ComboFix 09-03-15.01 - M.M Telang 2009-03-17 21:27:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1271.902 [GMT 5.5:30]
Running from: c:\documents and settings\M.M Telang\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Uninstall Fun Web Products.dll
c:\windows\system32\28463
c:\windows\system32\MabryObj.dll
c:\windows\system32\mdm.exe
c:\windows\system32\nhatquanglan18.exe
c:\windows\system32\SCVHSOT.exe
c:\windows\system32\setting.ini
c:\windows\system32\setup.ini
c:\windows\system32\test1.exe
F:\autorun.inf
F:\New Folder .exe
F:\regsvr.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.
2009-03-08 14:27 . 2009-03-09 20:16 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-08 14:27 . 2009-03-08 14:27 1,409 --a------ c:\windows\QTFont.for
2009-03-08 12:23 . 2009-03-08 12:23 <DIR> d-------- c:\windows\Applian FLV Player
2009-03-08 12:23 . 2009-03-08 12:23 <DIR> d-------- c:\program files\FLV Player
2009-03-07 18:48 . 2009-03-07 18:48 61,440 --a------ c:\windows\system32\drivers\xtiob.sys
2009-03-06 23:57 . 2009-03-06 23:57 61,440 --a------ c:\windows\system32\drivers\wdwhpr.sys
2009-03-06 23:50 . 2009-03-06 23:50 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-06 23:50 . 2009-03-06 23:50 <DIR> d-------- c:\documents and settings\M.M Telang\Application Data\Malwarebytes
2009-03-06 23:50 . 2009-03-06 23:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-06 23:50 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-06 23:50 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-05 23:03 . 2009-03-05 23:03 87,040 -rahs---- c:\windows\system32\krwqyxle.dll
2009-03-05 19:50 . 2009-03-05 19:50 <DIR> d-------- c:\program files\Trend Micro
2009-02-25 21:09 . 2008-09-18 19:19 35,232 --a------ c:\windows\hq386.win
2009-02-22 07:12 . 2009-02-22 07:12 4,096 --a------ c:\windows\system32\
03.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 15:58 --------- d-----w c:\documents and settings\M.M Telang\Application Data\uTorrent
2009-03-01 17:35 --------- d-----w c:\documents and settings\Administrator\Application Data\AVG7
2009-03-01 17:34 --------- d-----w c:\documents and settings\M.M Telang\Application Data\AVG7
2009-03-01 17:34 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
2009-03-01 17:13 --------- d-----w c:\program files\Google
2009-02-23 06:42 --------- d-----w c:\program files\uTorrent
2009-01-28 16:16 4,096 ----a-w c:\windows\system32\
01.tmp
2009-01-27 16:21 4,096 ----a-w c:\windows\system32\
02.tmp
2009-01-26 16:28 90,112 ----a-w c:\windows\DUMP541b.tmp
2009-01-19 17:14 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-19 17:14 --------- d-----w c:\program files\Java
2009-01-18 05:57 --------- d-----w c:\program files\HTML Help Workshop
2009-01-18 05:56 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-04-20 11:54 486,108,144 ----a-w c:\program files\ADBEPHSPCS3_WWE.exe
2008-04-20 11:36 423,321,216 ------w c:\program files\ADBEFLPRCS3_WWE.exe
2008-04-20 11:20 473,261,536 ----a-w c:\program files\PSE_6.0_WIN_TB_WEB_WWE.exe
2008-04-20 11:18 299,294,000 ------w c:\program files\ADBEDRWVCS3_WWE.exe
2008-01-30 07:00 24,192 ----a-w c:\documents and settings\M.M Telang\usbsermptxp.sys
2008-01-30 07:00 22,768 ----a-w c:\documents and settings\M.M Telang\usbsermpt.sys
2008-01-30 06:49 92,064 ----a-w c:\documents and settings\M.M Telang\mqdmmdm.sys
2008-01-30 06:49 9,232 ----a-w c:\documents and settings\M.M Telang\mqdmmdfl.sys
2008-01-30 06:49 79,328 ----a-w c:\documents and settings\M.M Telang\mqdmserd.sys
2008-01-30 06:49 66,656 ----a-w c:\documents and settings\M.M Telang\mqdmbus.sys
2008-01-30 06:49 6,208 ----a-w c:\documents and settings\M.M Telang\mqdmcmnt.sys
2008-01-30 06:49 5,936 ----a-w c:\documents and settings\M.M Telang\mqdmwhnt.sys
2008-01-30 06:49 4,048 ----a-w c:\documents and settings\M.M Telang\mqdmcr.sys
2007-12-01 09:48 4,046 ----a-w c:\program files\jdk-6u3-windows-i586-p.exe.sdm
2007-10-08 08:07 8,937,608 ----a-w c:\program files\setup2.exe
2007-10-08 07:46 9,614,472 ----a-w c:\program files\setup1.exe
