ComboFix 09-11-11.02 - Udeme Ndon 11/11/2009 23:17.1.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.340 [GMT -8:00]
Running from: c:\documents and settings\Udeme Ndon\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\hemodizi.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\iehelper.dll
c:\windows\system32\jajusema.exe
c:\windows\system32\lahesumo.dll
c:\windows\system32\lipoyiya.dll
c:\windows\system32\maguhugi.dll
c:\windows\system32\mikolobe.dll
c:\windows\system32\nahuhiju.dll
c:\windows\system32\nevibuni.dll
c:\windows\system32\nilejonu.dll
c:\windows\system32\nirepuna.dll
c:\windows\system32\nitekufi.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\ribehige.dll
c:\windows\system32\ruliyevi.dll
c:\windows\system32\sizugomu.dll
c:\windows\system32\sozivado.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vejidoyu.dll
c:\windows\system32\WS2Fix.exe
c:\windows\system32\wuholove.exe
C:\ydlcgx.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-12 to 2009-11-12 )))))))))))))))))))))))))))))))
.
2009-11-12 06:20 . 2009-11-12 06:20 -------- d-----w- c:\documents and settings\Udeme Ndon\Local Settings\Application Data\Threat Expert
2009-11-12 01:27 . 2009-11-12 01:27 -------- d-----w- c:\program files\comcasttb
2009-11-11 21:32 . 2009-11-11 21:32 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-11 20:38 . 2009-11-12 01:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-11 20:38 . 2009-11-12 01:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-11 04:01 . 2009-11-11 04:03 -------- d-----w- c:\documents and settings\Udeme Ndon\.SunDownloadManager
2009-11-11 02:21 . 2009-11-11 02:21 -------- d-----w- c:\program files\Trend Micro
2009-11-10 17:43 . 2009-11-10 17:43 0 ----a-w- c:\windows\Afefazalebinuri.bin
2009-11-10 17:43 . 2009-11-11 04:11 120 ----a-w- c:\windows\Vbalayewe.dat
2009-11-10 17:41 . 2009-11-10 17:41 -------- d-----w- c:\documents and settings\Udeme Ndon\Local Settings\Application Data\frglbe
2009-11-10 17:36 . 2009-11-10 17:36 22016 ----a-w- C:\gsho.exe
2009-11-10 17:36 . 2009-11-10 17:36 53248 ----a-w- C:\luobk.exe
2009-10-30 01:37 . 2009-10-30 01:37 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-30 01:37 . 2009-10-31 03:09 -------- d-----w- c:\documents and settings\Udeme Ndon\Application Data\skypePM
2009-10-30 01:21 . 2009-11-12 01:49 -------- d-----w- c:\documents and settings\Udeme Ndon\Application Data\Skype
2009-10-30 01:20 . 2009-10-30 01:20 -------- d-----w- c:\program files\Common Files\Skype
2009-10-30 01:20 . 2009-10-30 01:21 -------- d-----r- c:\program files\Skype
2009-10-30 01:20 . 2009-10-30 01:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-10-29 16:42 . 2009-10-29 16:42 -------- d-----w- c:\program files\Common Files\Software Update Utility
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-12 06:43 . 2009-01-20 08:02 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-12 01:55 . 2009-01-20 08:44 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-11-11 02:26 . 2009-01-20 08:43 -------- d-----w- c:\program files\Lavasoft
2009-11-11 01:51 . 2009-01-20 08:01 -------- d-----w- c:\program files\Common Files\Download Manager
2009-11-11 01:39 . 2008-06-12 00:07 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-11-07 03:31 . 2008-07-14 17:40 -------- d-----w- c:\documents and settings\Udeme Ndon\Application Data\uTorrent
2009-10-29 18:22 . 2008-06-13 07:37 -------- d-----w- c:\program files\Common Files\AOL
2009-10-18 17:37 . 2008-07-20 02:05 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-10-04 02:44 . 2008-08-14 09:42 -------- d-----w- c:\documents and settings\Udeme Ndon\Application Data\LimeWire
2009-09-27 23:43 . 2008-06-13 07:35 -------- d-----w- c:\program files\Yahoo!
2009-09-11 02:03 . 2009-09-11 02:03 98816 ----a-w- c:\documents and settings\Udeme Ndon\Application Data\Sun\Java\Deployment\cache\6.0\30\519a115e-1e32a203-n\WinVideo.dll
2009-09-11 02:03 . 2009-09-11 02:03 74240 ----a-w- c:\documents and settings\Udeme Ndon\Application Data\Sun\Java\Deployment\cache\6.0\51\3e6873f3-1eb47217-n\JINECELP.dll
2009-09-11 02:03 . 2009-09-11 02:03 68608 ----a-w- c:\documents and settings\Udeme Ndon\Application Data\Sun\Java\Deployment\cache\6.0\51\3e6873f3-1eb47217-n\JIWAudio.dll
2009-09-11 02:03 . 2009-09-11 02:03 66048 ----a-w- c:\documents and settings\Udeme Ndon\Application Data\Sun\Java\Deployment\cache\6.0\51\3e6873f3-1eb47217-n\JIWMixer.dll
2009-09-11 02:03 . 2009-09-11 02:03 65536 ----a-w- c:\documents and settings\Udeme Ndon\Application Data\Sun\Java\Deployment\cache\6.0\21\216b13d5-12c978a7-n\ICE_JNIRegistry.dll
2009-09-11 02:03 . 2009-09-11 02:03 60928 ----a-w- c:\documents and settings\Udeme Ndon\Application Data\Sun\Java\Deployment\cache\6.0\21\216b13d5-12c978a7-n\WinPlatform.dll
2009-08-11 05:37 . 2009-08-11 05:37 138240 --sha-w- c:\windows\system32\hefihiru.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-30 57344]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-30 40960]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"SetDefPrt"="c:\program files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-27 49152]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"qalylryf"="c:\documents and settings\Udeme Ndon\Local Settings\Application Data\frglbe\subdsysguard.exe" [2009-11-10 252672]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\QuickTime\\QTTask.exe"=
"c:\\Program Files\\Brother\\Brmfcmon\\BrMfcWnd.exe"=
"c:\\Program Files\\Brother\\ControlCenter3\\BrccMCtl.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\WINDOWS\\system32\\wbem\\unsecapp.exe"=
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/12/2008 11:39 PM 24652]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.comcast.net/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {18F4F4ED-543E-49C9-A54D-4D95522F1E93} = 77.74.48.113
.
- - - - ORPHANS REMOVED - - - -
BHO-{908d7b7d-e923-4913-ba77-334e4f426ff5} - vejidoyu.dll
WebBrowser-{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)
HKLM-Run-zalupehos - c:\windows\system32\lahesumo.dll
HKLM-Run-jinozufadu - nevibuni.dll
SharedTaskScheduler-{9544d431-7ea1-4d6b-a096-c08c8f1381d2} - c:\windows\system32\lahesumo.dll
SSODL-bomopusud-{9544d431-7ea1-4d6b-a096-c08c8f1381d2} - c:\windows\system32\lahesumo.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-11 23:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
Completion time: 2009-11-12 23:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-12 07:35
Pre-Run: 288,647,946,240 bytes free
Post-Run: 288,726,507,520 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 27918B277128FD330C67D930C6173A01