Here is the Combofix Log.
ComboFix 08-08-04.01 - Jeff Dalton 2008-08-04 19:59:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.98 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jeff Dalton\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
C:\Documents and Settings\Jeff Dalton\Application Data\CROSOF~1.NET
C:\Documents and Settings\Jeff Dalton\Application Data\ICROSO~1
C:\Documents and Settings\Jeff Dalton\Application Data\macromedia\Flash Player\#SharedObjects\T7PDPPRZ\interclick.com
C:\Documents and Settings\Jeff Dalton\Application Data\macromedia\Flash Player\#SharedObjects\T7PDPPRZ\interclick.com\ud.sol
C:\Documents and Settings\Jeff Dalton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Jeff Dalton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Jeff Dalton\Application Data\rhcg23j0ea45
C:\Documents and Settings\Jeff Dalton\Application Data\YMBOLS~1
C:\Documents and Settings\Jeff Dalton\My Documents\YMANTE~1
C:\Documents and Settings\Jeff Dalton\My Documents\YMANTE~1\?ymantec\
C:\Program Files\appatc~1
C:\Program Files\Common Files\asembl~1
C:\Program Files\Common Files\ecurit~1
C:\Program Files\Common Files\mbols~1
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\stem~1
C:\Program Files\dobe~1
C:\Program Files\ecurit~1
C:\Program Files\fnts~1
C:\Program Files\mantec~1
C:\Program Files\mcroso~1
C:\Program Files\MyWay
C:\Program Files\racle~1
C:\Program Files\rhcg23j0ea45
C:\Program Files\sks~1
C:\WINDOWS\cdmxtras
C:\WINDOWS\cdmxtras\uninst.exe
C:\WINDOWS\dobe~1
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\ecurit~1
C:\WINDOWS\mbols~1
C:\WINDOWS\racle~1
C:\WINDOWS\sks~1
C:\WINDOWS\sks~2
C:\WINDOWS\ssembl~1
C:\WINDOWS\stem~1
C:\WINDOWS\stem32~1
C:\WINDOWS\system32\acnbvfdq.ini
C:\WINDOWS\system32\bjlbjdqc.ini
C:\WINDOWS\system32\cache329
C:\WINDOWS\system32\cache329\B_329_0_0_106800.htm
C:\WINDOWS\system32\cache329\B_329_0_0_107400.htm
C:\WINDOWS\system32\cache329\B_329_1_0_449200.gif
C:\WINDOWS\system32\cache329\B_329_1_0_449600.gif
C:\WINDOWS\system32\cache329\B_329_1_0_454300.gif
C:\WINDOWS\system32\cache329\B_329_2_0_106800.htm
C:\WINDOWS\system32\cache329\B_329_2_0_107400.htm
C:\WINDOWS\system32\cache329\B_329_3_0_106800.htm
C:\WINDOWS\system32\cache329\B_329_3_0_107400.htm
C:\WINDOWS\system32\cache329\B_329_4_0_111600.htm
C:\WINDOWS\system32\cache329\B_329_4_0_155300.htm
C:\WINDOWS\system32\cache329\t_B_329_0_0_106800.htm
C:\WINDOWS\system32\cache329\t_B_329_0_0_107400.htm
C:\WINDOWS\system32\cache329\t_B_329_2_0_106800.htm
C:\WINDOWS\system32\cache329\t_B_329_2_0_107400.htm
C:\WINDOWS\system32\cache329\t_B_329_3_0_106800.htm
C:\WINDOWS\system32\cache329\t_B_329_3_0_107400.htm
C:\WINDOWS\system32\cache329\t_B_329_4_0_111600.htm
C:\WINDOWS\system32\cache329\t_B_329_4_0_155300.htm
C:\WINDOWS\system32\cache329\Thumbs.db
C:\WINDOWS\system32\cbXOEtqQ.dll
C:\WINDOWS\system32\crosof~1.net
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\fecmicfj.ini
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\hgGwUkLf.dll
C:\WINDOWS\system32\icroso~1.net
C:\WINDOWS\system32\kamadwpj.ini
C:\WINDOWS\system32\lphcl23j0ea45.exe
C:\WINDOWS\system32\mbols~1
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nxajhjgc.ini
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\phcl23j0ea45.bmp
C:\WINDOWS\system32\ppatch~1
C:\WINDOWS\system32\pppatc~1
C:\WINDOWS\system32\pppatc~2
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\puebkdby.ini
C:\WINDOWS\system32\pyqxorbn.ini
C:\WINDOWS\system32\qaihxoru.dll
C:\WINDOWS\system32\qhikubgl.ini
C:\WINDOWS\system32\QqtEOXbc.ini
C:\WINDOWS\system32\QqtEOXbc.ini2
C:\WINDOWS\system32\racle~1
C:\WINDOWS\system32\rqgxvx.dll
C:\WINDOWS\system32\sembly~1
C:\WINDOWS\system32\sks~1
C:\WINDOWS\system32\sks~2
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\stem~1
C:\WINDOWS\system32\udqqwxmp.ini
C:\WINDOWS\system32\uerrnqcg.ini
C:\WINDOWS\system32\vuqqjymv.ini
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wnsxs~1
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\wtssvtr.exe
C:\WINDOWS\system32\ymante~1
C:\WINDOWS\ymbols~1
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-07-05 to 2008-08-05 )))))))))))))))))))))))))))))))
.
