heres the log
_____________
ComboFix 09-09-03.02 - dhiraj 4-Sep-2009 8:37.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526.1050 [GMT 5.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\program files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\docs\gs_clnt.pdf
c:\program files\Symantec Client Security\Symantec AntiVirus\DoScan.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\DoScanTVT.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\DWHWizrd.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\dwLdPntScan.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\GenMar.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\I2ldvp3.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\IMail.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\LDVPREG.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\LuaWrap.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\LuHstEdt.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\Navap32.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\NAVAPI32.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\NAVLU.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\NAVNTUTL.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\nlnhook.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\nLNVP.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\nnewdefs.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\notesext.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\OEHeur.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\OEMConfigWizard.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\patch25d.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\PATCH32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\PLATFORM.DAT
c:\program files\Symantec Client Security\Symantec AntiVirus\qscomm32.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\QsInfo.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\qspak32.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\ReadMeForDoScanTVT.txt
c:\program files\Symantec Client Security\Symantec AntiVirus\Rec2.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\SAVCProd.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\SavEmail.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\savhelp.chm
c:\program files\Symantec Client Security\Symantec AntiVirus\savmain.chm
c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\savrt.cat
c:\program files\Symantec Client Security\Symantec AntiVirus\savrt.dat
c:\program files\Symantec Client Security\Symantec AntiVirus\savrt.inf
c:\program files\Symantec Client Security\Symantec AntiVirus\savrt.sys
c:\program files\Symantec Client Security\Symantec AntiVirus\SAVRT\0943NAV~.TMP
c:\program files\Symantec Client Security\Symantec AntiVirus\SavRT32.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\savrtpel.cat
c:\program files\Symantec Client Security\Symantec AntiVirus\savrtpel.inf
c:\program files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys
c:\program files\Symantec Client Security\Symantec AntiVirus\savsess.txt
c:\program files\Symantec Client Security\Symantec AntiVirus\SCANCFG.DAT
c:\program files\Symantec Client Security\Symantec AntiVirus\SCANDLVR.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SCANDRES.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SDPCK32I.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\SDSNAPSX.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\SDSND32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SDSOK32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SDSTP32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SMSTR32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SRTLEXCL.DAT
c:\program files\Symantec Client Security\Symantec AntiVirus\SRTSEXCL.DAT
c:\program files\Symantec Client Security\Symantec AntiVirus\SymProtectStorage.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\SystemSnapshotRules.bin
c:\program files\Symantec Client Security\Symantec AntiVirus\VPC32.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\VPDN_LU.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\vpmsece3.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\VPTray.exe
c:\windows\system32\019A.dat
c:\windows\system32\drivers\ecbqyvrxmxvxtuij.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_SavRoam
((((((((((((((((((((((((( Files Created from 2009-08-04 to 2009-09-04 )))))))))))))))))))))))))))))))
.
2009-09-02 17:39 . 2009-09-02 17:48 ——– d—–w- C:\Rooter$
2009-08-29 07:45 . 2009-08-29 07:45 ——– d—–w- c:\documents and settings\dhiraj\Application Data\IObit
2009-08-29 07:45 . 2009-08-29 07:45 ——– d—–w- c:\program files\IObit
2009-08-29 07:30 . 2009-08-29 07:30 0 —-a-w- c:\windows\nsreg.dat
2009-08-29 07:30 . 2009-08-29 07:30 ——– d—–w- c:\documents and settings\dhiraj\Local Settings\Application Data\Mozilla
2009-08-28 17:34 . 2009-08-28 17:34 ——– d—–w- c:\program files\Trend Micro
2009-08-24 05:59 . 2009-08-24 05:59 ——– d—–w- c:\documents and settings\dhiraj\Local Settings\Application Data\pjwjlldf
2009-08-24 05:59 . 2009-08-24 05:59 ——– d—–w- c:\documents and settings\dhiraj\Application Data\pjwjlldf
2009-08-23 06:13 . 2009-08-23 06:13 ——– d—–w- c:\windows\ie8updates
2009-08-22 23:41 . 2009-08-22 23:41 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\pjwjlldf
2009-08-22 23:41 . 2009-08-22 23:41 ——– d—–w- c:\documents and settings\NetworkService\Application Data\pjwjlldf
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Malwarebytes
