I had to run combofix twice because the first time I launched it, it shut down my Internet and then it started saying that it needs to download Windows Console but I'm not connected to the Internet and before I could restart the Internet, it started scanning so I let it finish and then it rebooted the PC. On the second go, I was ready to restart my Internet and I restarted it as soon as Combofix shut it down and then it was able to download the Windows Console and proceeded with the scan.
COMBOFIX REPORT
ComboFix 09-06-16.05 - Sachin 06/17/2009 22:37.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.446.151 [GMT 5.5:30]
Running from: c:\documents and settings\Sachin\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))
.
2009-06-17 06:56 . 2009-06-17 06:56 -------- d-----w- c:\documents and settings\Sachin\Application Data\FastStone
2009-06-17 05:44 . 2009-06-17 05:44 -------- d-----w- c:\documents and settings\Sachin\Application Data\Malwarebytes
2009-06-17 05:44 . 2009-05-26 07:50 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 05:44 . 2009-06-17 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-17 05:44 . 2009-05-26 07:49 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-16 07:29 . 2009-06-16 07:29 -------- d-----w- c:\documents and settings\Sachin\Local Settings\Application Data\Ashampoo
2009-06-16 06:42 . 2009-06-16 06:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-16 05:43 . 2009-06-16 05:43 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-15 18:48 . 2009-06-15 18:48 -------- d-----w- c:\program files\In2Cable
2009-06-15 12:05 . 2009-06-15 12:05 -------- d-----w- c:\program files\Trend Micro
2009-06-15 11:36 . 2009-06-15 11:36 -------- d-----w- c:\program files\ERUNT
2009-06-14 07:38 . 2009-06-14 07:39 152576 ----a-w- c:\documents and settings\Sachin\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-13 15:26 . 2005-09-16 22:14 157184 ------r- c:\windows\system32\RtlCPAPI.dll
2009-06-13 15:24 . 2005-05-04 02:43 69632 ------r- c:\windows\Alcmtr.exe
2009-06-06 14:58 . 2009-06-06 14:58 -------- d-----w- c:\documents and settings\LocalService\Application Data\PC Suite
2009-06-03 14:11 . 2009-06-03 14:12 61440 ----a-r- c:\documents and settings\Sachin\Application Data\Microsoft\Installer\{04DB4871-BC1D-44BF-AADB-47326365EB8C}\ARPPRODUCTICON.exe
2009-05-22 19:31 . 2009-05-22 19:31 -------- d-----w- c:\documents and settings\Sachin\Application Data\Apple Computer
2009-05-19 08:29 . 2009-05-19 08:29 -------- d-----w- c:\windows\PaltalkScene
2009-05-19 08:29 . 2009-05-19 08:29 -------- d-----w- c:\program files\Paltalk Messenger
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM5.dll
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM4.dll
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM3.dll
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM2.dll
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM1.dll
2009-05-21 06:03 . 2009-04-15 19:04 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-03 09:01 . 2009-05-03 09:01 -------- d-----w- c:\documents and settings\Sachin\Application Data\Nokia Multimedia Player
2009-05-03 08:58 . 2009-05-03 08:58 -------- d-----w- c:\documents and settings\Sachin\Application Data\Nokia
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\program files\DIFX
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\program files\Common Files\Nokia
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\documents and settings\Sachin\Application Data\PC Suite
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\program files\Common Files\PCSuite
2009-05-03 08:48 . 2009-05-03 08:48 -------- d-----w- c:\program files\Nokia
2009-05-03 08:48 . 2009-05-03 08:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-04-29 07:18 . 2009-04-29 07:18 198064 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-04-29 07:15 . 2009-04-29 07:15 -------- d-----w- c:\documents and settings\Sachin\Application Data\IDM
2009-04-25 08:50 . 2009-04-15 11:16 68456 ----a-w- c:\documents and settings\Sachin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-23 15:09 . 2009-04-23 15:09 -------- d-----w- c:\documents and settings\Sachin\Application Data\Winamp
2009-04-22 07:54 . 2009-04-22 07:55 138512 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-22 07:53 . 2009-04-22 07:54 201440 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-04-22 07:53 . 2009-04-22 07:53 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-04-16 08:18 . 2009-04-15 11:09 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-16 07:32 . 2009-04-16 07:32 1915520 ----a-w- c:\documents and settings\Sachin\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-04-15 19:02 . 2009-04-15 19:02 152576 ----a-w- c:\documents and settings\Sachin\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-15 11:48 . 2009-04-15 11:18 16608 ----a-w- c:\windows\gdrv.sys
2009-04-15 11:06 . 2009-04-15 11:06 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-03-26 15:35 . 2009-04-03 13:24 210352 ----a-w- c:\windows\system32\idmmbc.dll
