Ok. I was finally able to complete both steps.
When I first ran the Combofix file, it took very long to get started and was displaying "scanning.." for a long time.
So I stepped away from my machine and my machine went into hibernation. This was not supposed to happen as I never had the Power Options set that way. So i awakend the machine and the dos command prompt had a message saying "dump hive not recognized.." etc. I thought it would continue from there but it didn't. So after waiting for an hour or so I had to close that window and reboot my machine. I then changed the Power Options back to what I usually have so it won't hibernate. Not sure how the setting changed. On the good side, the image at the center of my screen which displayed the message "Warning spyware detected…" was gone. Also suddenly the internet started to work on the machine. And the screen saver problem was also gone.
I tried to run combofix again but it wouldn't do anything and even the dos prompt wouldn't come up. So I deleted a folder and a file called "bug.txt" from the C:\ drive, which from the timestamp looked like it was created by Combofix the first time I ran it and also had contents saying "ComboFix..", and then rebooted the machine. Ran Combofix again and this time it ran properly all the way till it created the log file.
All through this process my Trend Micro kept giving me warnings about some programs which were trying to run on the machine and trying to send data to the internet. Form the names and description it looked like they were spyware.
I hope we can get rid of these programs.
ComboFix Log :
ComboFix 08-08-25.01 - Anoop 2008-08-26 19:50:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1121 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\bin.clearspring.com
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\interclick.com
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\interclick.com\ud.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com\v1.0.0097\qplayer.swf\youku.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com\v1.0.0200\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com\v1.0.0213\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com\v1.0.0214\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com\v1.0.0227\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com\v1.0.0261\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\#SharedObjects\FSQHNLZX\static.youku.com\v1.0.0288\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\Anoop\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\Documents and Settings\Anoop\Cookies\anoop@circuitcity[1].txt
C:\Documents and Settings\Anoop\Cookies\[removed][1].txt
C:\Documents and Settings\Anoop\Cookies\[removed][2].txt
C:\Documents and Settings\Anoop\Cookies\[removed][1].txt
C:\Documents and Settings\Anoop\Cookies\[removed][1].txt
C:\Documents and Settings\Anoop\Cookies\anoop@turn[1].txt
C:\Documents and Settings\Guest\Cookies\[removed][2].txt
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\bin.clearspring.com
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\interclick.com
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\interclick.com\ud.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\static.youku.com
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\static.youku.com\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\static.youku.com\v1.0.0214\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\static.youku.com\v1.0.0221\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\static.youku.com\v1.0.0234\v\swf\qplayer.swf\youku.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\static.youku.com\v1.0.0281\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\static.youku.com\v1.0.0288\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\#SharedObjects\JJW47HGZ\static.youku.com\v1.0.0314\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\Sandhya\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\Documents and Settings\Sandhya\Cookies\sandhya@2o7[1].txt
C:\Documents and Settings\Sandhya\Cookies\[removed][2].txt
C:\Documents and Settings\Sandhya\Cookies\[removed][2].txt
C:\Documents and Settings\Sandhya\Cookies\sandhya@advertising[1].txt
C:\Documents and Settings\Sandhya\Cookies\sandhya@edge.ru4[2].txt
C:\Documents and Settings\Sandhya\Cookies\[removed][2].txt
C:\Documents and Settings\Sandhya\Cookies\[removed][2].txt
C:\Documents and Settings\Sandhya\Cookies\[removed][1].txt
C:\Documents and Settings\Sandhya\Cookies\sandhya@insightexpressai[1].txt
C:\Documents and Settings\Sandhya\Cookies\sandhya@revsci[2].txt
C:\Documents and Settings\Sandhya\Cookies\[removed][1].txt
C:\Documents and Settings\Sandhya\Cookies\sandhya@turn[2].txt
C:\Documents and Settings\Sandhya\Cookies\[removed][2].txt
C:\Documents and Settings\Sandhya\Cookies\[removed][2].txt
C:\WINDOWS\system32\a.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_SYSREST.SYS
——-\Legacy_TDSSSERV
——-\Service_tdssserv
((((((((((((((((((((((((( Files Created from 2008-07-27 to 2008-08-27 )))))))))))))))))))))))))))))))
.
