ComboFix 08-12-15.03 - alok sinha 2008-12-15 17:43:45.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.185 [GMT -8:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\alok sinha\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\ALOKSI~1\LOCALS~1\Temp\tmp2.tmp c:\documents and settings\alok sinha\Application Data\gadcom c:\program files\INSTALL.LOG c:\temp\1cb c:\temp\1cb\syscheck.log c:\temp\tn3 c:\windows\Downloaded Program Files\Temp c:\windows\system32\drivers\core.cache.dsk c:\windows\system32\drivers\fad.sys c:\windows\system32\foo.dll c:\windows\system32\instsrv.exe c:\windows\system32\ipxqse.dll c:\windows\system32\kuntgmni.dll c:\windows\system32\ljJYQIXn.dll c:\windows\SYSTEM32\nXIQYJjl.ini c:\windows\system32\nXIQYJjl.ini2 c:\windows\system32\opqthrla.ini c:\windows\system32\rcxwpaxg.dll c:\windows\SYSTEM32\VDJmlnnn.ini c:\windows\SYSTEM32\VDJmlnnn.ini2 c:\windows\Tasks\nqmuirik.job c:\windows\Tasks\qrzpvwcd.job . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ISEXENG ((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 ))))))))))))))))))))))))))))))) . 2008-12-14 00:08 . 2008-12-14 00:08 d-------- c:\documents and settings\Guest\Application Data\Apple Computer 2008-12-13 18:47 . 2008-12-13 18:46 35,888 -ra------ c:\windows\SYSTEM32\DRIVERS\SymIM.sys 2008-12-13 18:46 . 2008-12-13 18:46 d-------- c:\program files\Symantec 2008-12-13 18:46 . 2008-12-13 18:51 d-------- c:\program files\Common Files\Symantec Shared 2008-12-13 18:46 . 2008-12-13 18:46 124,464 --a------ c:\windows\SYSTEM32\DRIVERS\SYMEVENT.SYS 2008-12-13 18:46 . 2008-12-13 18:46 60,808 --a------ c:\windows\SYSTEM32\S32EVNT1.DLL 2008-12-13 18:46 . 2008-12-13 18:46 10,635 --a------ c:\windows\SYSTEM32\DRIVERS\SYMEVENT.CAT 2008-12-13 18:46 . 2008-12-13 18:46 806 --a------ c:\windows\SYSTEM32\DRIVERS\SYMEVENT.INF 2008-12-13 18:45 . 2008-12-13 18:45 d-------- c:\windows\SYSTEM32\DRIVERS\NAV 2008-12-13 18:45 . 2008-12-13 18:45 d-------- c:\program files\Windows Sidebar 2008-12-13 18:45 . 2008-12-13 18:45 d-------- c:\program files\NortonInstaller 2008-12-13 18:45 . 2008-12-13 18:46 d-------- c:\program files\Norton AntiVirus 2008-12-13 17:57 . 2008-12-13 17:57 d-------- c:\documents and settings\alok sinha\Application Data\Twain 2008-12-13 14:13 . 2008-12-13 18:21 46,640 --a------ c:\windows\SYSTEM32\msln.exe 2008-12-13 14:09 . 2008-12-13 14:09 d-------- c:\documents and settings\All Users\Application Data\Symantec 2008-12-13 14:04 . 2008-12-13 18:35 d-------- c:\documents and settings\All Users\Application Data\NortonInstaller 2008-12-13 14:04 . 2008-12-13 18:45 d-------- c:\documents and settings\All Users\Application Data\Norton 2008-12-13 14:02 . 2008-12-13 14:02 d-------- c:\documents and settings\All Users\Symantec Temporary Files 2008-12-12 17:55 . 2008-12-13 15:20 d--hs---- c:\windows\YWxvayBzaW5oYQ 2008-12-12 17:55 . 2008-12-13 17:04 d-------- c:\windows\SYSTEM32\DL5 2008-12-12 17:55 . 2008-12-13 21:15 d-------- c:\windows\SYSTEM32\cap2 2008-12-12 17:55 . 2008-12-12 17:56 d-------- c:\windows\SYSTEM32\ain 2008-12-12 17:55 . 2008-12-12 17:55 d-------- c:\temp\REX81 2008-12-12 17:55 . 2008-12-15 17:45 d-------- C:\Temp 2008-11-30 22:43 . 2008-11-30 22:44 d-------- c:\program files\iTunes 2008-11-30 22:43 . 2008-11-30 22:44 d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-11-30 22:41 . 2008-11-30 22:41 d-------- c:\program files\Bonjour 2008-11-30 22:32 . 2008-11-30 22:32 d-------- c:\program files\Safari 2008-11-26 13:35 . 2008-11-26 13:35 d-------- c:\program files\CCleaner . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-14 16:46 --------- d-----w c:\documents and settings\Guest\Application Data\ArcSoft 2008-12-11 23:20 --------- d-----w c:\documents and settings\alok sinha\Application Data\Skype 2008-12-11 16:08 --------- d-----w c:\documents and settings\alok sinha\Application Data\skypePM 2008-12-10 23:42 --------- d-----w c:\program files\Common Files\Adobe 2008-12-10 23:42 --------- d-----w c:\documents and settings\alok sinha\Application Data\AdobeUM 2008-12-02 00:46 --------- d-----w c:\documents and settings\alok sinha\Application Data\Apple Computer 2008-12-01 07:02 --------- d-----w c:\program files\QuickTime 2008-12-01 06:44 --------- d-----w c:\program files\iPod 2008-12-01 06:43 --------- d-----w c:\program files\Common Files\Apple 2008-11-26 21:28 --------- d--h--w c:\program files\InstallShield Installation Information 2008-11-26 21:28 --------- d-----w c:\program files\Canon 2008-11-26 08:09 --------- d-----w c:\documents and settings\All Users\Application Data\RetroExp 2008-11-23 05:35 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2008-11-21 18:05 --------- d-----w c:\program files\CA 2008-11-21 18:04 --------- d-----w c:\program files\Viewpoint 2008-11-16 02:56 --------- d-----w c:\program files\Google 2008-11-15 18:31 --------- d-----w c:\documents and settings\Guest\Application Data\Skype 2008-11-15 17:32 --------- d-----w c:\documents and settings\Guest\Application Data\skypePM 2008-11-14 21:06 --------- d-----w c:\program files\Skype 2008-11-14 21:06 --------- d-----w c:\program files\Common Files\Skype 2008-11-14 21:06 --------- d-----w c:\documents and settings\All Users\Application Data\Skype 2008-11-07 04:34 --------- d-----w c:\program files\Microsoft Silverlight 2008-10-30 21:34 --------- d-----w c:\program files\Sonos 2008-10-27 01:22 --------- d-----w c:\documents and settings\alok sinha\Application Data\Download Manager 2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-20 17:36 --------- d-----w c:\program files\Java 2008-10-20 17:34 --------- d-----w c:\program files\Common Files\Java 2005-05-16 18:00 85,504 ----a-w c:\documents and settings\alok sinha\certadm.dll 2005-05-16 18:00 585,728 ----a-w c:\documents and settings\alok sinha\certutil.exe 2005-05-16 18:00 233,472 ----a-w c:\documents and settings\alok sinha\certcli.dll 2004-04-30 05:33 41,312 ----a-w c:\documents and settings\alok sinha\Application Data\GDIPFONTCACHEV1.DAT 2004-03-26 00:35 41,312 ----a-w c:\documents and settings\Upasana Sinha\Application Data\GDIPFONTCACHEV1.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976] "DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672] "ComcastSUPPORT"="c:\program files\Support.com\bin\tgkill.exe" [2001-11-21 57344] "AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-06-12 24576] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360] TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-08-25 270336] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.SP53"= SP5X_32.DLL "VIDC.SP54"= SP5X_32.DLL "VIDC.SP55"= SP5X_32.DLL "VIDC.SP56"= SP5X_32.DLL "VIDC.SP57"= SP5X_32.DLL "VIDC.SP58"= SP5X_32.DLL "VIDC.SP59"= SP5X_32.DLL [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Date Manager.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Date Manager.lnk backup=c:\windows\pss\Date Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GStartup.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\GStartup.lnk backup=c:\windows\pss\GStartup.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0] --a------ 2005-03-03 20:47 483328 c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-03 23:56 15360 c:\windows\SYSTEM32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DwlClient] --a------ 2005-10-13 22:26 69632 c:\program files\Common Files\Dell\EUSW\Support.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2004-09-13 14:49 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM] --a------ 2006-03-20 16:34 213936 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\masqform.exe] --a------ 2003-07-18 09:55 1048576 c:\program files\PureEdge\Viewer 6.0\masqform.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch] --a------ 2005-02-08 14:37 823296 c:\program files\Maxtor\OneTouch\Utils\OneTouch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MXOBG] --a------ 2003-10-10 10:23 94208 c:\windows\MXOALDR.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] --a------ 2007-08-30 16:43 4670704 c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Program Files\\Support.com\\bin\\tgcmd.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"= "c:\\Program Files\\Microsoft Digital Image 2006\\PIXPhotoStory.exe"= "c:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"= "c:\\WINDOWS\\SYSTEM32\\ftp.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Digital Spectrum\\Digital PixMaster 6.1\\DigitalPixMaster.exe"= "c:\\Program Files\\Ipswitch\\WS_FTP Home\\wsftpgui.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 stcvsm;stcvsm;c:\windows\system32\drivers\stcvsm.sys [2008-08-25 127520] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1001000.021\SYMEFA.SYS [2008-12-13 309296] R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\DRIVERS\tffsport.sys [2004-02-05 149376] R1 BHDrvx86;Symantec Heuristics Driver;\??\c:\windows\system32\drivers\NAV\1001000.021\BHDrvx86.sys [2008-12-13 255536] R1 ccHP;Symantec Hash Provider;\??\c:\windows\system32\drivers\NAV\1001000.021\ccHPx86.sys [2008-12-13 362544] R1 IDSxpx86;IDSxpx86;\??\c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20081212.001\IDSxpx86.sys [2008-12-15 274808] R1 sbmount;StorageCraft Image Mount Driver;c:\windows\system32\drivers\sbmount.sys [2008-08-25 86560] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-13 99376] S3 GR433S;GR433S;c:\windows\system32\Drivers\GR433s.sys [2004-01-06 66896] S3 pfusb;pfusb;c:\windows\system32\drivers\pfusb.sys [2007-05-06 12272] S3 PID_0900_V;Logitech ClickSmart 310(PID_0900_V);c:\windows\system32\DRIVERS\LV551AV.sys [2002-11-22 220079] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24e8c232-b603-11d9-8967-000bdb2a2fb2}] \Shell\AutoRun\command - F:\WinHECWiFi.exe . Contents of the 'Scheduled Tasks' folder 2008-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34] 2008-12-15 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20] . - - - - ORPHANS REMOVED - - - - BHO-{068CC6AE-42CA-4680-9F3D-EE517CAD5F98} - c:\windows\system32\ljJYQIXn.dll BHO-{53F60149-996C-48FD-A884-8931E29C8EF9} - c:\windows\system32\nnnlmJDV.dll BHO-{5443b8d5-0d37-472f-b1ca-564d45958a3b} - c:\windows\system32\qsgxsg.dll Toolbar-{9FF7AAC8-31D0-4659-9880-CBD98E306B47} - c:\windows\system32\winda77.dll WebBrowser-{9FF7AAC8-31D0-4659-9880-CBD98E306B47} - c:\windows\system32\winda77.dll Notify-Accessibility - c:\windows\system32\6wO4SVC.DLL MSConfigStartUp-a8261341 - c:\windows\system32\alrhtqpo.dll MSConfigStartUp-BullsEye Network - c:\program files\BullsEye Network\bin\bargains.exe MSConfigStartUp-gadcom - c:\documents and settings\alok sinha\Application Data\gadcom\gadcom.exe MSConfigStartUp-googletalk - c:\program files\Google\Google Talk\googletalk.exe MSConfigStartUp-loads - c:\windows\medload.exe MSConfigStartUp-msnappau - c:\program files\MSN Apps\Updater\[u]0[/u]1.02.3000.1001\en-us\msnappau.exe MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe MSConfigStartUp-RetroExpress - c:\progra~1\Dantz\RETROS~1\RetroExpress.exe MSConfigStartUp-SrchfstUpdate - c:\windows\srchupdt.exe MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html mWindow Title = Microsoft Internet Explorer provided by Comcast IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 IE: {{C21AE3DD-2E97-406B-8C87-A9AD5BBD49D1} - http://www.downloadalot.com IE: {{C21AE3DD-2E97-406B-8C87-A9AD5BBD49D1} - http://www.downloadalot.com - O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd c:\windows\System32\msvcrt.dll - c:\windows\System32\mfc42.dll c:\windows\System32\olepro32.dll c:\windows\Downloaded Program Files\mainRdr.dll c:\windows\System32\SDRes.dll c:\windows\Downloaded Program Files\smartdiagX.ocx O16 -: {00C1446A-F80F-47CB-8644-DCCF0C39B5D8} hxxp://support.gemplus.com/gemdownload/readers/smartdiagx_XP2000.cab c:\windows\Downloaded Program Files\smartdiagx.inf c:\windows\Downloaded Program Files\scroll360.ocx - O16 -: {1D077753-DF32-11CF-AEC2-00A0C90C2B47} file://d:\retro360\Future\scroll360.ocx c:\windows\Downloaded Program Files\Manager.exe - c:\windows\Downloaded Program Files\DownloadManagerV2.ocx O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab c:\windows\Downloaded Program Files\DownloadManagerV2.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-15 18:26:04 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Norton AntiVirus] "ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.1.0.33\diMaster.dll\" /prefetch:1" . ------------------------ Other Running Processes ------------------------ . c:\windows\SYSTEM32\scardsvr.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe c:\program files\Viewpoint\Common\ViewpointService.exe c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe c:\program files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe c:\program files\Support.com\bin\tgcmd.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2008-12-15 19:13:36 - machine was rebooted ComboFix-quarantined-files.txt 2008-12-16 03:13:26 Pre-Run: 58,848,346,112 bytes free Post-Run: 58,876,047,360 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn 278 --- E O F --- 2008-12-05 01:25:49