nem126
Topic Starter
This is a continuation of the thread i have started earlier, but due to the lack of time lately my forum got closed.
This is a combofix log in safemode
ComboFix 09-06-17.02 - Kathey 11/07/2009 23:03.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.2038.1665 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combofix.exe.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\PAV
c:\program files\PAV\pav.exe
c:\windows\system32\drivers\glaide32.sys
c:\windows\system32\uacinit.dll
c:\windows\system32\winexplorer.dll
.
((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.
2009-06-18 03:58 . 2009-06-18 03:59 ——– d-s—w- C:\program.exe
2009-06-16 03:21 . 2007-05-16 06:24 172032 —-a-w- c:\windows\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 03:30 . 2008-04-17 17:38 1356 —-a-w- c:\users\Kathey\AppData\Local\d3d9caps.dat
2009-06-05 00:15 . 2009-06-01 17:09 ——– d—–w- c:\progra~2\rajadeda
2009-06-05 00:06 . 2009-06-05 00:06 ——– d—–w- c:\progra~2\fudoneze
2009-06-05 00:06 . 2009-06-05 00:06 ——– d—–w- c:\progra~2\senifetu
2009-06-01 17:09 . 2009-06-01 17:09 ——– d—–w- c:\progra~2\kebivozu
2009-06-01 05:09 . 2009-06-01 05:09 ——– d—–w- c:\progra~2\modisemi
2009-06-01 05:09 . 2009-06-01 05:09 ——– d—–w- c:\progra~2\lugarine
2009-05-31 18:40 . 2009-05-31 18:40 ——– d—–w- c:\program files\Common Files\Uninstall
2009-05-31 17:09 . 2009-05-31 17:09 ——– d—–w- c:\progra~2\rinihuye
2009-05-31 17:09 . 2009-05-31 17:09 ——– d—–w- c:\progra~2\wimavogu
2009-05-31 04:35 . 2009-05-30 21:49 ——– d—–w- c:\progra~2\nilezisu
2009-05-30 21:49 . 2009-05-30 21:49 ——– d—–w- c:\progra~2\zidutufi
2009-05-30 10:10 . 2009-05-30 09:49 ——– d—–w- c:\progra~2\rojideze
2009-05-30 09:49 . 2009-05-30 09:49 ——– d—–w- c:\progra~2\lusajuwo
2009-05-29 22:11 . 2009-05-29 21:49 ——– d—–w- c:\progra~2\tutepega
2009-05-29 21:49 . 2009-05-29 21:49 ——– d—–w- c:\progra~2\zahuzihi
2009-05-28 23:12 . 2009-05-28 00:23 ——– d—–w- c:\progra~2\dararudi
2009-05-28 22:51 . 2009-05-28 22:51 ——– d—–w- c:\progra~2\vuseyiju
2009-05-28 22:51 . 2009-05-28 22:51 ——– d—–w- c:\progra~2\mohohimu
2009-05-28 00:23 . 2009-05-28 00:23 ——– d—–w- c:\progra~2\ganoseho
2009-05-27 02:20 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\lezuyawo
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\weyalomi
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\tesidaye
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\bemetanu
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\progra~2\tosilihu
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\progra~2\lotibuye
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\progra~2\giseyeyi
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\mahogiwe
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\dayugapu
2009-05-26 11:28 . 2009-05-26 11:07 ——– d—–w- c:\progra~2\jezegunu
2009-05-26 11:07 . 2009-05-26 11:07 ——– d—–w- c:\progra~2\fupuvuyu
2009-05-26 02:49 . 2009-01-08 18:41 ——– d—–w- c:\users\Kathey\AppData\Roaming\ZoomBrowser EX
2009-05-26 02:15 . 2009-01-08 18:39 ——– d—–w- c:\users\Kathey\AppData\Roaming\CameraWindowDC
2009-05-25 23:28 . 2009-05-25 23:07 ——– d—–w- c:\progra~2\vabuwida
2009-05-25 23:07 . 2009-05-25 23:07 ——– d—–w- c:\progra~2\moyomego
2009-05-25 02:14 . 2009-05-25 01:53 ——– d—–w- c:\progra~2\muzupera
2009-05-25 01:53 . 2009-05-25 01:53 ——– d—–w- c:\progra~2\vajetezo
2009-05-24 00:15 . 2009-05-22 22:29 ——– d—–w- c:\progra~2\lakopayi
2009-05-22 22:29 . 2009-05-20 22:24 ——– d—–w- c:\progra~2\wupoyahi
2009-05-22 22:29 . 2009-05-22 22:29 ——– d—–w- c:\progra~2\yeteyohi
2009-05-21 22:09 . 2009-05-21 22:09 ——– d—–w- c:\progra~2\wojigovu
2009-05-21 22:09 . 2009-05-21 22:09 ——– d—–w- c:\progra~2\sunufajo
2009-05-20 22:24 . 2009-05-20 22:24 ——– d—–w- c:\progra~2\hozefudu
2009-05-20 10:45 . 2009-05-20 10:24 ——– d—–w- c:\progra~2\yilipagi
2009-05-20 10:24 . 2009-05-20 10:24 ——– d—–w- c:\progra~2\wupuyera
2009-05-19 22:45 . 2009-05-19 22:23 ——– d—–w- c:\progra~2\vibevije
2009-05-19 22:23 . 2009-05-19 22:23 ——– d—–w- c:\progra~2\kagejade
2009-05-19 22:23 . 2009-05-18 19:55 ——– d—–w- c:\progra~2\gosezale
2009-05-18 19:55 . 2009-05-18 19:55 ——– d—–w- c:\progra~2\yadubupi
2009-05-18 08:16 . 2009-05-18 07:55 ——– d—–w- c:\progra~2\rahawufi
2009-05-18 07:55 . 2009-05-18 07:55 ——– d—–w- c:\progra~2\dunahewa
2009-05-17 20:16 . 2009-05-17 19:55 ——– d—–w- c:\progra~2\navaguke
2009-05-17 19:55 . 2009-05-17 19:55 ——– d—–w- c:\progra~2\lugopuko
2009-05-17 17:54 . 2009-05-15 22:03 ——– d—–w- c:\progra~2\nifolije
2009-05-17 01:54 . 2009-05-17 01:54 ——– d—–w- c:\progra~2\kanejuhe
2009-05-17 01:54 . 2009-05-17 01:54 ——– d—–w- c:\progra~2\pozofohu
2009-05-15 22:03 . 2009-05-15 22:03 ——– d—–w- c:\progra~2\hutudoki
2009-05-15 03:46 . 2009-05-15 03:25 ——– d—–w- c:\progra~2\poroyoju
2009-05-15 03:25 . 2009-05-15 03:25 ——– d—–w- c:\progra~2\simageme
2009-05-14 11:54 . 2009-05-14 11:33 ——– d—–w- c:\progra~2\dupopazi
2009-05-14 11:33 . 2009-05-14 11:33 ——– d—–w- c:\progra~2\hitihofi
2009-05-13 23:57 . 2009-05-13 23:36 ——– d—–w- c:\progra~2\kiwasuge
2009-05-13 23:36 . 2009-05-13 23:36 ——– d—–w- c:\progra~2\zudawahi
2009-05-13 23:36 . 2009-05-13 23:36 ——– d—–w- c:\progra~2\zadoleso
2009-05-13 22:49 . 2009-05-13 03:14 ——– d—–w- c:\progra~2\tefiyuvu
2009-05-13 22:42 . 2007-08-15 23:39 ——– d—–w- c:\progra~2\Microsoft Help
2009-05-13 22:36 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 03:14 . 2009-05-13 03:14 ——– d—–w- c:\progra~2\ginameye
2009-05-03 17:17 . 2009-05-03 17:17 48128 —-a-w- c:\users\Kathey\a.exe
2009-04-19 02:55 . 2007-08-28 08:20 130895 —-a-w- c:\windows\hpoins18.dat
2007-08-16 07:17 . 2007-08-16 07:14 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ida"="c:\program files\Ida\IdaLaunch.exe" [2007-09-01 32136]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"henugamupu"="c:\programdata\bemetanu\bemetanu.dll" [2009-02-26 48640]
