Belahzur
Log from Combofix below:
ComboFix 09-08-10.06 - Graham 18/08/2009 20:24.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.493 [GMT 1:00]
Running from: c:\documents and settings\Graham\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Graham\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FILE ::
"C:\43214354.bat"
"c:\documents and settings\All Users\Application Data\12848124"
"c:\documents and settings\All Users\Application Data\rysal.reg"
"c:\documents and settings\All Users\Application Data\tacihoq.com"
"c:\documents and settings\claire\claire.exe"
"c:\documents and settings\Graham\Local Settings\Application Data\dybaci.sys"
"c:\documents and settings\James\Application Data\LimeWire"
"c:\documents and settings\Wilma\otvdno.bat"
"c:\documents and settings\Wilma\Wilma.exe"
"c:\documents and settings\Wilma\YXJTHK.exe"
"c:\program files\Common Files\cajede.sys"
"c:\program files\Common Files\nujoz.dl"
"c:\program files\LimeWire"
"c:\program files\PC_Antispyware2010"
"c:\windows\ikadesimoc.dat"
"c:\windows\imehofuji.bat"
"c:\windows\mezynu.exe"
"c:\windows\system32\msxm192z.dll"
"c:\windows\system32\ofimyqu.com"
"c:\windows\system32\sofatnet.exe"
"c:\windows\system32\yzygepo.pif"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\43214354.bat
c:\documents and settings\All Users\Application Data\rysal.reg
c:\documents and settings\All Users\Application Data\tacihoq.com
c:\documents and settings\claire\claire.exe
c:\documents and settings\Graham\Local Settings\Application Data\dybaci.sys
c:\documents and settings\Wilma\otvdno.bat
c:\documents and settings\Wilma\Wilma.exe
c:\documents and settings\Wilma\YXJTHK.exe
c:\program files\Common Files\cajede.sys
c:\program files\Common Files\nujoz.dl
c:\windows\ikadesimoc.dat
c:\windows\imehofuji.bat
c:\windows\Install.txt
c:\windows\mezynu.exe
c:\windows\system32\FInstall.sys
c:\windows\system32\msxm192z.dll
c:\windows\system32\ofimyqu.com
c:\windows\system32\sofatnet.exe
c:\windows\system32\wiawow32.sys
c:\windows\system32\wiwow64.exe
c:\windows\system32\yzygepo.pif
c:\windows\TEMP\mpj98108.dll
c:\windows\TEMP\mta80562.dll
c:\windows\system32\grpconv.exe . . . is missing!!
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SOFATNET
-------\Service_sofatnet
((((((((((((((((((((((((( Files Created from 2009-07-18 to 2009-08-18 )))))))))))))))))))))))))))))))
.
2009-08-18 19:30 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-08-18 19:30 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-08-14 13:58 . 2009-08-14 13:58 -------- d-----w- c:\documents and settings\Graham\Local Settings\Application Data\ABBYY
2009-08-12 15:31 . 2009-08-12 15:31 -------- d-----w- c:\documents and settings\Wilma\Application Data\DivX
2009-08-12 14:37 . 2009-08-12 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\12848124
2009-08-12 14:36 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 22:44 . 2009-08-11 22:44 -------- d-----w- c:\program files\PC_Antispyware2010
2009-08-10 19:15 . 2009-08-10 19:15 -------- d-----w- c:\documents and settings\Graham\Application Data\Malwarebytes
2009-08-10 19:14 . 2009-08-03 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-10 19:14 . 2009-08-10 19:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-10 19:14 . 2009-08-10 19:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-10 19:14 . 2009-08-03 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-08 22:23 . 2009-08-08 22:23 -------- d-----w- c:\program files\Sun
2009-08-08 21:55 . 2009-08-08 22:27 -------- d-----w- c:\documents and settings\Graham\.SunDownloadManager
2009-08-08 21:19 . 2009-08-08 21:19 -------- d-----w- c:\program files\Trend Micro
2009-08-05 09:01 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 19:41 . 2009-08-04 19:41 -------- d-----w- c:\documents and settings\Graham\Application Data\AVG8
2009-08-02 08:16 . 2009-08-02 08:16 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-02 08:16 . 2009-08-02 08:16 -------- d-----w- c:\program files\MSBuild
2009-08-02 08:16 . 2009-08-02 08:16 -------- d-----w- c:\program files\Reference Assemblies
