32\jyvettnu.ini
C:\WINDOWS\system32\keibqhdt.ini
C:\WINDOWS\system32\kgfmrpsq.ini
C:\WINDOWS\system32\kgwhxefg.ini
C:\WINDOWS\system32\khoblxlm.dll
C:\WINDOWS\system32\lkqigrwt.ini
C:\WINDOWS\system32\m8
C:\WINDOWS\system32\mggbkqao.ini
C:\WINDOWS\system32\mohsqevj.dll
C:\WINDOWS\system32\mp43.exe
C:\WINDOWS\system32\msrkjurc.dll
C:\WINDOWS\system32\nirxxphk.dll
C:\WINDOWS\system32\nlwjjllh.dll
C:\WINDOWS\system32\npvmisoe.dll
C:\WINDOWS\system32\nsudrcrq.dll
C:\WINDOWS\system32\nswxrlwy.ini
C:\WINDOWS\system32\ntload.sys
C:\WINDOWS\system32\oaqkbggm.dll
C:\WINDOWS\system32\odxeucnk.dll
C:\WINDOWS\system32\ojuhtvbb.dll
C:\WINDOWS\system32\okieljkd.dll
C:\WINDOWS\system32\olpkykwq.ini
C:\WINDOWS\system32\oltbhxcp.dllbox
C:\WINDOWS\system32\omsotqih.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pfatsoik.ini
C:\WINDOWS\system32\pgbuwoep.dll
C:\WINDOWS\system32\pharklka.dll
C:\WINDOWS\system32\pipcivpn.dll
C:\WINDOWS\system32\pvrkrxpx.dll
C:\WINDOWS\system32\qbcsaiso.dll
C:\WINDOWS\system32\qdwaumnt.ini
C:\WINDOWS\system32\qehbnqob.dll
C:\WINDOWS\system32\qeyrrqxb.ini
C:\WINDOWS\system32\qmcpkpwv.dll
C:\WINDOWS\system32\qqgponej.dll
C:\WINDOWS\system32\qratutbe.dll
C:\WINDOWS\system32\qsiimvjr.dll
C:\WINDOWS\system32\quocheol.dll
C:\WINDOWS\system32\qwkykplo.dll
C:\WINDOWS\system32\rknsxjau.ini
C:\WINDOWS\system32\rnxbejqc.dll
C:\WINDOWS\system32\roryxuru.ini
C:\WINDOWS\system32\rvcppjxo.ini
C:\WINDOWS\system32\rwleyqxx.ini
C:\WINDOWS\system32\rxwghjxy.dll
C:\WINDOWS\system32\rxwghjxy.dllbox
C:\WINDOWS\system32\sklbsnqs.dll
C:\WINDOWS\system32\slahcctn.ini
C:\WINDOWS\system32\smnnpspc.dll
C:\WINDOWS\system32\snlvlmtx.dll
C:\WINDOWS\system32\spturons.ini
C:\WINDOWS\system32\srkrfmkj.ini
C:\WINDOWS\system32\suawabyo.ini
C:\WINDOWS\system32\suirtmjg.exe
C:\WINDOWS\system32\sxtgbdsu.dll
C:\WINDOWS\system32\taxvdhgr.dll
C:\WINDOWS\system32\thwccbnl.dll
C:\WINDOWS\system32\twrgiqkl.dll
C:\WINDOWS\system32\txfvtxou.dll
C:\WINDOWS\system32\umlapbdd.ini
C:\WINDOWS\system32\uojxpmxe.dll
C:\WINDOWS\system32\uychovkj.ini
C:\WINDOWS\system32\vaxhaqah.dll
C:\WINDOWS\system32\vbaetpmb.dll
C:\WINDOWS\system32\vtjimhky.ini
C:\WINDOWS\system32\vurqdres.dll
C:\WINDOWS\system32\vvmrvkng.dllbox
C:\WINDOWS\system32\wbeqdowp.dll
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\winupdate.exe
C:\WINDOWS\system32\wloiekox.ini
C:\WINDOWS\system32\wmyotkon.dll
C:\WINDOWS\system32\wnsapisv32.exe
C:\WINDOWS\system32\wxtvlqsj.ini
C:\WINDOWS\system32\xfqmuqmi.ini
C:\WINDOWS\system32\xjujtixh.dll
C:\WINDOWS\system32\xmijslhk.dll
C:\WINDOWS\system32\xoxrplpd.dll
C:\WINDOWS\system32\yamofxgk.dll
C:\WINDOWS\system32\yeublnyk.dll
C:\WINDOWS\system32\yhbsprfd.dll
C:\WINDOWS\system32\ylsfscmm.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_CMDSERVICE
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService
——-\core
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.
