Blade,
Successfully ran ComboFix, plus ran DDS, as requested. Please see below and attached.
ComboFix 09-10-28.08 - Administrator 10/31/2009 10:33.5.1 - NTFSx86
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\ficaqamati.exe
c:\documents and settings\Administrator\Application Data\joliw.lib
c:\documents and settings\Administrator\Application Data\lizkavd.exe
c:\documents and settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Administrator\Application Data\notisyc.dll
c:\documents and settings\Administrator\Application Data\udeqymof.vbs
c:\documents and settings\Administrator\Application Data\umyvata.sys
c:\documents and settings\Administrator\Desktop\AntivirusPro_2010.lnk
c:\documents and settings\Administrator\Desktop\Windows Police Pro.lnk
c:\documents and settings\Administrator\Local Settings\Application Data\heji.dl
c:\documents and settings\Administrator\Local Settings\Application Data\tanur.pif
c:\documents and settings\Administrator\Local Settings\Application Data\xihohike.inf
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\alanutala.reg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\duhasy.com
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\pobu.dat
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\wapucabaqa.lib
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\wicase.scr
c:\documents and settings\Administrator\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Administrator\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Administrator\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Security Tool.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Windows Police Pro
c:\documents and settings\Administrator\Start Menu\Programs\Windows Police Pro\Windows Police Pro.lnk
c:\documents and settings\All Users\Application Data\mejywa.bin
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\vyqax.lib
c:\documents and settings\All Users\Documents\qywerige.pif
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\AntivirusPro_2010\Uninstall.exe
c:\program files\AntivirusPro_2010\wscui.cpl
c:\program files\Common Files\byjun.pif
c:\program files\Common Files\cimo.scr
c:\program files\Common Files\fuqyfawyg.inf
c:\program files\Common Files\uravulega.pif
c:\program files\Common Files\uzowo.exe
c:\program files\Common Files\yrosif.scr
c:\windows\alejo.inf
c:\windows\aqunu.scr
c:\windows\bexajy.bat
c:\windows\emevumejabi.dll
c:\windows\idymiwav.exe
c:\windows\lovacavezu.bin
c:\windows\msa.exe
c:\windows\qamuzivisu.dl
c:\windows\system32\_scui.cpl
c:\windows\system32\~.exe
c:\windows\system32\18467.exe
c:\windows\system32\AVR09.exe
c:\windows\system32\buju.reg
c:\windows\system32\certstore.dat
c:\windows\system32\dipamola.dll
c:\windows\system32\FInstall.sys
c:\windows\system32\gimujewa.dll
c:\windows\system32\hahohetu.dll
c:\windows\system32\Install.txt
c:\windows\system32\isapeep.sys
c:\windows\system32\lupujuye.dll
c:\windows\system32\mibuviza.dll
c:\windows\system32\moluvedu.dll
c:\windows\system32\nosunilo.dll
c:\windows\system32\novomuzi.dll
c:\windows\system32\nuar.old
c:\windows\system32\papehehi.dll
c:\windows\system32\pofoyoru.dll
c:\windows\system32\qydewofo.pif
c:\windows\system32\rawijihe.dll
c:\windows\system32\rekomuzu.dll
c:\windows\system32\rohuzeta.dll
c:\windows\system32\schtml
c:\windows\system32\schtml\images\i1.gif
c:\windows\system32\schtml\images\i2.gif
c:\windows\system32\schtml\images\i3.gif
c:\windows\system32\schtml\images\j1.gif
c:\windows\system32\schtml\images\j2.gif
c:\windows\system32\schtml\images\j3.gif
c:\windows\system32\schtml\images\jj1.gif
c:\windows\system32\schtml\images\jj2.gif
c:\windows\system32\schtml\images\jj3.gif
c:\windows\system32\schtml\images\l1.gif
c:\windows\system32\schtml\images\l2.gif
c:\windows\system32\schtml\images\l3.gif
c:\windows\system32\schtml\images\pix.gif
c:\windows\system32\schtml\images\t1.gif
c:\windows\system32\schtml\images\t2.gif
c:\windows\system32\schtml\images\up1.gif
c:\windows\system32\schtml\images\up2.gif
c:\windows\system32\schtml\images\w1.gif
c:\windows\system32\schtml\images\w11.gif
c:\windows\system32\schtml\images\w2.gif
c:\windows\system32\schtml\images\w3.gif
c:\windows\system32\schtml\images\w3.jpg
c:\windows\system32\schtml\images\word.doc
c:\windows\system32\schtml\images\wt1.gif
c:\windows\system32\schtml\images\wt2.gif
c:\windows\system32\schtml\images\wt3.gif
c:\windows\system32\schtml\wispex.html
c:\windows\system32\skynet.dat
c:\windows\system32\sodolevu.dll
c:\windows\system32\tagiboja.dll
c:\windows\system32\tisitora.exe
c:\windows\system32\uvupypon.dl
c:\windows\system32\vizadapa.dll
c:\windows\system32\vudoyabi.dll
c:\windows\system32\winhelper.dll
c:\windows\system32\xafi.pif
c:\windows\system32\zagebare.dll
c:\windows\TEMP\mta13187.dll
c:\windows\toxenoger.bin
----- BITS: Possible infected sites -----
hxxp://82.98.235.208
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Service_6to4
-------\Legacy_isapeep
-------\Service_isapeep
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-31 )))))))))))))))))))))))))))))))
.