2009-08-22 10:07 . 2009-08-03 08:06 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 10:07 . 2009-08-03 08:06 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 08:31 . 2009-08-22 08:31 ——– d—–w- c:\program files\NIC
2009-08-22 02:21 . 2009-08-22 02:21 ——– d—–w- c:\program files\Aladdin
2009-08-21 04:02 . 2009-08-21 04:02 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-21 03:45 . 2009-08-21 03:45 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-08-21 02:59 . 2009-07-03 17:09 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2009-08-21 02:59 . 2009-07-03 17:09 246272 ——w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-21 02:28 . 2009-08-21 02:28 ——– d—–w- c:\program files\FileSignerPlus
2009-08-20 18:35 . 2009-08-20 18:35 ——– d-sh–w- c:\documents and settings\dhiraj\IECompatCache
2009-08-20 18:34 . 2009-08-20 18:34 ——– d-sh–w- c:\documents and settings\dhiraj\PrivacIE
2009-08-20 18:31 . 2009-08-20 18:31 ——– d-sh–w- c:\documents and settings\dhiraj\IETldCache
2009-08-20 18:09 . 2009-08-20 18:10 ——– dc-h–w- c:\windows\ie8
2009-08-12 17:26 . 2009-08-12 17:26 ——– d—–w- c:\windows\ServicePackFiles
2009-08-12 16:31 . 2009-06-05 07:42 655872 ——w- c:\windows\system32\dllcache\mstscax.dll
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\program files\MSBuild
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\program files\Reference Assemblies
2009-08-12 09:33 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-12 09:33 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-12 09:33 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-12 09:33 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-12 09:33 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-12 09:33 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-12 09:33 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- C:\68d61042816a94014e
2009-08-12 09:32 . 2009-08-12 09:41 ——– d—–w- c:\windows\SxsCaPendDel
2009-08-12 09:29 . 2009-08-12 09:29 ——– d—–w- c:\program files\MSXML 6.0
2009-08-12 08:05 . 2009-08-12 08:05 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Sonic
2009-08-12 08:04 . 2009-08-12 08:04 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Leadertech
2009-08-05 09:11 . 2009-08-05 09:11 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-04 03:13 . 2008-10-22 06:47 1683744 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-09-04 03:13 . 2008-10-22 06:47 71337760 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-04 02:54 . 2007-05-20 02:36 ——– d—–w- c:\program files\Microsoft SQL Server
2009-09-04 02:42 . 2008-06-18 18:45 ——– d—–w- c:\program files\Common Files\Akamai
2009-09-03 18:26 . 2008-02-10 16:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Metacafe
2009-09-03 18:26 . 2009-04-18 04:58 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Metacafe
2009-09-03 18:26 . 2008-02-10 16:00 ——– d—–w- c:\program files\Metacafe
2009-09-03 17:17 . 2008-10-22 06:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-09-03 17:13 . 2008-10-22 06:47 956252 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-03 17:13 . 2008-10-22 06:47 159716 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-09-03 07:04 . 2009-09-03 07:04 ——– d—–w- c:\program files\ESET
2009-08-30 06:14 . 2007-05-19 03:03 5427 —-a-w- c:\windows\system32\EGATHDRV.SYS
2009-08-27 09:10 . 2009-04-11 14:29 191352 —-a-w- c:\documents and settings\dhiraj\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 17:49 . 2008-10-15 12:31 ——– d—–w- c:\program files\CCleaner
2009-08-26 01:22 . 2007-05-19 03:03 ——– d—–w- c:\program files\Google
2009-08-25 13:05 . 2007-05-19 06:45 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-08-24 06:21 . 2007-08-19 21:15 ——– d—–w- c:\program files\EphPod
2009-08-24 06:21 . 2007-05-19 02:40 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-12 08:04 . 2007-05-19 02:52 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-08-05 09:11 . 1980-01-01 07:00 204800 ——w- c:\windows\system32\mswebdvd.dll
2009-08-02 18:47 . 2009-07-31 18:59 ——– d—–w- c:\documents and settings\dhiraj\Application Data\LimeWire
2009-07-29 12:13 . 2009-07-29 12:12 ——– d—–w- c:\documents and settings\dhiraj\Application Data\U3
2009-07-27 19:39 . 2009-07-27 19:39 ——– d—–w- c:\program files\FLV Converter
2009-07-27 18:52 . 2009-07-27 18:52 ——– d—–w- c:\program files\KeepV Converter
2009-07-27 18:36 . 2009-07-13 05:02 ——– d—–w- c:\program files\Cucusoft
2009-07-27 18:35 . 2009-07-27 18:31 ——– d—–w- c:\documents and settings\dhiraj\Application Data\GetRightToGo
2009-07-17 18:55 . 1980-01-01 07:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 18:13 . 1980-01-01 07:00 286208 ——w- c:\windows\system32\wmpdxm.dll
2009-07-09 17:35 . 2009-07-09 17:35 ——– d—–w- c:\program files\Windows Mobile Device Handbook
2009-07-03 17:09 . 1980-01-01 07:00 915456 ——w- c:\windows\system32\wininet.dll
2009-07-01 09:46 . 2009-07-27 18:36 94854 —-a-w- c:\windows\system32\HKCU_GNU.reg
2009-06-25 18:36 . 1980-01-01 07:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 1980-01-01 07:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 1980-01-01 07:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 1980-01-01 07:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 1980-01-01 07:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 1980-01-01 07:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 1980-01-01 07:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 1980-01-01 07:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 1980-01-01 07:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 1980-01-01 07:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 1980-01-01 07:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 1980-01-01 07:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-25 08:17 . 1980-01-01 07:00 729600 ——w- c:\windows\system32\lsasrv.dll
