ComboFix 09-01-13.04 - Steph and Pete 2009-01-14 18:38:01.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.404 [GMT 0:00]
Running from: c:\documents and settings\Steph and Pete\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090114-0] *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\_000003_.tmp.dll
c:\windows\system32\_000004_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000025_.tmp.dll
c:\windows\system32\cgrxlysp.ini
c:\windows\system32\fvjmrypf.ini
c:\windows\system32\ififimef.ini
c:\windows\system32\nnnUxyxx.ini
c:\windows\system32\nnnUxyxx.ini2
c:\windows\system32\ohizihug.ini
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://77.74.48.105
.
((((((((((((((((((((((((( Files Created from 2008-12-14 to 2009-01-14 )))))))))))))))))))))))))))))))
.
2009-01-14 18:27 . 2009-01-14 18:27 101,376 --ah----- c:\windows\system32\BIT2.tmp
2009-01-14 18:27 . 2009-01-14 18:27 87,552 --ah----- c:\windows\system32\BIT1.tmp
2009-01-14 18:27 . 2009-01-14 18:27 63,488 --ah----- c:\windows\system32\BIT4.tmp
2009-01-14 18:27 . 2009-01-14 18:27 2,713 ---hs---- c:\windows\system32\savahusu.dll
2009-01-14 18:27 . 2009-01-14 18:27 2,713 ---hs---- c:\windows\system32\hozutoza.dll
2009-01-13 17:49 . 2009-01-13 17:49 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-13 17:49 . 2009-01-04 18:41 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-13 17:49 . 2009-01-04 18:41 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-13 17:39 . 2009-01-13 17:39 2,713 ---hs---- c:\windows\system32\sovetayu.dll
2009-01-13 17:39 . 2009-01-13 17:39 2,713 ---hs---- c:\windows\system32\laninejo.dll
2009-01-13 17:39 . 2009-01-13 17:39 2,713 ---hs---- c:\windows\system32\gukehere.dll
2009-01-12 18:31 . 2009-01-12 18:31 2,713 ---hs---- c:\windows\system32\tovituta.dll
2009-01-12 18:31 . 2009-01-12 18:31 2,713 ---hs---- c:\windows\system32\ratikolo.dll
2009-01-12 18:31 . 2009-01-12 18:31 2,713 ---hs---- c:\windows\system32\fuyizeve.dll
2009-01-11 15:19 . 2009-01-11 15:19 2,713 ---hs---- c:\windows\system32\diwikewo.dll
2009-01-10 06:57 . 2009-01-10 06:57 2,713 ---hs---- c:\windows\system32\raromozo.dll
2009-01-09 17:02 . 2009-01-09 17:02 2,713 ---hs---- c:\windows\system32\ropofotu.dll
2009-01-09 17:02 . 2009-01-09 17:02 2,713 ---hs---- c:\windows\system32\gizoroda.dll
2009-01-07 18:00 . 2009-01-07 18:00 2,713 ---hs---- c:\windows\system32\pipiwuhi.dll
2009-01-06 17:16 . 2009-01-06 17:16 2,713 ---hs---- c:\windows\system32\dileloso.dll
2009-01-05 18:32 . 2009-01-05 18:32 2,713 ---hs---- c:\windows\system32\vozaposo.dll
2009-01-04 17:57 . 2009-01-04 17:57 2,713 ---hs---- c:\windows\system32\vubabuku.dll
2008-12-14 13:17 . 2008-12-14 13:17 <DIR> d-------- c:\program files\iTunes
2008-12-14 13:17 . 2008-12-14 13:17 <DIR> d-------- c:\program files\iPod
2008-12-14 13:17 . 2008-12-14 13:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-14 13:16 . 2008-12-14 13:16 <DIR> d-------- c:\program files\Bonjour
2008-12-14 13:16 . 2008-11-07 14:23 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys
2008-12-14 13:12 . 2008-12-14 13:15 <DIR> d-------- c:\program files\QuickTime
2008-12-14 13:11 . 2008-12-14 13:11 <DIR> d-------- c:\program files\Apple Software Update
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-14 18:43 --------- d-----w c:\documents and settings\Steph and Pete\Application Data\Skype
2009-01-14 18:33 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-14 18:28 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-14 18:26 --------- d-----w c:\documents and settings\Steph and Pete\Application Data\skypePM
2009-01-13 19:36 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-13 18:05 --------- d-----w c:\program files\Spyware Doctor
2009-01-06 19:17 --------- d-----w c:\program files\CCleaner
2008-12-21 06:39 --------- d-----w c:\program files\Yahoo!