"ee74d711"="c:\programdata\rajadeda\rajadeda.dll" [2009-06-01 80384]
"CPMed47e48d"="c:\programdata\senifetu\senifetu.dll" [2009-06-05 81408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-06-25 405504]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-12-03 107112]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2006-12-03 22696]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 17920]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2007-03-14 321088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
c:\users\Kathey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
OneNote Table Of Contents.onetoc2 [2008-9-1 3656]
rncsys32.exe [2006-11-2 19968]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
c:\users\Kathey\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
OneNote Table Of Contents.onetoc2 [2008-9-1 3656]
rncsys32.exe [2006-11-2 19968]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A41F51A2-4BA6-4E0F-B976-D8211BFB577B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5641C23F-8F46-4572-8DAD-CD59187E4E37}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{37EBEF9F-C5CA-4598-B6DA-7FCF8169D93D}"= c:\program files\Dell\MediaDirect\PowerCinema.exe:CyberLink PowerCinema
"{060318CD-695E-4F0C-8610-A2DC3A7C2382}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{0C67E48B-1053-4B5D-9730-E261DBE817DA}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{52AF30A5-0192-4ED4-A819-D89F48896206}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{FEDFD9DB-6160-4A91-A360-78E801541C68}"= UDP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{5D3E2CB8-50A8-4653-A34E-7A479CFDBC89}"= TCP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{8C9B90A2-E9D4-4501-8E87-B8F1227D4151}"= UDP:c:\program files\ApexDC++\ApexDC.exe:ApexDC++ - Pinnacle of File Sharing
"{18BCBFE1-72A5-4EDD-91FF-DBB4CED7CC00}"= TCP:c:\program files\ApexDC++\ApexDC.exe:ApexDC++ - Pinnacle of File Sharing
"{3A3DEC64-8C1C-4626-8E0D-8B91B9293D7D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8AE5B72A-B5E3-4E6B-94A0-3DDC8E3CA09A}"= TCP:67:0.0.0.0:DHCP Discovery Service
"{34AF3807-0DA3-48F9-BA7C-ED7B7810CCD4}"= UDP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{F7956B14-E376-4FA0-A88C-DCD45C525207}"= TCP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{36D686CA-ED61-4EC6-821B-43177FAB1350}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D433F1D4-DF77-4873-94EF-AC3EFDBD4266}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{62A7A877-505A-4B41-8FE6-F68782D6E84D}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{7F71CED3-2BF7-430E-9D7B-C82C2508475F}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 glaide32;glaide32;c:\windows\system32\drivers\glaide32.sys [x]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20070921.001\IDSvix86.sys [2007-09-13 180272]
R2 MrHealthyService;MrHealthy;c:\program files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe [2009-01-29 578920]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2006-12-03 37008]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a8a65ff-88bf-11dd-b205-ff778f8db775}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
.
- - - - ORPHANS REMOVED - - - -
HKLM-RunOnce- - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://queensu.ca/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-11 23:05
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\system32\drivers\UACmsvcpmbnjrreeoe.sys 53248 bytes executable
c:\users\Kathey\AppData\Local\Temp\UAC000 0 bytes
c:\users\Kathey\AppData\Local\Temp\UAC3fdc.tmp 681472 bytes executable
c:\windows\system32\UACghpaeitblnkhinx.dll 19456 bytes executable
c:\windows\system32\UACgxqmwdruqbnpobi.dat 224 bytes
c:\windows\system32\UACmguycyymworakgv.log 21689 bytes
c:\windows\system32\UACmiloxhibjbfvkts.dll 25088 bytes executable
c:\windows\system32\UACnkxqyjttufbgusk.dll 17408 bytes executable
c:\windows\system32\UACrsjllydicbuwyrj.dll 66560 bytes executable
c:\windows\system32\UACrtvnpwpdtoksjqt.dll 19968 bytes executable
scan completed successfully
hidden files: 10
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\UACd.sys]
"imagepath"="\systemroot\system32\drivers\UACmsvcpmbnjrreeoe.sys"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(1920)
c:\program files\Pure Networks\Network Magic\nmrsrc.dll
.
Completion time: 2009-07-12 23:07
ComboFix-quarantined-files.txt 2009-07-12 03:07
ComboFix2.txt 2008-06-12 02:34
Pre-Run: 64,766,668,800 bytes free
Post-Run: 64,646,119,424 bytes free
233 — E O F — 2009-05-13 22:42
And then this is in normal mode
ComboFix 09-07-09.08 - Kathey 11/07/2009 23:26.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.2038.1233 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combofix.exe.exe
SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Microsoft\Windows\Start Menu\PAV
c:\programdata\Microsoft\Windows\Start Menu\PAV\Personal Antivirus.lnk
c:\programdata\Microsoft\Windows\Start Menu\PAV\Uninstall.lnk
c:\programdata\rajadeda\rajadeda.dll
c:\users\Kathey\a.exe
c:\users\Kathey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rncsys32.exe
c:\users\Kathey\AppData\Roaming\wiaserva.log
c:\users\Kathey\Desktop\Personal Antivirus.lnk
c:\windows\Installer\216f4.msi
c:\windows\system32\drivers\UACmsvcpmbnjrreeoe.sys
c:\windows\system32\UACghpaeitblnkhinx.dll
c:\windows\system32\UACgxqmwdruqbnpobi.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiojvwmyhcknuvsv.log
c:\windows\system32\UACmguycyymworakgv.log
c:\windows\system32\UACmiloxhibjbfvkts.dll
c:\windows\system32\UACnkxqyjttufbgusk.dll
c:\windows\system32\UACrsjllydicbuwyrj.dll
c:\windows\system32\UACrtvnpwpdtoksjqt.dll
c:\windows\system32\UACtwwmixarcjocwok.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
——-\Service_glaide32
((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.
