ComboFix 09-10-28.08 - j 30/10/2009 15:16.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.246.55 [GMT 0:00]
Running from: c:\documents and settings\j\Desktop\Eatmalware.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Documents\jawyre.bat
c:\documents and settings\j\Application Data\divubod.bat
c:\documents and settings\j\Application Data\patica.bat
c:\documents and settings\j\Cookies\ehexavavo.dl
c:\documents and settings\j\Cookies\itoqoju.lib
c:\documents and settings\j\delself.bat
c:\documents and settings\j\Local Settings\Application Data\urigyfaq.vbs
c:\documents and settings\j\Local Settings\Temporary Internet Files\eredice.exe
c:\documents and settings\j\Local Settings\Temporary Internet Files\idus._sy
c:\documents and settings\j\Local Settings\Temporary Internet Files\nimojubu.pif
c:\documents and settings\j\Local Settings\Temporary Internet Files\nori.bin
c:\documents and settings\j\Local Settings\Temporary Internet Files\qutifyf._dl
c:\documents and settings\j\Local Settings\Temporary Internet Files\tyqyn.inf
c:\documents and settings\j\Local Settings\Temporary Internet Files\xinikar.dat
c:\program files\AVI Codec Pack
c:\program files\AVI Codec Pack\AC3\ac3filter.ax
c:\program files\TinyProxy
c:\recycler\S-1-5-21-1606980848-839522115-725345543-1003
c:\recycler\S-1-5-21-1696900801-673444254-1198706582-1003
c:\recycler\S-1-5-21-2325207520-1955753301-4288126109-1003
c:\recycler\S-1-5-21-3611587196-4038010048-3432065643-1003
c:\recycler\S-1-5-21-3617300515-1142314785-2478053788-1003
c:\recycler\S-1-5-21-72906647-2416302709-964523486-1003
c:\recycler\S-1-5-21-981462108-2766100533-1366851002-1003
c:\windows\a.bat
c:\windows\aqere.scr
c:\windows\base64.tmp
c:\windows\bdn.com
c:\windows\bolivar24.exe
c:\windows\bolivar25.exe
c:\windows\brastk.exe
c:\windows\eciryx.reg
c:\windows\f49f4daa.dat
c:\windows\fmark2.dat
c:\windows\FVProtect.exe
c:\windows\ipuhina.inf
c:\windows\iTunesMusic.exe
c:\windows\karna.dat
c:\windows\mslagent
c:\windows\mslagent\2_mslagent.dll
c:\windows\mslagent\mslagent.exe
c:\windows\mslagent\uninstall.exe
c:\windows\mssecu.exe
c:\windows\ocyliniq.reg
c:\windows\pugiso._sy
c:\windows\system32\akttzn.exe
c:\windows\system32\anticipator.dll
c:\windows\system32\awtoolb.dll
c:\windows\system32\bdn.com
c:\windows\system32\brastk.exe
c:\windows\system32\bsva-egihsg52.exe
c:\windows\system32\dpcproxy.exe
c:\windows\system32\emesx.dll
c:\windows\system32\hoproxy.dll
c:\windows\system32\hxiwlgpm.dat
c:\windows\system32\hxiwlgpm.exe
c:\windows\system32\karna.dat
c:\windows\system32\medup012.dll
c:\windows\system32\medup020.dll
c:\windows\system32\msgp.exe
c:\windows\system32\msnbho.dll
c:\windows\system32\mssecu.exe
c:\windows\system32\MSVolumeAMP.dll
c:\windows\system32\mtr2.exe
c:\windows\system32\mwin32.exe
c:\windows\system32\netode.exe
c:\windows\system32\newsd32.exe
c:\windows\system32\ps1.exe
c:\windows\system32\psoft1.exe
c:\windows\system32\recotiv.vbs
c:\windows\system32\regm64.dll
c:\windows\system32\rosyzod.inf
c:\windows\system32\Rundl1.exe
c:\windows\system32\smp
c:\windows\system32\smp\msrc.exe
c:\windows\system32\ssurf022.dll
c:\windows\system32\ssvchost.exe
c:\windows\system32\sysreq.exe
c:\windows\system32\taack.dat
c:\windows\system32\taack.exe
c:\windows\system32\temp#01.exe
c:\windows\system32\VBIEWER.OCX
c:\windows\system32\vcatchpi.dll
c:\windows\system32\wini104552502.exe
c:\windows\system32\winlogonpc.exe
c:\windows\system32\WINWGPX.EXE
c:\windows\tmark2.dat
c:\windows\tysybacyg._sy
c:\windows\userconfig9x.dll
c:\windows\winsystem.exe
c:\windows\ybaris.bat
c:\windows\ycuxe.inf
c:\windows\yqunylegu.inf
c:\windows\zip1.tmp
c:\windows\zip2.tmp
c:\windows\zip3.tmp
c:\windows\zipped.tmp
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
c:\windows\system32\drivers\beep.sys . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-30 )))))))))))))))))))))))))))))))
.