2009-08-02 08:15 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-02 08:15 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-02 08:15 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-02 08:15 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-02 08:15 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-02 08:15 . 2009-08-02 08:15 -------- d-----w- C:\09c6fbee40c940fe6129
2009-08-02 08:15 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-02 08:15 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-07-29 17:42 . 2009-07-29 17:42 458 ----a-w- c:\documents and settings\James\joqxij.bat
2009-07-21 18:55 . 2009-07-21 18:55 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 18:54 . 2009-07-21 18:54 152576 ----a-w- c:\documents and settings\Graham\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-18 09:09 . 2008-09-03 14:36 47232 ----a-w- c:\documents and settings\James\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-16 11:01 . 2008-11-01 19:48 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-08-15 00:43 . 2008-09-25 13:18 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-08 22:22 . 2005-12-09 09:26 -------- d-----w- c:\program files\Java
2009-08-07 15:05 . 2008-08-09 10:13 -------- d-----w- c:\documents and settings\Graham\Application Data\AdobeUM
2009-08-07 03:36 . 2008-09-11 19:30 -------- d-----w- c:\program files\Dl_cats
2009-08-05 09:01 . 2005-08-16 04:18 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 21:34 . 2008-08-08 20:59 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-04 21:34 . 2008-08-08 20:59 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-04 21:34 . 2008-08-08 20:59 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-04 21:29 . 2008-08-08 20:59 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-03 00:49 . 2009-06-19 14:15 47232 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-07-23 20:37 . 2008-12-24 20:08 -------- d-----w- c:\documents and settings\Graham\Application Data\BitTorrent
2009-07-17 19:01 . 2005-08-16 04:18 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 16:58 . 2008-09-07 21:55 -------- d-----w- c:\program files\Bonjour
2009-07-17 16:46 . 2008-10-18 15:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Kodak
2009-07-17 14:53 . 2009-07-17 14:50 -------- d-----w- c:\documents and settings\Graham\Application Data\Temp
2009-07-17 14:52 . 2008-10-18 15:56 -------- d-----w- c:\program files\Kodak
2009-07-13 22:43 . 2005-08-16 04:19 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-11 07:08 . 2009-06-27 11:51 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-07-10 17:49 . 2008-08-08 23:24 -------- d-----w- c:\program files\CCleaner
2009-07-06 21:17 . 2008-09-09 21:53 -------- d-----w- c:\program files\LimeWire
2009-07-06 19:29 . 2008-09-09 21:57 -------- d-----w- c:\documents and settings\James\Application Data\LimeWire
2009-06-29 16:12 . 2005-08-16 04:18 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2005-08-16 04:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-08-16 04:18 17408 ------w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2005-08-16 04:18 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 04:18 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-14 15:07 . 2009-06-27 12:00 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-12 12:31 . 2005-08-16 04:18 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-08-16 04:18 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2005-08-16 04:18 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 08:19 . 2005-08-16 04:37 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2005-08-16 04:18 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2005-08-16 04:18 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-03 17:27 . 2008-11-06 22:39 47232 ----a-w- c:\documents and settings\Wilma\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-24 23:24 . 2008-05-26 21:18 350208 ------w- c:\windows\system32\mssph.dll
2008-09-03 14:36 . 2008-09-03 14:36 251 ----a-w- c:\program files\wt3d.ini