2008-12-14 13:12 --------- d-----w c:\program files\Common Files\Apple
2008-12-14 12:34 --------- d-----w c:\program files\Common Files\Logitech
2008-12-14 12:30 --------- d-----w c:\program files\Common Files\Sonic Shared
2008-12-08 18:29 --------- d-----w c:\program files\Java
2008-11-24 18:40 --------- d-----w c:\documents and settings\Steph and Pete\Application Data\PC Tools
2008-11-24 18:40 --------- d-----w c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-11-24 18:35 --------- d-----w c:\program files\Skype
2008-01-19 08:39 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2006-10-25 17:08 278,528 ----a-w c:\program files\Common Files\FDEUnInstaller.exe
2007-06-21 17:38 30,280 ----a-w c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-06-21 17:38 79,432 ----a-w c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-06-21 17:38 71,240 ----a-w c:\program files\mozilla firefox\plugins\confmgr.dll
2007-06-21 17:38 140,872 ----a-w c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-06-21 17:39 38,472 ----a-w c:\program files\mozilla firefox\plugins\icafile.dll
2007-06-21 17:39 46,664 ----a-w c:\program files\mozilla firefox\plugins\icalogon.dll
2006-05-06 16:42 7,260,160 ----a-w c:\program files\mozilla firefox\plugins\libvlc.dll
2007-06-21 17:39 34,376 ----a-w c:\program files\mozilla firefox\plugins\logging.dll
2007-06-21 17:39 685,640 ----a-w c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-06-21 17:40 30,280 ----a-w c:\program files\mozilla firefox\plugins\TcpPServ.dll
2006-07-17 17:24 22 --sha-w c:\windows\SMINST\HPCD.sys
1601-01-01 00:12 65,669 --sha-w c:\windows\system32\hobavana.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-02 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-02 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-02 118784]
"DetectorApp"="c:\program files\Sonic\DigitalMedia Plus v7\MyDVD Plus\DetectorApp.exe" [2005-10-20 102400]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-11 761945]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-11-16 503808]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 405504]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-05-18 233534]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2005-12-28 c:\windows\system32\CHDAudPropShortcut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-08-16 577597]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\windows\system32\lavejipu.dll c:\windows\system32\pasugusa.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-10-18 19:05 204288 c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\Spyware Doctor\\pctsAuxs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-14 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-10-14 20560]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-10-14 356920]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{60334b1e-c874-11dd-9399-0013024233af}]
\Shell\AutoRun\command - F:\DPFMate.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{908bea9a-037d-11dc-8c35-0013024233af}]
\Shell\AutoRun\command - g:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{14b02bc6-ebdb-43c5-a646-45c71235c971} - c:\windows\system32\lutovute.dll
HKLM-Run-sogurupeme - c:\windows\system32\zilozama.dll
Notify-mlJApOIb - mlJApOIb.dll
MSConfigStartUp-sogurupeme - c:\windows\system32\zilozama.dll
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.orange.co.uk/all?brand=ouk&tab=web&p=_adr&q={searchTerms}
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: orange search - file://c:\program files\ORANGE3\Cache\SelectedContextSearch.htm
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Steph and Pete\Application Data\Mozilla\Firefox\Profiles\qofdtp15.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-14 18:56:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????????P??|?????? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Sonic\DigitalMedia Plus v7\MyDVD Plus\USBDeviceService.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-01-14 18:58:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-14 18:58:43
Pre-Run: 56,147,742,720 bytes free
Post-Run: 56,048,328,704 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
221 --- E O F --- 2008-12-18 18:19:16