ComboFix 09-02-27.01 - Sriram 2009-02-27 16:41:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.282 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: Norton AntiVirus *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Sriram\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\virusremover2009_setup_paid_en.exe
c:\documents and settings\Sriram\Local Settings\Temporary Internet Files\fbk.sts
c:\temp\abW9
c:\windows\cookies.ini
c:\windows\IE4 Error Log.txt
c:\windows\system\oeminfo.ini
c:\windows\system32\afrfcs.dll
c:\windows\system32\ahujeput.ini
c:\windows\system32\aviwizim.ini
c:\windows\system32\awatimej.ini
c:\windows\system32\bapubeni.dll
c:\windows\system32\cggkhirf.ini
c:\windows\system32\dabepoyi.dll
c:\windows\system32\dkrmrd.dll
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\ehggh.bak1
c:\windows\system32\ehggh.bak2
c:\windows\system32\ehggh.ini
c:\windows\system32\ehggh.ini2
c:\windows\system32\ehggh.tmp
c:\windows\system32\eiywcjfy.ini
c:\windows\system32\ejuzohaz.ini
c:\windows\system32\evezejon.ini
c:\windows\system32\fcqvtg.dll
c:\windows\system32\gafuyowo.dll
c:\windows\system32\gajapuda.dll
c:\windows\system32\gerajome.dll
c:\windows\system32\hasayaha.dll
c:\windows\system32\hszhzn.dll
c:\windows\system32\htgpifck.ini
c:\windows\system32\ibujupop.ini
c:\windows\system32\ifisikat.ini
c:\windows\system32\izazabun.ini
c:\windows\system32\kebukilo.dll
c:\windows\system32\khmtiv.dll
c:\windows\system32\kokemabo.dll
c:\windows\system32\lafokune.dll
c:\windows\system32\mdm.exe
c:\windows\system32\ngghipkg.ini
c:\windows\system32\nseudbom.dll
c:\windows\system32\nubazazi.dll
c:\windows\system32\ofilihan.ini
c:\windows\system32\ohanzr.dll
c:\windows\system32\orelehup.ini
c:\windows\system32\owoyufag.ini
c:\windows\system32\pprBLkkj.ini
c:\windows\system32\pprBLkkj.ini2
c:\windows\system32\pubulasi.dll
c:\windows\system32\puhelero.dll
c:\windows\system32\remafari.dll
c:\windows\system32\repozuyi.dll
c:\windows\system32\rijegazo.dll
c:\windows\system32\rMa02yy
c:\windows\system32\rovonahu.dll
c:\windows\system32\senekaqgtswrua.dat
c:\windows\system32\senekayslptmuu.dat
c:\windows\system32\siropati.dll
c:\windows\system32\sopekago.dll
c:\windows\system32\tifakq.dll
c:\windows\system32\tinonere.dll
c:\windows\system32\tobirugo.dll
c:\windows\system32\uhupamur.ini
c:\windows\system32\uzunivep.ini
c:\windows\system32\vujabono.dll
c:\windows\system32\wakemoza.dll
c:\windows\system32\xglugy.dll
c:\windows\system32\ykujeb.dll
----- BITS: Possible infected sites -----
hxxp://82.98.235.205
.
((((((((((((((((((((((((( Files Created from 2009-01-27 to 2009-02-27 )))))))))))))))))))))))))))))))
.
