here r the logs of combo fix n HJT .... when i checked my sygate firewall .... 2 new processes have been blocked by the sygate firewall... i wud like to know what they r .... these r the 2 processes which have been blocked :-
"Application Layer GatewayService" residing in c:\windows\system32\alg.exe
"Services and controller app" residing in C:\windows\system32\services.exe
ComboFix 08-07-31.06 - Sreejith 2008-08-01 21:31:43.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.218 [GMT -12:00]
Running from: C:\Documents and Settings\Sreejith\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\FNUEgfii.ini
C:\WINDOWS\system32\FNUEgfii.ini2
C:\WINDOWS\system32\JilVyyay.ini
C:\WINDOWS\system32\JilVyyay.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mnpriaxl.dll
C:\WINDOWS\system32\npxozt.dll
C:\WINDOWS\system32\qoMfGAsq.dll
C:\WINDOWS\system32\qsAGfMoq.ini
C:\WINDOWS\system32\qsAGfMoq.ini2
C:\WINDOWS\system32\tixmntut.ini
C:\WINDOWS\system32\wjchqcvn.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.
2008-08-01 16:07 . 2008-08-01 16:07 <DIR> d-------- C:\Documents and Settings\Sreejith\Application Data\Malwarebytes
2008-08-01 16:07 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-01 16:07 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-01 16:06 . 2008-08-01 16:07 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-01 16:06 . 2008-08-01 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-01 11:43 . 2008-08-01 11:43 577,024 --a------ C:\WINDOWS\system32\dllcache\user32.dll
2008-08-01 11:41 . 2008-08-01 11:42 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-01 11:34 . 2008-08-01 04:33 <DIR> d-------- C:\SDFix
2008-08-01 10:11 . 2008-08-01 10:11 <DIR> d--hs---- C:\FOUND.008
2008-07-30 01:09 . 2008-07-30 01:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-30 00:49 . 2008-07-30 00:49 <DIR> d-------- C:\Program Files\Safer Networking
2008-07-28 01:36 . 2008-07-28 01:36 <DIR> d-------- C:\Program Files\ESET
2008-07-28 00:37 . 2008-07-28 00:37 <DIR> d-------- C:\Documents and Settings\Sreejith\Application Data\ESET
2008-07-28 00:34 . 2008-07-28 00:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-07-27 17:34 . 2008-07-27 17:34 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-27 17:34 . 2008-07-27 17:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-27 17:09 . 2008-07-27 17:09 <DIR> d---s---- C:\Documents and Settings\Sreejith\UserData
2008-07-27 17:01 . 2008-07-27 17:01 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-07-27 02:00 . 2008-07-27 02:00 1,632 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-07-27 00:22 . 2008-07-27 00:22 <DIR> d-------- C:\Program Files\Sygate
2008-07-27 00:22 . 2003-10-14 19:20 77,824 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-07-27 00:22 . 2003-10-14 19:09 55,888 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-07-27 00:22 . 2003-10-14 19:11 18,515 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-07-27 00:22 . 2003-10-14 19:06 11,914 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-07-27 00:10 . 2008-07-27 00:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\sentinel
2008-07-27 00:08 . 2008-07-27 00:08 <DIR> d-------- C:\Program Files\Panda Security
2008-07-26 23:57 . 2008-07-26 23:57 26 --a------ C:\WINDOWS\DGcounter.ini
2008-07-26 23:39 . 2008-07-26 23:39 <DIR> d--hs---- C:\FOUND.007
2008-07-26 19:27 . 2008-07-26 19:27 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 18:39 . 2008-07-26 18:39 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2008-07-26 14:12 . 2008-07-26 14:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-23 22:55 . 2008-07-23 22:55 <DIR> d-------- C:\Program Files\NCH Software
2008-07-23 22:55 . 2008-07-23 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-07-23 22:55 . 2008-07-23 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-07-23 22:54 . 2008-07-23 22:54 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-07-23 22:54 . 2008-07-23 22:54 <DIR> d-------- C:\Documents and Settings\Sreejith\Application Data\NCH Swift Sound
2008-07-23 22:50 . 2008-07-23 22:50 <DIR> d--hs---- C:\FOUND.006
2008-07-22 23:14 . 2008-07-22 23:14 53,248 --a------ C:\WINDOWS\system32\suppdll.dll