2008-08-04 21:57 . 2008-08-04 21:57 d——– C:\WINDOWS\system32\Quarantine
2008-08-04 07:28 . 2008-08-04 07:28 129,920 –a—— C:\WINDOWS\system32\tfphsl.dll
2008-08-04 07:28 . 2008-08-04 07:28 129,920 –a—— C:\WINDOWS\system32\jcitpelb.dll
2008-08-04 07:28 . 2008-08-04 07:28 99,200 –a—— C:\WINDOWS\system32\pmxwqqdu.dll
2008-08-03 21:03 . 2008-08-03 21:03 d——– C:\Deckard
2008-08-03 20:49 . 2008-08-03 20:49 130,432 –a—— C:\WINDOWS\system32\whlyffeg.dll
2008-08-03 20:49 . 2008-08-03 20:49 130,432 –a—— C:\WINDOWS\system32\lnecdn.dll
2008-08-03 12:32 . 2007-07-30 19:19 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2008-08-03 12:32 . 2007-07-30 19:19 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2008-08-03 10:12 . 2008-08-03 10:14 d——– C:\WINDOWS\ERUNT
2008-08-02 16:57 . 2008-08-02 16:57 98,688 –a—— C:\WINDOWS\system32\uskfyuil.dll
2008-08-02 16:57 . 2008-08-02 16:57 294 –ahs—- C:\WINDOWS\system32\liuyfksu.ini
2008-08-02 16:54 . 2008-08-02 16:54 130,432 –a—— C:\WINDOWS\system32\yfefpplh.dll
2008-08-02 16:54 . 2008-08-02 16:54 130,432 –a—— C:\WINDOWS\system32\qwdjoi.dll
2008-07-28 09:24 . 2008-07-28 09:24 294 –ahs—- C:\WINDOWS\system32\uwltbssm.ini
2008-07-27 07:52 . 2008-07-24 01:27 d——– C:\SDFix
2008-07-27 07:44 . 2008-07-27 07:44 d——– C:\Documents and Settings\Jeff Dalton\Application Data\Uniblue
2008-07-27 07:43 . 2008-07-27 07:43 d——– C:\Program Files\Uniblue
2008-07-23 09:50 . 2008-08-03 06:35 10,752 –a—— C:\WINDOWS\DCEBoot.exe
2008-07-20 23:38 . 2008-02-16 00:07 138,384 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-20 23:38 . 2008-02-16 00:07 52,496 –a—— C:\WINDOWS\system32\drivers\tmactmon.sys
2008-07-20 23:38 . 2008-02-16 00:07 52,240 –a—— C:\WINDOWS\system32\drivers\tmevtmgr.sys
2008-07-20 23:26 . 2008-07-20 23:38 d——– C:\Program Files\Trend Micro
2008-07-20 18:21 . 2008-07-20 22:49 d——– C:\Program Files\Norton AntiVirus
2008-07-20 13:31 . 2008-07-20 13:31 d——– C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-07-19 23:07 . 2008-07-19 23:07 d——– C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
2008-07-19 22:50 . 2008-07-20 13:03 d——– C:\Program Files\Norton Security Scan
2008-07-19 18:07 . 2008-07-20 23:18 d——– C:\Program Files\Symantec
2008-07-19 18:07 . 2008-07-20 22:41 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-09 13:57 . 2008-06-20 12:36 245,248 ——— C:\WINDOWS\system32\dllcache\mswsock.dll
2008-07-09 13:57 . 2008-06-20 05:44 138,368 ——— C:\WINDOWS\system32\dllcache\afd.sys
2008-07-06 21:57 . 2008-07-20 18:21 d——– C:\Documents and Settings\Jeff Dalton\Application Data\Symantec
2008-07-05 22:24 . 2008-07-05 22:24 d——– C:\Documents and Settings\Jeff Dalton\log
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-05 02:48 ——— d—–w C:\Documents and Settings\Jeff Dalton\Application Data\DNA
2008-08-04 19:13 ——— d—–w C:\Program Files\LogMeIn
2008-07-21 04:19 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-07-20 21:27 ——— d—–w C:\Program Files\Google
2008-07-19 22:55 ——— d—–w C:\Program Files\ImTOO
2008-07-19 22:52 ——— d—–w C:\Program Files\WS_FTP
2008-07-05 04:16 ——— d—–w C:\Program Files\Java
2008-07-05 02:13 ——— d—–w C:\Program Files\Creative
2008-07-05 02:07 ——— d—–w C:\Program Files\XBC
2008-07-05 02:02 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-04 00:08 ——— d—–w C:\Documents and Settings\Jeff Dalton\Application Data\BitTorrent
2008-06-27 17:29 ——— d—–w C:\Program Files\DivX
2008-06-25 00:19 ——— d—–w C:\Program Files\Sigmatel
2008-06-20 17:36 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:36 147,968 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:44 360,960 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 360,960 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:32 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:32 225,920 —-a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-19 01:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\LogMeIn
