Hiya Sneakyone,
I will be home after work today around 3pm Pacific Time. Thanks for all your help so far. Our computer seems so much faster now.
Sincerely,
ckelliher
ComboFix 10-06-18.03 - Sarah 06/19/2010 4:27.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.1061 [GMT -7:00]
Running from: c:\documents and settings\Sarah\Desktop\Commy.exe
Command switches used :: c:\documents and settings\Sarah\Desktop\CFScript.txt
FILE ::
"c:\windows\Ajeziniyetasoyu.bin"
"c:\windows\Jjegutibo.dat"
"c:\windows\system32\114.tmp"
"c:\windows\system32\drivers\qlnnj.sys"
"c:\windows\system32\rundinst.dll"
"c:\windows\system32\setvdown.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Sarah\Local Settings\Application Data\fffgyrnv
c:\documents and settings\Sarah\Local Settings\Application Data\swegrfhoj
c:\documents and settings\Sarah\SmitfraudFix
c:\documents and settings\Sarah\SmitfraudFix\404Fix.exe
c:\documents and settings\Sarah\SmitfraudFix\Agent.OMZ.Fix.exe
c:\documents and settings\Sarah\SmitfraudFix\beep_2K_original.sys
c:\documents and settings\Sarah\SmitfraudFix\beep_XP_original.sys
c:\documents and settings\Sarah\SmitfraudFix\dumphive.exe
c:\documents and settings\Sarah\SmitfraudFix\exit.exe
c:\documents and settings\Sarah\SmitfraudFix\GenericRenosFix.exe
c:\documents and settings\Sarah\SmitfraudFix\HostsChk.exe
c:\documents and settings\Sarah\SmitfraudFix\IEDFix.C.exe
c:\documents and settings\Sarah\SmitfraudFix\IEDFix.exe
c:\documents and settings\Sarah\SmitfraudFix\o4Patch.exe
c:\documents and settings\Sarah\SmitfraudFix\Policies.exe
c:\documents and settings\Sarah\SmitfraudFix\Process.exe
c:\documents and settings\Sarah\SmitfraudFix\ProxyDisable.exe
c:\documents and settings\Sarah\SmitfraudFix\Reboot.exe
c:\documents and settings\Sarah\SmitfraudFix\restart.exe
c:\documents and settings\Sarah\SmitfraudFix\SmitfraudFix.cmd
c:\documents and settings\Sarah\SmitfraudFix\SmiUpdate.exe
c:\documents and settings\Sarah\SmitfraudFix\SrchSTS.exe
c:\documents and settings\Sarah\SmitfraudFix\swreg.exe
c:\documents and settings\Sarah\SmitfraudFix\swsc.exe
c:\documents and settings\Sarah\SmitfraudFix\swxcacls.exe
c:\documents and settings\Sarah\SmitfraudFix\UIFix.exe
c:\documents and settings\Sarah\SmitfraudFix\unzip.exe
c:\documents and settings\Sarah\SmitfraudFix\VACFix.exe
c:\documents and settings\Sarah\SmitfraudFix\VCCLSID.exe
c:\documents and settings\Sarah\SmitfraudFix\WS2Fix.exe
c:\program files\Viewpoint
c:\program files\Viewpoint\Viewpoint Manager\CPtask.xml
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html
c:\program files\Viewpoint\Viewpoint Toolbar\3.8.0\eula.txt
c:\windows\Ajeziniyetasoyu.bin
c:\windows\Jjegutibo.dat
c:\windows\system32\drivers\qlnnj.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MEMSWEEP2
-------\Legacy_qlnnj
-------\Service_qlnnj
((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.
