ComboFix 08-12-15.03 - alok sinha 2008-12-15 17:43:45.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.185 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\alok sinha\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ALOKSI~1\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\alok sinha\Application Data\gadcom
c:\program files\INSTALL.LOG
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\tn3
c:\windows\Downloaded Program Files\Temp
c:\windows\system32\drivers\core.cache.dsk
c:\windows\system32\drivers\fad.sys
c:\windows\system32\foo.dll
c:\windows\system32\instsrv.exe
c:\windows\system32\ipxqse.dll
c:\windows\system32\kuntgmni.dll
c:\windows\system32\ljJYQIXn.dll
c:\windows\SYSTEM32\nXIQYJjl.ini
c:\windows\system32\nXIQYJjl.ini2
c:\windows\system32\opqthrla.ini
c:\windows\system32\rcxwpaxg.dll
c:\windows\SYSTEM32\VDJmlnnn.ini
c:\windows\SYSTEM32\VDJmlnnn.ini2
c:\windows\Tasks\nqmuirik.job
c:\windows\Tasks\qrzpvwcd.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ISEXENG
((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
.
2008-12-14 00:08 . 2008-12-14 00:08
d-------- c:\documents and settings\Guest\Application Data\Apple Computer
2008-12-13 18:47 . 2008-12-13 18:46 35,888 -ra------ c:\windows\SYSTEM32\DRIVERS\SymIM.sys
2008-12-13 18:46 . 2008-12-13 18:46 d-------- c:\program files\Symantec
2008-12-13 18:46 . 2008-12-13 18:51 d-------- c:\program files\Common Files\Symantec Shared
2008-12-13 18:46 . 2008-12-13 18:46 124,464 --a------ c:\windows\SYSTEM32\DRIVERS\SYMEVENT.SYS
2008-12-13 18:46 . 2008-12-13 18:46 60,808 --a------ c:\windows\SYSTEM32\S32EVNT1.DLL
2008-12-13 18:46 . 2008-12-13 18:46 10,635 --a------ c:\windows\SYSTEM32\DRIVERS\SYMEVENT.CAT
2008-12-13 18:46 . 2008-12-13 18:46 806 --a------ c:\windows\SYSTEM32\DRIVERS\SYMEVENT.INF
2008-12-13 18:45 . 2008-12-13 18:45 d-------- c:\windows\SYSTEM32\DRIVERS\NAV
2008-12-13 18:45 . 2008-12-13 18:45 d-------- c:\program files\Windows Sidebar
2008-12-13 18:45 . 2008-12-13 18:45 d-------- c:\program files\NortonInstaller
2008-12-13 18:45 . 2008-12-13 18:46 d-------- c:\program files\Norton AntiVirus
2008-12-13 17:57 . 2008-12-13 17:57 d-------- c:\documents and settings\alok sinha\Application Data\Twain
2008-12-13 14:13 . 2008-12-13 18:21 46,640 --a------ c:\windows\SYSTEM32\msln.exe
2008-12-13 14:09 . 2008-12-13 14:09 d-------- c:\documents and settings\All Users\Application Data\Symantec
2008-12-13 14:04 . 2008-12-13 18:35 d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2008-12-13 14:04 . 2008-12-13 18:45 d-------- c:\documents and settings\All Users\Application Data\Norton
2008-12-13 14:02 . 2008-12-13 14:02 d-------- c:\documents and settings\All Users\Symantec Temporary Files
2008-12-12 17:55 . 2008-12-13 15:20 d--hs---- c:\windows\YWxvayBzaW5oYQ
2008-12-12 17:55 . 2008-12-13 17:04 d-------- c:\windows\SYSTEM32\DL5
2008-12-12 17:55 . 2008-12-13 21:15 d-------- c:\windows\SYSTEM32\cap2
2008-12-12 17:55 . 2008-12-12 17:56 d-------- c:\windows\SYSTEM32\ain
2008-12-12 17:55 . 2008-12-12 17:55 d-------- c:\temp\REX81
2008-12-12 17:55 . 2008-12-15 17:45 d-------- C:\Temp
2008-11-30 22:43 . 2008-11-30 22:44 d-------- c:\program files\iTunes
2008-11-30 22:43 . 2008-11-30 22:44 d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-30 22:41 . 2008-11-30 22:41 d-------- c:\program files\Bonjour
2008-11-30 22:32 . 2008-11-30 22:32 d-------- c:\program files\Safari
2008-11-26 13:35 . 2008-11-26 13:35 d-------- c:\program files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-14 16:46 --------- d-----w c:\documents and settings\Guest\Application Data\ArcSoft
2008-12-11 23:20 --------- d-----w c:\documents and settings\alok sinha\Application Data\Skype
2008-12-11 16:08 --------- d-----w c:\documents and settings\alok sinha\Application Data\skypePM
2008-12-10 23:42 --------- d-----w c:\program files\Common Files\Adobe
2008-12-10 23:42 --------- d-----w c:\documents and settings\alok sinha\Application Data\AdobeUM