2008-07-22 23:14 . 2008-07-22 23:14 35,363 --a------ C:\WINDOWS\system32\windrvNT.sys
2008-07-22 15:48 . 2008-07-22 15:48 <DIR> d-------- C:\Documents and Settings\Sreejith\Contacts
2008-07-22 15:20 . 2008-07-22 15:20 <DIR> d--hs---- C:\FOUND.005
2008-07-21 01:32 . 2008-07-21 01:32 <DIR> d-------- C:\WINDOWS\system32\AppData
2008-07-21 01:31 . 2008-07-21 01:31 <DIR> d-------- C:\Program Files\WinUtilities
2008-07-19 22:42 . 2008-07-19 22:42 <DIR> d--hs---- C:\FOUND.004
2008-07-17 22:22 . 2008-07-17 22:22 <DIR> d--hs---- C:\FOUND.003
2008-07-14 03:08 . 2008-07-26 20:29 268 --ah----- C:\sqmdata19.sqm
2008-07-14 03:08 . 2008-07-26 20:29 244 --ah----- C:\sqmnoopt19.sqm
2008-07-13 23:14 . 2008-07-13 23:14 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-07-13 23:11 . 2008-07-13 23:11 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-07-13 23:11 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-07-06 03:02 . 2008-07-26 15:45 268 --ah----- C:\sqmdata18.sqm
2008-07-06 03:02 . 2008-07-26 15:45 244 --ah----- C:\sqmnoopt18.sqm
2008-07-06 00:10 . 2008-07-26 03:11 268 --ah----- C:\sqmdata17.sqm
2008-07-06 00:10 . 2008-07-26 03:11 244 --ah----- C:\sqmnoopt17.sqm
2008-07-05 01:33 . 2008-07-26 02:18 268 --ah----- C:\sqmdata16.sqm
2008-07-05 01:33 . 2008-07-26 02:18 244 --ah----- C:\sqmnoopt16.sqm
2008-07-02 23:05 . 2008-07-25 23:17 268 --ah----- C:\sqmdata15.sqm
2008-07-02 23:05 . 2008-07-25 23:17 244 --ah----- C:\sqmnoopt15.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-01 21:04 71,688 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-07-01 21:04 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-07-01 21:04 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-07-01 20:57 53,256 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-07-01 20:56 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-06-30 12:26 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\Nokia Multimedia Player
2008-06-30 10:37 --------- d-----w C:\Program Files\IVT Corporation
2008-06-29 16:43 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\ACD Systems
2008-06-29 08:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-06-29 07:44 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-29 07:44 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-06-29 07:01 --------- d-----w C:\Program Files\BitLord
2008-06-29 06:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-06-29 06:25 --------- d-----w C:\Program Files\MSXML 6.0
2008-06-29 06:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-06-29 06:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\U3
2008-06-29 05:56 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\U3
2008-06-29 04:16 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\vlc
2008-06-29 04:15 --------- d-----w C:\Program Files\VideoLAN
2008-06-29 00:53 806 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-29 00:53 8,014 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-29 00:05 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\Datalayer
2008-06-28 23:35 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\AdobeUM
2008-06-28 23:35 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\AdobeAUM
2008-06-28 23:21 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\Nokia
2008-06-28 23:18 --------- d-----w C:\Program Files\DIFX
2008-06-28 23:17 --------- d-----w C:\Program Files\Common Files\Nokia
2008-06-28 23:17 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\PC Suite
2008-06-28 23:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-28 23:16 --------- d-----w C:\Program Files\Nokia
2008-06-28 23:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-06-24 09:56 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-24 09:56 --------- d-----w C:\Program Files\ACD Systems
2008-06-24 09:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-06-24 09:53 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\Ahead
2008-06-24 09:52 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-24 09:52 --------- d-----w C:\Program Files\Ahead
2008-06-24 09:50 --------- d-----w C:\Program Files\Opera
2008-06-24 09:37 --------- d-----w C:\Program Files\MSN Messenger
2008-06-24 09:36 --------- d-----w C:\Program Files\Yahoo!