2009-07-12 03:30 . 2009-07-12 03:33 ——– d—–w- c:\users\Kathey\AppData\Local\temp
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\pipiwuhi
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\judinoyo
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\babetafu
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\jakonehu
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\bufetoyo
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\fuyayeka
2009-06-18 03:58 . 2009-06-18 03:59 ——– d-s—w- C:\program.exe
2009-06-16 03:21 . 2007-05-16 06:24 172032 —-a-w- c:\windows\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-12 03:30 . 2009-06-01 17:09 ——– d—–w- c:\programdata\rajadeda
2009-07-12 03:17 . 2007-08-15 23:42 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-07-12 03:17 . 2007-08-15 23:42 ——– d—–w- c:\programdata\Symantec
2009-07-12 03:17 . 2007-08-15 23:42 ——– d—–w- c:\program files\Symantec
2009-07-12 03:10 . 2009-05-26 23:07 ——– d—–w- c:\programdata\weyalomi
2009-07-12 03:10 . 2009-05-26 23:07 ——– d—–w- c:\programdata\tesidaye
2009-07-12 03:10 . 2009-05-26 23:07 ——– d—–w- c:\programdata\bemetanu
2009-07-12 03:10 . 2009-04-12 03:10 49664 –sha-w- c:\programdata\fuyayeka\fuyayeka.dll
2009-07-12 03:10 . 2009-04-12 03:10 84992 –sha-w- c:\programdata\bufetoyo\bufetoyo.dll
2009-07-12 03:10 . 2009-04-12 03:10 79872 –sha-w- c:\programdata\jakonehu\jakonehu.dll
2009-06-16 03:30 . 2008-04-17 17:38 1356 —-a-w- c:\users\Kathey\AppData\Local\d3d9caps.dat
2009-06-05 00:06 . 2009-06-05 00:06 ——– d—–w- c:\programdata\fudoneze
2009-06-05 00:06 . 2009-03-05 00:06 81408 –sha-w- c:\programdata\senifetu\senifetu.dll
2009-06-05 00:06 . 2009-03-05 00:06 80384 –sha-w- c:\programdata\fudoneze\fudoneze.dll
2009-06-05 00:06 . 2009-06-05 00:06 ——– d—–w- c:\programdata\senifetu
2009-06-01 17:09 . 2009-03-01 17:09 82432 –sha-w- c:\programdata\kebivozu\kebivozu.dll
2009-06-01 17:09 . 2009-06-01 17:09 ——– d—–w- c:\programdata\kebivozu
2009-06-01 05:09 . 2009-06-01 05:09 ——– d—–w- c:\programdata\modisemi
2009-06-01 05:09 . 2009-03-01 05:09 80896 –sha-w- c:\programdata\lugarine\lugarine.dll
2009-06-01 05:09 . 2009-03-01 05:09 79360 ——w- c:\programdata\modisemi\modisemi.dll
2009-06-01 05:09 . 2009-06-01 05:09 ——– d—–w- c:\programdata\lugarine
2009-05-31 18:40 . 2009-05-31 18:40 ——– d—–w- c:\program files\Common Files\Uninstall
2009-05-31 17:09 . 2009-05-31 17:09 ——– d—–w- c:\programdata\rinihuye
2009-05-31 17:09 . 1601-01-01 00:12 80896 –sha-w- c:\programdata\wimavogu\wimavogu.dll
2009-05-31 17:09 . 1601-01-01 00:12 79360 ——w- c:\programdata\rinihuye\rinihuye.dll
2009-05-31 17:09 . 2009-05-31 17:09 ——– d—–w- c:\programdata\wimavogu
2009-05-31 04:35 . 2009-05-30 21:49 ——– d—–w- c:\programdata\nilezisu
2009-05-30 21:49 . 1601-01-01 00:12 79360 ——w- c:\programdata\nilezisu\nilezisu.dll
2009-05-30 21:49 . 1601-01-01 00:12 80896 –sha-w- c:\programdata\zidutufi\zidutufi.dll
2009-05-30 21:49 . 2009-05-30 21:49 ——– d—–w- c:\programdata\zidutufi
2009-05-30 10:10 . 2009-05-30 09:49 ——– d—–w- c:\programdata\rojideze
2009-05-30 09:49 . 1601-01-01 00:12 81408 –sha-w- c:\programdata\lusajuwo\lusajuwo.dll
2009-05-30 09:49 . 1601-01-01 00:12 80896 ——w- c:\programdata\rojideze\rojideze.dll
2009-05-30 09:49 . 2009-05-30 09:49 ——– d—–w- c:\programdata\lusajuwo
2009-05-29 22:11 . 2009-05-29 21:49 ——– d—–w- c:\programdata\tutepega
2009-05-29 21:49 . 1601-01-01 00:12 80896 ——w- c:\programdata\tutepega\tutepega.dll
2009-05-29 21:49 . 1601-01-01 00:12 81408 –sha-w- c:\programdata\zahuzihi\zahuzihi.dll
2009-05-29 21:49 . 2009-05-29 21:49 ——– d—–w- c:\programdata\zahuzihi
2009-05-28 23:12 . 2009-05-28 00:23 ——– d—–w- c:\programdata\dararudi
2009-05-28 22:51 . 2009-05-28 22:51 ——– d—–w- c:\programdata\vuseyiju
2009-05-28 22:51 . 2009-02-28 22:51 79872 –sha-w- c:\programdata\vuseyiju\vuseyiju.dll
2009-05-28 22:51 . 2009-02-28 22:51 81920 –sha-w- c:\programdata\mohohimu\mohohimu.dll
2009-05-28 22:51 . 2009-05-28 22:51 ——– d—–w- c:\programdata\mohohimu
2009-05-28 00:23 . 2009-05-28 00:23 ——– d—–w- c:\programdata\ganoseho
2009-05-28 00:23 . 2009-02-28 00:23 82432 –sha-w- c:\programdata\ganoseho\ganoseho.dll
2009-05-28 00:23 . 2009-02-28 00:23 80384 ——w- c:\programdata\dararudi\dararudi.dll
2009-05-27 02:20 . 2009-05-26 23:07 ——– d—–w- c:\programdata\lezuyawo
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\programdata\tosilihu
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\programdata\lotibuye
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\programdata\giseyeyi
2009-05-26 23:07 . 2009-02-26 23:07 48640 –sha-w- c:\programdata\dayugapu\dayugapu.dll
2009-05-26 23:07 . 2009-02-26 23:07 80896 ——w- c:\programdata\lezuyawo\lezuyawo.dll
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\programdata\mahogiwe
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\programdata\dayugapu
2009-05-26 23:07 . 2009-02-26 23:07 81408 –sha-w- c:\programdata\mahogiwe\mahogiwe.dll
2009-05-26 11:28 . 2009-05-26 11:07 ——– d—–w- c:\programdata\jezegunu
2009-05-26 11:07 . 2009-02-26 11:07 78848 ——w- c:\programdata\jezegunu\jezegunu.dll
2009-05-26 11:07 . 2009-02-26 11:07 81920 –sha-w- c:\programdata\fupuvuyu\fupuvuyu.dll
2009-05-26 11:07 . 2009-05-26 11:07 ——– d—–w- c:\programdata\fupuvuyu
2009-05-26 02:49 . 2009-01-08 18:41 ——– d—–w- c:\users\Kathey\AppData\Roaming\ZoomBrowser EX
2009-05-26 02:15 . 2009-01-08 18:39 ——– d—–w- c:\users\Kathey\AppData\Roaming\CameraWindowDC
2009-05-25 23:28 . 2009-05-25 23:07 ——– d—–w- c:\programdata\vabuwida
2009-05-25 23:07 . 2009-02-25 23:07 81920 –sha-w- c:\programdata\moyomego\moyomego.dll
2009-05-25 23:07 . 2009-02-25 23:07 78848 ——w- c:\programdata\vabuwida\vabuwida.dll
2009-05-25 23:07 . 2009-05-25 23:07 ——– d—–w- c:\programdata\moyomego
2009-05-25 02:14 . 2009-05-25 01:53 ——– d—–w- c:\programdata\muzupera
2009-05-25 01:53 . 2009-05-25 01:53 ——– d—–w- c:\programdata\vajetezo
2009-05-25 01:53 . 2009-02-25 01:53 81920 –sha-w- c:\programdata\vajetezo\vajetezo.dll
2009-05-25 01:53 . 2009-02-25 01:53 78848 ——w- c:\programdata\muzupera\muzupera.dll
2009-05-24 00:15 . 2009-05-22 22:29 ——– d—–w- c:\programdata\lakopayi
2009-05-22 22:29 . 2009-05-20 22:24 ——– d—–w- c:\programdata\wupoyahi
2009-05-22 22:29 . 2009-02-22 22:29 81920 –sha-w- c:\programdata\yeteyohi\yeteyohi.dll
2009-05-22 22:29 . 2009-02-22 22:29 78848 ——w- c:\programdata\lakopayi\lakopayi.dll
