ComboFix 09-12-30.01 - Todd Eskra 12/30/2009 21:36:55.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1982.1622 [GMT -8:00]
Running from: c:\documents and settings\Todd Eskra\Desktop\commy.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\igemaq.vbs
c:\documents and settings\All Users\Application Data\igofamocut.inf
c:\documents and settings\All Users\Documents\xurucilefe.reg
c:\documents and settings\Allenda R\Application Data\obuk.bat
c:\documents and settings\Allenda R\Cookies\ucafakybuk.dl
c:\documents and settings\Allenda R\Local Settings\Application Data\dytyro.reg
c:\documents and settings\Allenda R\Local Settings\Application Data\yjazynot.inf
c:\documents and settings\Allenda R\Local Settings\Temporary Internet Files\qekikoziqy.lib
c:\documents and settings\Allenda R\Local Settings\Temporary Internet Files\ufupej.pif
c:\documents and settings\Todd Eskra\Cookies\umucalyna.bin
c:\documents and settings\Todd Eskra\Local Settings\Application Data\bojusopyte.inf
c:\documents and settings\Todd Eskra\Local Settings\Application Data\obakuru.bat
c:\documents and settings\Todd Eskra\Local Settings\Temporary Internet Files\alawifyhi._sy
c:\documents and settings\Todd Eskra\Local Settings\Temporary Internet Files\jabomives.vbs
c:\documents and settings\Todd Eskra\Local Settings\Temporary Internet Files\ovanu.bin
c:\windows\akuwy.exe
c:\windows\aqosoh.vbs
c:\windows\arizybop.reg
c:\windows\axadufet.inf
c:\windows\axypom._sy
c:\windows\baxytat.vbs
c:\windows\cytytu.vbs
c:\windows\ecadeput.dll
c:\windows\ehim.exe
c:\windows\eqamukile.reg
c:\windows\inijetup.reg
c:\windows\locetimoky.bat
c:\windows\regeripi.scr
c:\windows\roporiv._sy
c:\windows\system32\drivers\H8SRTjnodoyqjwm.sys
c:\windows\system32\eqyryh.reg
c:\windows\system32\H8SRTixuwylllqt.dll
c:\windows\system32\H8SRTlrdvvmpwey.dll
c:\windows\system32\H8SRToqbivekmup.dat
c:\windows\system32\krl32mainweq.dll
c:\windows\system32\srcr.dat
c:\windows\system32\ygyd.vbs
c:\windows\uheliqe.exe
c:\windows\wafufur.bat
c:\windows\wazuk.inf
c:\windows\ytomu.vbs
c:\windows\zesuzehof.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-31 )))))))))))))))))))))))))))))))
.
2009-12-31 04:02 . 2009-12-31 04:06 -------- d-----w- C:\commy
2009-12-30 02:46 . 2009-12-30 02:46 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-12-29 00:40 . 2009-12-29 00:43 -------- d-sh--w- C:\System Volume Information3
2009-12-28 02:12 . 2009-12-28 02:12 -------- d-sh--w- c:\documents and settings\Todd.ESKRA\PrivacIE
2009-12-28 02:12 . 2009-12-28 02:12 -------- d-----w- c:\documents and settings\Todd.ESKRA\Local Settings\Application Data\Apple Computer
2009-12-28 02:12 . 2009-12-28 02:12 -------- d-----w- c:\documents and settings\Todd.ESKRA\Local Settings\Application Data\SupportSoft
2009-12-28 02:12 . 2009-12-28 02:12 -------- d-sh--w- c:\documents and settings\Todd.ESKRA\IETldCache
2009-12-28 01:28 . 2009-12-28 01:28 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-27 05:03 . 2009-12-27 05:03 -------- d-----w- c:\documents and settings\Todd Eskra\Local Settings\Application Data\cwosgg
2009-12-26 03:46 . 2009-12-26 03:46 -------- d-----w- c:\documents and settings\Todd Eskra\Local Settings\Application Data\uapomv
2009-12-24 23:39 . 2009-12-24 23:39 -------- d-----w- c:\documents and settings\Todd Eskra\Local Settings\Application Data\xsojsm
2009-12-20 21:22 . 2009-12-20 21:22 -------- d-----w- c:\documents and settings\Todd Eskra\Local Settings\Application Data\ufijfk
2009-12-15 01:03 . 2009-12-15 01:03 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-15 00:55 . 2009-12-15 00:55 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-12-13 22:21 . 2009-12-13 22:21 -------- d-----w- c:\documents and settings\Todd\Application Data\HPAppData
2009-12-12 20:18 . 2009-12-12 20:31 23122 ----a-w- c:\windows\hpqins15.dat
2009-12-12 19:51 . 2009-12-12 19:54 -------- d-----w- c:\documents and settings\Todd\Application Data\HpUpdate
2009-12-12 07:26 . 2009-12-12 07:26 -------- d-----w- c:\documents and settings\Todd\PrivacIE
2009-12-12 07:26 . 2009-12-12 07:26 -------- d-----w- c:\documents and settings\Todd\Local Settings\Application Data\Apple Computer
2009-12-12 07:26 . 2009-12-12 07:26 -------- d-----w- c:\documents and settings\Todd\Local Settings\Application Data\SupportSoft
2009-12-12 00:49 . 2009-12-12 00:49 -------- d-----w- c:\documents and settings\Todd Eskra\Application Data\MSNInstaller
2009-12-05 22:44 . 2009-12-05 22:46 77352 ----a-w- c:\windows\hpqins05.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 05:35 . 2008-08-22 22:34 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-31 03:57 . 2008-08-22 22:38 -------- d-----w- c:\program files\Common Files\McAfee
2009-12-31 03:57 . 2008-08-22 22:38 -------- d-----w- c:\program files\McAfee
2009-12-30 02:44 . 2009-12-28 02:55 39152 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-29 01:21 . 2009-09-29 22:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-28 02:12 . 2009-12-28 02:11 39152 ----a-w- c:\documents and settings\Todd.ESKRA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-28 02:06 . 2008-08-22 23:15 39152 ----a-w- c:\documents and settings\Allenda Eskra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-23 05:45 . 2009-09-17 02:23 36268 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-23 00:43 . 2009-09-17 01:30 -------- d-----w- c:\documents and settings\Allenda R\Application Data\HpUpdate