2009-10-30 11:30 . 2009-10-30 11:30 16845 ----a-w- c:\windows\system32\inezohal.dat
2009-10-30 11:11 . 2009-10-31 13:04 0 ----a-r- c:\windows\win32k.sys
2009-10-23 04:35 . 2009-10-23 04:35 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2009-10-23 04:35 . 2009-10-23 04:35 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-10-21 12:18 . 2009-10-21 12:18 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\{1483BFAC-5771-4FE5-9714-6F79C3F44B6A}
2009-10-18 06:11 . 2009-10-23 08:35 -------- d-----w- c:\documents and settings\All Users\Application Data\62382930
2009-10-17 20:09 . 2009-10-17 20:09 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-10-17 18:30 . 2009-10-17 18:30 10362 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\lasale.dat
2009-10-17 18:30 . 2009-10-17 18:30 16529 ----a-w- c:\windows\udicolype.dat
2009-10-17 18:16 . 2009-10-17 21:01 58 ----a-w- c:\windows\wp4.dat
2009-10-17 18:16 . 2009-10-17 21:01 2 ----a-w- c:\windows\wp3.dat
2009-10-17 18:15 . 2009-10-31 05:25 0 ----a-r- c:\windows\Iguqevo.bin
2009-10-17 18:14 . 2009-10-31 05:25 120 ----a-w- c:\windows\Wzuxujika.dat
2009-10-17 18:12 . 2009-10-17 21:02 -------- d-----w- c:\documents and settings\All Users\Application Data\72487533
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-30 15:31 . 2009-05-27 15:30 -------- d-----w- c:\program files\McAfee
2009-10-30 11:30 . 2009-10-30 11:30 16718 ----a-w- c:\program files\Common Files\ohykotide.lib
2009-10-25 22:45 . 2009-02-23 00:49 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-10-17 18:30 . 2009-10-17 18:30 13165 ----a-w- c:\documents and settings\All Users\Application Data\wuqysuqoc.dat
2009-10-15 23:33 . 2009-03-01 05:39 -------- d-----w- c:\program files\Java
2009-09-24 07:08 . 2009-01-30 14:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-24 02:15 . 2009-02-23 02:28 -------- d-----w- c:\program files\FLAC
2009-09-24 01:57 . 2009-02-23 02:12 -------- d--h--w- c:\program files\Creative Installation Information
2009-09-24 01:56 . 2009-02-22 22:39 -------- d-----w- c:\program files\Creative
2009-09-24 01:15 . 2009-02-23 02:16 -------- d-----w- c:\program files\Audible
2009-09-22 04:28 . 2009-09-12 23:01 -------- d-----w- c:\program files\Runtime Software
2009-09-22 02:21 . 2009-02-23 01:40 -------- d-----w- c:\program files\BitTornado
2009-09-20 04:50 . 2009-09-20 04:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-09-20 04:49 . 2009-09-20 04:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-20 04:49 . 2009-09-20 04:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-20 03:07 . 2009-01-29 22:22 26352 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-18 01:56 . 2009-02-22 21:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-09-16 14:22 . 2009-05-27 16:12 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 14:22 . 2009-05-27 16:12 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 14:22 . 2009-05-27 16:12 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 14:22 . 2009-03-25 15:06 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 14:22 . 2009-05-27 15:12 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-12 22:13 . 2009-09-11 03:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-11 14:33 . 2004-08-04 12:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 10:21 . 2009-09-11 03:29 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-11 01:25 . 2009-09-11 01:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-11 01:15 . 2009-09-11 01:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-11 01:13 . 2009-09-11 01:13 -------- d-----w- c:\program files\Lavasoft