2009-05-22 22:29 . 2009-05-22 22:29 ——– d—–w- c:\programdata\yeteyohi
2009-05-21 22:09 . 2009-05-21 22:09 ——– d—–w- c:\programdata\wojigovu
2009-05-21 22:09 . 2009-02-21 22:09 81920 –sha-w- c:\programdata\sunufajo\sunufajo.dll
2009-05-21 22:09 . 2009-02-21 22:09 78848 –sha-w- c:\programdata\wojigovu\wojigovu.dll
2009-05-21 22:09 . 2009-05-21 22:09 ——– d—–w- c:\programdata\sunufajo
2009-05-20 22:24 . 2009-05-20 22:24 ——– d—–w- c:\programdata\hozefudu
2009-05-20 22:24 . 2009-02-20 22:24 81920 –sha-w- c:\programdata\hozefudu\hozefudu.dll
2009-05-20 22:24 . 2009-02-20 22:24 78848 ——w- c:\programdata\wupoyahi\wupoyahi.dll
2009-05-20 10:45 . 2009-05-20 10:24 ——– d—–w- c:\programdata\yilipagi
2009-05-20 10:24 . 2009-02-20 10:24 81920 –sha-w- c:\programdata\wupuyera\wupuyera.dll
2009-05-20 10:24 . 2009-02-20 10:24 78848 ——w- c:\programdata\yilipagi\yilipagi.dll
2009-05-20 10:24 . 2009-05-20 10:24 ——– d—–w- c:\programdata\wupuyera
2009-05-19 22:45 . 2009-05-19 22:23 ——– d—–w- c:\programdata\vibevije
2009-05-19 22:23 . 2009-02-19 22:23 81920 –sha-w- c:\programdata\kagejade\kagejade.dll
2009-05-19 22:23 . 2009-05-19 22:23 ——– d—–w- c:\programdata\kagejade
2009-05-19 22:23 . 2009-02-19 22:23 78848 ——w- c:\programdata\vibevije\vibevije.dll
2009-05-19 22:23 . 2009-05-18 19:55 ——– d—–w- c:\programdata\gosezale
2009-05-18 19:55 . 2009-02-18 19:55 81920 –sha-w- c:\programdata\yadubupi\yadubupi.dll
2009-05-18 19:55 . 2009-02-18 19:55 78848 ——w- c:\programdata\gosezale\gosezale.dll
2009-05-18 19:55 . 2009-05-18 19:55 ——– d—–w- c:\programdata\yadubupi
2009-05-18 08:16 . 2009-05-18 07:55 ——– d—–w- c:\programdata\rahawufi
2009-05-18 07:55 . 2009-02-18 07:55 81920 –sha-w- c:\programdata\dunahewa\dunahewa.dll
2009-05-18 07:55 . 2009-02-18 07:55 78848 ——w- c:\programdata\rahawufi\rahawufi.dll
2009-05-18 07:55 . 2009-05-18 07:55 ——– d—–w- c:\programdata\dunahewa
2009-05-17 20:16 . 2009-05-17 19:55 ——– d—–w- c:\programdata\navaguke
2009-05-17 19:55 . 2009-02-17 19:55 81920 –sha-w- c:\programdata\lugopuko\lugopuko.dll
2009-05-17 19:55 . 2009-02-17 19:55 78848 ——w- c:\programdata\navaguke\navaguke.dll
2007-08-16 07:17 . 2007-08-16 07:14 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ida"="c:\program files\Ida\IdaLaunch.exe" [2007-09-01 32136]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"CPMed47e48d"="c:\programdata\bufetoyo\bufetoyo.dll" [2009-07-12 84992]
"henugamupu"="c:\programdata\pipiwuhi\pipiwuhi.dll" [2009-04-12 49664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-06-25 405504]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 17920]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2007-03-14 321088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
c:\users\Kathey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
OneNote Table Of Contents.onetoc2 [2008-9-1 3656]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A41F51A2-4BA6-4E0F-B976-D8211BFB577B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5641C23F-8F46-4572-8DAD-CD59187E4E37}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{37EBEF9F-C5CA-4598-B6DA-7FCF8169D93D}"= c:\program files\Dell\MediaDirect\PowerCinema.exe:CyberLink PowerCinema
"{060318CD-695E-4F0C-8610-A2DC3A7C2382}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{0C67E48B-1053-4B5D-9730-E261DBE817DA}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{52AF30A5-0192-4ED4-A819-D89F48896206}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{FEDFD9DB-6160-4A91-A360-78E801541C68}"= UDP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{5D3E2CB8-50A8-4653-A34E-7A479CFDBC89}"= TCP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{8C9B90A2-E9D4-4501-8E87-B8F1227D4151}"= UDP:c:\program files\ApexDC++\ApexDC.exe:ApexDC++ - Pinnacle of File Sharing
"{18BCBFE1-72A5-4EDD-91FF-DBB4CED7CC00}"= TCP:c:\program files\ApexDC++\ApexDC.exe:ApexDC++ - Pinnacle of File Sharing
"{3A3DEC64-8C1C-4626-8E0D-8B91B9293D7D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8AE5B72A-B5E3-4E6B-94A0-3DDC8E3CA09A}"= TCP:67:0.0.0.0:DHCP Discovery Service
"{34AF3807-0DA3-48F9-BA7C-ED7B7810CCD4}"= UDP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{F7956B14-E376-4FA0-A88C-DCD45C525207}"= TCP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{36D686CA-ED61-4EC6-821B-43177FAB1350}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D433F1D4-DF77-4873-94EF-AC3EFDBD4266}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{62A7A877-505A-4B41-8FE6-F68782D6E84D}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{7F71CED3-2BF7-430E-9D7B-C82C2508475F}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 MrHealthyService;MrHealthy;c:\program files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe -service –> c:\program files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-ee74d711 - c:\programdata\rajadeda\rajadeda.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://queensu.ca/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\Kathey\AppData\Roaming\Mozilla\Firefox\Profiles\jnjnyspw.default\
FF - prefs.js: browser.startup.homepage - hxxp://facebook.com/
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-11 23:33
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\users\Kathey\AppData\Roaming\Microsoft\Windows\Cookies\kathey@purenetworks[1].txt 114 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(4012)
c:\programdata\bufetoyo\bufetoyo.dll
c:\programdata\pipiwuhi\pipiwuhi.dll
c:\program files\Pure Networks\Network Magic\nmrsrc.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\System32\stacsv.exe
c:\progra~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Pure Networks\Network Magic\nmsrvc.exe
c:\windows\System32\conime.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Completion time: 2009-07-12 23:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-12 03:37
ComboFix2.txt 2009-07-12 03:07
ComboFix3.txt 2008-06-12 02:34
Pre-Run: 61,904,211,968 bytes free
Post-Run: 61,518,245,888 bytes free
288 — E O F — 2009-05-13 22:42
This is a combofix log in safemode
ComboFix 09-06-17.02 - Kathey 11/07/2009 23:03.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.2038.1665 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combofix.exe.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\PAV
c:\program files\PAV\pav.exe
c:\windows\system32\drivers\glaide32.sys
c:\windows\system32\uacinit.dll
c:\windows\system32\winexplorer.dll
.