2007-04-16 15:52 166,048 --sha-r c:\windows\system32\qrvevuj.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-05 68856]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-12-14 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-12-14 118784]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SoundMan"="SOUNDMAN.EXE" [2004-02-09 c:\windows\SOUNDMAN.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Visual Studio\\Common\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56423:TCP"= 56423:TCP:MobileLive Mediaschemas
"59868:UDP"= 59868:UDP:MobileLive SoftwareSpeech
"48478:TCP"= 48478:TCP:MobileLive MicrosoftApp
"18853:UDP"= 18853:UDP:MobileLive twainWeb
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\drivers\RMSPPPOE.SYS [2007-10-04 31424]
S0 ScreenNT;ScreenNT;c:\windows\system32\drivers\ScreenNT.sys --> c:\windows\system32\drivers\ScreenNT.sys [?]
S2 EMLSS;EMLSS;c:\windows\system32\drivers\emltdi.sys --> c:\windows\system32\drivers\emltdi.sys [?]
S2 OnlineNT;OnlineNT;\??\c:\progra~1\QUICKH~1\QUICKH~1\ONLINENT.SYS --> c:\progra~1\QUICKH~1\QUICKH~1\ONLINENT.SYS [?]
S3 s716bus;Sony Ericsson Device 716 driver (WDM);c:\windows\system32\drivers\s716bus.sys [2008-10-20 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter;c:\windows\system32\drivers\s716mdfl.sys [2008-11-02 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver;c:\windows\system32\drivers\s716mdm.sys [2008-11-02 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s716mgmt.sys [2008-12-25 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS);c:\windows\system32\drivers\s716nd5.sys [2008-12-25 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface;c:\windows\system32\drivers\s716obex.sys [2008-12-25 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM);c:\windows\system32\drivers\s716unic.sys [2008-12-25 98952]
S3 sbzxhtddw;sbzxhtddw;c:\windows\system32\
02.tmp [2009-01-27 21:51:20 4096]
--- Other Services/Drivers In Memory ---
*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - Browser
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - helpsvc
*Deregistered* - ImapiService
*Deregistered* - JavaQuickStarterService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MSSQL$SQLEXPRESS
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RemoteRegistry
*Deregistered* - RichVideo
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - ServiceLayer
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SLService
*Deregistered* - Spooler
*Deregistered* - SRaccess
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
*Deregistered* - xuubga
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
SRaccess
xuubga
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4feb5cfa-d618-11dc-9542-00110916b494}]
\Shell\AutoRun\command - b.com
\Shell\explore\Command - b.com
\Shell\open\Command - b.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{84e0d03c-8a2e-11dd-9662-00110916b494}]
\Shell\AutoRun\command - F:\tyktjfww.exe
\Shell\explore\Command - F:\tyktjfww.exe
\Shell\open\Command - F:\tyktjfww.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c875bcb4-72eb-11dc-94d2-00110916b494}]
\Shell\Open(&O)\command - RECYCLED\appmgmt.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-09-19 17:36]
2009-02-23 c:\windows\Tasks\At1.job
- c:\windows\system32\svchost []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.igoogle.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {FD7BECD7-86A2-4D67-AC2D-4B189612B43F} = 203.115.71.66 203.115.81.38
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-17 21:31:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet049\Services\sbzxhtddw]
"ImagePath"="\??\c:\windows\system32\
02.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet049\Services\xuubga]
"ServiceDll"="c:\windows\system32\qrvevuj.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1482476501-436374069-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
.
**************************************************************************
.
Completion time: 2009-03-17 21:47:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-17 16:17:03
Pre-Run: 18,904,989,696 bytes free
Post-Run: 18,757,865,472 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=49 Default=49 Failed=48 LastKnownGood=50 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,
29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50
250 --- E O F --- 2007-10-24 14:10:23