2009-09-10 18:54 . 2009-09-20 04:49 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-09-20 04:49 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 04:35 . 2009-09-09 04:35 -------- d-----w- c:\documents and settings\Administrator\Application Data\McAfee
2009-09-09 03:40 . 2009-02-21 22:02 79270 ----a-w- c:\windows\hpfins05.dat
2009-09-04 20:45 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-26 08:16 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-22 19:50 . 2009-02-21 22:01 47648 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-06 23:24 . 2009-01-29 22:23 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2009-01-29 22:23 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2009-01-29 22:23 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2008-10-16 19:09 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2009-01-29 22:23 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2009-01-29 22:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2009-01-29 22:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:11 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 14:00 . 2004-08-04 12:00 2180352 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 13:13 . 2004-08-03 22:59 2057728 ------w- c:\windows\system32\ntkrnlpa.exe
2009-07-20 15:32 . 2009-07-20 15:32 27136 --sha-w- c:\windows\system32\diyobela.exe
2009-07-28 21:38 . 2009-07-28 21:38 91648 --sha-w- c:\windows\system32\gisitiwi.dll
2009-07-26 21:38 . 2009-07-26 21:38 39424 --sha-w- c:\windows\system32\gobekiyo.dll
2009-07-26 21:38 . 2009-07-26 21:38 53248 --sha-w- c:\windows\system32\henivihe.dll
2009-07-27 21:38 . 2009-07-27 21:38 91136 --sha-w- c:\windows\system32\huwulita.dll
2009-07-27 09:37 . 2009-07-27 09:37 39424 --sha-w- c:\windows\system32\jisiponu.dll
2009-07-30 09:39 . 2009-07-30 09:39 92160 --sha-w- c:\windows\system32\jitajavo.dll
2009-07-29 21:39 . 2009-07-29 21:39 39424 --sha-w- c:\windows\system32\kesowojo.dll
2009-07-31 09:39 . 2009-07-31 09:39 39424 --sha-w- c:\windows\system32\luruvube.dll
2009-07-30 21:39 . 2009-07-30 21:39 92160 --sha-w- c:\windows\system32\matodife.dll
2009-07-27 21:38 . 2009-07-27 21:38 39424 --sha-w- c:\windows\system32\mejiyuwo.dll
2009-07-30 21:39 . 2009-07-30 21:39 39424 --sha-w- c:\windows\system32\nowowise.dll
2009-07-29 21:39 . 2009-07-29 21:39 91648 --sha-w- c:\windows\system32\palimode.dll
2009-07-28 09:38 . 2009-07-28 09:38 91648 --sha-w- c:\windows\system32\siteleki.dll
2009-07-29 09:39 . 2009-07-29 09:39 39424 --sha-w- c:\windows\system32\sokajuji.dll
2009-07-30 09:39 . 2009-07-30 09:39 39424 --sha-w- c:\windows\system32\sufiluba.dll
2009-07-28 21:38 . 2009-07-28 21:38 39424 --sha-w- c:\windows\system32\tizuguve.dll
2009-07-26 21:39 . 2009-07-26 21:39 53248 --sha-w- c:\windows\system32\vuzolike.dll
2009-07-17 18:11 . 2009-07-17 18:11 24576 --sha-w- c:\windows\system32\yukeheja.exe
.