2005-07-16 05:41 . 2005-12-09 09:38 41573 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2005-07-16 05:41 . 2005-12-09 09:38 48223 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2005-07-16 05:41 . 2005-12-09 09:38 160871 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-08-12_20.01.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-18 19:35 . 2009-08-18 19:35 16384 c:\windows\Temp\Perflib_Perfdata_4e0.dat
+ 2009-08-18 19:33 . 2009-08-18 19:33 16384 c:\windows\Temp\Perflib_Perfdata_474.dat
+ 2009-08-18 19:28 . 2009-08-18 19:28 16384 c:\windows\Temp\Perflib_Perfdata_17d0.dat
+ 2004-08-10 05:00 . 2004-08-10 05:00 44032 c:\windows\system32\EvdoServer.dll
+ 2008-08-24 10:59 . 2009-08-17 04:37 69120 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\xlicons.exe
- 2008-08-24 10:59 . 2009-05-04 18:50 69120 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\xlicons.exe
- 2008-08-24 10:59 . 2009-05-04 18:50 35328 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\wordicon.exe
+ 2008-08-24 10:59 . 2009-08-17 04:37 35328 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\wordicon.exe
- 2008-08-24 10:59 . 2009-05-04 18:50 30208 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\pptico.exe
+ 2008-08-24 10:59 . 2009-08-17 04:37 30208 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\pptico.exe
+ 2008-08-24 10:59 . 2009-08-17 04:37 11264 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\PEicons.exe
- 2008-08-24 10:59 . 2009-05-04 18:50 11264 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\PEicons.exe
- 2008-08-24 10:59 . 2009-05-04 18:50 28160 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\misc.exe
+ 2008-08-24 10:59 . 2009-08-17 04:37 28160 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\misc.exe
- 2008-08-24 10:59 . 2009-05-04 18:50 73216 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\fpicon.exe
+ 2008-08-24 10:59 . 2009-08-17 04:37 73216 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\fpicon.exe
+ 2008-08-24 10:59 . 2009-08-17 04:37 22528 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\bindico.exe
- 2008-08-24 10:59 . 2009-05-04 18:50 22528 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\bindico.exe
- 2009-08-12 19:57 . 2009-08-12 19:57 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-18 19:31 . 2009-08-18 19:31 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
- 2009-08-12 19:57 . 2009-08-12 19:57 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
+ 2009-08-18 19:31 . 2009-08-18 19:31 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
- 2008-08-24 10:59 . 2009-05-04 18:50 104960 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\outicon.exe
+ 2008-08-24 10:59 . 2009-08-17 04:37 104960 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\outicon.exe
+ 2008-08-24 10:59 . 2009-08-17 04:37 155136 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\accicons.exe
- 2008-08-24 10:59 . 2009-05-04 18:50 155136 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\accicons.exe
+ 2009-08-18 19:31 . 2009-08-18 19:31 172032 c:\windows\ERDNT\subs\Users\00000008\UsrClass.dat
+ 2009-08-18 19:31 . 2009-08-18 19:31 172032 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
- 2009-08-12 19:57 . 2009-08-12 19:57 172032 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
+ 2009-08-18 19:31 . 2009-08-18 19:31 237568 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
- 2009-08-12 19:57 . 2009-08-12 19:57 237568 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
+ 2009-08-18 19:31 . 2009-08-18 19:31 237568 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
- 2009-08-12 19:57 . 2009-08-12 19:57 237568 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
+ 2009-08-18 19:35 . 2009-06-29 16:12 1159680 c:\windows\Temp\x1c79505.dll
+ 2009-08-18 19:33 . 2009-06-29 16:12 1159680 c:\windows\Temp\mta58299.dll
+ 2009-08-18 19:36 . 2009-06-29 16:12 1159680 c:\windows\Temp\mta13187.dll
+ 2009-08-18 19:36 . 2009-06-29 16:12 1159680 c:\windows\Temp\mta107616.dll
+ 2009-08-18 19:36 . 2009-06-29 16:12 1159680 c:\windows\Temp\mpj80794.dll
+ 2009-08-18 19:31 . 2009-08-18 19:31 3952640 c:\windows\ERDNT\subs\Users\00000007\ntuser.dat
+ 2009-08-18 19:31 . 2009-08-18 19:31 4026368 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT