ComboFix 09-07-22.01 - Nidhi c 07/22/2009 23:48.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1006.652 [GMT -4:00]
Running from: c:\documents and settings\Nidhi c\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\-1341985594
C:\gfub.exe
C:\p2hhr.bat
c:\windows\010112010146118114.dat
c:\windows\0101120101464849.dat
c:\windows\0101120101465752.dat
c:\windows\freddy49.exe
c:\windows\Installer\33b3e.msi
c:\windows\Installer\b4c0c.msi
c:\windows\ld12.exe
c:\windows\system32\drivers\geyekrkltofrft.sys
c:\windows\system32\geyekrbfrsipxd.dat
c:\windows\system32\geyekrewbvpibo.dll
c:\windows\system32\geyekrulhrklos.dll
c:\windows\system32\geyekrvnbosthx.dat
c:\windows\system32\ghaf8jkdfd.dll
c:\windows\system32\wbem\proquota.exe
.
---- Previous Run -------
.
c:\docume~1\ALLUSE~1\APPLIC~1\17778254\17778254
c:\docume~1\ALLUSE~1\APPLIC~1\17778254\17778254.exe
c:\windows\Install.txt
c:\windows\Installer\14b300.msi
c:\windows\Installer\14b306.msi
c:\windows\Installer\14b30c.msi
c:\windows\Installer\48db3.msp
c:\windows\Installer\c63d56.msp
c:\windows\msa.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\certstore.dat
c:\windows\system32\drivers\UACbotgenalmpixmkhbo.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\Install.txt
c:\windows\system32\net.net
c:\windows\system32\o4Patch.exe
c:\windows\system32\pcmstub.sys
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\tpsaxyd.exe
c:\windows\system32\UACbhxgppjejtxbieqhw.dll
c:\windows\system32\UACbvlkkyijtsvoreuiu.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UAClsbiqmntakyydowqf.dll
c:\windows\system32\UACsequdnebxvjuvdpiq.db
c:\windows\system32\UACsowywkmkhljyuyjou.dat
c:\windows\system32\uactmp.db
c:\windows\system32\UACuxcomttscjscjmoop.dll
c:\windows\system32\UACyrultpmgomwhlqfnv.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wiawow32.sys
c:\windows\system32\wiwow64.exe
c:\windows\system32\WS2Fix.exe
c:\windows\wiaserviv.log
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_6TO4
-------\Legacy_MSNCACHE
-------\Legacy_PCMSTUB
-------\Legacy_SOPIDKC
-------\Service_6to4
-------\Service_pcmstub
((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 )))))))))))))))))))))))))))))))
.
2009-07-23 03:55 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-07-23 03:55 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-07-22 03:18 . 2009-07-22 03:18 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-07-22 03:18 . 2009-07-22 03:18 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\SiteAdvisor
2009-07-22 03:13 . 2009-07-22 03:13 -------- d-----w- c:\program files\Common Files\McAfee
2009-07-22 03:12 . 2009-07-23 00:09 -------- d-----w- c:\program files\McAfee
2009-07-22 03:12 . 2009-07-22 03:13 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\McAfee
2009-07-19 23:02 . 2009-07-19 23:02 1 ---h--w- c:\windows\bf23567.dat
2009-07-19 21:58 . 2009-07-19 21:58 69845 ----a-w- C:\vphih.exe
2009-07-19 21:53 . 2009-07-19 21:58 22016 ----a-w- C:\fhlyeby.exe
2009-07-19 21:53 . 2009-07-19 21:58 11264 ----a-w- C:\benfuse.exe
2009-07-19 21:53 . 2009-07-19 21:58 39936 ----a-w- C:\sitkrb.exe
2009-07-03 18:07 . 2009-07-03 18:07 -------- d-----w- c:\windows\system32\wbem\Repository
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-22 03:12 . 2008-12-15 13:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-19 21:58 . 2006-04-11 02:08 -------- d-----w- c:\program files\Google
2009-07-11 05:30 . 2008-11-02 06:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-03 05:18 . 2009-07-03 05:18 65536 ----a-w- c:\windows\system32\12D.tmp
2009-06-16 14:36 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-10 17:51 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:09 . 2004-08-10 17:51 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-10 17:51 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-10 17:51 78336 ----a-w- c:\windows\system32\ieencode.dll
2008-11-02 05:13 . 2008-11-02 05:13 17509 ----a-w- c:\program files\Common Files\ogoku.bat
2008-11-02 05:13 . 2008-11-02 05:13 10781 ----a-w- c:\program files\Common Files\vaxux.ban
2009-07-23 02:31 . 2009-02-06 03:08 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2005-08-09 13:18 . 2005-07-27 19:16 56 --sh--r- c:\windows\system32\8DBC359ACF.sys
2005-08-09 13:18 . 2005-07-27 19:16 1890 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-07-22 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"tgcmd"="c:\program files\support.com\bin\tgcmd.exe" [2002-04-25 1544192]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-23 94208]
"sealmon"="c:\program files\SealedMedia\sealmon.exe" [2006-06-20 94208]
"Network Associates Error Reporting Service"="c:\program files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 147514]
"medicsp2"="c:\program files\twc\medicsp2\bin\sprtcmd.exe" [2008-02-01 198184]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2005-02-25 139320]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-11-08 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-11-08 696320]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-04 111936]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-7-13 24576]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-9-19 282624]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-02 20:35 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\support.com\\bin\\tgcmd.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_03\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [4/5/2006 10:52 AM 58464]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [12/4/2008 2:50 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 55024]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [7/21/2009 11:13 PM 210216]
R2 sprtsvc_medicsp2;SupportSoft Sprocket Service (medicsp2);c:\program files\twc\medicsp2\bin\sprtsvc.exe [3/30/2008 11:51 AM 202280]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6449166C-2951-4105-B1A9-481F56B5DAFA}]
c:\windows\UMBS\IPPRIN~1.0\PerUser.exe /S
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-net - c:\windows\system32\net.net
HKLM-Run-17778254 - c:\documents and settings\All Users\Application Data\17778254\17778254.exe
HKLM-Run-sysfbtray - c:\windows\freddy49.exe
.
------- Supplementary Scan -------
.
uStart Page =
www.nytimes.commStart Page =
hxxp://www.google.comuInternet Connection Wizard,ShellNext =
hxxp://www.dell4me.com/mywayuInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\docume~1\NIDHIC~1\APPLIC~1\Mozilla\Firefox\Profiles\1f1uect8.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Nidhi c\Application Data\Mozilla\Firefox\Profiles\1f1uect8.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-22 23:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(816)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2009-07-23 23:58
ComboFix-quarantined-files.txt 2009-07-23 03:58
Pre-Run: 42,233,901,056 bytes free
Post-Run: 42,216,038,400 bytes free
224 --- E O F --- 2009-07-23 00:35