2008-12-02 00:46 --------- d-----w c:\documents and settings\alok sinha\Application Data\Apple Computer
2008-12-01 07:02 --------- d-----w c:\program files\QuickTime
2008-12-01 06:44 --------- d-----w c:\program files\iPod
2008-12-01 06:43 --------- d-----w c:\program files\Common Files\Apple
2008-11-26 21:28 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-26 21:28 --------- d-----w c:\program files\Canon
2008-11-26 08:09 --------- d-----w c:\documents and settings\All Users\Application Data\RetroExp
2008-11-23 05:35 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-21 18:05 --------- d-----w c:\program files\CA
2008-11-21 18:04 --------- d-----w c:\program files\Viewpoint
2008-11-16 02:56 --------- d-----w c:\program files\Google
2008-11-15 18:31 --------- d-----w c:\documents and settings\Guest\Application Data\Skype
2008-11-15 17:32 --------- d-----w c:\documents and settings\Guest\Application Data\skypePM
2008-11-14 21:06 --------- d-----w c:\program files\Skype
2008-11-14 21:06 --------- d-----w c:\program files\Common Files\Skype
2008-11-14 21:06 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-07 04:34 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-30 21:34 --------- d-----w c:\program files\Sonos
2008-10-27 01:22 --------- d-----w c:\documents and settings\alok sinha\Application Data\Download Manager
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-20 17:36 --------- d-----w c:\program files\Java
2008-10-20 17:34 --------- d-----w c:\program files\Common Files\Java
2005-05-16 18:00 85,504 ----a-w c:\documents and settings\alok sinha\certadm.dll
2005-05-16 18:00 585,728 ----a-w c:\documents and settings\alok sinha\certutil.exe
2005-05-16 18:00 233,472 ----a-w c:\documents and settings\alok sinha\certcli.dll
2004-04-30 05:33 41,312 ----a-w c:\documents and settings\alok sinha\Application Data\GDIPFONTCACHEV1.DAT
2004-03-26 00:35 41,312 ----a-w c:\documents and settings\Upasana Sinha\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"ComcastSUPPORT"="c:\program files\Support.com\bin\tgkill.exe" [2001-11-21 57344]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-06-12 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-08-25 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP53"= SP5X_32.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"VIDC.SP59"= SP5X_32.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Date Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Date Manager.lnk
backup=c:\windows\pss\Date Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GStartup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\GStartup.lnk
backup=c:\windows\pss\GStartup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2005-03-03 20:47 483328 c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-03 23:56 15360 c:\windows\SYSTEM32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DwlClient]
--a------ 2005-10-13 22:26 69632 c:\program files\Common Files\Dell\EUSW\Support.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 14:49 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a------ 2006-03-20 16:34 213936 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\masqform.exe]
--a------ 2003-07-18 09:55 1048576 c:\program files\PureEdge\Viewer 6.0\masqform.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
--a------ 2005-02-08 14:37 823296 c:\program files\Maxtor\OneTouch\Utils\OneTouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MXOBG]
--a------ 2003-10-10 10:23 94208 c:\windows\MXOALDR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 16:43 4670704 c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Support.com\\bin\\tgcmd.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Digital Image 2006\\PIXPhotoStory.exe"=
"c:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"=
"c:\\WINDOWS\\SYSTEM32\\ftp.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Digital Spectrum\\Digital PixMaster 6.1\\DigitalPixMaster.exe"=
