ComboFix 10-08-15.01 - Waqar 08/16/2010 0:52.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.358 [GMT -4:00]
Running from: c:\documents and settings\Waqar\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Update\seupd.exe
c:\documents and settings\LocalService\Application Data\Sky-Banners
c:\documents and settings\LocalService\Application Data\Street-Ads
c:\documents and settings\Waqar\Application Data\5E184C8E1602A42187F2A0BF820911F1
c:\documents and settings\Waqar\Application Data\5E184C8E1602A42187F2A0BF820911F1\enemies-names.txt
c:\documents and settings\Waqar\Application Data\5E184C8E1602A42187F2A0BF820911F1\local.ini
c:\documents and settings\Waqar\Application Data\5E184C8E1602A42187F2A0BF820911F1\lsrslt.ini
c:\documents and settings\Waqar\Application Data\Luuds
c:\documents and settings\Waqar\Application Data\Luuds\kuet.exe
c:\documents and settings\Waqar\Application Data\Sky-Banners
c:\documents and settings\Waqar\Application Data\Street-Ads
c:\documents and settings\Waqar\Start Menu\Programs\Antimalware Doctor
c:\documents and settings\Waqar\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
c:\documents and settings\Waqar\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
c:\program files\Mozilla Firefox\searchplugins\google_search.xml
c:\windows\$NtUninstallMTF1011$
c:\windows\$NtUninstallMTF1011$\apUninstall.exe
c:\windows\$NtUninstallMTF1011$\zrpt.xml
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\ilavesaz.dll
c:\windows\kbdbgsi.dll
c:\windows\system32\drivers\ndisrd.sys
c:\windows\system32\drivers\srenum.sys
c:\windows\system32\msrun.exe
c:\windows\system32\qiwgp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_ATAPIDRV
-------\Service_ndisrd
-------\Legacy_srenum
-------\Service_srenum
((((((((((((((((((((((((( Files Created from 2010-07-16 to 2010-08-16 )))))))))))))))))))))))))))))))
.
2010-08-13 22:51 . 2010-08-13 22:51 -------- d-----w- c:\documents and settings\Waqar\Application Data\BitComet
2010-08-11 21:47 . 2010-08-11 21:47 6656 ----a-w- c:\windows\system32\3B38C503.exe
2010-08-08 22:18 . 2010-08-08 22:18 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2010-08-08 22:18 . 2010-08-08 22:18 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\AIM Toolbar
2010-08-08 22:18 . 2010-08-09 21:57 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\dsitjkcbc
2010-08-07 23:23 . 2010-08-15 20:15 27591840 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\msgup1000_1270_us_u2.exe
2010-08-01 04:59 . 2010-08-01 04:59 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-07-28 00:15 . 2010-07-28 00:15 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-07-26 23:28 . 2010-07-26 23:28 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-26 21:27 . 2010-07-26 21:27 -------- d-----w- c:\documents and settings\Waqar\Application Data\Malwarebytes
2010-07-26 21:26 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-26 21:26 . 2010-07-26 21:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-26 21:26 . 2010-07-26 21:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-26 21:26 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-26 21:08 . 2010-07-26 21:31 -------- d-----w- c:\documents and settings\Waqar\Local Settings\Application Data\exbnwpfwf
2010-07-26 21:08 . 2010-07-26 21:08 -------- d-----w- c:\documents and settings\Waqar\Local Settings\Application Data\{116E1CDE-1499-4068-BEE3-3C0DB2E07A0D}
2010-07-26 21:06 . 2010-07-26 21:31 -------- d-----w- c:\documents and settings\Waqar\Local Settings\Application Data\gygbthdjk
2010-07-26 21:06 . 2010-08-16 04:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Update
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 04:51 . 2009-07-17 22:14 -------- d-----w- c:\program files\BitComet
2010-08-12 09:22 . 2006-02-28 12:00 37248 ----a-w- c:\windows\system32\drivers\isapnp.sys
2010-08-12 02:25 . 2009-10-27 00:12 -------- d-----w- c:\documents and settings\Waqar\Application Data\Oply
2010-07-01 01:58 . 2010-07-01 01:57 -------- d-----w- c:\program files\iTunes
2010-07-01 01:58 . 2010-07-01 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-01 01:57 . 2010-07-01 01:57 -------- d-----w- c:\program files\iPod
2010-07-01 01:57 . 2009-07-17 03:57 -------- d-----w- c:\program files\Common Files\Apple
2010-07-01 01:54 . 2010-01-03 02:52 -------- d-----w- c:\program files\QuickTime
2010-07-01 01:51 . 2010-07-01 01:51 -------- d-----w- c:\program files\Bonjour
2010-07-01 01:45 . 2010-07-01 01:45 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-30 12:31 . 2006-02-28 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2006-02-28 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2006-02-28 12:00 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2006-02-28 12:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2006-02-28 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-07-17 02:33 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2006-02-28 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-05-22 19:35 . 2010-05-22 19:35 503808 ----a-w- c:\documents and settings\Waqar\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-7424c877-n\msvcp71.dll
2010-05-22 19:35 . 2010-05-22 19:35 499712 ----a-w- c:\documents and settings\Waqar\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-7424c877-n\jmc.dll
2010-05-22 19:35 . 2010-05-22 19:35 348160 ----a-w- c:\documents and settings\Waqar\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-7424c877-n\msvcr71.dll
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-04-07 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-04-07 114688]
"AGRSMMSG"="AGRSMMSG.exe" [2003-05-23 88363]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-26 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-29 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26439:TCP"= 26439:TCP:BitComet 26439 TCP
"26439:UDP"= 26439:UDP:BitComet 26439 UDP
S3 3B38C503;3B38C503;c:\windows\system32\3B38C503.exe [8/11/2010 5:47 PM 6656]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:6522
FF - ProfilePath - c:\documents and settings\Waqar\Application Data\Mozilla\Firefox\Profiles\orf8mrek.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.google.com
FF - prefs.js: keyword.URL - hxxp://search.search-star.net/?sid=10101046100&s=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\Waqar\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npWebLaunch.dll
FF - plugin: c:\program files\thriXXX\WebLaunch\Binaries\npWebLaunch.dll
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BitComet - c:\program files\BitComet\BitComet.exe
HKCU-Run-{3E22F618-7EBF-DAD1-F566-648CEB8CC750} - c:\documents and settings\Waqar\Application Data\Luuds\kuet.exe
HKLM-Run-sta - uiwgp.dll
HKU-Default-Run-Udusis - c:\windows\kbdbgsi.dll
SafeBoot-klmdb.sys
AddRemove-$NtUninstallMTF1011$ - c:\windows\$NtUninstallMTF1011$\apUninstall.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3592)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\AGRSMMSG.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2010-08-16 01:08:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-16 05:08
Pre-Run: 140,500,664,320 bytes free
Post-Run: 143,118,917,632 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - D67879B736817A88F5C651F622D7682C