2009-12-15 02:10 . 2009-05-09 01:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-15 02:06 . 2009-12-15 02:06 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-15 01:16 . 2009-09-03 07:27 -------- d-----w- c:\documents and settings\Todd Eskra\Application Data\HpUpdate
2009-12-15 00:55 . 2009-05-01 01:53 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-12-13 20:52 . 2009-05-01 15:20 -------- d-----w- c:\documents and settings\Allenda R\Application Data\HPAppData
2009-12-13 20:41 . 2009-05-01 01:59 -------- d-----w- c:\documents and settings\Todd Eskra\Application Data\HPAppData
2009-12-13 03:35 . 2009-01-28 00:57 11244 ----a-w- c:\documents and settings\Allenda R\Application Data\wklnhst.dat
2009-12-12 07:26 . 2009-12-12 07:25 39152 ----a-w- c:\documents and settings\Todd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-07 00:24 . 2009-01-28 00:55 39152 ----a-w- c:\documents and settings\Allenda R\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-05 23:49 . 2008-08-22 22:09 39152 ----a-w- c:\documents and settings\Todd Eskra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-04 00:14 . 2009-09-29 22:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:13 . 2009-09-29 22:55 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-01 15:30 . 2009-09-29 22:49 0 ----a-w- c:\windows\Shakuburuyaxub.bin
2009-12-01 15:30 . 2009-09-29 22:49 120 ----a-w- c:\windows\Yxohuqavefogut.dat
2009-10-29 23:37 . 2009-10-29 23:37 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-29 07:45 . 2004-08-10 17:51 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 17:51 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 17:51 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 04:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-16 21:18 . 2009-10-16 21:17 126970 ----a-w- c:\documents and settings\Todd Eskra\Application Data\Move Networks\uninstall.exe
2009-10-16 21:18 . 2009-08-03 21:48 4187512 ----a-w- c:\documents and settings\Todd Eskra\Application Data\Move Networks\plugins\npqmp071505000010.dll
2009-10-13 10:30 . 2004-08-10 17:51 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 17:51 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 17:51 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 21:13 . 2008-08-22 22:11 1720 ----a-w- c:\documents and settings\Todd Eskra\Application Data\wklnhst.dat
2009-09-28 22:36 . 2009-09-28 22:36 13047 ----a-w- c:\program files\Common Files\qotati._dl
2009-09-28 16:46 . 2009-09-28 16:46 17251 ----a-w- c:\program files\Common Files\vijego.sys
2009-09-28 16:46 . 2009-09-28 16:46 15215 ----a-w- c:\program files\Common Files\polumaci.exe
2009-09-28 16:46 . 2009-09-28 16:46 16631 ----a-w- c:\program files\Common Files\pynahug._sy
2009-09-28 16:45 . 2009-09-28 16:45 17604 ----a-w- c:\program files\Common Files\uwore.exe
2009-09-28 16:26 . 2009-09-28 16:26 18052 ----a-w- c:\program files\Common Files\ykiwopi.lib
2009-09-28 16:26 . 2009-09-28 16:26 15435 ----a-w- c:\program files\Common Files\corenib.bin
2009-09-28 16:20 . 2009-09-28 16:20 12354 ----a-w- c:\program files\Common Files\yduxyvibyw.scr
2009-09-28 16:20 . 2009-09-28 16:20 11718 ----a-w- c:\program files\Common Files\hajis.lib
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-03-11 202544]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-22 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-07 8466432]
"nwiz"="nwiz.exe" [2008-04-07 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-07 81920]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-07 16859648]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-22 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"HostManager"="c:\program files\Common Files\AOL\1208827316\EE\AOLHostManager.exe" [2004-11-03 125528]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-10-20 34904]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 79448]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-03-11 202544]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\Todd Eskra\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2008-10-10 256000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1208827316\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-12-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6080422uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: internet
Trusted Zone: mcafee.com
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-30 21:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-765718398-3582225506-1518988564-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2828)
c:\windows\system32\WININET.dll
c:\program files\Common Files\AOL\ACS\WLHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\progra~1\COMMON~1\AOL\120882~1\EE\AOLHOS~1.EXE
c:\progra~1\COMMON~1\AOL\120882~1\EE\AOLServiceHost.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2009-12-30 21:51:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-31 05:51
Pre-Run: 130,984,214,528 bytes free
Post-Run: 132,317,405,184 bytes free
- - End Of File - - 530C164DBB3EC3BF399F64C2639663B0