"c:\\Program Files\\Ipswitch\\WS_FTP Home\\wsftpgui.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 stcvsm;stcvsm;c:\windows\system32\drivers\stcvsm.sys [2008-08-25 127520]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1001000.021\SYMEFA.SYS [2008-12-13 309296]
R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\DRIVERS\tffsport.sys [2004-02-05 149376]
R1 BHDrvx86;Symantec Heuristics Driver;\??\c:\windows\system32\drivers\NAV\1001000.021\BHDrvx86.sys [2008-12-13 255536]
R1 ccHP;Symantec Hash Provider;\??\c:\windows\system32\drivers\NAV\1001000.021\ccHPx86.sys [2008-12-13 362544]
R1 IDSxpx86;IDSxpx86;\??\c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20081212.001\IDSxpx86.sys [2008-12-15 274808]
R1 sbmount;StorageCraft Image Mount Driver;c:\windows\system32\drivers\sbmount.sys [2008-08-25 86560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-13 99376]
S3 GR433S;GR433S;c:\windows\system32\Drivers\GR433s.sys [2004-01-06 66896]
S3 pfusb;pfusb;c:\windows\system32\drivers\pfusb.sys [2007-05-06 12272]
S3 PID_0900_V;Logitech ClickSmart 310(PID_0900_V);c:\windows\system32\DRIVERS\LV551AV.sys [2002-11-22 220079]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24e8c232-b603-11d9-8967-000bdb2a2fb2}]
\Shell\AutoRun\command - F:\WinHECWiFi.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -
BHO-{068CC6AE-42CA-4680-9F3D-EE517CAD5F98} - c:\windows\system32\ljJYQIXn.dll
BHO-{53F60149-996C-48FD-A884-8931E29C8EF9} - c:\windows\system32\nnnlmJDV.dll
BHO-{5443b8d5-0d37-472f-b1ca-564d45958a3b} - c:\windows\system32\qsgxsg.dll
Toolbar-{9FF7AAC8-31D0-4659-9880-CBD98E306B47} - c:\windows\system32\winda77.dll
WebBrowser-{9FF7AAC8-31D0-4659-9880-CBD98E306B47} - c:\windows\system32\winda77.dll
Notify-Accessibility - c:\windows\system32\6wO4SVC.DLL
MSConfigStartUp-a8261341 - c:\windows\system32\alrhtqpo.dll
MSConfigStartUp-BullsEye Network - c:\program files\BullsEye Network\bin\bargains.exe
MSConfigStartUp-gadcom - c:\documents and settings\alok sinha\Application Data\gadcom\gadcom.exe
MSConfigStartUp-googletalk - c:\program files\Google\Google Talk\googletalk.exe
MSConfigStartUp-loads - c:\windows\medload.exe
MSConfigStartUp-msnappau - c:\program files\MSN Apps\Updater\[u]0[/u]1.02.3000.1001\en-us\msnappau.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-RetroExpress - c:\progra~1\Dantz\RETROS~1\RetroExpress.exe
MSConfigStartUp-SrchfstUpdate - c:\windows\srchupdt.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
mWindow Title = Microsoft Internet Explorer provided by Comcast
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{C21AE3DD-2E97-406B-8C87-A9AD5BBD49D1} - http://www.downloadalot.com
IE: {{C21AE3DD-2E97-406B-8C87-A9AD5BBD49D1} - http://www.downloadalot.com -
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\System32\msvcrt.dll - c:\windows\System32\mfc42.dll
c:\windows\System32\olepro32.dll
c:\windows\Downloaded Program Files\mainRdr.dll
c:\windows\System32\SDRes.dll
c:\windows\Downloaded Program Files\smartdiagX.ocx
O16 -: {00C1446A-F80F-47CB-8644-DCCF0C39B5D8}
hxxp://support.gemplus.com/gemdownload/readers/smartdiagx_XP2000.cab
c:\windows\Downloaded Program Files\smartdiagx.inf
c:\windows\Downloaded Program Files\scroll360.ocx - O16 -: {1D077753-DF32-11CF-AEC2-00A0C90C2B47}
file://d:\retro360\Future\scroll360.ocx
c:\windows\Downloaded Program Files\Manager.exe - c:\windows\Downloaded Program Files\DownloadManagerV2.ocx
O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
c:\windows\Downloaded Program Files\DownloadManagerV2.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-15 18:26:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.1.0.33\diMaster.dll\" /prefetch:1"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
c:\program files\Support.com\bin\tgcmd.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-12-15 19:13:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-16 03:13:26
Pre-Run: 58,848,346,112 bytes free
Post-Run: 58,876,047,360 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
278 --- E O F --- 2008-12-05 01:25:49