2010-06-19 03:50 . 2010-06-19 04:09 -------- d-----w- C:\Commy
2010-06-17 00:31 . 2010-06-17 00:31 -------- d-----w- C:\_OTL
2010-06-15 05:16 . 2010-06-15 05:16 -------- d-----w- c:\program files\Sophos
2010-06-13 04:56 . 2010-06-13 04:56 439816 ----a-w- c:\documents and settings\Sarah\Application Data\Real\Update\setup3.10\setup.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-19 04:10 . 2007-12-16 18:32 -------- d-----w- c:\program files\Mozilla Firefox 3 Beta 1
2010-06-18 19:42 . 2007-11-26 21:24 -------- d-----w- c:\documents and settings\Sarah\Application Data\uTorrent
2010-06-10 10:12 . 2009-08-15 23:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-09 20:07 . 2010-01-13 23:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-09 19:01 . 2006-09-23 18:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-09 14:46 . 2009-03-23 18:59 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-03 02:42 . 2007-11-22 15:42 -------- d-----w- c:\program files\uTorrent
2010-05-11 01:15 . 2010-05-11 01:14 50354 ----a-w- c:\documents and settings\Sarah\Application Data\Facebook\uninstall.exe
2010-05-11 01:14 . 2010-05-11 01:14 -------- d-----w- c:\documents and settings\Sarah\Application Data\Facebook
2010-05-02 05:56 . 2004-08-10 17:51 1850880 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 22:39 . 2010-01-13 23:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 22:39 . 2010-01-13 23:36 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:51 . 2004-08-10 17:50 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 15:20 . 2004-08-10 17:51 668672 ----a-w- c:\windows\system32\wininet.dll
2010-04-16 15:20 . 2004-08-10 17:51 81920 ----a-w- c:\windows\system32\ieencode.dll
2007-09-10 19:45 . 2007-09-10 19:45 3393369 ----a-w- c:\program files\openofficeorg4.cab
2007-09-10 19:44 . 2007-09-10 19:44 66502315 ----a-w- c:\program files\openofficeorg3.cab
2007-09-10 19:36 . 2007-09-10 19:36 17643096 ----a-w- c:\program files\openofficeorg2.cab
2007-09-10 19:34 . 2007-09-10 19:34 18779946 ----a-w- c:\program files\openofficeorg1.cab
2007-09-10 19:32 . 2007-09-10 19:32 217 ----a-w- c:\program files\setup.ini
2007-09-10 19:32 . 2007-09-10 19:32 4362752 ----a-w- c:\program files\openofficeorg23.msi
2002-03-11 09:06 . 2002-03-11 09:06 1822520 ----a-w- c:\program files\instmsiw.exe
2002-03-11 08:45 . 2002-03-11 08:45 1708856 ----a-w- c:\program files\instmsia.exe
2007-12-05 23:01 . 2007-01-30 21:47 88 --sh--r- c:\windows\system32\991A48BF09.sys
2007-12-05 23:01 . 2007-01-30 21:47 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 202024]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"SigmatelSysTrayApp"="stsystra.exe" [2006-02-10 282624]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-11-22 185632]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-04 8491008]
"nwiz"="nwiz.exe" [2007-10-04 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-04 81920]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-01-11 166304]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-09-12 36352]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-16 141608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Last.fm Helper.lnk - c:\program files\Last.fm\LastFMHelper.exe [2007-11-25 110592]
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2008-12-21 1261568]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Last.fm\\LastFM.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2/17/2010 10:45 PM 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2/17/2010 10:45 PM 8456]
S3 NdisWDM;Dynex Wireless G USB Network Adapter Service;c:\windows\system32\DRIVERS\ndiswdm.sys --> c:\windows\system32\DRIVERS\ndiswdm.sys [?]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [12/21/2008 5:34 PM 194304]
S3 USB_NDISXP;RCA USB Digital Cable Modem Driver;c:\windows\system32\drivers\NetRcaCmXP.sys [8/26/2008 4:36 PM 14336]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext =
hxxp://updates.installshield.com/GetUpdates.asp?p={8A9B8148-DDD7-448F-BD6C-358386D32354}&r=6.33&v=ISUA%204.50&u={60EA1B5E-C015-4471-8946-CB4D1EE30CCD}&l=1033&K=ZCEACA7AFC9CCD7EFC9AC4748495C978FF9AB908F498C97A8CE6B90EFC9ECC01FD9FB500FDEACIE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Sarah\Application Data\Mozilla\Firefox\Profiles\pg3sb7lb.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.yahoo.com/search?fr=ffsp1&p=FF - prefs.js: browser.search.selectedengine - Yahoo
FF - plugin: c:\documents and settings\Sarah\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Sarah\Application Data\Mozilla\Firefox\Profiles\pg3sb7lb.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-19 04:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\RtlGina2.dll
- - - - - - - > 'explorer.exe'(3128)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-06-19 04:41:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-19 11:41
ComboFix2.txt 2010-06-19 04:09
Pre-Run: 16,268,673,024 bytes free
Post-Run: 16,233,902,080 bytes free
- - End Of File - - 1F29AB2DB7BE1740E1A148EB8995091C