2008-02-24 18:18 . 2008-02-26 12:18 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-24 18:18 . 2008-02-24 18:18 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-13 22:41 . 2008-02-13 22:41 d——– C:\My Music
2008-02-13 22:36 . 2008-02-13 22:36 d——– C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2008-02-07 17:20 . 2008-02-07 17:20 d——– C:\Program Files\Avant Browser
2008-02-07 17:20 . 2008-02-07 17:20 d——– C:\Documents and Settings\JPascoal\Application Data\Avant Profiles
2008-02-06 19:45 . 2008-02-06 19:45 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-02-04 18:26 . 2008-02-04 18:26 34,816 –a—— C:\winrzeu.exe
2008-01-30 19:07 . 2002-08-29 03:40 20,480 –a—— C:\WINDOWS\system32\hidserv.dll
2008-01-30 19:07 . 2002-08-29 03:40 20,480 –a–c— C:\WINDOWS\system32\dllcache\hidserv.dll
2008-01-27 22:41 . 2008-01-27 22:41 34,816 –a—— C:\winwcny.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 01:18 ——— d—–w C:\Program Files\DivX
2008-02-01 02:29 ——— d—–w C:\Documents and Settings\JPascoal\Application Data\Apple Computer
2008-01-25 22:02 ——— d—–w C:\Program Files\XoftSpy
2008-01-25 01:53 ——— d—–w C:\Program Files\Trend Micro
2008-01-24 23:58 480,768 —-a-w C:\Documents and Settings\JPascoal\installer.exe
2008-01-24 23:58 0 –sha-w C:\Documents and Settings\JPascoal\Application Data\004799261e.dat
2008-01-24 23:54 14,336 —-a-w C:\winnnhh.exe
2008-01-24 23:54 14,336 —-a-w C:\Documents and Settings\JPascoal\Application Data\fntgo.exe
2008-01-09 21:54 ——— d—–w C:\Program Files\WebcrawlerToolbar
2008-01-06 21:56 34,816 —-a-w C:\wndmein.exe
2008-01-06 19:43 6,144 —-a-w C:\winnfpn.exe
2008-01-06 16:36 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-06 16:34 ——— d—–w C:\Program Files\Veoh Networks
2008-01-05 21:32 40,960 —-a-w C:\WINDOWS\itgood.exe
2008-01-05 21:31 20,480 —-a-w C:\WINDOWS\quit.exe
2008-01-02 16:38 ——— d—–w C:\Program Files\iTunes
2008-01-02 16:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Last.fm
2008-01-02 06:21 ——— d—–w C:\Program Files\iPod
2008-01-02 06:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-02 06:19 ——— d—–w C:\Program Files\QuickTime
2008-01-02 06:15 ——— d—–w C:\Program Files\Apple Software Update
2008-01-02 06:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-01-02 05:49 ——— d—–w C:\Program Files\Last.fm
2007-12-28 19:51 34,816 —-a-w C:\wndeeqf.exe
2005-04-04 17:18 212,992 —-a-w C:\Documents and Settings\JPascoal\xAutoUpdate.dll
2005-05-18 04:29 259,165 –sh–r C:\WINDOWS\8cube7.sys
2005-07-29 21:24 472 –sha-r C:\WINDOWS\Sk9TRSBQQVNDT0FM\m46nlm1kkphGnXIg.vbs
2005-05-18 04:29 214,213 –sh–r C:\WINDOWS\system32\5ql8gw.exe
2005-05-18 04:29 185,359 –sh–r C:\WINDOWS\system32\8cube7.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E843DC9-FAF2-47CD-9C56-06E6EEC93686}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B9A2D210-19AC-6D7A-DA2A-4DE605800E98}]
C:\WINDOWS\System32\ssj.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-25 21:00 335872]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2004-09-22 18:20 131072]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 22:40 159744]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
"ATIModeChange"="Ati2mdxx.exe" [2003-10-07 22:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-02-06 21:17 180269]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"ec972a81"="C:\WINDOWS\System32\eqoumsmh.dll" [ ]
C:\Documents and Settings\JPascoal\Start Menu\Programs\Startup\
