ComboFix 09-10-13.04 - Cody 10/14/2009 15:08.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.502 [GMT -4:00]
Running from: c:\documents and settings\Cody\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1356 [VPS 090924-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\All Users\Application Data\awacenex._sy
c:\documents and settings\All Users\Application Data\cahowoz.pif
c:\documents and settings\All Users\Application Data\cegida.exe
c:\documents and settings\All Users\Application Data\efiz.dll
c:\documents and settings\All Users\Application Data\hytem.pif
c:\documents and settings\All Users\Application Data\osyqiravi.scr
c:\documents and settings\All Users\Application Data\oxycufo.dll
c:\documents and settings\All Users\Application Data\qibikazo.exe
c:\documents and settings\All Users\Application Data\ukocig.dl
c:\documents and settings\All Users\Documents\iwegowowa.exe
c:\documents and settings\All Users\Documents\nagemofuq.dl
c:\documents and settings\All Users\Documents\ojevo._dl
c:\documents and settings\All Users\Documents\ripexasugi.ban
c:\documents and settings\Cody\Application Data\awijyny._dl
c:\documents and settings\Cody\Application Data\byhyhak.com
c:\documents and settings\Cody\Application Data\ebupogoc.vbs
c:\documents and settings\Cody\Application Data\enyfage._dl
c:\documents and settings\Cody\Application Data\fytul.ban
c:\documents and settings\Cody\Application Data\iniasd.txt
c:\documents and settings\Cody\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Cody\Application Data\seres.exe
c:\documents and settings\Cody\Application Data\svcst.exe
c:\documents and settings\Cody\Application Data\zyryd.bat
c:\documents and settings\Cody\Cookies\ekohuqigil.bat
c:\documents and settings\Cody\Cookies\oqijib.pif
c:\documents and settings\Cody\Cookies\telejowulo.dl
c:\documents and settings\Cody\Cookies\ucir.reg
c:\documents and settings\Cody\Cookies\xyxozepyt.vbs
c:\documents and settings\Cody\Local Settings\Application Data\gypiqyge.vbs
c:\documents and settings\Cody\Local Settings\Application Data\iwaciwyrit.com
c:\documents and settings\Cody\Local Settings\Application Data\kudetutyma.scr
c:\documents and settings\Cody\Local Settings\Application Data\nyfuniwyv.ban
c:\documents and settings\Cody\Local Settings\Application Data\qyhahod.vbs
c:\documents and settings\Cody\Local Settings\Application Data\ucuvasygu.com
c:\documents and settings\Cody\Local Settings\Temporary Internet Files\covawoziw.com
c:\documents and settings\Cody\Local Settings\Temporary Internet Files\igykaro.bat
c:\documents and settings\Cody\Local Settings\Temporary Internet Files\kuluc.com
c:\documents and settings\Cody\Local Settings\Temporary Internet Files\wexizylod.pif
C:\p2hhr.bat
c:\program files\Common Files\cyxilode._dl
c:\program files\Common Files\ipyzewix.vbs
c:\program files\Common Files\iwamyxomu.dll
c:\program files\Common Files\leju.pif
c:\program files\Common Files\wunubin.ban
c:\program files\Common Files\wurego.vbs
c:\program files\Internet Explorer\msn.exe
c:\program files\Internet Explorer\stm.exe
c:\windows\cyhoqab.dll
c:\windows\ejigefodib.reg
c:\windows\emih.inf
c:\windows\epavagihy._sy
c:\windows\Installer\2b59a.msp
c:\windows\Installer\6f5b14.msp
c:\windows\kb913800.exe
c:\windows\noqeq._dl
c:\windows\rudycone.inf
c:\windows\saside.sys
c:\windows\system32\_scui.cpl
c:\windows\system32\abaz._sy
c:\windows\system32\akokojad.bat
c:\windows\system32\AVR09.exe
c:\windows\system32\bojime.exe
c:\windows\system32\c2d.dat
c:\windows\system32\critical_warning.html
c:\windows\system32\drivers\gasfkydktuirqo.sys
c:\windows\system32\gasfkycjeyfqjo.dll
c:\windows\system32\gasfkylxruxewq.dll
c:\windows\system32\gasfkyvabdubdg.dat
c:\windows\system32\idm.dat
c:\windows\system32\jc.dat
c:\windows\system32\limereju.exe
c:\windows\system32\nk.dat
c:\windows\system32\ofoleru.sys
c:\windows\system32\q1.dat
c:\windows\system32\qyryr.pif
c:\windows\system32\rylyv.scr
c:\windows\system32\uvyqit._dl
c:\windows\system32\winhelper.dll
c:\windows\ugopud.bat
c:\windows\win32k.sys
c:\windows\ykigi.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ovfsthxoewfvpya
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_ovfsthxoewfvpya
((((((((((((((((((((((((( Files Created from 2009-09-14 to 2009-10-14 )))))))))))))))))))))))))))))))
.
