ComboFix 09-04-19.05 - Owner 04/19/2009 11:24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.75 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: *On-access scanning disabled* (Outdated)
AV: Panda Antivirus Pro 2009 *On-access scanning disabled* (Updated)
FW: *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\err.log
c:\program files\Common Files\Companion Wizard
C:\WA6P
c:\windows\system32\binatoko.dll
c:\windows\system32\delobevu.dll
c:\windows\system32\ejenenas.ini
c:\windows\system32\eloguhit.ini
c:\windows\system32\emividol.ini
c:\windows\system32\ezufatek.ini
c:\windows\system32\famavebe.dll
c:\windows\system32\femareza.dll
c:\windows\system32\fofugapi.dll
c:\windows\system32\hegubagu.exe
c:\windows\system32\hifofiga.dll
c:\windows\system32\idodumen.ini
c:\windows\system32\igiwuzuf.ini
c:\windows\system32\ipayivun.ini
c:\windows\system32\jodujuni.dll
c:\windows\system32\ketafuze.dll
c:\windows\system32\kihufupu.dll
c:\windows\system32\kudafane.dll
c:\windows\system32\lavekibi.exe
c:\windows\system32\lodivime.dll
c:\windows\system32\muyolule.dll
c:\windows\system32\nuviyapi.dll
c:\windows\system32\oyumokim.ini
c:\windows\system32\riyijuvu.dll
c:\windows\system32\saneneje.dll
c:\windows\system32\sizebave.exe
c:\windows\system32\sofigeda.dll
c:\windows\system32\stera.log
c:\windows\system32\tavawame.exe
c:\windows\system32\tibepozi.dll
c:\windows\system32\unihuvov.ini
c:\windows\system32\upufuhik.ini
c:\windows\system32\usasemoz.ini
c:\windows\system32\veyekuke.exe
c:\windows\system32\vodewenu.dll
c:\windows\system32\yanukoka.dll
c:\windows\system32\zilebobi.dll
c:\windows\system32\zomesasu.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
.
2009-04-19 16:42 . 2009-04-19 16:42 0 —-a-w c:\windows\system32\NvApps.xml
2009-04-19 16:38 . 2009-04-19 16:40 2148 —-a-w c:\windows\system32\wpa.dbl
2009-04-19 16:21 . 2009-04-19 16:21 ——– d—–w C:\32788R22FWJFW
2009-04-15 23:18 . 2009-04-15 23:18 9216 —-a-w c:\windows\instsp2.exe
2009-04-07 17:23 . 2009-04-18 00:21 8627 —-a-w c:\windows\system32\PAV_FOG.OPC
2009-04-07 17:22 . 2009-04-19 16:40 13880 —-a-w c:\windows\system32\drivers\COMFiltr.sys
2009-04-07 17:22 . 2009-04-07 17:22 ——– d—–w c:\documents and settings\Owner\Local Settings\Application Data\Panda Security
2009-04-07 17:21 . 2008-04-28 22:35 84024 —-a-w c:\windows\system32\drivers\pavdrv51.sys
2009-04-07 17:21 . 2007-03-16 00:38 54832 —-a-w c:\windows\system32\pavcpl.cpl
2009-04-07 17:21 . 2003-10-22 23:23 446464 —-a-w c:\windows\system32\HHActiveX.dll
2009-04-07 17:20 . 2008-06-24 19:48 193280 —-a-w c:\windows\system32\TpUtil.dll
2009-04-07 17:20 . 2008-06-18 23:03 520448 —-a-w c:\windows\system32\PavSHook.dll
2009-04-07 17:20 . 2008-06-18 23:03 87296 —-a-w c:\windows\system32\PavLspHook.dll
2009-04-07 17:20 . 2008-06-18 23:03 55552 —-a-w c:\windows\system32\pavipc.dll
2009-04-07 17:20 . 2007-02-08 16:53 107568 —-a-w c:\windows\system32\SYSTOOLS.DLL
