ComboFix 10-01-04.01 - Shane 01/08/2010 13:48:35.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1015.757 [GMT -7:00]
Running from: e:\new folder\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Shane\Local Settings\Application Data\ehocmf
c:\documents and settings\Shane\Local Settings\Application Data\ehocmf\xgfasysguard.exe
c:\documents and settings\Shane\Local Settings\Application Data\xvellx
c:\documents and settings\Shane\Local Settings\Application Data\xvellx\xxacsysguard.exe
c:\program files\Common Files\Uninstall
c:\windows\system32\config\systemprofile\Templates\info.tmp
c:\windows\system32\drivers\H8SRTnkvrsoucvy.sys
c:\windows\system32\drivers\ndisrd.sys
c:\windows\system32\dzwbgch3y.dll
c:\windows\system32\H8SRTmxfuwprrtq.dll
c:\windows\system32\H8SRTpfpvtowuje.dat
c:\windows\system32\H8SRTvyftiuoqcm.dll
c:\windows\system32\H8SRTyxwilxrujk.dll
c:\windows\system32\kbdsock.dll
c:\windows\system32\mshlps.dll
c:\windows\system32\ndisapi.dll
c:\windows\system32\srcr.dat
c:\windows\Temp\157d9bf1.exe
c:\windows\Temp\5bc83b60.exe
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_H8SRTd.sys
-------\Legacy_NDISRD
-------\Service_H8SRTd.sys
-------\Service_NDISRD
((((((((((((((((((((((((( Files Created from 2009-12-08 to 2010-01-08 )))))))))))))))))))))))))))))))
.
2010-01-08 19:53 . 2010-01-08 19:53 44544 ----a-w- C:\afburr.exe
2010-01-08 19:53 . 2010-01-08 19:53 29695 ----a-w- C:\khkil.exe
2010-01-08 19:53 . 2010-01-08 19:53 242688 ----a-w- C:\qfhtgw.exe
2010-01-08 19:53 . 2010-01-08 19:53 52224 ----a-w- C:\eujbmv.exe
2010-01-08 19:53 . 2010-01-08 19:53 27136 ----a-w- C:\jdmhvwpg.exe
2010-01-08 19:53 . 2010-01-08 19:53 22016 ----a-w- C:\vwylecru.exe
2010-01-08 18:06 . 2010-01-08 18:06 -------- d-----w- c:\program files\TrendMicro
2010-01-08 15:37 . 2010-01-07 23:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 15:37 . 2010-01-08 15:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-08 15:37 . 2010-01-07 23:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-08 02:54 . 2010-01-08 02:54 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-08 02:48 . 2010-01-08 15:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-01-08 02:48 . 2010-01-08 02:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-08 02:48 . 2010-01-08 02:48 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-08 02:25 . 2010-01-08 02:25 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2010-01-08 02:23 . 2010-01-08 02:23 -------- d-----w- c:\program files\Common Files\iS3
2010-01-08 02:23 . 2010-01-08 15:11 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-01-08 02:00 . 2010-01-08 02:00 -------- d-----w- c:\documents and settings\Shane\Local Settings\Application Data\Threat Expert
2010-01-08 01:52 . 2010-01-08 20:41 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-07 23:57 . 2010-01-08 02:27 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\bpdiqc
2010-01-07 23:56 . 2010-01-08 02:27 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\drgyat
2010-01-04 01:17 . 2010-01-08 01:16 857 ----a-w- c:\windows\system32\krl32mainweq.dll
2010-01-04 01:14 . 2010-01-04 01:14 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2010-01-03 15:38 . 2010-01-03 15:38 -------- d-----w- c:\program files\Enigma Software Group
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-08 18:06 . 2010-01-08 18:06 388096 ----a-r- c:\documents and settings\Shane\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-08 00:13 . 2008-08-27 17:38 20292 ----a-w- c:\documents and settings\Shane\Application Data\wklnhst.dat
2010-01-07 22:55 . 2008-09-08 03:56 -------- d-----w- c:\program files\Incomplete
2010-01-07 22:55 . 2008-09-08 03:47 -------- d-----w- c:\program files\K-Lite Pro
2010-01-07 19:11 . 2007-03-26 13:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-07 19:11 . 2010-01-07 19:11 12840432 ----a-w- c:\documents and settings\All Users\Application Data\Google Updater\cache\packdata_ci_earth_5.1.3533.1731_en_setup.exe
2010-01-03 16:04 . 2006-11-29 20:14 85592 -c--a-w- c:\documents and settings\Shane\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-01 21:32 . 2008-09-08 03:49 -------- d-----w- c:\documents and settings\Shane\Application Data\FileVOoM
2009-12-17 16:38 . 2006-12-21 03:06 -------- d-----w- c:\program files\Dl_cats
2009-12-10 17:20 . 2008-08-27 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-29 07:46 . 2004-08-10 18:51 832512 ----a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2004-08-10 18:51 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2004-08-10 18:50 17408 ----a-w- c:\windows\system32\corpol.dll
2009-10-21 06:00 . 2004-08-10 18:51 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2004-08-10 18:51 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-04 05:00 263552 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:53 . 2004-08-10 18:51 266752 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2004-08-10 18:51 69632 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2004-08-10 18:51 112128 ----a-w- c:\windows\system32\rastls.dll
2009-07-18 18:19 . 2006-12-06 05:24 88 --sh--r- c:\windows\system32\8EC486DAE2.sys
2009-07-18 18:19 . 2006-12-06 05:24 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-09 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 282624]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-15 257088]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-20 24576]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\K-Lite Pro\\K-Lite.exe"=
"c:\\Program Files\\K-Lite Pro\\IeEmbed.exe"=
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [11/20/2006 5:04 PM 30192]
.
Contents of the 'Scheduled Tasks' folder
2010-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 22:42]
2010-01-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-03-26 03:46]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {705EC6D4-B138-4079-A307-EF13E4889A82} - hxxps://tsslvpn.terracon.com/CACHE/sdesktop/install/binaries/instweb.cab
.
- - - - ORPHANS REMOVED - - - -
Notify-TPSvc - TPSvc.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-08 13:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(3500)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\stsystra.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-08 14:01:38 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-08 21:01
Pre-Run: 38,256,463,872 bytes free
Post-Run: 38,881,087,488 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - D1BEF94720290FF774204D4B038FB797
Anything else that I need to do? Is there anything you see on my computer that may have caused these problems?
Thanks