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-30 23:22 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 —-a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 —-a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 -c–a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 -c–a-w C:\WINDOWS\system32\dpu10.dll
2008-05-30 23:22 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2008-05-28 17:33 83,288 —-a-w C:\WINDOWS\system32\LMIRfsClientNP.dll
2008-05-28 17:32 87,352 —-a-w C:\WINDOWS\system32\LMIinit.dll
2008-05-28 17:32 24,608 —-a-w C:\WINDOWS\system32\LMIport.dll
2008-05-28 17:32 23,736 —-a-w C:\WINDOWS\system32\lmimirr.dll
2008-05-28 17:32 10,040 —-a-w C:\WINDOWS\system32\lmimirr2.dll
2008-05-22 22:22 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-22 22:22 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:20 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-22 22:20 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-05-22 22:19 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-05-22 22:19 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2008-05-22 22:19 161,096 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-13 01:49 630,784 —-a-w C:\WINDOWS\system32\nszB45.tmp
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2006-10-03 08:43 2,402,550 -c–a-w C:\WINDOWS\inf\SET42A.tmp
2006-10-03 08:43 2,402,550 -c—-w C:\WINDOWS\inf\SET5B3.tmp
2006-10-03 07:43 2,402,550 -c–a-w C:\WINDOWS\inf\SET16A.tmp
2005-10-26 00:13 774,144 -c–a-w C:\Program Files\RngInterstitial.dll
2007-08-09 19:08 8,784 —-a-w C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-08-09 19:10 245,408 —-a-w C:\Program Files\mozilla firefox\plugins\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f672b7aa-d454-4531-b558-54436f0557c7}]
2008-08-04 07:28 129920 –a—— C:\WINDOWS\system32\tfphsl.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-08 11:26 289088]
"ares"="C:\Program Files\Ares\Ares.exe" [2008-02-20 09:33 963072]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2008-07-23 13:16 1927448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 15:02 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 15:02 126976]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 11:26 606208]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33 155648]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 05:33 122941]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-24 03:24 282624]
"HostManager"="C:\Program Files\Common Files\AOL\1136499357\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-12 22:58 185896]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2006-01-13 19:20 172032]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03 63048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-02-26 14:19 1398024]
"4835c4b4"="C:\WINDOWS\system32\pmxwqqdu.dll" [2008-08-04 07:28 99200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SymLnch"="C:\Documents and Settings\Jeff Dalton\Application Data\Symantec\Layouts\Norton AntiVirus\15.0\SymAllLanguages\NAV_ESD\20070828\Support\SymLnch\SymLnch.exe" [2007-08-26 19:04 687976]
C:\Documents and Settings\Jeff Dalton\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 22:07:32 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-05-28 12:32 87352 C:\WINDOWS\system32\LMIinit.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a–c— 2006-05-09 19:24 50760 C:\Program Files\Common Files\AOL\Launch\aollaunch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
–a—— 2008-02-20 09:33 963072 C:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
—–c— 2004-12-02 18:23 102400 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
—–c— 2004-04-26 08:04 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
–a—— 2006-05-09 19:24 50760 C:\Program Files\Common Files\AOL\1136499357\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a–c— 2005-12-15 11:18 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-24 03:24 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a–c— 2005-11-10 13:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
—–c— 2004-01-07 01:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
–a–c— 2004-11-10 23:15 111816 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Kazaa\\kazaa.exe"=
"C:\\WINDOWS\\system32\\javaw.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Documents and Settings\\Jeff Dalton\\Desktop\\Games\\Conquerors Download\\Age of Empires II.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Common Files\\AOL\\1136499357\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1136499357\\ee\\aim6.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Documents and Settings\\Jeff Dalton\\Desktop\\Games\\Age of Empires\\Empires.exe"=
"C:\Program Files\Bradford Networks\Client Security Agent\bnpagent.exe"= C:\Program Files\Bradford Networks\Client Security Agent\bnpagent.exe
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 BNPagent;Client Security Agent;C:\Program Files\Bradford Networks\Client Security Agent\bnpagent.exe [2007-03-22 09:39]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2008-02-28 15:31]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 21:26]
S3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [2006-03-27 15:02]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e069c77c-1e27-11da-8bfd-00123f0c7537}]
\Shell\AutoRun\command - F:\JDSecure\Windows\JDSecure31.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e8d75c02-6635-11dc-8d31-0014a40a89c0}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{effc3810-1e60-11dc-8d1b-0014a40a89c0}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-08-04 C:\WINDOWS\Tasks\Disk Cleanup.job
- C:\WINDOWS\system32\cleanmgr.exe [2004-08-04 05:00]
2008-07-25 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
.
- - - - ORPHANS REMOVED - - - -
BHO-{0A3F2498-FA33-CF9F-7454-BDC0AC50F9AC} - C:\WINDOWS\system32\jsx.dll
BHO-{25C4FCE7-3A77-1CA6-7797-168341D09CBD} - C:\WINDOWS\system32\enl.dll
BHO-{3B12149F-D701-89AC-5964-FEED9B65D49F} - C:\WINDOWS\system32\jsx.dll
BHO-{EBB734EB-B91B-8DEC-0136-FBA42A3849F7} - C:\WINDOWS\system32\blzmjz.dll
HKCU-Run-Tair - C:\WINDOWS\STEM32~1\services.exe
HKCU-Run-WeatherWatcher - C:\Program Files\Weather Watcher\ww.exe
HKCU-Run-MsnMsgr - C:\Program Files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-Time Zones for PCs - C:\Program Files\Digital Design Ltd\Time Zones for PCs\TZPC.EXE
HKLM-Run-ISUSPM Startup - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
HKLM-Run-lphcl23j0ea45 - C:\WINDOWS\system32\lphcl23j0ea45.exe
SharedTaskScheduler-{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b} - (no file)
SSODL-buprestidae-{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b} - (no file)
MSConfigStartUp-areslite - C:\Program Files\Ares Lite Edition\Ares Lite Edition\AresLite.exe
MSConfigStartUp-IPHSend - C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
MSConfigStartUp-PlaxoUpdate - C:\Program Files\Plaxo\2.6.2.15\PlaxoHelper.exe
MSConfigStartUp-Shareaza - C:\Program Files\Shareaza\Shareaza.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Jeff Dalton\Application Data\Mozilla\Firefox\Profiles\2ufk3514.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://my.yahoo.com/index.html
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-04 22:01:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
C:\WINDOWS\system32\udqqwxmp.ini 1381975 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSSdk23]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk23.drv"
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\pmxwqqdu.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\BAsfIpM.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\LogMeIn\x86\ramaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\WLTRAY.EXE
C:\Program Files\Apoint\ApntEx.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2008-08-04 22:31:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-05 03:28:37
Pre-Run: 19,346,243,584 bytes free
Post-Run: 19,207,503,872 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
421 — E O F — 2008-07-10 08:04:32