ComboFix 09-08-22.06 - Owner 23/08/2009 17:30.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.287 [GMT 1:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\info.exe
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000012_.tmp.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\UACkmtnsbavto.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\UACimrdlyouxb.db
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjkjbowmalt.dat
c:\windows\system32\UAClijxvmdxmv.dll
c:\windows\system32\UACmfuwulrqjd.dll
c:\windows\system32\UACnvogomykhe.dll
c:\windows\system32\UACrkcqkqoygl.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
D:\AUTORUN.INF
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-07-23 to 2009-08-23 )))))))))))))))))))))))))))))))
.
2009-08-23 13:08 . 2009-08-23 13:09 -------- d-----w- c:\program files\trend micro
2009-08-23 13:08 . 2009-08-23 13:09 -------- d-----w- C:\rsit
2009-08-22 13:52 . 2009-08-22 14:03 -------- d-----w- c:\program files\Enigma Software Group
2009-08-20 22:26 . 2009-08-20 22:26 194064 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-20 22:02 . 2009-08-20 22:02 -------- d-----w- c:\program files\Uniblue
2009-08-20 21:52 . 2009-08-20 21:52 -------- d-----w- c:\program files\Virgin Broadband
2009-08-20 21:06 . 2009-08-20 21:06 -------- d-----w- C:\VundoFix Backups
2009-08-20 17:23 . 2009-08-20 17:23 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-13 12:41 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-27 12:43 . 2009-08-23 17:43 -------- d-----w- c:\documents and settings\Owner\Application Data\WTablet
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-23 15:03 . 2007-07-04 22:34 -------- d-----w- c:\program files\mIRC
2009-08-23 14:56 . 2009-04-14 00:11 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-23 13:25 . 2007-12-22 16:52 -------- d-----w- c:\program files\BitLord
2009-08-20 22:03 . 2008-04-15 12:30 -------- d-----w- c:\documents and settings\Owner\Application Data\Uniblue
2009-08-20 21:58 . 2009-04-14 00:11 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-17 22:40 . 2009-07-16 18:19 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype
2009-08-17 22:17 . 2009-07-16 18:23 -------- d-----w- c:\documents and settings\Owner\Application Data\skypePM
2009-08-05 18:24 . 2009-04-03 10:14 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-05 09:01 . 2002-06-27 20:29 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-27 12:43 . 2009-07-27 12:42 -------- d-----w- c:\program files\Tablet
2009-07-17 19:01 . 2002-06-27 20:27 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 18:24 . 2009-07-16 18:24 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-07-16 18:17 . 2009-07-16 18:17 -------- d-----w- c:\program files\Common Files\Skype
2009-07-16 18:16 . 2009-07-16 18:16 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Skype
2009-07-13 22:43 . 2007-07-03 23:22 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2002-05-08 22:43 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-07-10 23:35 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2002-06-27 20:28 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2002-06-27 20:30 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-06-27 20:30 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-06-27 20:30 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-06-27 20:29 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2002-06-27 20:28 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2002-05-08 22:43 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-24 11:18 . 2002-05-08 22:43 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2002-06-27 20:30 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2002-06-27 20:28 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2002-05-08 22:43 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2002-06-27 20:27 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 08:19 . 2002-06-27 20:29 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2002-06-27 20:30 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2002-06-27 20:29 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-02 01:23 . 2009-05-02 01:23 113504 ----a-w- c:\program files\mozilla firefox\components\FFConnectorLauncher.dll
2009-05-02 01:23 . 2009-05-02 01:23 232288 ----a-w- c:\program files\mozilla firefox\components\FFSource.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-22 155648]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"wltray.exe"="c:\windows\system32\wltray.exe" [2005-01-29 696422]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2009-05-27 2303216]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Suite"="regedit -s" [X]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
hp center.lnk - c:\program files\hp center\137903\Program\BackWeb-137903.exe [2002-5-21 16384]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ 'autocheck autochk *'
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BT Broadband Desktop Help.lnk]
backup=c:\windows\pss\BT Broadband Desktop Help.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\IObit\\Advanced SystemCare 3\\AWC.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Avira\\AntiVir Desktop\\avcenter.exe"=
"c:\\Program Files\\XP TCPIP Repair\\netrepair.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\Haroon & Musawir\\Musawir\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [03/04/2009 11:14 108289]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [27/07/2009 13:42 3032360]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [27/07/2009 13:42 15144]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local;localhost
uInternet Settings,ProxyServer = 127.0.0.1:81
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} - hxxp://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
FF - ProfilePath - c:\docume~1\Owner\APPLIC~1\Mozilla\Firefox\Profiles\0qr0oo5m.default\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0qr0oo5m.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\program files\Mozilla Firefox\components\FFConnectorLauncher.dll
FF - component: c:\program files\Mozilla Firefox\components\FFSource.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0qr0oo5m.default\extensions\flashplugin@idm\platform\WINNT\plugins\npidmdcp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\nppdf32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Virgin Broadband\advisor\nprpspa.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-23 18:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(2128)
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\docume~1\Owner\LOCALS~1\Temp\IadHide3.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wltrysvc.exe
c:\windows\system32\bcmwltry.exe
c:\program files\Virgin Broadband Wireless\AffinegyService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-08-23 18:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-23 17:53
Pre-Run: 42,056,515,584 bytes free
Post-Run: 42,085,871,616 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
216 --- E O F --- 2009-08-22 13:10