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2008-01-02 00:49:22 106496]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 03:20:40 233472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"zip"= {83fff275-2baa-4680-9403-36b5ef148325} - C:\WINDOWS\Installer\{83fff275-2baa-4680-9403-36b5ef148325}\zip.dll [2008-02-25 18:22 24102]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vvmrvkng]
vvmrvkng.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4sFQ39l]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aaou]
C:\DOCUME~1\JPascoal\MYDOCU~1\MCROSO~1.NET\rundll.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
-ra—— 2003-09-30 13:31 88363 C:\WINDOWS\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoUpdater]
C:\Program Files\AutoUpdate\AutoUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS\VCMnet11.exe]
C:\WINDOWS\VCMnet11.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\checkrun]
C:\windows\system32\elitenzy32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cltjt]
C:\Program Files\Common Files\s?stem\?hkntfs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ec972a81]
C:\WINDOWS\System32\oybawaus.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun]
C:\windows\system32\elitetun32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\exp.exe]
C:\WINDOWS\System32\exp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\farmmext]
C:\WINDOWS\farmmext.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
–a—— 2003-06-26 20:50 212992 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2003-06-25 13:24 49152 C:\Program Files\HP\HP Software Update\HPWuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IESet]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
——— 2001-12-04 19:42 868352 C:\Program Files\ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider]
C:\Program Files\Insider\Insider.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LBw4RVJ9h]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-09-22 18:20 53248 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
–a—— 2004-09-22 18:20 131072 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
–a—— 2003-06-18 14:00 200704 C:\Program Files\Microsoft Money\System\mnyexpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-11-15 16:18 1670144 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
——— 2001-07-09 04:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaciSoft]
C:\WINDOWS\System32\pacis.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
–a—— 2003-07-18 19:23 868352 C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
–a—— 2003-05-01 20:44 65536 C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu572.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sbwp]
C:\WINDOWS\sbwp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
–a—— 2005-02-10 09:09 95960 C:\PROGRA~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2005-02-06 21:17 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vaudlgcl]
c:\windows\system32\vaudlgcl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VBouncer]
C:\PROGRA~1\VBouncer\VirtualBouncer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]
C:\Program Files\Web Buying\v1.8.6\webbuying.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTask driver]
C:\WINDOWS\System32\wintask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XoftSpy]
C:\Program Files\XoftSpy\XoftSpy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VEQC"=2 (0x2)
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\System32\DRIVERS\bsstor.sys [2001-11-08 11:00]
R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido\security suite\guard.sys [2004-11-22 09:15]
R2 BsUDF;InCD UDF Driver;C:\WINDOWS\System32\drivers\BsUDF.sys [2001-12-04 19:31]
S4 VEQC;Security Service;C:\WINDOWS\System32\svcd\svchost.exe []
.
Contents of the 'Scheduled Tasks' folder