2009-10-14 01:21 . 2009-10-14 01:21 -------- d-----w- c:\program files\Trend Micro
2009-10-01 00:42 . 2009-09-15 10:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-01 00:42 . 2009-09-15 10:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-10-01 00:42 . 2009-09-15 10:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-01 00:42 . 2009-09-15 10:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-01 00:42 . 2009-09-15 10:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-01 00:42 . 2009-09-15 10:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-01 00:42 . 2009-09-15 10:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-01 00:42 . 2009-09-15 10:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-01 00:42 . 2009-09-15 10:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-30 20:50 . 2009-09-30 20:50 14873 ----a-w- c:\windows\wobox.dat
2009-09-30 20:50 . 2009-09-30 20:50 13258 ----a-w- c:\windows\axoqa.com
2009-09-30 20:50 . 2009-09-30 20:50 11566 ----a-w- c:\windows\system32\orekynuh.com
2009-09-30 20:43 . 2009-09-30 20:43 10960 ----a-w- c:\windows\isehyne.dat
2009-09-30 20:25 . 2009-09-30 20:25 16569 ----a-w- c:\documents and settings\Cody\Local Settings\Application Data\muxyk.dat
2009-09-30 20:24 . 2009-09-30 20:24 1 ----a-w- c:\windows\system32\xd.dat
2009-09-30 01:53 . 2009-09-30 01:53 -------- d-----w- c:\documents and settings\Cody\Application Data\Turbine
2009-09-26 19:20 . 2009-09-26 19:20 -------- d-----w- c:\documents and settings\Cody\Local Settings\Application Data\Turbine
2009-09-26 17:33 . 2009-09-26 17:33 -------- d-----w- c:\program files\Turbine
2009-09-26 15:05 . 2009-09-30 18:27 -------- d-----w- c:\documents and settings\Cody\Local Settings\Application Data\PMB Files
2009-09-26 15:05 . 2009-09-30 02:45 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-09-26 15:05 . 2009-09-26 15:05 -------- d-----w- c:\program files\Pando Networks
2009-09-21 21:17 . 2009-09-21 21:17 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-09-21 21:06 . 2009-09-21 21:06 -------- d-----w- c:\program files\Adobe Media Player
2009-09-21 21:04 . 2009-09-21 21:04 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-09-21 20:59 . 2009-09-21 20:59 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-09-16 02:55 . 2009-09-30 20:28 -------- d-----w- c:\documents and settings\Cody\Application Data\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-14 01:28 . 2009-08-08 02:42 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-10-14 01:28 . 2009-08-08 02:42 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-10-14 01:28 . 2009-08-08 02:42 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-10-14 01:27 . 2007-12-13 15:15 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-14 01:27 . 2007-12-13 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-13 20:41 . 2009-08-08 02:24 -------- d-----w- c:\program files\Diablo II
2009-10-13 20:21 . 2009-08-24 20:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-13 20:21 . 2009-08-24 20:06 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2009-10-13 20:11 . 2009-04-28 05:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-30 20:50 . 2009-09-30 20:50 19561 ----a-w- c:\documents and settings\Cody\Application Data\xiqulimu.dat
2009-09-30 17:51 . 2009-04-29 16:40 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-30 01:58 . 2008-01-11 20:44 -------- d-----w- c:\documents and settings\Cody\Application Data\LimeWire
2009-09-30 01:43 . 2009-06-25 04:03 -------- d-----w- c:\documents and settings\Cody\Application Data\FrostWire
2009-09-30 01:43 . 2009-06-25 03:42 -------- d-----w- c:\program files\FrostWire
2009-09-29 03:30 . 2007-12-01 16:11 -------- d-----w- c:\documents and settings\Cody\Application Data\OpenOffice.org2
2009-09-28 14:06 . 2009-08-19 22:33 -------- d-----w- c:\documents and settings\Cody\Application Data\gtk-2.0
2009-09-28 03:58 . 2009-08-24 20:13 -------- d-----w- c:\documents and settings\Cody\Application Data\codeblocks
2009-09-21 21:17 . 2008-03-26 02:46 42592 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-09-21 21:07 . 2007-11-28 23:30 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-14 14:45 . 2007-11-28 23:29 -------- d-----w- c:\program files\Microsoft Works
