ComboFix 08-12-26.03 - Kids 12/27/2008 20:30:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1255.1.1033.18.503.116 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\program files\autorun.inf
c:\windows\adaway.lic
c:\windows\Downloaded Program Files\setup.inf
c:\windows\IE4 Error Log.txt
c:\windows\system32\aoilpxma.ini
c:\windows\system32\awuoevjl.dll
c:\windows\system32\bmmofwrw.dll
c:\windows\system32\buxqitve.ini
c:\windows\system32\dgaqshvp.dll
c:\windows\system32\dkllqreh.ini
c:\windows\system32\dveftplq.ini
c:\windows\system32\efcbCuTm.dll
c:\windows\system32\egatuwee.ini
c:\windows\system32\eranghuk.ini
c:\windows\system32\exdomqxs.ini
c:\windows\system32\fchqpgek.ini
c:\windows\system32\fwmsalkr.ini
c:\windows\system32\gwwjuceu.ini
c:\windows\system32\hPrYxyxx.ini
c:\windows\system32\hqxcfwod.ini
c:\windows\system32\iafqhrnb.ini
c:\windows\system32\ihdtkyuq.ini
c:\windows\system32\ihwfdstk.dll
c:\windows\system32\jijqofty.ini
c:\windows\system32\joqcoodl.ini
c:\windows\system32\kkihhbii.ini
c:\windows\system32\ktsdfwhi.ini
c:\windows\system32\kuhgnare.dll
c:\windows\system32\kvutnnov.dll
c:\windows\system32\ljveouwa.ini
c:\windows\system32\madnfcfu.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\mTuCbcfe.ini
c:\windows\system32\mTuCbcfe.ini2
c:\windows\system32\pgxqsvou.ini
c:\windows\system32\pvhsqagd.ini
c:\windows\system32\quyktdhi.dll
c:\windows\system32\rtglyifi.ini
c:\windows\system32\rwxktwvw.ini
c:\windows\system32\sawkesrg.ini
c:\windows\system32\sktcnjvh.dll
c:\windows\system32\sxqmodxe.dll
c:\windows\system32\sytyqfsx.ini
c:\windows\system32\tckwtjro.ini
c:\windows\system32\ueensiva.ini
c:\windows\system32\ufcfndam.dll
c:\windows\system32\ulbkgmyd.ini
c:\windows\system32\vonntuvk.ini
c:\windows\system32\wcprjhck.ini
c:\windows\system32\wrwfommb.ini
c:\windows\system32\xuwumesj.ini
.
((((((((((((((((((((((((( Files Created from 2008-11-27 to 2008-12-27 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 18:23 ——— d—–w c:\documents and settings\Guest\Application Data\Windows Desktop Search
2008-12-27 16:19 ——— d—–w c:\program files\Trend Micro
2008-12-27 15:28 ——— d—–w c:\program files\LogMeIn
2008-12-25 23:53 ——— d—–w c:\documents and settings\Kids.BEYCHOK-KIDS\Application Data\U3
2008-12-23 12:17 ——— d—–w c:\program files\util
2008-12-23 12:17 ——— d—–w c:\program files\Setup
2008-12-23 12:17 ——— d—–w c:\program files\enu
2008-12-23 12:17 ——— d—–w c:\program files\drivers
2008-12-23 12:17 ——— d—–w c:\program files\common
2008-12-23 12:07 ——— d—–w c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2008-12-16 14:27 10,219 —-a-w c:\windows\TLCLINK.EXE
2008-12-16 14:26 ——— d—–w c:\program files\The Learning Company
2008-12-16 13:19 4,096 —-a-w c:\windows\system32\drivers\Start2Driver.SYS
2008-12-16 09:44 3,584 —-a-w c:\windows\system32\drivers\Start1Driver.SYS
2008-12-12 13:55 ——— d—–w c:\program files\HASBRO Interactive
2008-12-10 14:20 ——— d—–w c:\documents and settings\Kids.BEYCHOK-KIDS\Application Data\Apple Computer
2008-12-05 11:56 3,532 —-a-w C:\drmHeader.bin
2008-11-27 17:03 ——— d—–w c:\documents and settings\Kids.BEYCHOK-KIDS\Application Data\BSplayer
2008-11-19 13:51 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-11-19 13:29 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-19 12:53 ——— d—–w c:\program files\Lavasoft
2008-11-19 05:39 ——— d—–w c:\documents and settings\All Users\Application Data\LogMeIn
2008-11-17 17:14 76,288 —-a-w c:\windows\system32\nuggqabe.dll
2008-11-16 05:59 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-15 21:32 ——— d—–w c:\program files\ESET
2008-11-09 15:41 1,905,517 –sha-w c:\windows\system32\whhhfxaw.tmp
2008-10-16 18:35 87,352 —-a-w c:\windows\system32\LMIinit.dll
2008-10-16 18:35 83,288 —-a-w c:\windows\system32\LMIRfsClientNP.dll
2008-10-16 18:35 28,984 —-a-w c:\windows\system32\LMIport.dll
2008-10-16 18:35 23,736 —-a-w c:\windows\system32\lmimirr.dll
2008-10-16 18:35 10,040 —-a-w c:\windows\system32\lmimirr2.dll
2008-10-16 12:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 12:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 12:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 12:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 12:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 12:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 12:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 12:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-09-27 19:01 0 —-a-w c:\documents and settings\Kids.BEYCHOK-KIDS\jagex_runescape_preferences.dat
2004-06-22 02:20 5,529 —-a-w c:\program files\hpoprl01.dat
2004-06-22 02:20 17,218 —-a-w c:\program files\hpomdl04.dat
2004-06-21 22:06 399 —-a-w c:\program files\hpzprl01.dat
2004-05-11 20:03 314 —-a-w c:\program files\hpqprl01.dat
2004-05-11 20:03 1,073,152 —-a-w c:\program files\Setup.exe
2004-04-28 12:35 66,431 —-a-w c:\program files\hpoprl04.dat
2004-04-26 07:12 53,670 —-a-w c:\program files\hposcu08.cat
2004-04-26 07:12 52,349 —-a-w c:\program files\hpzius13.cat
2004-04-26 07:12 52,349 —-a-w c:\program files\HPZius12.cat
2004-04-26 07:12 51,467 —-a-w c:\program files\hpzist13.cat
2004-04-26 07:12 51,467 —-a-w c:\program files\hpzist12.cat
2004-04-26 07:12 51,467 —-a-w c:\program files\hpzipr13.cat
2004-04-26 07:12 51,467 —-a-w c:\program files\HPZipr12.cat
2004-04-26 07:12 51,467 —-a-w c:\program files\hpzid413.cat
2004-04-26 07:12 51,467 —-a-w c:\program files\HPZid412.cat
2004-04-26 07:12 51,026 —-a-w c:\program files\HPOunp08.cat
2004-04-26 07:12 447,400 —-a-w c:\program files\hpoprn08.cat
2004-04-16 08:14 2,542 —-a-w c:\program files\hpoprl02.dat
2004-04-13 06:26 19,578 —-a-w c:\program files\hpoprl03.dat
2004-04-12 02:44 94,438 —-a-w c:\program files\hposcu08.inf
2004-04-08 02:08 65,420 —-a-w c:\program files\hpoprl05.dat
2004-04-07 05:39 200,704 —-a-w c:\program files\hpzpnp10.dll
2004-04-07 05:39 176,128 —-a-w c:\program files\hpzscr10.dll
2004-04-07 05:37 270,336 —-a-w c:\program files\hpzglu10.exe
2004-04-07 05:23 137,124 —-a-w c:\program files\hpoprn08.inf
2004-03-22 03:55 9,777 —-a-w c:\program files\hpzipr13.inf
2004-03-22 03:55 4,132 —-a-w c:\program files\hpzist13.inf
2004-03-22 03:55 22,636 —-a-w c:\program files\hpzid413.inf
2004-03-22 03:55 14,815 —-a-w c:\program files\hpzius13.inf
2004-03-14 01:46 6,704 —-a-w c:\program files\hpounp08.inf
2004-03-14 01:46 50,615 —-a-w c:\program files\hpzid412.inf
2004-03-14 01:46 5,538 —-a-w c:\program files\hpzist12.inf
2004-03-14 01:46 22,608 —-a-w c:\program files\usbprint.sys
2004-03-14 01:46 20,168 —-a-w c:\program files\hpzius12.inf
2004-03-14 01:46 12,922 —-a-w c:\program files\hpzipr12.inf
2004-03-14 01:46 1,391 —-a-w c:\program files\readme.txt
2004-03-14 01:34 70,656 —-a-w c:\program files\msvcirt.dll
2004-03-14 01:34 49,212 —-a-w c:\program files\hpzjvp01.dll
2004-03-14 01:34 458,752 —-a-w c:\program files\tls704d.dll
2004-03-14 01:34 442,425 —-a-w c:\program files\hpzjpp01.dll
2004-03-14 01:34 290,873 —-a-w c:\program files\hpzjut01.dll
2004-03-14 01:34 28,722 —-a-w c:\program files\hpzjlog.dll
2004-03-14 01:34 270,336 —-a-w c:\program files\hpzc3212.dll
2004-03-14 01:34 254,005 —-a-w c:\program files\msvcrt.dll
2004-03-14 01:34 16,416 —-a-w c:\program files\HPZUCI12.DLL
2004-03-14 01:34 12,288 —-a-w c:\program files\usbmon.dll
2003-11-07 16:05 205 —-a-w c:\program files\hpzprl02.dat
2008-12-26 10:28 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-26 10:28 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-26 10:28 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-26 10:28 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-26 10:28 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [08/16/2007 04:19 PM 5728112]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [10/11/2005 06:25 PM 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [02/07/2006 08:39 AM 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [02/07/2006 08:36 AM 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [02/07/2006 08:40 AM 118784]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [03/23/2006 05:06 PM 1398272]