2004-08-03 14:26 . 2004-08-03 14:26 164824 --sh--r- c:\windows\system32\xreftpd.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-17_16.59.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-17 17:03 . 2009-06-17 17:03 16384 c:\windows\Temp\Perflib_Perfdata_1f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"NetMeter"="d:\soft\NetMeter\NetMeter114beta_3.exe" [2009-01-28 297984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-04-15 282624]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"WinampAgent"="d:\soft\Winamp\New Folder\Winamp\winampa.exe" [2009-04-10 37888]
"SunJavaUpdateSched"="d:\soft\Jre6\bin\jusched.exe" [2009-05-21 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-10-15 14864384]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
In2Cable Login.lnk - c:\program files\In2Cable\CMAAClient.exe [2004-4-21 499712]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\soft\\Limewire\\New Folder\\LimeWire\\LimeWire.exe"=
"d:\\soft\\Opera\\New Folder\\Opera.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3373:TCP"= 3373:TCP:hlzqptka
R0 ENO;ENO;c:\windows\system32\drivers\ENO.sys [4/20/2004 11:31 AM 42972]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/17/2009 12:04 AM 210216]
S2 gyfyqjeci;Universal Microsoft;c:\windows\system32\svchost.exe -k netsvcs [8/3/2004 7:56 PM 14336]
S2 zntphf;Image Shell;c:\windows\system32\svchost.exe -k netsvcs [8/3/2004 7:56 PM 14336]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
gyfyqjeci
zntphf
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.co.in/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
IE: Download all links with IDM - d:\soft\Internet Download Manager\New Folder\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - d:\soft\Internet Download Manager\New Folder\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - d:\soft\Internet Download Manager\New Folder\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4B4695D1-F431-4C59-A0E7-5E5BFEC65BC2} = 203.192.198.7,203.192.195.18
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-17 22:39
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\Sachin\LOCALS~1\Temp\ASFWHide"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gyfyqjeci]
"ServiceDll"="c:\windows\system32\xreftpd.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zntphf]
"ServiceDll"="c:\windows\system32\xreftpd.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):06,54,4b,0e,7a,13,98,c3,36,b4,0a,0c,b6,ad,6a,77,f8,5e,61,8d,f4,
c4,0a,23,25,79,a8,99,e0,50,9b,55,1a,96,5c,de,ad,8a,5f,4a,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6cc5b596-55bd-44a8-a092-d025a6e47e96}]
@Denied: (Full) (Everyone)
"Model"=dword:0000007c
"Therad"=dword:00000014
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1552)
c:\program files\McAfee\SiteAdvisor\saHook.dll
.
Completion time: 2009-06-17 22:40
ComboFix-quarantined-files.txt 2009-06-17 17:10
ComboFix2.txt 2009-06-17 17:00
Pre-Run: 4,788,051,968 bytes free
Post-Run: 4,769,406,976 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
158
NEW HIJACKTHIS LOG
ComboFix 09-06-16.05 - Sachin 06/17/2009 22:37.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.446.151 [GMT 5.5:30]
Running from: c:\documents and settings\Sachin\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))
.
2009-06-17 06:56 . 2009-06-17 06:56 -------- d-----w- c:\documents and settings\Sachin\Application Data\FastStone
2009-06-17 05:44 . 2009-06-17 05:44 -------- d-----w- c:\documents and settings\Sachin\Application Data\Malwarebytes
2009-06-17 05:44 . 2009-05-26 07:50 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 05:44 . 2009-06-17 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-17 05:44 . 2009-05-26 07:49 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-16 07:29 . 2009-06-16 07:29 -------- d-----w- c:\documents and settings\Sachin\Local Settings\Application Data\Ashampoo
2009-06-16 06:42 . 2009-06-16 06:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-16 05:43 . 2009-06-16 05:43 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-15 18:48 . 2009-06-15 18:48 -------- d-----w- c:\program files\In2Cable
2009-06-15 12:05 . 2009-06-15 12:05 -------- d-----w- c:\program files\Trend Micro
2009-06-15 11:36 . 2009-06-15 11:36 -------- d-----w- c:\program files\ERUNT
2009-06-14 07:38 . 2009-06-14 07:39 152576 ----a-w- c:\documents and settings\Sachin\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-13 15:26 . 2005-09-16 22:14 157184 ------r- c:\windows\system32\RtlCPAPI.dll
2009-06-13 15:24 . 2005-05-04 02:43 69632 ------r- c:\windows\Alcmtr.exe
2009-06-06 14:58 . 2009-06-06 14:58 -------- d-----w- c:\documents and settings\LocalService\Application Data\PC Suite
2009-06-03 14:11 . 2009-06-03 14:12 61440 ----a-r- c:\documents and settings\Sachin\Application Data\Microsoft\Installer\{04DB4871-BC1D-44BF-AADB-47326365EB8C}\ARPPRODUCTICON.exe
2009-05-22 19:31 . 2009-05-22 19:31 -------- d-----w- c:\documents and settings\Sachin\Application Data\Apple Computer
2009-05-19 08:29 . 2009-05-19 08:29 -------- d-----w- c:\windows\PaltalkScene
2009-05-19 08:29 . 2009-05-19 08:29 -------- d-----w- c:\program files\Paltalk Messenger
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM5.dll
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM4.dll
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM3.dll
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM2.dll
2009-06-01 08:24 . 2009-04-29 07:31 28672 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\NP_IDM1.dll