((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.
2009-06-18 03:58 . 2009-06-18 03:59 ——– d-s—w- C:\program.exe
2009-06-16 03:21 . 2007-05-16 06:24 172032 —-a-w- c:\windows\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 03:30 . 2008-04-17 17:38 1356 —-a-w- c:\users\Kathey\AppData\Local\d3d9caps.dat
2009-06-05 00:15 . 2009-06-01 17:09 ——– d—–w- c:\progra~2\rajadeda
2009-06-05 00:06 . 2009-06-05 00:06 ——– d—–w- c:\progra~2\fudoneze
2009-06-05 00:06 . 2009-06-05 00:06 ——– d—–w- c:\progra~2\senifetu
2009-06-01 17:09 . 2009-06-01 17:09 ——– d—–w- c:\progra~2\kebivozu
2009-06-01 05:09 . 2009-06-01 05:09 ——– d—–w- c:\progra~2\modisemi
2009-06-01 05:09 . 2009-06-01 05:09 ——– d—–w- c:\progra~2\lugarine
2009-05-31 18:40 . 2009-05-31 18:40 ——– d—–w- c:\program files\Common Files\Uninstall
2009-05-31 17:09 . 2009-05-31 17:09 ——– d—–w- c:\progra~2\rinihuye
2009-05-31 17:09 . 2009-05-31 17:09 ——– d—–w- c:\progra~2\wimavogu
2009-05-31 04:35 . 2009-05-30 21:49 ——– d—–w- c:\progra~2\nilezisu
2009-05-30 21:49 . 2009-05-30 21:49 ——– d—–w- c:\progra~2\zidutufi
2009-05-30 10:10 . 2009-05-30 09:49 ——– d—–w- c:\progra~2\rojideze
2009-05-30 09:49 . 2009-05-30 09:49 ——– d—–w- c:\progra~2\lusajuwo
2009-05-29 22:11 . 2009-05-29 21:49 ——– d—–w- c:\progra~2\tutepega
2009-05-29 21:49 . 2009-05-29 21:49 ——– d—–w- c:\progra~2\zahuzihi
2009-05-28 23:12 . 2009-05-28 00:23 ——– d—–w- c:\progra~2\dararudi
2009-05-28 22:51 . 2009-05-28 22:51 ——– d—–w- c:\progra~2\vuseyiju
2009-05-28 22:51 . 2009-05-28 22:51 ——– d—–w- c:\progra~2\mohohimu
2009-05-28 00:23 . 2009-05-28 00:23 ——– d—–w- c:\progra~2\ganoseho
2009-05-27 02:20 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\lezuyawo
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\weyalomi
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\tesidaye
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\bemetanu
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\progra~2\tosilihu
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\progra~2\lotibuye
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\progra~2\giseyeyi
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\mahogiwe
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\progra~2\dayugapu
2009-05-26 11:28 . 2009-05-26 11:07 ——– d—–w- c:\progra~2\jezegunu
2009-05-26 11:07 . 2009-05-26 11:07 ——– d—–w- c:\progra~2\fupuvuyu
2009-05-26 02:49 . 2009-01-08 18:41 ——– d—–w- c:\users\Kathey\AppData\Roaming\ZoomBrowser EX
2009-05-26 02:15 . 2009-01-08 18:39 ——– d—–w- c:\users\Kathey\AppData\Roaming\CameraWindowDC
2009-05-25 23:28 . 2009-05-25 23:07 ——– d—–w- c:\progra~2\vabuwida
2009-05-25 23:07 . 2009-05-25 23:07 ——– d—–w- c:\progra~2\moyomego
2009-05-25 02:14 . 2009-05-25 01:53 ——– d—–w- c:\progra~2\muzupera
2009-05-25 01:53 . 2009-05-25 01:53 ——– d—–w- c:\progra~2\vajetezo
2009-05-24 00:15 . 2009-05-22 22:29 ——– d—–w- c:\progra~2\lakopayi
2009-05-22 22:29 . 2009-05-20 22:24 ——– d—–w- c:\progra~2\wupoyahi
2009-05-22 22:29 . 2009-05-22 22:29 ——– d—–w- c:\progra~2\yeteyohi
2009-05-21 22:09 . 2009-05-21 22:09 ——– d—–w- c:\progra~2\wojigovu
2009-05-21 22:09 . 2009-05-21 22:09 ——– d—–w- c:\progra~2\sunufajo
2009-05-20 22:24 . 2009-05-20 22:24 ——– d—–w- c:\progra~2\hozefudu
2009-05-20 10:45 . 2009-05-20 10:24 ——– d—–w- c:\progra~2\yilipagi
2009-05-20 10:24 . 2009-05-20 10:24 ——– d—–w- c:\progra~2\wupuyera
2009-05-19 22:45 . 2009-05-19 22:23 ——– d—–w- c:\progra~2\vibevije
2009-05-19 22:23 . 2009-05-19 22:23 ——– d—–w- c:\progra~2\kagejade
2009-05-19 22:23 . 2009-05-18 19:55 ——– d—–w- c:\progra~2\gosezale
2009-05-18 19:55 . 2009-05-18 19:55 ——– d—–w- c:\progra~2\yadubupi
2009-05-18 08:16 . 2009-05-18 07:55 ——– d—–w- c:\progra~2\rahawufi
2009-05-18 07:55 . 2009-05-18 07:55 ——– d—–w- c:\progra~2\dunahewa
2009-05-17 20:16 . 2009-05-17 19:55 ——– d—–w- c:\progra~2\navaguke
2009-05-17 19:55 . 2009-05-17 19:55 ——– d—–w- c:\progra~2\lugopuko
2009-05-17 17:54 . 2009-05-15 22:03 ——– d—–w- c:\progra~2\nifolije
2009-05-17 01:54 . 2009-05-17 01:54 ——– d—–w- c:\progra~2\kanejuhe
2009-05-17 01:54 . 2009-05-17 01:54 ——– d—–w- c:\progra~2\pozofohu
2009-05-15 22:03 . 2009-05-15 22:03 ——– d—–w- c:\progra~2\hutudoki
2009-05-15 03:46 . 2009-05-15 03:25 ——– d—–w- c:\progra~2\poroyoju
2009-05-15 03:25 . 2009-05-15 03:25 ——– d—–w- c:\progra~2\simageme
2009-05-14 11:54 . 2009-05-14 11:33 ——– d—–w- c:\progra~2\dupopazi
2009-05-14 11:33 . 2009-05-14 11:33 ——– d—–w- c:\progra~2\hitihofi
2009-05-13 23:57 . 2009-05-13 23:36 ——– d—–w- c:\progra~2\kiwasuge
2009-05-13 23:36 . 2009-05-13 23:36 ——– d—–w- c:\progra~2\zudawahi
2009-05-13 23:36 . 2009-05-13 23:36 ——– d—–w- c:\progra~2\zadoleso
2009-05-13 22:49 . 2009-05-13 03:14 ——– d—–w- c:\progra~2\tefiyuvu
2009-05-13 22:42 . 2007-08-15 23:39 ——– d—–w- c:\progra~2\Microsoft Help
2009-05-13 22:36 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 03:14 . 2009-05-13 03:14 ——– d—–w- c:\progra~2\ginameye
2009-05-03 17:17 . 2009-05-03 17:17 48128 —-a-w- c:\users\Kathey\a.exe
2009-04-19 02:55 . 2007-08-28 08:20 130895 —-a-w- c:\windows\hpoins18.dat
2007-08-16 07:17 . 2007-08-16 07:14 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ida"="c:\program files\Ida\IdaLaunch.exe" [2007-09-01 32136]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"henugamupu"="c:\programdata\bemetanu\bemetanu.dll" [2009-02-26 48640]
"ee74d711"="c:\programdata\rajadeda\rajadeda.dll" [2009-06-01 80384]