"2008-01-07 00:46:46 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - JPascoal.job"
- C:\PROGRA~1\NORTON~1\NAVW32.EXEh/task:
"2008-02-23 08:08:43 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2008-02-26 16:51:01 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2008-02-26 17:00:00 C:\WINDOWS\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 13:51:35
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\explorer.exe [6.00.2800.1106]
-> C:\WINDOWS\Installer\{83fff275-2baa-4680-9403-36b5ef148325}\zip.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-26 13:56:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-26 18:56:10
HiJack This Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:09:12 PM, on 2/26/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Avant Browser\avant.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\itgood.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E843DC9-FAF2-47CD-9C56-06E6EEC93686} - \
O2 - BHO: (no name) - {B9A2D210-19AC-6D7A-DA2A-4DE605800E98} - C:\WINDOWS\System32\ssj.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ec972a81] rundll32.exe "C:\WINDOWS\System32\eqoumsmh.dll",b
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKUS\S-1-5-18\..\Run: [IESet] IExplorer.dll .dbt (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [IESet] IExplorer.dll .dbt (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O20 - Winlogon Notify: vvmrvkng - vvmrvkng.dll (file missing)
O21 - SSODL: zip - {83fff275-2baa-4680-9403-36b5ef148325} - C:\WINDOWS\Installer\{83fff275-2baa-4680-9403-36b5ef148325}\zip.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O24 - Desktop Component 0: (no name) - http://64.4.56.250/cgi-bin/getmsg/supercut…410a4f224a948d6
–
End of file - 4978 bytes
ComboFix Log:
ComboFix 08-02-25.3 - JPascoal 2008-02-26 13:38:01.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\JPascoal\Favorites\Online Security Guide.lnk
C:\Documents and Settings\JPascoal\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\JPascoal\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\JPascoal\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Program Files\Common Files\sstem~1
C:\Program Files\ystem3~1
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\asembl~1
C:\WINDOWS\asembl~1\l?gonui.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b148.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\mrofinu72.exe
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\adwetfwi.dll
C:\WINDOWS\system32\atacmdlo.ini
C:\WINDOWS\system32\ayqcxtvr.dll
C:\WINDOWS\system32\bbvthujo.ini
C:\WINDOWS\system32\blgogtjt.ini
C:\WINDOWS\system32\bucssgmw.dll
C:\WINDOWS\system32\bymgxrkr.dll
C:\WINDOWS\system32\c1
C:\WINDOWS\system32\ccbeg.ini
C:\WINDOWS\system32\ccbeg.ini2
C:\WINDOWS\system32\cdmsshdd.dll
C:\WINDOWS\system32\cgonptic.dll
C:\WINDOWS\system32\cmcdgdrr.dll
C:\WINDOWS\system32\d1
C:\WINDOWS\system32\d1\cby1stp.exe
C:\WINDOWS\system32\ddbpalmu.dll
C:\WINDOWS\system32\djlubfww.dll
C:\WINDOWS\system32\dkjleiko.ini
C:\WINDOWS\system32\dlhqwjre.dll
C:\WINDOWS\system32\drivers\core.cache(2).dsk
C:\WINDOWS\system32\drivers\core.cache(3).dsk
C:\WINDOWS\system32\drivers\core.cache(4).dsk
C:\WINDOWS\system32\dvdoafbq.ini
C:\WINDOWS\system32\eeyhccuc.dll
C:\WINDOWS\system32\efcbyay.dll
C:\WINDOWS\system32\ehpfputh.dll
C:\WINDOWS\system32\ekdscpnk.dll
C:\WINDOWS\system32\eosimvpn.ini
C:\windows\system32\explorer.exe
C:\WINDOWS\system32\fcnkxjgb.ini
C:\WINDOWS\system32\fgnrurbx.dll
C:\WINDOWS\system32\fuxklvyj.dll
C:\WINDOWS\system32\fvwslfad.ini
C:\WINDOWS\system32\gebcc.dll
C:\WINDOWS\system32\ginsuwqm.dll
C:\WINDOWS\system32\gsaxjtgg.ini