"DiskeeperSystray"="c:\program files\Executive Software\Diskeeper\DkIcon.exe" [07/26/2005 05:52 PM 184408]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 03:25 AM 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM 40048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [05/27/2008 09:50 AM 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [07/22/2008 07:42 PM 116040]
"iTunesHelper"="d:\my documents\Avishai\everything itunes\iTunesHelper.exe" [07/30/2008 09:47 AM 289064]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [08/18/2008 01:23 PM 1447168]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [07/24/2008 06:46 PM 63048]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [01/07/2005 05:07 PM 61952 c:\windows\system32\HdAShCut.exe]
"SkyTel"="SkyTel.EXE" [05/16/2006 06:04 PM 2879488 c:\windows\SkyTel.exe]
"SoundMan"="SOUNDMAN.EXE" [07/21/2006 04:14 PM 86016 c:\windows\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [05/04/2006 04:26 PM 2808832 c:\windows\alcwzrd.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\progra~1\DVDREG~1\DVDShell.dll" [10/09/2004 03:18 PM 49152]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [02/05/2007 03:39 PM 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
10/16/2008 08:35 PM 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\My Documents\\Avishai\\everything itunes\\iTunes.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 34312]
R1 Start1Driver;Start1Driver;c:\windows\system32\drivers\Start1Driver.sys [2008-12-26 3584]
R2 ekrn;Eset Service;"c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe" [2008-08-18 468224]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2008-09-01 222456]
R2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys [2008-07-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\c:\windows\system32\drivers\LMIRfsDriver.sys [2008-11-19 47640]
R2 Start2Driver;Start2Driver;c:\windows\system32\drivers\Start2Driver.sys [2008-12-26 4096]
S4 LMIRfsClientNP;LMIRfsClientNP; []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{180a7aa6-8a67-11dd-a236-0002b308cc13}]
\Shell\AutoRun\command - f:\wd_windows_tools\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{460ba1b0-6949-11dc-a1d0-00116b3006fc}]
\Shell\AutoRun\command - a.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69f53704-9889-11dd-a23f-0002b308cc13}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d46efce0-bec3-11dc-a1f5-00116b3006fc}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
.
- - - - ORPHANS REMOVED - - - -
BHO-{20469943-A824-49B6-BDD0-6388ED3B989B} - c:\windows\system32\xxyxYrPh.dll
BHO-{B3641865-83B5-419B-B45A-037D56EF72B3} - c:\windows\system32\efcbCuTm.dll
BHO-{BF48ACBC-CA77-4DDB-AE26-4473A0F636F1} - c:\windows\system32\wvUoLcDv.dll
HKCU-Run-AdVantage - c:\program files\AdVantage\AdVantage.exe
Notify-khfDTnol - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &יצא ל- Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {7BCAE25D-3F56-4A94-985A-37170D36FCF0} = 192.168.2.1
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Kids.BEYCHOK-KIDS\Application Data\Mozilla\Firefox\Profiles\x90zqk1k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.bsplayer-search.com/startpage
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-27 20:33:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\igfxdev.dll
- - - - - - - > 'winlogon.exe'(2940)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 12/27/2008 20:35:02
ComboFix-quarantined-files.txt 2008-12-27 18:34:03
Pre-Run: 5,497,540,608 bytes free
Post-Run: 5,473,632,256 bytes free
276 — E O F — 2008-10-24 14:19:11