2009-04-07 17:20 . 2009-04-07 17:20 ——– d—–w c:\windows\system32\PAV
2009-04-07 17:20 . 2008-03-18 21:58 58672 —-a-w c:\windows\system32\avldr.dll
2009-04-07 17:20 . 2009-04-07 17:20 ——– d—–w c:\documents and settings\Owner\Application Data\Panda Security
2009-04-07 17:20 . 2009-04-07 17:20 ——– d—–w c:\program files\Panda Security
2009-04-07 17:20 . 2009-04-07 17:20 ——– d—–w c:\documents and settings\All Users\Application Data\Panda Security
2009-04-07 17:18 . 2008-06-19 22:24 28544 —-a-w c:\windows\system32\drivers\pavboot.sys
2009-04-07 17:18 . 2009-04-07 17:18 ——– d—–w c:\program files\Common Files\Panda Security
2009-04-07 17:18 . 2008-03-04 20:59 41144 —-a-w c:\windows\system32\drivers\ShlDrv51.sys
2009-04-07 17:18 . 2008-02-07 17:03 179640 —-a-w c:\windows\system32\drivers\PavProc.sys
2009-04-07 16:55 . 2009-04-07 16:55 ——– d—–w C:\ProgramData
2009-04-07 16:55 . 2009-04-07 16:55 ——– d—–w c:\program files\Angle Interactive
2009-03-28 03:58 . 2009-03-28 03:58 ——– d—–w c:\documents and settings\Owner\Local Settings\Application Data\Apple
2009-03-28 03:58 . 2009-03-28 03:58 ——– d—–w c:\program files\Apple Software Update
2009-03-28 03:58 . 2009-03-28 03:58 ——– d—–w c:\documents and settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-19 16:42 . 2007-06-15 05:40 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-19 16:35 . 2006-12-11 04:04 ——– d—–w c:\program files\BitComet
2009-04-19 15:55 . 2006-09-03 01:21 ——– d—–w c:\program files\Trend Micro
2009-04-19 14:46 . 2009-02-26 23:01 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-19 14:35 . 2009-01-19 14:35 52224 –sha-w c:\windows\system32\jebayeni.exe
2009-04-19 01:45 . 2009-01-19 01:45 52224 –sha-w c:\windows\system32\jahizoho.exe
2009-04-18 14:12 . 2009-02-26 23:12 ——– d—–w c:\program files\Spyware Doctor
2009-04-18 13:46 . 2009-01-18 13:46 52224 –sha-w c:\windows\system32\geheyani.exe
2009-04-18 00:07 . 2009-01-18 00:07 52224 –sha-w c:\windows\system32\kujonage.exe
2009-04-16 20:06 . 2009-02-26 23:05 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-16 20:01 . 2009-02-26 23:05 ——– d—–w c:\program files\Norton Security Scan
2009-04-15 23:18 . 2009-01-15 23:18 79872 –sha-w c:\windows\system32\jepazeje.dll
2009-04-07 17:20 . 2006-05-11 13:19 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-31 15:28 . 1601-01-01 00:12 49152 –sha-w c:\windows\system32\mibewoja.dll
2009-03-28 03:59 . 2006-05-11 13:37 ——– d—–w c:\program files\QuickTime
2009-03-28 03:58 . 2007-01-30 01:21 ——– d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-09 03:08 . 2009-03-09 03:08 491040 —-a-w c:\windows\java\Packages\RNXJPVL7.ZIP
2009-03-01 06:52 . 2006-09-20 16:59 ——– d—–w c:\program files\Canon
2009-03-01 06:50 . 2006-09-25 17:47 ——– d—–w c:\program files\Yahoo!
2009-03-01 06:50 . 2006-11-29 00:18 150 —-a-w C:\YServer.txt
2009-03-01 06:49 . 2006-09-25 18:06 ——– d—–w c:\documents and settings\All Users\Application Data\yahoo!