"CPMed47e48d"="c:\programdata\senifetu\senifetu.dll" [2009-06-05 81408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-06-25 405504]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-12-03 107112]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2006-12-03 22696]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 17920]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2007-03-14 321088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
c:\users\Kathey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
OneNote Table Of Contents.onetoc2 [2008-9-1 3656]
rncsys32.exe [2006-11-2 19968]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
c:\users\Kathey\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
OneNote Table Of Contents.onetoc2 [2008-9-1 3656]
rncsys32.exe [2006-11-2 19968]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A41F51A2-4BA6-4E0F-B976-D8211BFB577B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5641C23F-8F46-4572-8DAD-CD59187E4E37}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{37EBEF9F-C5CA-4598-B6DA-7FCF8169D93D}"= c:\program files\Dell\MediaDirect\PowerCinema.exe:CyberLink PowerCinema
"{060318CD-695E-4F0C-8610-A2DC3A7C2382}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{0C67E48B-1053-4B5D-9730-E261DBE817DA}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{52AF30A5-0192-4ED4-A819-D89F48896206}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{FEDFD9DB-6160-4A91-A360-78E801541C68}"= UDP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{5D3E2CB8-50A8-4653-A34E-7A479CFDBC89}"= TCP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{8C9B90A2-E9D4-4501-8E87-B8F1227D4151}"= UDP:c:\program files\ApexDC++\ApexDC.exe:ApexDC++ - Pinnacle of File Sharing
"{18BCBFE1-72A5-4EDD-91FF-DBB4CED7CC00}"= TCP:c:\program files\ApexDC++\ApexDC.exe:ApexDC++ - Pinnacle of File Sharing
"{3A3DEC64-8C1C-4626-8E0D-8B91B9293D7D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8AE5B72A-B5E3-4E6B-94A0-3DDC8E3CA09A}"= TCP:67:0.0.0.0:DHCP Discovery Service
"{34AF3807-0DA3-48F9-BA7C-ED7B7810CCD4}"= UDP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{F7956B14-E376-4FA0-A88C-DCD45C525207}"= TCP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{36D686CA-ED61-4EC6-821B-43177FAB1350}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D433F1D4-DF77-4873-94EF-AC3EFDBD4266}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{62A7A877-505A-4B41-8FE6-F68782D6E84D}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{7F71CED3-2BF7-430E-9D7B-C82C2508475F}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 glaide32;glaide32;c:\windows\system32\drivers\glaide32.sys [x]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20070921.001\IDSvix86.sys [2007-09-13 180272]
R2 MrHealthyService;MrHealthy;c:\program files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe [2009-01-29 578920]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2006-12-03 37008]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a8a65ff-88bf-11dd-b205-ff778f8db775}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
.
- - - - ORPHANS REMOVED - - - -
HKLM-RunOnce- - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://queensu.ca/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-11 23:05
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\system32\drivers\UACmsvcpmbnjrreeoe.sys 53248 bytes executable
c:\users\Kathey\AppData\Local\Temp\UAC000 0 bytes
c:\users\Kathey\AppData\Local\Temp\UAC3fdc.tmp 681472 bytes executable
c:\windows\system32\UACghpaeitblnkhinx.dll 19456 bytes executable
c:\windows\system32\UACgxqmwdruqbnpobi.dat 224 bytes
c:\windows\system32\UACmguycyymworakgv.log 21689 bytes
c:\windows\system32\UACmiloxhibjbfvkts.dll 25088 bytes executable
c:\windows\system32\UACnkxqyjttufbgusk.dll 17408 bytes executable
c:\windows\system32\UACrsjllydicbuwyrj.dll 66560 bytes executable
c:\windows\system32\UACrtvnpwpdtoksjqt.dll 19968 bytes executable
scan completed successfully
hidden files: 10
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\UACd.sys]
"imagepath"="\systemroot\system32\drivers\UACmsvcpmbnjrreeoe.sys"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(1920)
c:\program files\Pure Networks\Network Magic\nmrsrc.dll
.
Completion time: 2009-07-12 23:07
ComboFix-quarantined-files.txt 2009-07-12 03:07
ComboFix2.txt 2008-06-12 02:34
Pre-Run: 64,766,668,800 bytes free
Post-Run: 64,646,119,424 bytes free
233 — E O F — 2009-05-13 22:42
And then this is in normal mode
ComboFix 09-07-09.08 - Kathey 11/07/2009 23:26.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.2038.1233 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combofix.exe.exe
SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Microsoft\Windows\Start Menu\PAV
c:\programdata\Microsoft\Windows\Start Menu\PAV\Personal Antivirus.lnk
c:\programdata\Microsoft\Windows\Start Menu\PAV\Uninstall.lnk
c:\programdata\rajadeda\rajadeda.dll
c:\users\Kathey\a.exe
c:\users\Kathey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rncsys32.exe
c:\users\Kathey\AppData\Roaming\wiaserva.log
c:\users\Kathey\Desktop\Personal Antivirus.lnk
c:\windows\Installer\216f4.msi
c:\windows\system32\drivers\UACmsvcpmbnjrreeoe.sys
c:\windows\system32\UACghpaeitblnkhinx.dll
c:\windows\system32\UACgxqmwdruqbnpobi.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiojvwmyhcknuvsv.log
c:\windows\system32\UACmguycyymworakgv.log
c:\windows\system32\UACmiloxhibjbfvkts.dll
c:\windows\system32\UACnkxqyjttufbgusk.dll
c:\windows\system32\UACrsjllydicbuwyrj.dll
c:\windows\system32\UACrtvnpwpdtoksjqt.dll
c:\windows\system32\UACtwwmixarcjocwok.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
——-\Service_glaide32
((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.