------- Sigcheck -------
[-] 2008-04-14 10:42 . C7E39EA41233E9F5B86C8DA3A9F1E4A8 . 52224 . . [9.0.1.56] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[-] 2008-04-14 10:42 . C7E39EA41233E9F5B86C8DA3A9F1E4A8 . 52224 . . [9.0.1.56] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\mspmsnsv.dll
[-] 2006-10-19 01:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-10-19 01:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll
[7] 2004-08-04 12:00 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\ERDNT\cache\mspmsnsv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46cc19ee-a635-4dd9-992a-b5a3c8b7baec}]
2009-07-26 21:39 53248 --sha-w- c:\windows\system32\vuzolike.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-09-01 1200178]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 217194]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-12 73728]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\McAfee\\MSC\\mcupdui.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcvsshld.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpprop.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Product Assistant\\bin\\hprblog.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcvsmap.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
"c:\\Program Files\\McAfee\\MSC\\mcupdmgr.exe"=
"c:\\Program Files\\Creative\\Sync Manager Unicode\\CTSyncU.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcods.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9/10/2009 9:26 PM 64160]
R2 BtwSrv;BtwSrv;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 8:00 AM 14336]
R2 fastnetsrv;fastnetsrv Service;c:\windows\system32\FastNetSrv.exe [8/4/2004 8:00 AM 47616]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 AM 1028432]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [5/27/2009 12:17 PM 210216]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - BTWSRV
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*NewlyCreated* - PCIIDEX_2
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
*Deregistered* - PCIIDEX_2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
BtwSrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-10-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 01:25]
2009-10-31 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-05-27 16:22]
2009-10-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-05-27 16:22]
2009-10-31 c:\windows\Tasks\User_Feed_Synchronization-{1D897C43-4A84-463F-8FB7-F37BCDD2F837}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
HKLM-Run-naduvajab - c:\windows\system32\papehehi.dll
HKLM-Run-Kpoza - c:\windows\emevumejabi.dll
HKLM-Run-fosotafupo - nosunilo.dll
HKU-Default-Run-Advanced Virus Remover - c:\program files\AdvancedVirusRemover\PAVRM.exe
SharedTaskScheduler-{aeaaae86-dfcb-4e3b-ab3b-5b7b28f37f91} - c:\windows\system32\papehehi.dll
SSODL-tuwaniyuf-{4fc09871-9969-47d1-a233-7f6da2f2bc4d} - (no file)
SSODL-vafeyivul-{eecb14b5-793c-4d6e-8a1b-1b92c0e98a68} - (no file)
SSODL-liputesip-{aeaaae86-dfcb-4e3b-ab3b-5b7b28f37f91} - c:\windows\system32\papehehi.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-31 10:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\BtwSrv.dllx 46592 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2588)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\msi.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\CTsvcCDA.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\opeia.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\system32\HPZipm12.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\system32\lsm32.sys
.
**************************************************************************
.
Completion time: 2009-10-31 11:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-31 15:13
Pre-Run: 134,868,992 bytes free
Post-Run: 134,279,168 bytes free
Current=5 Default=5 Failed=2 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - A0746BADA7A7DC0852A32B4767138310
DDS log below:DDS (Ver_09-10-13.01) - NTFSx86
Run by Administrator at 14:06:46.65 on Sat 10/31/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.225 [GMT -4:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\opeia.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\FastNetSrv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\lsm32.sys
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: {46cc19ee-a635-4dd9-992a-b5a3c8b7baec} - vuzolike.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [InCD] c:\program files\ahead\incd\InCD.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238636355359