2009-06-25 08:17 . 1980-01-01 07:00 59392 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:17 . 1980-01-01 07:00 56320 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:17 . 1980-01-01 07:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:17 . 1980-01-01 07:00 168448 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:17 . 1980-01-01 07:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:49 . 1980-01-01 07:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 1980-01-01 07:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 1980-01-01 07:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 1980-01-01 07:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-22 11:35 . 1980-01-01 07:00 92544 ——w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:55 . 1980-01-01 07:00 82432 ——w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 1980-01-01 07:00 119808 ——w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 1980-01-01 07:00 80896 ——w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 1980-01-01 07:00 76288 ——w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 1980-01-01 07:00 84992 ——w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 1980-01-01 07:00 132096 ——w- c:\windows\system32\wkssvc.dll
2009-06-08 08:59 . 2008-01-23 12:37 5194 —-a-w- c:\program files\Exportcerts.txt
2009-06-08 08:59 . 2008-01-23 12:37 34 —-a-w- c:\program files\Exportcerts1.txt
2007-06-02 03:46 . 2007-06-02 03:32 526 ——w- c:\program files\DataCardInfo.ini
2006-02-23 15:01 . 2007-06-02 03:32 0 -c—-w- c:\program files\EW600APICfg.dat
2006-01-11 11:18 . 2007-06-02 03:32 294912 ——w- c:\program files\vWTP.mdb
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-20 39408]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2005-11-07 106496]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Metacafe.lnk - c:\program files\Metacafe\MetacafeAgent.exe [2009-2-18 145736]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2007-5-20 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2005-12-22 01:42 32768 ——w- c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-12-08 21:59 39936 ——w- c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ——w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 03:16 24576 ——w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd csspwntfy
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CONE EXPERT Grey Report.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CONE EXPERT Grey Report.lnk
backup=c:\windows\pss\CONE EXPERT Grey Report.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^REPORTS.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\REPORTS.lnk
backup=c:\windows\pss\REPORTS.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Dhiraj.MAHABIR^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\Dhiraj.MAHABIR\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Dhiraj.MAHABIR^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Dhiraj.MAHABIR\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^dhiraj^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\dhiraj\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STCAgent"=2 (0x2)
"btwdins"=2 (0x2)
"ETOKSRV"=2 (0x2)
"DefWatch"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AcPrfMgrSvc"=2 (0x2)
"Autodesk Licensing Service"=3 (0x3)
"SymSecurePort"=2 (0x2)
"Symantec AntiVirus"=2 (0x2)
"SPBBCSvc"=3 (0x3)
"gusvc"=3 (0x3)
"ccPwdSvc"=3 (0x3)
"ccProxy"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4260:TCP"= 4260:TCP:@xpsp2res.dll,-22009
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [19-May-2007 8:11 AM 85760]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [19-May-2007 8:11 AM 4736]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [19-May-2007 8:34 AM 4442]
R2 Akamai;Akamai;c:\windows\System32\svchost.exe -k Akamai [01-Jan-1980 12:30 PM 14336]
R2 eTSrv;ETOKSRV;c:\program files\Aladdin\eToken\PKIClient\x32\eTSrv.exe [03-Nov-2008 1:29 PM 7168]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [22-Dec-2005 5:44 AM 12544]
R2 IntelliAdminRC3;IntelliAdminRC3;c:\windows\IntelliAdminRC3\Agent32.exe [03-Feb-2009 1:51 PM 2279904]
R2 PrivateDisk;PrivateDisk;c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\privatediskm.sys [16-Nov-2005 1:41 AM 46142]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [22-Dec-2005 5:15 AM 3968]
R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [09-Dec-2005 3:14 AM 3328]
R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;c:\windows\system32\drivers\ewusbmdm.sys [19-May-2007 12:45 PM 65152]
R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;c:\windows\system32\drivers\ewusbser.sys [19-May-2007 12:45 PM 65152]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13-Dec-2007 1:28 PM 24592]
S1 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [23-Mar-2008 8:41 PM 49792]
S3 AKSUP;AKSUP;c:\windows\system32\drivers\aksup.sys [15-Apr-2009 4:01 PM 34472]
S3 BTPCCARD;Bluetooth BCSP Transport for Pc Card;c:\windows\system32\drivers\btpcbcsp.sys [01-Jul-2003 12:30 PM 232444]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\DRIVERS\CSVirtA.sys –> c:\windows\system32\DRIVERS\CSVirtA.sys [?]