2009-07-12 03:30 . 2009-07-12 03:33 ——– d—–w- c:\users\Kathey\AppData\Local\temp
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\pipiwuhi
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\judinoyo
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\babetafu
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\jakonehu
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\bufetoyo
2009-07-12 03:10 . 2009-07-12 03:10 ——– d—–w- c:\programdata\fuyayeka
2009-06-18 03:58 . 2009-06-18 03:59 ——– d-s—w- C:\program.exe
2009-06-16 03:21 . 2007-05-16 06:24 172032 —-a-w- c:\windows\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-12 03:30 . 2009-06-01 17:09 ——– d—–w- c:\programdata\rajadeda
2009-07-12 03:17 . 2007-08-15 23:42 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-07-12 03:17 . 2007-08-15 23:42 ——– d—–w- c:\programdata\Symantec
2009-07-12 03:17 . 2007-08-15 23:42 ——– d—–w- c:\program files\Symantec
2009-07-12 03:10 . 2009-05-26 23:07 ——– d—–w- c:\programdata\weyalomi
2009-07-12 03:10 . 2009-05-26 23:07 ——– d—–w- c:\programdata\tesidaye
2009-07-12 03:10 . 2009-05-26 23:07 ——– d—–w- c:\programdata\bemetanu
2009-07-12 03:10 . 2009-04-12 03:10 49664 –sha-w- c:\programdata\fuyayeka\fuyayeka.dll
2009-07-12 03:10 . 2009-04-12 03:10 84992 –sha-w- c:\programdata\bufetoyo\bufetoyo.dll
2009-07-12 03:10 . 2009-04-12 03:10 79872 –sha-w- c:\programdata\jakonehu\jakonehu.dll
2009-06-16 03:30 . 2008-04-17 17:38 1356 —-a-w- c:\users\Kathey\AppData\Local\d3d9caps.dat
2009-06-05 00:06 . 2009-06-05 00:06 ——– d—–w- c:\programdata\fudoneze
2009-06-05 00:06 . 2009-03-05 00:06 81408 –sha-w- c:\programdata\senifetu\senifetu.dll
2009-06-05 00:06 . 2009-03-05 00:06 80384 –sha-w- c:\programdata\fudoneze\fudoneze.dll
2009-06-05 00:06 . 2009-06-05 00:06 ——– d—–w- c:\programdata\senifetu
2009-06-01 17:09 . 2009-03-01 17:09 82432 –sha-w- c:\programdata\kebivozu\kebivozu.dll
2009-06-01 17:09 . 2009-06-01 17:09 ——– d—–w- c:\programdata\kebivozu
2009-06-01 05:09 . 2009-06-01 05:09 ——– d—–w- c:\programdata\modisemi
2009-06-01 05:09 . 2009-03-01 05:09 80896 –sha-w- c:\programdata\lugarine\lugarine.dll
2009-06-01 05:09 . 2009-03-01 05:09 79360 ——w- c:\programdata\modisemi\modisemi.dll
2009-06-01 05:09 . 2009-06-01 05:09 ——– d—–w- c:\programdata\lugarine
2009-05-31 18:40 . 2009-05-31 18:40 ——– d—–w- c:\program files\Common Files\Uninstall
2009-05-31 17:09 . 2009-05-31 17:09 ——– d—–w- c:\programdata\rinihuye
2009-05-31 17:09 . 1601-01-01 00:12 80896 –sha-w- c:\programdata\wimavogu\wimavogu.dll
2009-05-31 17:09 . 1601-01-01 00:12 79360 ——w- c:\programdata\rinihuye\rinihuye.dll
2009-05-31 17:09 . 2009-05-31 17:09 ——– d—–w- c:\programdata\wimavogu
2009-05-31 04:35 . 2009-05-30 21:49 ——– d—–w- c:\programdata\nilezisu
2009-05-30 21:49 . 1601-01-01 00:12 79360 ——w- c:\programdata\nilezisu\nilezisu.dll
2009-05-30 21:49 . 1601-01-01 00:12 80896 –sha-w- c:\programdata\zidutufi\zidutufi.dll
2009-05-30 21:49 . 2009-05-30 21:49 ——– d—–w- c:\programdata\zidutufi
2009-05-30 10:10 . 2009-05-30 09:49 ——– d—–w- c:\programdata\rojideze
2009-05-30 09:49 . 1601-01-01 00:12 81408 –sha-w- c:\programdata\lusajuwo\lusajuwo.dll
2009-05-30 09:49 . 1601-01-01 00:12 80896 ——w- c:\programdata\rojideze\rojideze.dll
2009-05-30 09:49 . 2009-05-30 09:49 ——– d—–w- c:\programdata\lusajuwo
2009-05-29 22:11 . 2009-05-29 21:49 ——– d—–w- c:\programdata\tutepega
2009-05-29 21:49 . 1601-01-01 00:12 80896 ——w- c:\programdata\tutepega\tutepega.dll
2009-05-29 21:49 . 1601-01-01 00:12 81408 –sha-w- c:\programdata\zahuzihi\zahuzihi.dll
2009-05-29 21:49 . 2009-05-29 21:49 ——– d—–w- c:\programdata\zahuzihi
2009-05-28 23:12 . 2009-05-28 00:23 ——– d—–w- c:\programdata\dararudi
2009-05-28 22:51 . 2009-05-28 22:51 ——– d—–w- c:\programdata\vuseyiju
2009-05-28 22:51 . 2009-02-28 22:51 79872 –sha-w- c:\programdata\vuseyiju\vuseyiju.dll
2009-05-28 22:51 . 2009-02-28 22:51 81920 –sha-w- c:\programdata\mohohimu\mohohimu.dll
2009-05-28 22:51 . 2009-05-28 22:51 ——– d—–w- c:\programdata\mohohimu
2009-05-28 00:23 . 2009-05-28 00:23 ——– d—–w- c:\programdata\ganoseho
2009-05-28 00:23 . 2009-02-28 00:23 82432 –sha-w- c:\programdata\ganoseho\ganoseho.dll
2009-05-28 00:23 . 2009-02-28 00:23 80384 ——w- c:\programdata\dararudi\dararudi.dll
2009-05-27 02:20 . 2009-05-26 23:07 ——– d—–w- c:\programdata\lezuyawo
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\programdata\tosilihu
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\programdata\lotibuye
2009-05-26 23:07 . 2009-05-05 22:59 ——– d—–w- c:\programdata\giseyeyi
2009-05-26 23:07 . 2009-02-26 23:07 48640 –sha-w- c:\programdata\dayugapu\dayugapu.dll
2009-05-26 23:07 . 2009-02-26 23:07 80896 ——w- c:\programdata\lezuyawo\lezuyawo.dll
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\programdata\mahogiwe
2009-05-26 23:07 . 2009-05-26 23:07 ——– d—–w- c:\programdata\dayugapu
2009-05-26 23:07 . 2009-02-26 23:07 81408 –sha-w- c:\programdata\mahogiwe\mahogiwe.dll
2009-05-26 11:28 . 2009-05-26 11:07 ——– d—–w- c:\programdata\jezegunu
2009-05-26 11:07 . 2009-02-26 11:07 78848 ——w- c:\programdata\jezegunu\jezegunu.dll
2009-05-26 11:07 . 2009-02-26 11:07 81920 –sha-w- c:\programdata\fupuvuyu\fupuvuyu.dll
2009-05-26 11:07 . 2009-05-26 11:07 ——– d—–w- c:\programdata\fupuvuyu
2009-05-26 02:49 . 2009-01-08 18:41 ——– d—–w- c:\users\Kathey\AppData\Roaming\ZoomBrowser EX
2009-05-26 02:15 . 2009-01-08 18:39 ——– d—–w- c:\users\Kathey\AppData\Roaming\CameraWindowDC
2009-05-25 23:28 . 2009-05-25 23:07 ——– d—–w- c:\programdata\vabuwida
2009-05-25 23:07 . 2009-02-25 23:07 81920 –sha-w- c:\programdata\moyomego\moyomego.dll
2009-05-25 23:07 . 2009-02-25 23:07 78848 ——w- c:\programdata\vabuwida\vabuwida.dll
2009-05-25 23:07 . 2009-05-25 23:07 ——– d—–w- c:\programdata\moyomego
2009-05-25 02:14 . 2009-05-25 01:53 ——– d—–w- c:\programdata\muzupera
2009-05-25 01:53 . 2009-05-25 01:53 ——– d—–w- c:\programdata\vajetezo
2009-05-25 01:53 . 2009-02-25 01:53 81920 –sha-w- c:\programdata\vajetezo\vajetezo.dll
2009-05-25 01:53 . 2009-02-25 01:53 78848 ——w- c:\programdata\muzupera\muzupera.dll
2009-05-24 00:15 . 2009-05-22 22:29 ——– d—–w- c:\programdata\lakopayi
2009-05-22 22:29 . 2009-05-20 22:24 ——– d—–w- c:\programdata\wupoyahi
2009-05-22 22:29 . 2009-02-22 22:29 81920 –sha-w- c:\programdata\yeteyohi\yeteyohi.dll