C:\WINDOWS\system32\gswxfypx.dll
C:\WINDOWS\system32\gumnfyci.dll
C:\WINDOWS\system32\hatnymrh.dll
C:\WINDOWS\system32\hisdnhal.dll
C:\WINDOWS\system32\hmsmuoqe.ini
C:\WINDOWS\system32\hxitjujx.ini
C:\WINDOWS\system32\iehoielp.exe
C:\WINDOWS\system32\iexplorer.dll .dbt
C:\WINDOWS\system32\ijkvsfhw.dll
C:\WINDOWS\system32\imreuyop.dll
C:\WINDOWS\system32\iqcvaolf.dll
C:\WINDOWS\system32\isrmkmls.dll
C:\WINDOWS\system32\j2
C:\WINDOWS\system32\jkvohcyu.dll
C:\WINDOWS\system32\jlksvioq.ini
C:\WINDOWS\system32\jqkeqjqt.ini
C:\WINDOWS\system32\jqrmoosj.dll
C:\WINDOWS\system32\jsoomrqj.ini
C:\WINDOWS\system32\jveqshom.ini
C:\WINDOWS\system32\jwkkpngh.ini
C:\WINDOWS\system32\jxtoixth.ini
C:\WINDOWS\system32\jxyxcwqj.ini
C:\WINDOWS\system32\jyvettnu.ini
C:\WINDOWS\system32\keibqhdt.ini
C:\WINDOWS\system32\kgfmrpsq.ini
C:\WINDOWS\system32\kgwhxefg.ini
C:\WINDOWS\system32\khoblxlm.dll
C:\WINDOWS\system32\lkqigrwt.ini
C:\WINDOWS\system32\m8
C:\WINDOWS\system32\mggbkqao.ini
C:\WINDOWS\system32\mohsqevj.dll
C:\WINDOWS\system32\mp43.exe
C:\WINDOWS\system32\msrkjurc.dll
C:\WINDOWS\system32\nirxxphk.dll
C:\WINDOWS\system32\nlwjjllh.dll
C:\WINDOWS\system32\npvmisoe.dll
C:\WINDOWS\system32\nsudrcrq.dll
C:\WINDOWS\system32\nswxrlwy.ini
C:\WINDOWS\system32\ntload.sys
C:\WINDOWS\system32\oaqkbggm.dll
C:\WINDOWS\system32\odxeucnk.dll
C:\WINDOWS\system32\ojuhtvbb.dll
C:\WINDOWS\system32\okieljkd.dll
C:\WINDOWS\system32\olpkykwq.ini
C:\WINDOWS\system32\oltbhxcp.dllbox
C:\WINDOWS\system32\omsotqih.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pfatsoik.ini
C:\WINDOWS\system32\pgbuwoep.dll
C:\WINDOWS\system32\pharklka.dll
C:\WINDOWS\system32\pipcivpn.dll
C:\WINDOWS\system32\pvrkrxpx.dll
C:\WINDOWS\system32\qbcsaiso.dll
C:\WINDOWS\system32\qdwaumnt.ini
C:\WINDOWS\system32\qehbnqob.dll
C:\WINDOWS\system32\qeyrrqxb.ini
C:\WINDOWS\system32\qmcpkpwv.dll
C:\WINDOWS\system32\qqgponej.dll
C:\WINDOWS\system32\qratutbe.dll
C:\WINDOWS\system32\qsiimvjr.dll
C:\WINDOWS\system32\quocheol.dll
C:\WINDOWS\system32\qwkykplo.dll
C:\WINDOWS\system32\rknsxjau.ini
C:\WINDOWS\system32\rnxbejqc.dll
C:\WINDOWS\system32\roryxuru.ini
C:\WINDOWS\system32\rvcppjxo.ini
C:\WINDOWS\system32\rwleyqxx.ini
C:\WINDOWS\system32\rxwghjxy.dll
C:\WINDOWS\system32\rxwghjxy.dllbox
C:\WINDOWS\system32\sklbsnqs.dll
C:\WINDOWS\system32\slahcctn.ini
C:\WINDOWS\system32\smnnpspc.dll
C:\WINDOWS\system32\snlvlmtx.dll
C:\WINDOWS\system32\spturons.ini
C:\WINDOWS\system32\srkrfmkj.ini
C:\WINDOWS\system32\suawabyo.ini
C:\WINDOWS\system32\suirtmjg.exe
C:\WINDOWS\system32\sxtgbdsu.dll
C:\WINDOWS\system32\taxvdhgr.dll
C:\WINDOWS\system32\thwccbnl.dll
C:\WINDOWS\system32\twrgiqkl.dll
C:\WINDOWS\system32\txfvtxou.dll
C:\WINDOWS\system32\umlapbdd.ini
C:\WINDOWS\system32\uojxpmxe.dll
C:\WINDOWS\system32\uychovkj.ini
C:\WINDOWS\system32\vaxhaqah.dll
C:\WINDOWS\system32\vbaetpmb.dll
C:\WINDOWS\system32\vtjimhky.ini
C:\WINDOWS\system32\vurqdres.dll
C:\WINDOWS\system32\vvmrvkng.dllbox
C:\WINDOWS\system32\wbeqdowp.dll
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\winupdate.exe
C:\WINDOWS\system32\wloiekox.ini
C:\WINDOWS\system32\wmyotkon.dll
C:\WINDOWS\system32\wnsapisv32.exe
C:\WINDOWS\system32\wxtvlqsj.ini
C:\WINDOWS\system32\xfqmuqmi.ini
C:\WINDOWS\system32\xjujtixh.dll
C:\WINDOWS\system32\xmijslhk.dll
C:\WINDOWS\system32\xoxrplpd.dll
C:\WINDOWS\system32\yamofxgk.dll
C:\WINDOWS\system32\yeublnyk.dll
C:\WINDOWS\system32\yhbsprfd.dll
C:\WINDOWS\system32\ylsfscmm.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_CMDSERVICE
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService
——-\core
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.