2009-02-27 13:37 . 2009-02-27 13:19 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-27 13:19 . 2009-02-27 13:19 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-27 13:17 . 2009-02-27 13:19
d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-27 13:17 . 2009-02-27 13:18 d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-27 13:05 . 2009-02-27 13:05 230 --a------ c:\windows\system32\spupdsvc.inf
2009-02-27 00:00 . 2009-02-26 23:45 102,664 --a------ c:\windows\system32\drivers\tmcomm.sys
2009-02-26 23:45 . 2009-02-27 16:13 d-------- c:\documents and settings\Sriram\.housecall6.6
2009-02-26 08:49 . 2009-02-26 08:49 2,713 ---hs---- c:\windows\system32\pinapoyo.dll
2009-02-26 08:40 . 2009-02-26 09:20 84,992 --a------ c:\windows\system32\fasirozi.dll
2009-02-25 18:00 . 2009-02-25 19:02 84,992 --a------ c:\windows\system32\rezizafo.dll
2009-02-23 08:48 . 2009-02-23 08:48 d-------- c:\program files\Trend Micro
2009-02-22 12:35 . 2009-02-23 08:41 2,560 --a------ c:\windows\system32\drivers\mchInjDrv.sys
2009-02-21 14:18 . 2009-02-21 14:18 d-------- c:\documents and settings\Sriram\Application Data\PC Tools
2009-02-21 14:18 . 2008-08-25 12:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-02-21 14:18 . 2008-08-25 12:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-02-21 14:18 . 2008-08-25 12:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-02-21 14:18 . 2008-06-02 16:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-02-21 13:26 . 2009-02-21 13:26 d-a------ c:\program files\Norton Support
2009-02-21 13:10 . 2009-02-21 13:09 36,272 -ra------ c:\windows\system32\drivers\SymIM.sys
2009-02-21 13:09 . 2009-02-21 13:10 d-------- c:\program files\Symantec
2009-02-21 13:09 . 2009-02-21 13:09 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2009-02-21 13:09 . 2009-02-21 13:09 60,808 --a------ c:\windows\system32\S32EVNT1.DLL
2009-02-21 13:09 . 2009-02-21 13:09 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2009-02-21 13:09 . 2009-02-21 13:09 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2009-02-21 13:08 . 2009-02-21 13:08 d-------- c:\windows\system32\drivers\NAV
2009-02-21 13:08 . 2009-02-21 13:08 d-------- c:\program files\Windows Sidebar
2009-02-21 13:08 . 2009-02-21 13:08 d-------- c:\program files\Norton AntiVirus
2009-02-21 13:08 . 2009-02-21 13:13 d-------- c:\documents and settings\All Users\Application Data\Norton
2009-02-21 13:07 . 2009-02-21 13:07 d-------- c:\program files\NortonInstaller
2009-02-21 12:36 . 2009-02-21 12:36 d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-21 12:10 . 2009-02-23 09:36 d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-21 12:09 . 2009-02-22 12:45 d-------- c:\program files\Spyware Doctor
2009-02-21 09:06 . 2009-02-21 09:06 d-------- C:\My Downloads
2009-02-21 09:03 . 2009-02-21 09:03 d-------- c:\documents and settings\Sriram\Application Data\VirusRemover2009
2009-02-21 09:00 . 2009-02-21 15:39 d-------- c:\documents and settings\Sriram\Application Data\cogad
2009-02-21 08:54 . 2009-02-21 08:54 d-------- C:\Cache
2009-02-21 08:50 . 2009-02-27 16:45 2,204 --a------ c:\windows\srnlwcdh
2009-02-10 15:01 . 2009-02-21 08:57 d-------- c:\program files\CA Yahoo! Anti-Spy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 21:27 --------- d-----w c:\program files\Microsoft Money
2009-02-27 21:23 --------- d-----w c:\program files\DivX
2009-02-27 21:22 --------- d-----w c:\program files\Acro Software
2009-02-27 18:17 --------- d-----w c:\program files\Lavasoft
2009-02-27 14:33 --------- d-----w c:\documents and settings\Sriram\Application Data\Lavasoft
2009-02-21 18:14 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-21 17:05 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-02-15 14:46 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-02-15 14:45 --------- d--h--r c:\documents and settings\All Users\Application Data\yahoo!
2009-02-15 14:45 --------- d-----w c:\program files\Yahoo!
2009-02-11 03:28 --------- d-----w c:\program files\Google
2009-02-10 20:01 --------- d-----w c:\program files\Common Files\Scanner
2008-10-01 23:27 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-10-12 11:54 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101220081013\index.dat
.