2008-06-24 09:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-24 09:35 --------- d-----w C:\Program Files\Google
2008-06-24 09:22 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\ArcSoft
2008-06-24 09:20 --------- d-----w C:\Program Files\INITIO
2008-06-24 09:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-24 09:19 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-24 09:19 --------- d-----w C:\Program Files\Common Files\ArcSoft
2008-06-24 09:19 --------- d-----w C:\Program Files\ArcSoft
2008-06-24 08:54 --------- d-----w C:\Program Files\Common Files\HP
2008-06-24 08:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-06-24 08:52 --------- d-----w C:\Program Files\Hewlett-Packard
2008-06-24 08:50 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-06-24 08:47 --------- d-----w C:\Program Files\HP
2008-06-24 08:41 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\HP
2008-06-24 08:29 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-24 08:14 4,608 ----a-w C:\WINDOWS\system32\drivers\symlcbrd.sys
2008-06-24 08:14 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-24 08:14 --------- d-----w C:\Documents and Settings\Sreejith\Application Data\Symantec
2008-06-24 08:05 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-06-24 08:05 --------- d-----w C:\Program Files\Common Files\L&H
2008-06-24 08:04 --------- d-----w C:\Program Files\Microsoft Works
2008-06-24 08:03 --------- d-----w C:\Program Files\Microsoft.NET
2005-05-27 02:35 1,422 ----a-w C:\Program Files\ReadMe.txt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 09:22 3739648]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-08-09 15:41 4617720]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2003-10-21 16:36 2334792]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-07-01 09:01 1447168]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
TotalMedia Backup Monitor.lnk - C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-06-23 21:19:28 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winbi54.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winci16.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windj05.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winfl05.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wingm40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winio38.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winpv73.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winsc63.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winsy51.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winta40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winub40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winvc73.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwe40.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
R3 Start BT in service;Start BT in service;C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-04-21 14:54]
S0 Winbi54;Winbi54;C:\WINDOWS\system32\Drivers\Winbi54.sys []
S0 Winci16;Winci16;C:\WINDOWS\system32\Drivers\Winci16.sys []
S0 Windj05;Windj05;C:\WINDOWS\system32\Drivers\Windj05.sys []
S0 Winfl05;Winfl05;C:\WINDOWS\system32\Drivers\Winfl05.sys []
S0 Wingm40;Wingm40;C:\WINDOWS\system32\Drivers\Wingm40.sys []
S0 Winio38;Winio38;C:\WINDOWS\system32\Drivers\Winio38.sys []
S0 Winpv73;Winpv73;C:\WINDOWS\system32\Drivers\Winpv73.sys []
S0 Winsc63;Winsc63;C:\WINDOWS\system32\Drivers\Winsc63.sys []
S0 Winsy51;Winsy51;C:\WINDOWS\system32\Drivers\Winsy51.sys []
S0 Winta40;Winta40;C:\WINDOWS\system32\Drivers\Winta40.sys []
S0 Winub40;Winub40;C:\WINDOWS\system32\Drivers\Winub40.sys []
S0 Winvc73;Winvc73;C:\WINDOWS\system32\Drivers\Winvc73.sys []
S0 Winwe40;Winwe40;C:\WINDOWS\system32\Drivers\Winwe40.sys []
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 15:17]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 15:17]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a78e90b-4592-11dd-ac78-0080482fc059}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ff18e102-5648-11dd-ac92-00158309cee0}]
\Shell\AutoRun\command - System\DriveGuard\DriveProtect.exe -run*
\Shell\Explore\Command - System\DriveGuard\DriveProtect.exe -run**
\Shell\Open\Command - System\DriveGuard\DriveProtect.exe -run*
.
- - - - ORPHANS REMOVED - - - -
BHO-{00A76A07-7CE8-4033-A6BB-A4AFFC7E8327} - C:\WINDOWS\system32\yayyVliJ.dll
BHO-{C20A5313-F546-4CF6-8249-7F2C170111A4} - C:\WINDOWS\system32\iifgEUNF.dll
MSConfigStartUp-Sys9 - C:\Windows\Sys9.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Sreejith\Application Data\Mozilla\Firefox\Profiles\men0sm26.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-01 21:35:45
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIVTBTSrv.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
.
**************************************************************************
.
Completion time: 2008-08-01 21:37:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-02 09:36:58
Pre-Run: 5,421,678,592 bytes free
Post-Run: 5,372,067,840 bytes free
298
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:07 PM, on 8/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\PC Connectivity Solution\Transports\NclIVTBTSrv.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: TotalMedia Backup Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 4863 bytes