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxsrvc.dll
AppInit_DLLs: rawijihe.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Notification Packages = scecli nosunilo.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-9-10 64160]
R2 BtwSrv;BtwSrv;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
R2 fastnetsrv;fastnetsrv Service;c:\windows\system32\FastNetSrv.exe [2004-8-4 47616]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1028432]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-5-27 210216]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
S2 0234961257011555mcinstcleanup;McAfee Application Installer Cleanup (0234961257011555);c:\windows\temp\023496~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service --> c:\windows\temp\023496~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
=============== Created Last 30 ================
2009-10-31 10:28 236,544 a------- c:\windows\PEV.exe
2009-10-31 10:28 161,792 a------- c:\windows\SWREG.exe
2009-10-31 10:28 77,312 a------- c:\windows\MBR.exe
2009-10-31 10:28 98,816 a------- c:\windows\sed.exe
2009-10-31 00:02 0 a------- c:\windows\system32\t1p0_706886368055.b1k
2009-10-30 07:30 16,845 a------- c:\windows\system32\inezohal.dat
2009-10-30 07:11 0 a----r-- c:\windows\win32k.sys
2009-10-18 02:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\62382930
2009-10-17 14:30 13,165 a------- c:\docume~1\alluse~1\applic~1\wuqysuqoc.dat
2009-10-17 14:30 18,254 a------- c:\windows\ovuqiquc.lib
2009-10-17 14:30 16,529 a------- c:\windows\udicolype.dat
2009-10-17 14:30 13,550 a------- c:\windows\system32\bodyjyvyr.lib
2009-10-17 14:30 11,655 a------- c:\windows\aler.lib
2009-10-17 14:30 10,373 a------- c:\windows\pofynywo.lib
2009-10-17 14:16 58 a------- c:\windows\wp4.dat
2009-10-17 14:16 2 a------- c:\windows\wp3.dat
2009-10-17 14:15 34 a------- c:\windows\system32\wwp.htm
2009-10-17 14:15 0 a----r-- c:\windows\Iguqevo.bin
2009-10-17 14:14 120 a------- c:\windows\Wzuxujika.dat
2009-10-17 14:12 <DIR> --d----- c:\docume~1\alluse~1\applic~1\72487533
2009-10-15 19:34 73,728 a------- c:\windows\system32\javacpl.cpl
==================== Find3M ====================
2009-10-30 07:30 16,718 a------- c:\program files\common files\ohykotide.lib
2009-09-19 23:07 26,352 a------- c:\windows\system32\emptyregdb.dat
2009-09-16 10:22 214,664 a------- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 10:22 79,816 a------- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 10:22 40,552 a------- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 10:22 35,272 a------- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 10:22 34,248 a------- c:\windows\system32\drivers\mferkdk.sys
2009-09-11 10:33 133,632 a------- c:\windows\system32\msv1_0.dll
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-08 23:40 79,270 a------- c:\windows\hpfins05.dat
2009-09-04 16:45 58,880 a------- c:\windows\system32\msasn1.dll
2009-08-26 04:16 247,326 a------- c:\windows\system32\strmdll.dll
2009-08-05 05:11 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-04 10:00 2,180,352 -------- c:\windows\system32\ntoskrnl.exe
2009-08-04 09:13 2,057,728 -------- c:\windows\system32\ntkrnlpa.exe
2009-07-20 11:32 27,136 a--sh--- c:\windows\system32\diyobela.exe
2009-07-28 17:38 91,648 a--sh--- c:\windows\system32\gisitiwi.dll
2009-07-26 17:38 39,424 a--sh--- c:\windows\system32\gobekiyo.dll
2009-07-26 17:38 53,248 a--sh--- c:\windows\system32\henivihe.dll
2009-07-27 17:38 91,136 a--sh--- c:\windows\system32\huwulita.dll
2009-07-27 05:37 39,424 a--sh--- c:\windows\system32\jisiponu.dll
2009-07-30 05:39 92,160 a--sh--- c:\windows\system32\jitajavo.dll
2009-07-29 17:39 39,424 a--sh--- c:\windows\system32\kesowojo.dll
2009-07-31 05:39 39,424 a--sh--- c:\windows\system32\luruvube.dll
2009-07-30 17:39 92,160 a--sh--- c:\windows\system32\matodife.dll
2009-07-27 17:38 39,424 a--sh--- c:\windows\system32\mejiyuwo.dll
2009-07-30 17:39 39,424 a--sh--- c:\windows\system32\nowowise.dll
2009-07-29 17:39 91,648 a--sh--- c:\windows\system32\palimode.dll
2009-07-28 05:38 91,648 a--sh--- c:\windows\system32\siteleki.dll
2009-07-29 05:39 39,424 a--sh--- c:\windows\system32\sokajuji.dll
2009-07-30 05:39 39,424 a--sh--- c:\windows\system32\sufiluba.dll
2009-07-28 17:38 39,424 a--sh--- c:\windows\system32\tizuguve.dll
2009-07-26 17:39 53,248 a--sh--- c:\windows\system32\vuzolike.dll
2009-07-17 14:11 24,576 a--sh--- c:\windows\system32\yukeheja.exe
============= FINISH: 14:08:12.64 ===============