Run a new combofix scan
I did it and here is the scan results. After scan, I again reconnet the network card. Again the same problem pops up " Services and controller app has stopped working "
ComboFix 10-07-31.01 - sathia.gamesh 08/01/2010 4:47.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3573.2500 [GMT 5.5:30]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-31 )))))))))))))))))))))))))))))))
.
2010-07-31 23:23 . 2010-07-31 23:23 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\temp
2010-07-31 23:23 . 2010-07-31 23:23 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
2010-07-31 23:23 . 2010-07-31 23:23 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-07-31 23:23 . 2010-07-31 23:23 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-07-31 23:16 . 2010-07-31 23:16 ——– d—–w- C:\32788R22FWJFW
2010-07-30 20:01 . 2010-07-30 20:01 0 —-a-w- c:\windows\nsreg.dat
2010-07-30 20:01 . 2010-07-30 20:01 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Mozilla
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Malwarebytes
2010-07-30 18:14 . 2010-04-29 10:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\programdata\Malwarebytes
2010-07-30 18:14 . 2010-04-29 10:09 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 15:41 . 2010-07-30 15:41 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Microsoft Help
2010-07-30 15:41 . 2010-07-30 20:40 ——– d—–w- c:\programdata\Microsoft Help
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut106_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut104_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut102_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut101_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut107_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut103_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 ——– d—–w- c:\program files\WebEx
2010-07-24 18:25 . 2010-07-24 18:25 ——– d—–w- c:\programdata\muvee Technologies
2010-07-24 18:25 . 2010-07-24 18:37 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\muvee Technologies
2010-07-24 17:07 . 2010-07-24 17:07 ——– d—–w- c:\programdata\Seagate
2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Downloaded Installations
2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\program files\Carbonite
2010-07-24 17:06 . 2010-07-24 17:06 ——– d-sh–w- c:\windows\ftpcache
2010-07-24 17:05 . 2010-07-24 17:07 ——– d—–w- c:\program files\Seagate
2010-07-24 17:05 . 2010-07-24 17:05 ——– d—–w- c:\program files\Common Files\muvee Technologies
2010-07-24 17:02 . 2010-07-24 17:02 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Leadertech
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-31 22:16 . 2010-06-25 16:55 12 —-a-w- c:\windows\bthservsdp.dat
2010-07-31 19:49 . 2010-05-21 15:02 ——– d—–w- c:\program files\AmiBroker
2010-07-31 14:34 . 2010-03-18 13:04 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\vlc
2010-07-30 20:40 . 2010-03-18 14:57 ——– d—–w- c:\program files\Microsoft Works
2010-07-30 18:17 . 2010-03-29 12:46 ——– d—–w- c:\program files\Elecard
2010-07-30 15:56 . 2010-03-16 18:34 101216 —-a-w- c:\users\sathia.gamesh\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-24 17:08 . 2010-03-19 14:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-13 14:22 . 2010-06-13 14:17 ——– d—–w- c:\programdata\Yahoo! Companion
2010-06-13 14:18 . 2010-06-13 14:17 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Yahoo!
2010-06-13 14:17 . 2010-06-13 14:17 262144 —-a-w- C:\ntuser.dat
2010-06-13 14:17 . 2010-06-13 13:54 ——– d—–w- c:\program files\Yahoo!
2010-06-13 14:17 . 2010-06-13 14:16 ——– d—–w- c:\programdata\Yahoo!
2010-06-02 17:24 . 2010-06-02 17:23 ——– d—–w- c:\program files\Real Alternative
2010-06-02 14:37 . 2010-06-02 14:37 ——– d—–w- c:\program files\K-Lite Codec Pack
2010-06-01 04:58 . 2010-06-13 14:16 607544 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2007-02-21 19:49 . 2007-02-21 19:49 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2010-07-31_21.34.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-16 22:53 . 2010-07-31 22:19 42642 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2010-03-16 22:53 . 2010-07-31 21:04 42642 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:05 . 2010-07-31 21:21 59958 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2010-07-31 22:20 59958 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2010-03-16 18:35 . 2010-07-31 22:20 11354 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2165722446-2496424982-340524404-1000_UserData.bin
- 2010-03-16 18:35 . 2010-07-31 21:21 11354 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2165722446-2496424982-340524404-1000_UserData.bin
+ 2006-11-02 13:02 . 2010-07-31 22:17 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2010-07-31 21:31 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2010-07-31 22:17 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2010-07-31 21:31 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2010-07-31 21:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:02 . 2010-07-31 22:17 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-07-31 21:30 . 2010-07-31 21:31 1666 c:\windows\SoftwareDistribution\PostRebootEventCache\{5E6C7E83-AD80-4F04-8D79-14159147E1FB}.bin
+ 2010-07-31 21:30 . 2010-07-31 23:21 1666 c:\windows\SoftwareDistribution\PostRebootEventCache\{5E6C7E83-AD80-4F04-8D79-14159147E1FB}.bin
+ 2010-07-31 22:17 . 2010-07-31 22:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-07-31 21:02 . 2010-07-31 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-07-31 22:17 . 2010-07-31 22:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-07-31 21:02 . 2010-07-31 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2010-07-31 22:24 598588 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2010-07-31 21:26 598588 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2010-07-31 21:26 102194 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2010-07-31 22:24 102194 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:22 . 2010-07-31 22:22 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2010-07-31 21:23 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2010-07-31 21:25 . 2010-07-31 21:25 6414336 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2010-07-31 21:25 . 2010-07-31 23:16 6414336 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2010-03-18 07:38 . 2010-07-31 23:07 166733750 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-04-01 1180976]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-13 405504]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-01-29 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-12-18 197928]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(

:3f,40,0d,dd,77,c6,ca,01
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-04-27 83496]
R3 PCD5SRVC{0F020303-306A84E7-05040104};PCD5SRVC{0F020303-306A84E7-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-04-27 64304]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-04-27 160720]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-12-18 189736]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-04-27 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-04-27 141792]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-04-27 55456]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-04-27 312616]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-03-19 4233728]
— Other Services/Drivers In Memory —
*Deregistered* - ldkxkff
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
2010-03-18 c:\windows\Tasks\Uniblue DiskRescue 2009.job
- c:\program files\Uniblue\DiskRescue\UBDiskRescue.exe [2008-09-10 15:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://in.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-01 04:53
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{0F020303-306A84E7-05040104}]
"ImagePath"="\??\c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff]
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(4636)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
.
Completion time: 2010-08-01 04:56:33
ComboFix-quarantined-files.txt 2010-07-31 23:26
ComboFix2.txt 2010-07-31 21:38
Pre-Run: 41,988,214,784 bytes free
Post-Run: 41,831,972,864 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=1 Sets=1,2,3,4,5,6,7,8
- - End Of File - - 61583627C471DCABC1A29BD1C3986D14