ComboFix 08-02-18.1 - user 2008-02-13 20:42:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.82 [GMT -6:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\sstqp.dll
C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector
C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector\Data\ac
C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector\Data\em
C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector\Data\oid
C:\Documents and Settings\All Users.WINDOWS\Application Data\storageprotector\Data\user
C:\Documents and Settings\user\Application Data\storageprotector
C:\Documents and Settings\user\Application Data\storageprotector\Logs\update.log
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\Program Files\Common Files\StorageProtector
C:\Program Files\Common Files\StorageProtector\strpmon .exe
C:\Program Files\Common Files\StorageProtector\strpmon .exe
C:\Program Files\Common Files\StorageProtector\strpmon .exe
C:\Program Files\Common Files\StorageProtector\strpmon .exe
C:\Program Files\Common Files\StorageProtector\strpmon.exe
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YAHOOM~1.EXE
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\cahslbcj.dll
C:\WINDOWS\system32\cdvhkdvu.dll
C:\WINDOWS\system32\dcybpzeu.dll
C:\WINDOWS\system32\dcybpzeu.dll . . . . failed to delete
C:\WINDOWS\system32\dcybpzeu.dllbox
C:\WINDOWS\system32\deckdwho.dll
C:\WINDOWS\system32\erhfsdkp.ini
C:\WINDOWS\system32\iysfnmrj.dll
C:\WINDOWS\system32\jwrqblnc.dll
C:\WINDOWS\system32\kfcthtsw.ini
C:\WINDOWS\system32\kmhgvbhg.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mhtkuvjt.dll
C:\WINDOWS\system32\oivnguui.dll
C:\WINDOWS\system32\pkdsfhre.dll
C:\WINDOWS\system32\pqtss.ini
C:\WINDOWS\system32\pqtss.ini2
C:\WINDOWS\system32\qnbiyfvq.dll
C:\WINDOWS\system32\ssqonno.dll
C:\WINDOWS\system32\sstqp.dll
C:\WINDOWS\system32\sstqp.exe
C:\WINDOWS\system32\uvdkhvdc.ini
C:\WINDOWS\system32\vdjfnuvo.ini
C:\WINDOWS\system32\vturpqq.dll
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wjxlcmri.ini
C:\WINDOWS\system32\wvuurol.dll
<pre>
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE ---> C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
</pre>
.
.
((((((((((((((((((((((((( Files Created from 2008-01-19 to 2008-02-19 )))))))))))))))))))))))))))))))
.
2008-02-18 20:57 . 2008-02-18 20:58 134 ---hs---- C:\WINDOWS\system32\dcybpzeu.dllbox
2008-02-13 19:43 . 2008-02-13 19:43 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-13 16:45 . 2008-02-13 16:45 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-02-08 23:18 . 2008-02-13 19:02 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-02-08 22:14 . 2008-02-13 19:37 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-04 16:11 . 2008-02-04 16:11 <DIR> dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
2008-02-04 16:10 . 2004-10-07 13:39 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2008-02-04 16:07 . 2008-02-04 16:07 259,336 --a------ C:\Documents and Settings\user\Application Data\setup_en[1].exe
2008-02-04 15:07 . 2008-02-04 15:09 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-04 14:01 . 2008-02-13 19:41 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-02-04 11:47 . 2008-02-04 11:47 338,432 --a------ C:\WINDOWS\system32\RCX1DD.tmp
2008-01-28 19:25 . 2008-02-18 20:53 163,904 --a------ C:\WINDOWS\system32\dcybpzeu.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-14 01:38 --------- d-----w C:\Program Files\PartyGaming
2008-01-19 01:04 --------- d-----w C:\Documents and Settings\user\Application Data\Yahoo!
2008-01-16 04:47 32,764 ----a-w C:\WINDOWS\17PHolmes572.exe
2008-01-13 01:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\yahoo!
2008-01-07 07:07 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-01-04 20:05 --------- d-----w C:\Program Files\Yahoo!
2008-01-04 20:03 --------- d-----w C:\Program Files\SBC Self Support Tool
2008-01-04 20:02 --------- d-----w C:\Program Files\Common Files\Motive
2008-01-04 20:02 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Motive
2008-01-04 18:34 --------- d-----w C:\Program Files\BroadJump
2008-01-04 18:30 155,995 ----a-w C:\WINDOWS\java\Packages\PRZDNLVJ.ZIP
2007-12-24 04:05 --------- d-----w C:\Documents and Settings\user\Application Data\MSNInstaller
2007-12-07 01:07 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
.
<pre>
----a-w 39,792 2008-02-14 01:07:27 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
----a-w 368,706 2008-02-14 01:07:27 C:\Program Files\BroadJump\Client Foundation\CFD .exe
----a-w 847,872 2008-02-14 01:07:47 C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3 .exe
----a-w 1,410,304 2008-02-04 17:57:16 C:\Program Files\ESET\ESET NOD32 Antivirus\egui .exe
----a-w 442,455 2008-02-14 01:07:27 C:\Program Files\SBC Self Support Tool\SmartBridge\MotiveSB .exe
----a-w 129,536 2008-02-14 01:07:22 C:\Program Files\Yahoo!\browser\ybrwicon .exe
----a-w 4,670,704 2008-01-29 01:35:48 C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a5929854-e4b3-4170-8ea8-5262ae39d659}]
C:\WINDOWS\system32\iysfnmrj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2008-02-18 20:53 163904 --a------ C:\WINDOWS\system32\dcybpzeu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DAD1EBBE-8B72-4502-91FA-21E04062728A}]
C:\WINDOWS\system32\sstqp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NodLogin"="C:\Program Files\ESET\ESET NOD32 Antivirus\nodlogin.exe" [ ]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [ ]
"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [ ]
"Salestart(4)"="C:\Program Files\Common Files\StorageProtector\strpmon .exe" [ ]
"Salestart(6)"="C:\Program Files\Common Files\StorageProtector\strpmon .exe" [ ]
"Salestart(7)"="C:\Program Files\Common Files\StorageProtector\strpmon .exe" [ ]
"Salestart(8)"="C:\Program Files\Common Files\StorageProtector\strpmon .exe" [ ]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
SBC Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2008-01-04 14:01:28 217088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dcybpzeu]
dcybpzeu.dll 2008-02-18 20:53 163904 C:\WINDOWS\system32\dcybpzeu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyxurs]
xxyxurs.dll
R3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 06:48]
R3 EL556ND5;3Com 10/100 MiniPCI Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\EL556ND5.sys [2001-08-17 06:10]
R3 maestro;ESS Maestro 3 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es198x.sys [2001-08-17 06:19]
R3 WDHAALBA;WDHAALBAMiniPCI Winmodem;C:\WINDOWS\system32\DRIVERS\WDHAALBA.sys [2001-08-17 07:28]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-18 20:57:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\dcybpzeu.dll
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\system32\dcybpzeu.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Atievxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
.
**************************************************************************
.
Completion time: 2008-02-18 21:01:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-19 03:01:18
.
2008-02-10 08:00:26 --- E O F ---