2008-02-24 18:18 . 2008-02-26 12:18 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-24 18:18 . 2008-02-24 18:18 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-13 22:41 . 2008-02-13 22:41 d——– C:\My Music
2008-02-13 22:36 . 2008-02-13 22:36 d——– C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2008-02-07 17:20 . 2008-02-07 17:20 d——– C:\Program Files\Avant Browser
2008-02-07 17:20 . 2008-02-07 17:20 d——– C:\Documents and Settings\JPascoal\Application Data\Avant Profiles
2008-02-06 19:45 . 2008-02-06 19:45 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-02-04 18:26 . 2008-02-04 18:26 34,816 –a—— C:\winrzeu.exe
2008-01-30 19:07 . 2002-08-29 03:40 20,480 –a—— C:\WINDOWS\system32\hidserv.dll
2008-01-30 19:07 . 2002-08-29 03:40 20,480 –a–c— C:\WINDOWS\system32\dllcache\hidserv.dll
2008-01-27 22:41 . 2008-01-27 22:41 34,816 –a—— C:\winwcny.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 01:18 ——— d—–w C:\Program Files\DivX
2008-02-01 02:29 ——— d—–w C:\Documents and Settings\JPascoal\Application Data\Apple Computer
2008-01-25 22:02 ——— d—–w C:\Program Files\XoftSpy
2008-01-25 01:53 ——— d—–w C:\Program Files\Trend Micro
2008-01-24 23:58 480,768 —-a-w C:\Documents and Settings\JPascoal\installer.exe
2008-01-24 23:58 0 –sha-w C:\Documents and Settings\JPascoal\Application Data\004799261e.dat
2008-01-24 23:54 14,336 —-a-w C:\winnnhh.exe
2008-01-24 23:54 14,336 —-a-w C:\Documents and Settings\JPascoal\Application Data\fntgo.exe
2008-01-09 21:54 ——— d—–w C:\Program Files\WebcrawlerToolbar
2008-01-06 21:56 34,816 —-a-w C:\wndmein.exe
2008-01-06 19:43 6,144 —-a-w C:\winnfpn.exe
2008-01-06 16:36 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-06 16:34 ——— d—–w C:\Program Files\Veoh Networks
2008-01-05 21:32 40,960 —-a-w C:\WINDOWS\itgood.exe
2008-01-05 21:31 20,480 —-a-w C:\WINDOWS\quit.exe
2008-01-02 16:38 ——— d—–w C:\Program Files\iTunes
2008-01-02 16:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Last.fm
2008-01-02 06:21 ——— d—–w C:\Program Files\iPod
2008-01-02 06:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-02 06:19 ——— d—–w C:\Program Files\QuickTime
2008-01-02 06:15 ——— d—–w C:\Program Files\Apple Software Update
2008-01-02 06:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-01-02 05:49 ——— d—–w C:\Program Files\Last.fm
2007-12-28 19:51 34,816 —-a-w C:\wndeeqf.exe
2005-04-04 17:18 212,992 —-a-w C:\Documents and Settings\JPascoal\xAutoUpdate.dll
2005-05-18 04:29 259,165 –sh–r C:\WINDOWS\8cube7.sys
2005-07-29 21:24 472 –sha-r C:\WINDOWS\Sk9TRSBQQVNDT0FM\m46nlm1kkphGnXIg.vbs
2005-05-18 04:29 214,213 –sh–r C:\WINDOWS\system32\5ql8gw.exe
2005-05-18 04:29 185,359 –sh–r C:\WINDOWS\system32\8cube7.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E843DC9-FAF2-47CD-9C56-06E6EEC93686}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B9A2D210-19AC-6D7A-DA2A-4DE605800E98}]
C:\WINDOWS\System32\ssj.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-25 21:00 335872]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2004-09-22 18:20 131072]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 22:40 159744]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
"ATIModeChange"="Ati2mdxx.exe" [2003-10-07 22:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-02-06 21:17 180269]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"ec972a81"="C:\WINDOWS\System32\eqoumsmh.dll" [ ]
C:\Documents and Settings\JPascoal\Start Menu\Programs\Startup\
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2008-01-02 00:49:22 106496]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 03:20:40 233472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"zip"= {83fff275-2baa-4680-9403-36b5ef148325} - C:\WINDOWS\Installer\{83fff275-2baa-4680-9403-36b5ef148325}\zip.dll [2008-02-25 18:22 24102]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vvmrvkng]
vvmrvkng.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4sFQ39l]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aaou]
C:\DOCUME~1\JPascoal\MYDOCU~1\MCROSO~1.NET\rundll.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
-ra—— 2003-09-30 13:31 88363 C:\WINDOWS\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoUpdater]
C:\Program Files\AutoUpdate\AutoUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS\VCMnet11.exe]
C:\WINDOWS\VCMnet11.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\checkrun]
C:\windows\system32\elitenzy32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cltjt]
C:\Program Files\Common Files\s?stem\?hkntfs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ec972a81]