2009-03-01 06:47 . 2006-05-11 13:36 ——– d—–w c:\documents and settings\All Users\Application Data\AOL
2009-02-26 23:54 . 2009-02-26 23:12 81288 —-a-w c:\windows\system32\drivers\iksyssec.sys
2009-02-26 23:54 . 2009-02-26 23:12 66952 —-a-w c:\windows\system32\drivers\iksysflt.sys
2009-02-26 23:54 . 2009-02-26 23:12 40840 —-a-w c:\windows\system32\drivers\ikfilesec.sys
2009-02-26 23:12 . 2009-02-26 23:12 ——– d—–w c:\documents and settings\Owner\Application Data\PC Tools
2009-02-26 23:11 . 2009-02-26 23:10 ——– d—–w c:\program files\Common Files\Adobe
2009-02-26 23:08 . 2006-05-11 13:26 ——– d—–w c:\program files\Google
2009-02-10 03:13 . 2006-09-24 03:07 4578 —-a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-02-09 10:19 . 2004-08-26 16:12 1846272 —-a-w c:\windows\system32\win32k.sys
2008-03-13 20:31 . 2006-09-16 21:34 72064 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-10-29 22:00 . 2006-10-29 22:00 0 -c–a-w c:\program files\Common Files\err.log
2009-01-08 16:05 . 2009-01-08 16:05 49152 –sha-w c:\windows\system32\bivewede.dll.tmp
2009-01-08 16:05 . 2009-01-08 16:05 49152 –sha-w c:\windows\system32\fegigewi.dll.tmp
1601-01-01 00:12 . 1601-01-01 00:12 49152 –sha-w c:\windows\system32\galaduja.dll.tmp
2009-01-08 16:05 . 2009-01-08 16:05 49152 –sha-w c:\windows\system32\jopuhosi.dll.tmp
1601-01-01 00:12 . 1601-01-01 00:12 49152 –sha-w c:\windows\system32\kivigoru.dll.tmp
1601-01-01 00:12 . 1601-01-01 00:12 49152 –sha-w c:\windows\system32\tepusiga.dll.tmp
1601-01-01 00:12 . 1601-01-01 00:12 49152 –sha-w c:\windows\system32\vuranune.dll.tmp
2009-01-08 16:05 . 2009-01-08 16:05 174 –sha-w c:\windows\system32\wupadupo.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2009-01-20 2523960]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2005-09-27 169984]
"APVXDWIN"="c:\program files\Panda Security\Panda Antivirus Pro 2009\APVXDWIN.EXE" [2008-12-03 869632]
"SCANINICIO"="c:\program files\Panda Security\Panda Antivirus Pro 2009\Inicio.exe" [2008-07-07 50432]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-17 7204864]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-02-26 1168264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 21:58 58672 —-a-w c:\windows\system32\avldr.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^RDPlatinum v5.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\RDPlatinum v5.lnk
backup=c:\windows\pss\RDPlatinum v5.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^wkcalrem.LNK]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\wkcalrem.LNK
backup=c:\windows\pss\wkcalrem.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Java\\jre1.5.0_02\\bin\\javaw.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Spyware Doctor\\pctsGui.exe"=
"c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"26033:TCP"= 26033:TCP:BitComet 26033 TCP
"26033:UDP"= 26033:UDP:BitComet 26033 UDP
R2 gupdate1c99866c71a5e50;Google Update Service (gupdate1c99866c71a5e50);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-26 133104]
R3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-02-26 30192]
S0 pavboot;Panda boot driver;c:\windows\system32\Drivers\pavboot.sys [2008-06-19 28544]
S1 ShldDrv;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShlDrv51.sys [2008-03-04 41144]
S2 Gwmsrv;Panda Goodware Cache Manager; [x]
S2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe [2004-08-04 14336]
S2 PavProc;Panda Process Protection Driver;c:\windows\system32\DRIVERS\PavProc.sys [2008-02-07 179640]
S2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Antivirus Pro 2009\PskSvc.exe [2008-06-25 28928]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-06-13 356920]
S3 ComFiltr;Panda Anti-Dialer;c:\windows\system32\DRIVERS\COMFiltr.sys [2009-04-19 13880]
S3 PavTPK.sys;PavTPK.sys; [x]
— Other Services/Drivers In Memory —
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ee81ac1-e0f0-11da-8f12-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2009-03-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-04-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-04 04:16]
2009-04-19 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-26 23:05]
2006-09-03 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-26 19:00]
2006-09-03 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-26 19:00]
2009-04-16 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 01:20]
.
- - - - ORPHANS REMOVED - - - -
BHO-{a1e81bf3-2d32-4f37-810f-23651f8d9f86} - c:\windows\system32\hifofiga.dll
HKLM-Run-UpgConfVer - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: Yahoo! Dominoes - hxxp://origin.games.yahoo.net/games/clients/y/dot9_x.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-19 11:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(788)
c:\windows\system32\avldr.dll
- - - - - - - > 'explorer.exe'(544)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Panda Security\Panda Antivirus Pro 2009\TPSrv.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Panda Security\Panda Antivirus Pro 2009\PsCtrlS.exe
c:\program files\Panda Security\Panda Antivirus Pro 2009\PavFnSvr.exe
c:\program files\Common Files\Panda Security\PavShld\PavPrSrv.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Panda Security\Panda Antivirus Pro 2009\PsImSvc.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\Panda Security\Panda Antivirus Pro 2009\PAVSRV51.EXE
c:\program files\Panda Security\Panda Antivirus Pro 2009\AVENGINE.EXE
c:\windows\SoftwareDistribution\Download\542ca89b62f4b2b2eebea38f60812a7c\update\update.exe
.
**************************************************************************
.
Completion time: 2009-04-19 11:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-19 16:46
Pre-Run: 174,068,461,568 bytes free
Post-Run: 175,582,986,240 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
287 — E O F — 2009-03-18 15:33