S3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys –> c:\windows\system32\drivers\vvftav303.sys [?]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\Drivers\usbVM303.sys –> c:\windows\system32\Drivers\usbVM303.sys [?]
S4 ConeExpertUCOM;ConeExpertUCOM;c:\coexpert\bin\WatchUcom.exe ConeExpertUCOM –> c:\coexpert\bin\WatchUcom.exe ConeExpertUCOM [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-01-25 c:\windows\Tasks\Dhiraj 23102008.job
- c:\windows\system32\ntbackup.exe [1980-01-01 12:00]
2009-09-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-926495626-1003886262-1936394565-1004.job
- c:\documents and settings\Dhiraj.MAHABIR\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-07 02:17]
2008-09-23 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2007-05-19 08:12]
2009-08-09 c:\windows\Tasks\Scheduled backup of T60.job
- c:\windows\system32\ntbackup.exe [1980-01-01 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.rediff.com/
IE: &Download with &DAP - c:\progra~1\DAP\dapextie.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {7A98F4DF-39CA-46EE-94E0-AC5D4D412C79} = 192.168.0.101
TCP: {BA1F53B8-1E72-466F-B978-A9FC622BCD7F} = 192.9.100.1,192.9.100.100
DPF: {23ACBF1D-D7AF-4236-AD8C-CADF14234B78} - hxxp://dgftcom.nic.in/(n)CodeDGFT_new.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} - hxxp://122.160.111.150/WebDiginet.CAB
DPF: {BE90DF74-A983-4BBB-A9C1-F2C90807F548} - hxxp://www.mca.gov.in/DCAPortalWeb/dca/jsp/mydca/pki/AssureSignControl.cab
FF - ProfilePath - c:\documents and settings\dhiraj\Application Data\Mozilla\Firefox\Profiles\2v0krwal.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.rediff.com/|http://economictimes.indiatimes.com/
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-04 08:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\docume~1\dhiraj\LOCALS~1\Temp\Perflib_Perfdata_434.dat 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\ccEvtMgr]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SAVRT]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SNDSrvc]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SYMTDI]
"ImagePath"="-"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1560)
c:\windows\system32\vrlogon.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\klogon.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\windows\system32\biologon.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\windows\system32\tphklock.dll
c:\program files\ThinkVantage Fingerprint Software\crypto.dll
c:\windows\system32\mobilev.acm
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\windows\system32\igfxdev.dll
c:\windows\system32\notifyf2.dll
- - - - - - - > 'lsass.exe'(1616)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\IBM ThinkVantage\Client Security Solution\csspwntfy.dll
c:\windows\system32\WTSAPI32.dll
c:\program files\IBM ThinkVantage\Client Security Solution\ibmtsp.dll
c:\program files\IBM ThinkVantage\Client Security Solution\tcsrpc.dll
c:\program files\IBM ThinkVantage\Client Security Solution\cssuserdatadispatcher.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
c:\program files\Bonjour\mdnsNSP.dll
- - - - - - - > 'explorer.exe'(6024)
c:\windows\system32\WININET.dll
c:\windows\system32\PROCHLP.DLL
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-09-04 8:46
ComboFix-quarantined-files.txt 2009-09-04 03:16
ComboFix2.txt 2009-08-24 12:11
Pre-Run: 10,554,216,448 bytes free
Post-Run: 10,524,327,936 bytes free
424 — E O F — 2009-08-26 12:17