2009-05-22 22:29 . 2009-02-22 22:29 78848 ——w- c:\programdata\lakopayi\lakopayi.dll
2009-05-22 22:29 . 2009-05-22 22:29 ——– d—–w- c:\programdata\yeteyohi
2009-05-21 22:09 . 2009-05-21 22:09 ——– d—–w- c:\programdata\wojigovu
2009-05-21 22:09 . 2009-02-21 22:09 81920 –sha-w- c:\programdata\sunufajo\sunufajo.dll
2009-05-21 22:09 . 2009-02-21 22:09 78848 –sha-w- c:\programdata\wojigovu\wojigovu.dll
2009-05-21 22:09 . 2009-05-21 22:09 ——– d—–w- c:\programdata\sunufajo
2009-05-20 22:24 . 2009-05-20 22:24 ——– d—–w- c:\programdata\hozefudu
2009-05-20 22:24 . 2009-02-20 22:24 81920 –sha-w- c:\programdata\hozefudu\hozefudu.dll
2009-05-20 22:24 . 2009-02-20 22:24 78848 ——w- c:\programdata\wupoyahi\wupoyahi.dll
2009-05-20 10:45 . 2009-05-20 10:24 ——– d—–w- c:\programdata\yilipagi
2009-05-20 10:24 . 2009-02-20 10:24 81920 –sha-w- c:\programdata\wupuyera\wupuyera.dll
2009-05-20 10:24 . 2009-02-20 10:24 78848 ——w- c:\programdata\yilipagi\yilipagi.dll
2009-05-20 10:24 . 2009-05-20 10:24 ——– d—–w- c:\programdata\wupuyera
2009-05-19 22:45 . 2009-05-19 22:23 ——– d—–w- c:\programdata\vibevije
2009-05-19 22:23 . 2009-02-19 22:23 81920 –sha-w- c:\programdata\kagejade\kagejade.dll
2009-05-19 22:23 . 2009-05-19 22:23 ——– d—–w- c:\programdata\kagejade
2009-05-19 22:23 . 2009-02-19 22:23 78848 ——w- c:\programdata\vibevije\vibevije.dll
2009-05-19 22:23 . 2009-05-18 19:55 ——– d—–w- c:\programdata\gosezale
2009-05-18 19:55 . 2009-02-18 19:55 81920 –sha-w- c:\programdata\yadubupi\yadubupi.dll
2009-05-18 19:55 . 2009-02-18 19:55 78848 ——w- c:\programdata\gosezale\gosezale.dll
2009-05-18 19:55 . 2009-05-18 19:55 ——– d—–w- c:\programdata\yadubupi
2009-05-18 08:16 . 2009-05-18 07:55 ——– d—–w- c:\programdata\rahawufi
2009-05-18 07:55 . 2009-02-18 07:55 81920 –sha-w- c:\programdata\dunahewa\dunahewa.dll
2009-05-18 07:55 . 2009-02-18 07:55 78848 ——w- c:\programdata\rahawufi\rahawufi.dll
2009-05-18 07:55 . 2009-05-18 07:55 ——– d—–w- c:\programdata\dunahewa
2009-05-17 20:16 . 2009-05-17 19:55 ——– d—–w- c:\programdata\navaguke
2009-05-17 19:55 . 2009-02-17 19:55 81920 –sha-w- c:\programdata\lugopuko\lugopuko.dll
2009-05-17 19:55 . 2009-02-17 19:55 78848 ——w- c:\programdata\navaguke\navaguke.dll
2007-08-16 07:17 . 2007-08-16 07:14 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ida"="c:\program files\Ida\IdaLaunch.exe" [2007-09-01 32136]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"CPMed47e48d"="c:\programdata\bufetoyo\bufetoyo.dll" [2009-07-12 84992]
"henugamupu"="c:\programdata\pipiwuhi\pipiwuhi.dll" [2009-04-12 49664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-06-25 405504]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 17920]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2007-03-14 321088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
c:\users\Kathey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
OneNote Table Of Contents.onetoc2 [2008-9-1 3656]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A41F51A2-4BA6-4E0F-B976-D8211BFB577B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5641C23F-8F46-4572-8DAD-CD59187E4E37}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{37EBEF9F-C5CA-4598-B6DA-7FCF8169D93D}"= c:\program files\Dell\MediaDirect\PowerCinema.exe:CyberLink PowerCinema
"{060318CD-695E-4F0C-8610-A2DC3A7C2382}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{0C67E48B-1053-4B5D-9730-E261DBE817DA}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{52AF30A5-0192-4ED4-A819-D89F48896206}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{FEDFD9DB-6160-4A91-A360-78E801541C68}"= UDP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{5D3E2CB8-50A8-4653-A34E-7A479CFDBC89}"= TCP:c:\program files\FrostWire\FrostWire.exe:LimeWire
"{8C9B90A2-E9D4-4501-8E87-B8F1227D4151}"= UDP:c:\program files\ApexDC++\ApexDC.exe:ApexDC++ - Pinnacle of File Sharing
"{18BCBFE1-72A5-4EDD-91FF-DBB4CED7CC00}"= TCP:c:\program files\ApexDC++\ApexDC.exe:ApexDC++ - Pinnacle of File Sharing
"{3A3DEC64-8C1C-4626-8E0D-8B91B9293D7D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8AE5B72A-B5E3-4E6B-94A0-3DDC8E3CA09A}"= TCP:67:0.0.0.0:DHCP Discovery Service
"{34AF3807-0DA3-48F9-BA7C-ED7B7810CCD4}"= UDP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{F7956B14-E376-4FA0-A88C-DCD45C525207}"= TCP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe:Pure Networks Network Magic Service
"{36D686CA-ED61-4EC6-821B-43177FAB1350}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D433F1D4-DF77-4873-94EF-AC3EFDBD4266}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{62A7A877-505A-4B41-8FE6-F68782D6E84D}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{7F71CED3-2BF7-430E-9D7B-C82C2508475F}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 MrHealthyService;MrHealthy;c:\program files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe -service –> c:\program files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-ee74d711 - c:\programdata\rajadeda\rajadeda.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://queensu.ca/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\Kathey\AppData\Roaming\Mozilla\Firefox\Profiles\jnjnyspw.default\
FF - prefs.js: browser.startup.homepage - hxxp://facebook.com/
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-11 23:33
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\users\Kathey\AppData\Roaming\Microsoft\Windows\Cookies\kathey@purenetworks[1].txt 114 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(4012)
c:\programdata\bufetoyo\bufetoyo.dll
c:\programdata\pipiwuhi\pipiwuhi.dll
c:\program files\Pure Networks\Network Magic\nmrsrc.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Norton PC Checkup\executables\mrHealthy\MrHealthy.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\System32\stacsv.exe
c:\progra~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Pure Networks\Network Magic\nmsrvc.exe
c:\windows\System32\conime.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Completion time: 2009-07-12 23:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-12 03:37
ComboFix2.txt 2009-07-12 03:07
ComboFix3.txt 2008-06-12 02:34
Pre-Run: 61,904,211,968 bytes free
Post-Run: 61,518,245,888 bytes free
288 — E O F — 2009-05-13 22:42