2009-05-21 06:03 . 2009-04-15 19:04 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-03 09:01 . 2009-05-03 09:01 -------- d-----w- c:\documents and settings\Sachin\Application Data\Nokia Multimedia Player
2009-05-03 08:58 . 2009-05-03 08:58 -------- d-----w- c:\documents and settings\Sachin\Application Data\Nokia
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\program files\DIFX
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\program files\Common Files\Nokia
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\documents and settings\Sachin\Application Data\PC Suite
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-05-03 08:51 . 2009-05-03 08:51 -------- d-----w- c:\program files\Common Files\PCSuite
2009-05-03 08:48 . 2009-05-03 08:48 -------- d-----w- c:\program files\Nokia
2009-05-03 08:48 . 2009-05-03 08:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-04-29 07:18 . 2009-04-29 07:18 198064 ----a-w- c:\documents and settings\Sachin\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-04-29 07:15 . 2009-04-29 07:15 -------- d-----w- c:\documents and settings\Sachin\Application Data\IDM
2009-04-25 08:50 . 2009-04-15 11:16 68456 ----a-w- c:\documents and settings\Sachin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-23 15:09 . 2009-04-23 15:09 -------- d-----w- c:\documents and settings\Sachin\Application Data\Winamp
2009-04-22 07:54 . 2009-04-22 07:55 138512 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-22 07:53 . 2009-04-22 07:54 201440 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-04-22 07:53 . 2009-04-22 07:53 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-04-16 08:18 . 2009-04-15 11:09 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-16 07:32 . 2009-04-16 07:32 1915520 ----a-w- c:\documents and settings\Sachin\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-04-15 19:02 . 2009-04-15 19:02 152576 ----a-w- c:\documents and settings\Sachin\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-15 11:48 . 2009-04-15 11:18 16608 ----a-w- c:\windows\gdrv.sys
2009-04-15 11:06 . 2009-04-15 11:06 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-03-26 15:35 . 2009-04-03 13:24 210352 ----a-w- c:\windows\system32\idmmbc.dll
2004-08-03 14:26 . 2004-08-03 14:26 164824 --sh--r- c:\windows\system32\xreftpd.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-17_16.59.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-17 17:03 . 2009-06-17 17:03 16384 c:\windows\Temp\Perflib_Perfdata_1f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"NetMeter"="d:\soft\NetMeter\NetMeter114beta_3.exe" [2009-01-28 297984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-04-15 282624]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"WinampAgent"="d:\soft\Winamp\New Folder\Winamp\winampa.exe" [2009-04-10 37888]
"SunJavaUpdateSched"="d:\soft\Jre6\bin\jusched.exe" [2009-05-21 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-10-15 14864384]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
In2Cable Login.lnk - c:\program files\In2Cable\CMAAClient.exe [2004-4-21 499712]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\groove.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\soft\\Limewire\\New Folder\\LimeWire\\LimeWire.exe"=
"d:\\soft\\Opera\\New Folder\\Opera.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3373:TCP"= 3373:TCP:hlzqptka
R0 ENO;ENO;c:\windows\system32\drivers\ENO.sys [4/20/2004 11:31 AM 42972]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/17/2009 12:04 AM 210216]
S2 gyfyqjeci;Universal Microsoft;c:\windows\system32\svchost.exe -k netsvcs [8/3/2004 7:56 PM 14336]
S2 zntphf;Image Shell;c:\windows\system32\svchost.exe -k netsvcs [8/3/2004 7:56 PM 14336]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
gyfyqjeci
zntphf
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.co.in/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
IE: Download all links with IDM - d:\soft\Internet Download Manager\New Folder\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - d:\soft\Internet Download Manager\New Folder\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - d:\soft\Internet Download Manager\New Folder\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4B4695D1-F431-4C59-A0E7-5E5BFEC65BC2} = 203.192.198.7,203.192.195.18
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-17 22:39
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\Sachin\LOCALS~1\Temp\ASFWHide"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gyfyqjeci]
"ServiceDll"="c:\windows\system32\xreftpd.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zntphf]
"ServiceDll"="c:\windows\system32\xreftpd.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):06,54,4b,0e,7a,13,98,c3,36,b4,0a,0c,b6,ad,6a,77,f8,5e,61,8d,f4,
c4,0a,23,25,79,a8,99,e0,50,9b,55,1a,96,5c,de,ad,8a,5f,4a,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6cc5b596-55bd-44a8-a092-d025a6e47e96}]
@Denied: (Full) (Everyone)
"Model"=dword:0000007c
"Therad"=dword:00000014
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1552)
c:\program files\McAfee\SiteAdvisor\saHook.dll
.
Completion time: 2009-06-17 22:40
ComboFix-quarantined-files.txt 2009-06-17 17:10
ComboFix2.txt 2009-06-17 17:00
Pre-Run: 4,788,051,968 bytes free
Post-Run: 4,769,406,976 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
158
Edited by power333, 17 June 2009 - 12:47 PM.