2009-10-24 02:27 . 2009-10-24 02:27 -------- d-----w- c:\documents and settings\j\Application Data\Malwarebytes
2009-10-24 02:26 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-24 02:26 . 2009-10-24 02:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-24 02:26 . 2009-10-24 02:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-24 02:26 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-24 02:21 . 2009-10-24 02:22 -------- d-----w- c:\program files\Snoop
2009-10-24 02:21 . 2009-10-24 02:21 249856 ------w- c:\windows\Setup1.exe
2009-10-24 02:21 . 2009-10-24 02:21 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-10-24 02:20 . 2009-10-24 02:20 -------- d-----w- c:\program files\Trend Micro
2009-10-23 10:41 . 2009-10-23 10:41 -------- d-----w- c:\documents and settings\All Users\AVP 2009
2009-10-23 10:41 . 2009-10-23 10:42 -------- d-----w- c:\program files\AntiMalware_Pro
2009-10-23 01:07 . 2009-10-23 01:07 -------- d-----w- c:\documents and settings\j\Application Data\AVG8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-29 20:48 . 2007-10-14 00:39 -------- d-----w- c:\program files\uTorrent
2009-10-24 13:33 . 2008-10-03 01:05 -------- d-----w- c:\documents and settings\All Users\Application Data\uhyvalmj
2009-10-23 18:33 . 2007-10-14 00:39 -------- d-----w- c:\documents and settings\j\Application Data\uTorrent
2009-10-23 01:25 . 2008-10-13 19:09 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-23 01:22 . 2005-04-07 13:45 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-08-29 07:36 . 2004-12-30 08:22 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2004-12-30 08:21 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2004-12-30 08:21 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-06 18:24 . 2004-12-30 09:36 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 18:24 . 2004-12-30 09:36 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 18:24 . 2005-05-26 03:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 18:24 . 2005-04-07 18:40 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 18:24 . 2004-12-30 09:36 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 18:24 . 2004-12-30 08:21 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 18:23 . 2004-12-30 09:36 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 18:23 . 2004-12-30 09:36 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2008-11-18 04:05 . 2008-11-18 04:05 12133 -c--a-w- c:\program files\Common Files\uxeleq.sys
2008-11-18 04:05 . 2008-11-18 04:05 13880 -c--a-w- c:\program files\Common Files\suvinur.dat
2008-10-21 11:08 . 2008-10-21 11:08 19303 -c--a-w- c:\program files\Common Files\xabaqe._sy
2008-10-21 11:08 . 2008-10-21 11:08 16315 -c--a-w- c:\program files\Common Files\uqamuvicor.dl
2008-10-21 11:08 . 2008-10-21 11:08 13123 -c--a-w- c:\program files\Common Files\nacasucet.exe
2008-10-21 11:08 . 2008-10-21 11:08 10830 -c--a-w- c:\program files\Common Files\lalasumy.dl
2005-04-26 22:29 . 2005-04-26 22:29 56 -csh--r- c:\windows\system32\F31CC94AA7.sys
2005-04-26 22:29 . 2005-04-26 22:29 1890 -csha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Accessibility"="c:\program files\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-12-07 24576]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-12-27 61440]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"McRegWiz"="c:\progra~1\mcafee.com\agent\mcregwiz.exe" [2003-09-02 135168]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\TOSHIBA\\ConfigFree\\CFXFER.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\sopvod.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9832:TCP"= 9832:TCP:BitComet 9832 TCP
"9832:UDP"= 9832:UDP:BitComet 9832 UDP
"21891:TCP"= 21891:TCP:BitComet 21891 TCP
"21891:UDP"= 21891:UDP:BitComet 21891 UDP
"12114:TCP"= 12114:TCP:BitComet 12114 TCP
"12114:UDP"= 12114:UDP:BitComet 12114 UDP
"12749:TCP"= 12749:TCP:BitComet 12749 TCP
"12749:UDP"= 12749:UDP:BitComet 12749 UDP
S3 Dmuredd;Dmuredd; [x]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local;<local>
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward &Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Si&milar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-XP Antispyware 2009 - c:\program files\XP_Antispyware\XP_Antispyware.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-30 15:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-10-30 15:30
ComboFix-quarantined-files.txt 2009-10-30 15:29
Pre-Run: 2,102,878,208 bytes free
Post-Run: 4,093,988,864 bytes free
- - End Of File - - 1E2C8355361A0CB3CFC85B06493EF4BC