Combofix Log
ComboFix 09-08-27.02 - Dell 08/27/2009 14:21.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.341 [GMT -6:00]
Running from: c:\documents and settings\Dell\Desktop\Combo-pix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\djos.exe
c:\documents and settings\All Users\Application Data\ekaxomobot.dll
c:\documents and settings\All Users\Application Data\ekilaqaq.pif
c:\documents and settings\All Users\Application Data\fodosul.dll
c:\documents and settings\All Users\Documents\dywybanil.exe
c:\documents and settings\All Users\Documents\faky.reg
c:\documents and settings\All Users\Documents\icogew.dll
c:\documents and settings\All Users\Documents\owuqacisi._dl
c:\documents and settings\Dell\Application Data\eninan.lib
c:\documents and settings\Dell\Application Data\foxetik._sy
c:\documents and settings\Dell\Application Data\labim._dl
c:\documents and settings\Dell\Application Data\Microsoft\Internet Explorer\Quick Launch\PC_Antispyware2010.lnk
c:\documents and settings\Dell\Application Data\mutezasym.com
c:\documents and settings\Dell\Application Data\ohyrihoh.lib
c:\documents and settings\Dell\Application Data\tibakuze.reg
c:\documents and settings\Dell\Application Data\vajyjyt.dl
c:\documents and settings\Dell\Application Data\wazarehala.dll
c:\documents and settings\Dell\Application Data\wiaserva.log
c:\documents and settings\Dell\Application Data\ykemaci.vbs
c:\documents and settings\Dell\Desktop\PC_Antispyware2010.lnk
c:\documents and settings\Dell\Local Settings\Application Data\avabawi.exe
c:\documents and settings\Dell\Local Settings\Application Data\efojob.reg
c:\documents and settings\Dell\Local Settings\Application Data\etipu.dll
c:\documents and settings\Dell\Local Settings\Application Data\fegemaxufe.sys
c:\documents and settings\Dell\Local Settings\Application Data\goquc.inf
c:\documents and settings\Dell\Local Settings\Application Data\nidov.scr
c:\documents and settings\Dell\Local Settings\Application Data\ykis.ban
c:\documents and settings\Dell\Local Settings\Application Data\yvonykaniq.bat
c:\documents and settings\Dell\Local Settings\Temporary Internet Files\dobyk.bat
c:\documents and settings\Dell\Local Settings\Temporary Internet Files\fydocy.com
c:\documents and settings\Dell\Local Settings\Temporary Internet Files\igor.scr
c:\documents and settings\Dell\Local Settings\Temporary Internet Files\ivepa.dat
c:\documents and settings\Dell\Local Settings\Temporary Internet Files\rihile.lib
c:\documents and settings\Dell\Local Settings\Temporary Internet Files\uluheqiwi.exe
c:\documents and settings\Dell\Local Settings\Temporary Internet Files\vezeqytuf.com
c:\documents and settings\Dell\Local Settings\Temporary Internet Files\xejypemo.sys
c:\documents and settings\Dell\Start Menu\Programs\PC_Antispyware2010
c:\documents and settings\Dell\Start Menu\Programs\PC_Antispyware2010\PC_Antispyware2010.lnk
c:\documents and settings\Dell\Start Menu\Programs\PC_Antispyware2010\Uninstall.lnk
c:\program files\Common Files\dovo.ban
c:\program files\Common Files\eraxuleza.exe
c:\program files\Common Files\gegimunilo.exe
c:\program files\Common Files\isiw.pif
c:\program files\Common Files\niwelymybe.reg
c:\program files\PC_Antispyware2010
c:\program files\PC_Antispyware2010\AVEngn.dll
c:\program files\PC_Antispyware2010\data\daily.cvd
c:\program files\PC_Antispyware2010\htmlayout.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\PC_Antispyware2010\PC_Antispyware2010.cfg
c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe
c:\program files\PC_Antispyware2010\pthreadVC2.dll
c:\program files\PC_Antispyware2010\Uninstall.exe
c:\program files\PC_Antispyware2010\wscui.cpl
c:\windows\apyfuv.reg
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\elicoze.ban
c:\windows\evyr.bat
c:\windows\Installer\19d08cfd.msi
c:\windows\jiwa._dl
c:\windows\liwy._dl
c:\windows\maquqyzuqo.ban
c:\windows\msa.exe
c:\windows\ruriky.inf
c:\windows\system32\_scui.cpl
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\cyxobunym.ban
c:\windows\system32\dano.bat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\UACodlpjwrpkh.sys
c:\windows\system32\jypu.bat
c:\windows\system32\obedica.vbs
c:\windows\system32\UACacxylahnwn.dll
c:\windows\system32\UAChputyhxvcu.db
c:\windows\system32\uacinit.dll
c:\windows\system32\UACknoyumgcml.dll
c:\windows\system32\UACrjpeufoqel.dat
c:\windows\system32\UACtkerqcseey.dll
c:\windows\system32\UACtkxkdqxnwn.dll
c:\windows\system32\wisdstr.exe
c:\windows\system32\ycavykul.ban
c:\windows\zikapowe._dl
C:\yihw.exe
c:\windows\system32\drivers\beep.sys . . . is infected!!
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-07-27 to 2009-08-27 )))))))))))))))))))))))))))))))
.
2009-08-26 15:33 . 2009-08-26 15:33 15062 ----a-w- c:\windows\pynekijy.dat
2009-08-21 21:06 . 2009-08-21 21:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-20 20:50 . 2009-08-20 20:50 -------- d-----w- c:\documents and settings\Dell\Application Data\Malwarebytes
2009-08-20 20:38 . 2009-08-20 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-20 17:55 . 2009-08-21 21:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 21:09 . 2009-08-19 21:09 14545 ----a-w- c:\windows\system32\huqo.com
2009-08-19 21:09 . 2009-08-19 21:09 10591 ----a-w- c:\program files\Common Files\hajega.dat
2009-08-19 20:00 . 2009-08-19 20:00 -------- d-----w- c:\documents and settings\Dell\Application Data\Logs
2009-08-19 19:51 . 2009-08-19 19:56 -------- d-----w- c:\program files\AV Care
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 19:33 . 2008-10-11 04:36 -------- d-----w- c:\program files\Eset
2009-07-30 20:00 . 2008-10-11 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-30 20:00 . 2008-10-11 04:25 -------- d-----w- c:\program files\NOS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-15 39408]
"AV Care"="c:\program files\AV Care\AvCare.exe" [2009-08-11 1765376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-10-21 949376]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-04-20 149024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Dell\Start Menu\Programs\Startup\
dmaupd32.exe [2008-4-14 38912]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [10/10/2008 10:37 PM 15424]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-08-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PC Antispyware 2010 - c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-27 14:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(552)
c:\windows\system32\imon.dll
- - - - - - - > 'explorer.exe'(3832)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Maxtor\Schedule2\schedul2.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Eset\nod32krn.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-27 14:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-27 20:37
Pre-Run: 32,990,027,776 bytes free
Post-Run: 33,491,791,872 bytes free
211 --- E O F --- 2009-02-21 19:51