C:\WINDOWS\System32\oybawaus.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun]
C:\windows\system32\elitetun32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\exp.exe]
C:\WINDOWS\System32\exp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\farmmext]
C:\WINDOWS\farmmext.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
–a—— 2003-06-26 20:50 212992 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2003-06-25 13:24 49152 C:\Program Files\HP\HP Software Update\HPWuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IESet]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
——— 2001-12-04 19:42 868352 C:\Program Files\ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider]
C:\Program Files\Insider\Insider.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LBw4RVJ9h]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-09-22 18:20 53248 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
–a—— 2004-09-22 18:20 131072 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
–a—— 2003-06-18 14:00 200704 C:\Program Files\Microsoft Money\System\mnyexpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-11-15 16:18 1670144 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
——— 2001-07-09 04:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaciSoft]
C:\WINDOWS\System32\pacis.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
–a—— 2003-07-18 19:23 868352 C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
–a—— 2003-05-01 20:44 65536 C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu572.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sbwp]
C:\WINDOWS\sbwp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
–a—— 2005-02-10 09:09 95960 C:\PROGRA~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2005-02-06 21:17 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vaudlgcl]
c:\windows\system32\vaudlgcl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VBouncer]
C:\PROGRA~1\VBouncer\VirtualBouncer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]
C:\Program Files\Web Buying\v1.8.6\webbuying.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTask driver]
C:\WINDOWS\System32\wintask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XoftSpy]
C:\Program Files\XoftSpy\XoftSpy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VEQC"=2 (0x2)
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\System32\DRIVERS\bsstor.sys [2001-11-08 11:00]
R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido\security suite\guard.sys [2004-11-22 09:15]
R2 BsUDF;InCD UDF Driver;C:\WINDOWS\System32\drivers\BsUDF.sys [2001-12-04 19:31]
S4 VEQC;Security Service;C:\WINDOWS\System32\svcd\svchost.exe []
.
Contents of the 'Scheduled Tasks' folder
"2008-01-07 00:46:46 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - JPascoal.job"
- C:\PROGRA~1\NORTON~1\NAVW32.EXEh/task:
"2008-02-23 08:08:43 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2008-02-26 16:51:01 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2008-02-26 17:00:00 C:\WINDOWS\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 13:51:35
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\explorer.exe [6.00.2800.1106]
-> C:\WINDOWS\Installer\{83fff275-2baa-4680-9403-36b5ef148325}\zip.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-26 13:56:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-26 18:56:10
HiJack This Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:09:12 PM, on 2/26/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Avant Browser\avant.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\itgood.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E843DC9-FAF2-47CD-9C56-06E6EEC93686} - \
O2 - BHO: (no name) - {B9A2D210-19AC-6D7A-DA2A-4DE605800E98} - C:\WINDOWS\System32\ssj.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ec972a81] rundll32.exe "C:\WINDOWS\System32\eqoumsmh.dll",b
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKUS\S-1-5-18\..\Run: [IESet] IExplorer.dll .dbt (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [IESet] IExplorer.dll .dbt (User 'Default user')
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O20 - Winlogon Notify: vvmrvkng - vvmrvkng.dll (file missing)
O21 - SSODL: zip - {83fff275-2baa-4680-9403-36b5ef148325} - C:\WINDOWS\Installer\{83fff275-2baa-4680-9403-36b5ef148325}\zip.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O24 - Desktop Component 0: (no name) - http://64.4.56.250/cgi-bin/getmsg/supercut…410a4f224a948d6
–
End of file - 4978 bytes