------- Sigcheck -------
2004-09-29 13:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
2005-01-27 12:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
2005-05-02 15:57 658944 e1e18136f9dd3df1ad9c82193a5898a6 c:\windows\$hf_mig$\KB883939\SP2QFE\wininet.dll
2005-03-10 02:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
2005-09-02 18:53 660480 97a6fd7cafd688cf2c78939ebaf0cd0c c:\windows\$hf_mig$\KB896688\SP2QFE\wininet.dll
2005-07-02 21:09 659456 6e533d155b259eb2363d3e04b5be309f c:\windows\$hf_mig$\KB896727\SP2QFE\wininet.dll
2005-10-20 22:38 661504 af785c4947676a7fc1673fdc5c8d0b5b c:\windows\$hf_mig$\KB905915\SP2QFE\wininet.dll
2006-03-03 22:58 663552 c0845ecbf4f9164e618ee381b79c9032 c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
2006-05-10 00:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
2006-06-23 06:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-09-14 03:31 664576 d207370287cf769aebebf03837784963 c:\windows\$hf_mig$\KB922760\SP2QFE\wininet.dll
2007-03-07 12:40 823296 b8f4db39ca7353752f245379d285c80e c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
2007-04-25 04:08 823808 431defbb4a3d7b0dc062c1b064623a2f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
2007-06-27 09:40 824320 d6ed5e042c5207553e7f5e842918137f c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
2007-08-20 05:02 825344 357d54bf94fe9d6d8505a96b5c2a3bca c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
2007-10-10 18:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-06 21:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 08:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-22 22:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 11:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-08-26 04:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2008-10-16 15:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
2008-12-20 18:56 827904 044e0a4e9fe97c0fb9afe9c89e2a82e6 c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
2005-03-10 03:02 656896 6f018d6319be4f96426ea829b79e05d5 c:\windows\$NtUninstallKB883939$\wininet.dll
2005-07-02 21:11 658432 5b5ff992c0fa762ccf8655fc290e6e52 c:\windows\$NtUninstallKB896688$\wininet.dll
2005-05-02 15:52 657920 1a078af3f85d10ba56444c23b3a18e74 c:\windows\$NtUninstallKB896727$\wininet.dll
2005-09-02 18:52 658432 af61ebb1f550175eff406d545d6ab086 c:\windows\$NtUninstallKB905915$\wininet.dll
2005-10-20 22:39 658432 e7b27b6b6e06ce34ea019fd8b858c613 c:\windows\$NtUninstallKB912812$\wininet.dll
2006-03-03 22:33 658432 1c0979c7a489bee573cd0bf4ad94bb06 c:\windows\$NtUninstallKB916281$\wininet.dll
2006-05-10 00:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB918899$\wininet.dll
2006-06-23 06:02 658944 2b4db890936430c71419037039502752 c:\windows\$NtUninstallKB922760$\wininet.dll
2007-03-07 12:45 822784 5b35dae6e4886f64d1da58c4e3e01eb9 c:\windows\ie7updates\KB933566-IE7\wininet.dll
2007-10-10 18:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll
2008-03-01 08:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll
2008-06-23 11:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
2008-04-13 19:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\ServicePackFiles\i386\wininet.dll
2006-09-14 03:39 658944 621af3f6174a3f60677f5230e28bcc07 c:\windows\system32\wininet.dll
2006-09-14 03:39 658944 621af3f6174a3f60677f5230e28bcc07 c:\windows\system32\dllcache\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-23 68856]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-06-07 4670968]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"CLRHost"="c:\blp\API\Office Tools\bbxlcmd.exe" [2008-12-18 102400]
"BackupNotify"="c:\program files\HP\Digital Imaging\bin\backupnotify.exe" [2003-06-22 24576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" [2007-11-28 583048]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-07-15 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-07-15 618496]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-10 136600]
"Share-to-Web Namespace Daemon"="c:\program files\HP\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-05-22 483328]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-01 29744]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"CamMonitor"="c:\program files\HP\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 90112]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-13 335872]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-27 509784]