2009-09-10 18:54 . 2009-04-28 05:22 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-04-28 05:22 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-25 19:40 . 2009-08-25 19:40 -------- d-----w- c:\program files\iTunes
2009-08-25 19:40 . 2009-08-25 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-25 19:40 . 2009-08-25 19:40 -------- d-----w- c:\program files\iPod
2009-08-25 19:40 . 2008-06-13 04:07 -------- d-----w- c:\program files\Common Files\Apple
2009-08-25 19:38 . 2009-08-25 19:38 -------- d-----w- c:\program files\QuickTime
2009-08-24 20:10 . 2009-08-24 20:10 -------- d-----w- c:\program files\Microsoft SQL Server
2009-08-24 20:05 . 2009-08-24 20:05 -------- d-----w- c:\program files\Microsoft SDKs
2009-08-22 05:36 . 2009-08-22 05:36 -------- d-----w- c:\program files\MSBuild
2009-08-22 05:36 . 2009-08-22 05:36 -------- d-----w- c:\program files\Reference Assemblies
2009-08-19 22:37 . 2009-08-19 22:28 -------- d-----w- c:\documents and settings\Cody\Application Data\geany
2009-08-17 05:13 . 2009-08-17 05:13 -------- d-----w- c:\program files\Microsoft
2009-08-17 05:13 . 2009-08-17 05:12 -------- d-----w- c:\program files\Windows Live
2009-08-17 05:13 . 2009-08-17 05:13 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-08-17 05:07 . 2009-08-17 05:07 -------- d-----w- c:\program files\Common Files\Windows Live
2009-08-08 02:39 . 2009-08-08 02:28 33929 ----a-w- c:\windows\DIIUnin.dat
2009-08-08 02:28 . 2009-08-08 02:28 94208 ----a-w- c:\windows\DIIUnin.exe
2009-08-08 02:28 . 2009-08-08 02:28 2829 ----a-w- c:\windows\DIIUnin.pif
2009-08-07 06:03 . 2009-08-07 06:03 5270 ----a-w- c:\windows\DiabUnin.dat
2009-08-07 06:03 . 2009-08-07 06:03 2829 ----a-w- c:\windows\DiabUnin.pif
2009-08-07 06:03 . 2009-08-07 06:03 118784 ----a-w- c:\windows\DiabUnin.exe
2009-08-05 23:23 . 2008-10-08 02:50 1536 ----a-w- c:\windows\system32\drivers\GameNT.sys
2009-08-05 09:01 . 2005-08-16 10:18 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2005-08-16 10:18 58880 ----a-w- c:\windows\system32\atl.dll
.
------- Sigcheck -------
[7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[-] 2004-08-10 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll
c:\windows\system32\eventlog.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Extender Resource Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk
backup=c:\windows\pss\Extender Resource Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Cody^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
path=c:\documents and settings\Cody\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
backup=c:\windows\pss\OpenOffice.org 2.0.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Microsoft Games\\Mechwarrior Mercenaries\\MW4Mercs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"57304:TCP"= 57304:TCP:Pando Media Booster
"57304:UDP"= 57304:UDP:Pando Media Booster
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [9/30/2009 8:42 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/30/2009 8:42 PM 20560]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [8/16/2005 6:18 AM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder
2009-04-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://wikipedia.org/mStart Page =
hxxp://www.dell.comuInternet Settings,ProxyOverride = *.local
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} -
hxxp://lads.myspace.com/upload/MySpaceUploader2.cab.
- - - - ORPHANS REMOVED - - - -
BHO-{ace6998b-75a8-43fc-a71e-b69193ae4954} - reranavu.dll
HKLM-Run-dezobazusu - niyihese.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-14 15:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(964)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(3788)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\ehome\RMSvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-10-14 15:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-14 19:25
ComboFix2.txt 2009-04-29 23:24
Pre-Run: 78,545,969,152 bytes free
Post-Run: 78,651,895,808 bytes free
302 --- E O F --- 2009-09-10 13:29