"AGRSMMSG"="AGRSMMSG.exe" [2003-11-19 c:\windows\AGRSMMSG.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-09-12 503869]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-08-06 51776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv31"= c:\windows\system32\ir32_32.dll
"vidc.iv32"= c:\windows\system32\ir32_32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"InoTask"=2 (0x2)
"InoRT"=2 (0x2)
"InoRPC"=2 (0x2)
"SAVScan"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"c:\\blp\\Wintrv\\wintrv.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\blp\\API\\bbcomm.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-27 64160]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1002000.007\SymEFA.sys [2009-02-21 309296]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1002000.007\BHDrvx86.sys [2009-02-21 255536]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1002000.007\cchpx86.sys [2009-02-21 362544]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090217.002\IDSxpx86.sys [2009-02-21 276344]
R1 mchInjDrv;madCodeHook DLL injection driver;c:\windows\system32\drivers\mchInjDrv.sys [2009-02-22 2560]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe [2009-02-21 115560]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2005-05-06 14336]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-26 101936]
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [2004-04-18 26240]
S0 srnlwcdh;srnlwcdh;c:\windows\system32\drivers\linofmof.sys []
S2 mrtRate;mrtRate; [x]
S3 GPCCARD;GPCCARD;c:\windows\system32\drivers\gpccard.sys [2006-06-09 82176]
S3 GPR400;GEMPLUS GPR400 PCMCIA Smart Card Reader;c:\windows\system32\drivers\gpr400.sys [2004-10-24 17408]
S3 GTwinUSB;GTwinUSB;c:\windows\system32\drivers\GTwinUSB.sys [2002-10-04 61776]
S4 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2004-10-17 29744]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-02-21 356920]
S4 YahooAUService;Yahoo! Updater;c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
.
Contents of the 'Scheduled Tasks' folder
2009-02-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-27 13:19]
2009-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{415ee21d-ce08-45ce-b244-44e902d128c1} - c:\windows\system32\hihofuhi.dll
HKCU-Run-RecordNow! - (no file)
HKLM-Run-jinifofeba - c:\windows\system32\gewopeva.dll
HKLM-Run-SAClient - c:\program files\Comcast\BBClient\Programs\RegCon.exe
HKLM-Run-Realtime Monitor - c:\progra~1\CA\ETRUST~1\realmon.exe
HKLM-Run-mmtask - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
HKLM-Run-kdx - c:\windows\kdx\KHost.exe
HKLM-Run-HPHUPD05 - c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
HKLM-Run-CitiVAN - c:\program files\Citi Virtual Account Numbers\CitiVAN.exe
HKLM-Run-7058e831 - c:\windows\system32\nahilifo.dll
HKLM-Run-CPM736bdbad - c:\windows\system32\maguhugi.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/webhp?sourceid=navclient&ie=UTF-8
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: blackrock.com\citrix.amrs
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - hxxp://download.sidestep.com/get/k00719/sb028.cab
FF - ProfilePath - c:\documents and settings\Sriram\Application Data\Mozilla\Firefox\Profiles\fi2xzsde.gayathri\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-27 16:49:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????4?0?9?3??????? ?deB???????????????B? ??????
scanning hidden files ...
c:\windows\system32\drivers\linofmof.sys 25088 bytes executable
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2312533393-450040937-3754819232-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\scardsvr.exe
c:\program files\HP\HP Share-to-Web\hpgs2wnf.exe
c:\blp\API\Office Tools\Bloomberg.UIServer.exe
c:\blp\API\Office Tools\Bloomberg.RtdServer.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\SoftwareDistribution\Download\a2d74d883dc4c09154437641da2b8d16\update\update.exe
.
**************************************************************************
.
Completion time: 2009-02-27 16:57:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-27 21:56:23
Pre-Run: 9,656,836,096 bytes free
Post-Run: 10,516,254,720 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin
360 --- E O F --- 2009-02-12 04:45:12