2008-08-26 13:48 . 2008-08-26 15:11 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-25 18:32 . 2008-08-25 18:32 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-25 18:32 . 2008-08-25 18:32 d——– C:\Documents and Settings\Anoop\Application Data\Malwarebytes
2008-08-25 18:32 . 2008-08-25 18:32 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-25 18:32 . 2008-08-17 15:01 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-25 18:32 . 2008-08-17 15:01 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-24 11:12 . 2008-08-24 11:16 d——– C:\abc
2008-08-24 02:13 . 2008-08-24 02:13 d——– C:\VundoFix Backups
2008-08-23 23:30 . 2008-08-23 23:30 d——– C:\Documents and Settings\LocalService\Application Data\Webroot
2008-08-23 22:37 . 2008-08-23 22:37 d——– C:\Program Files\Webroot
2008-08-23 22:37 . 2008-08-23 22:37 d——– C:\Documents and Settings\Anoop\Application Data\Webroot
2008-08-23 22:37 . 2008-08-23 22:37 d——– C:\Documents and Settings\All Users\Application Data\Webroot
2008-08-23 22:37 . 2008-08-09 16:04 1,538,928 –a—— C:\WINDOWS\WRSetup.dll
2008-08-23 20:26 . 2008-07-18 18:51 1,195,448 –a—— C:\WINDOWS\system32\drivers\vsapint.sys
2008-08-23 20:26 . 2006-12-29 02:53 288,848 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2008-08-23 20:26 . 2008-07-18 19:08 205,328 –a—— C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-08-23 20:26 . 2006-12-29 02:53 111,888 –a—— C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2008-08-23 20:26 . 2006-12-29 02:53 75,088 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2008-08-23 20:26 . 2008-07-18 19:08 36,368 –a—— C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-08-20 00:52 . 2008-08-20 00:52 d——– C:\Documents and Settings\Sandhya\Application Data\Leadertech
2008-08-09 14:42 . 2008-08-09 14:42 166,512 –a—— C:\WINDOWS\system32\drivers\ssidrv.sys
2008-08-09 14:42 . 2008-08-09 14:42 29,808 –a—— C:\WINDOWS\system32\drivers\ssfs0bbc.sys
2008-08-09 14:42 . 2008-08-09 14:42 23,152 –a—— C:\WINDOWS\system32\drivers\sshrmd.sys
2008-08-06 16:03 . 2008-08-06 16:03 d——– C:\Documents and Settings\Guest\Application Data\vlc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 00:45 ——— d—–w C:\Program Files\BeautifulEarth
2008-08-24 00:45 ——— d—–w C:\Documents and Settings\Anoop\Application Data\BeautifulEarth
2008-08-24 00:24 ——— d—–w C:\Program Files\Trend Micro
2008-08-23 23:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-08-11 03:01 0 —-a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2008-08-10 04:26 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-07-19 04:30 ——— d—–w C:\Program Files\MediaCoder
2008-07-19 04:25 ——— d—–w C:\Program Files\MediaInfo
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-15 17:35 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-07-15 17:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-10 17:14 ——— d—–w C:\Program Files\Java
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-04 12:35 ——— d—–w C:\Program Files\TVUPlayer
2008-07-04 12:35 ——— d—–w C:\Documents and Settings\Anoop\Application Data\TVU Networks
2008-07-04 12:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:38 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2007-12-15 05:07 92,064 —-a-w C:\Documents and Settings\Sandhya\mqdmmdm.sys
2007-12-15 05:07 9,232 —-a-w C:\Documents and Settings\Sandhya\mqdmmdfl.sys
2007-12-15 05:07 79,328 —-a-w C:\Documents and Settings\Sandhya\mqdmserd.sys
2007-12-15 05:07 66,656 —-a-w C:\Documents and Settings\Sandhya\mqdmbus.sys
2007-12-15 05:07 6,208 —-a-w C:\Documents and Settings\Sandhya\mqdmcmnt.sys
2007-12-15 05:07 5,936 —-a-w C:\Documents and Settings\Sandhya\mqdmwhnt.sys
2007-12-15 05:07 4,048 —-a-w C:\Documents and Settings\Sandhya\mqdmcr.sys
2007-12-15 05:07 25,600 —-a-w C:\Documents and Settings\Sandhya\usbsermptxp.sys
2007-12-15 05:07 22,768 —-a-w C:\Documents and Settings\Sandhya\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 15:18 202024]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 18:43 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 11:19 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 11:17 970752]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 14:13 176128]
"Dell QuickSet"="C:\program files\dell\quickset\quickset.exe" [2005-09-01 17:24 684032]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 12:48 1392640]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-06-06 17:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-06-06 17:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-06-06 17:10 118784]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-11-07 05:20 122940]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 16:02 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 16:06 2027792]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 15:53 169264]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 09:51 1836328]
"Norton Ghost 12.0"="C:\Program Files\Norton Ghost\Agent\VProTray.exe" [2007-10-05 13:33 2037088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-19 20:56 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-12-29 02:52 3429904]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-01-14 19:54:48 479232]
HotSync Manager.lnk - C:\Program Files\Sony Handheld\HOTSYNC.EXE [2008-02-23 02:14:54 299008]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-09-16 21:56:44 67128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 ssfs0bbc;ssfs0bbc;C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys [2008-08-09 14:42]
R2 Maxtor Sync Service;Maxtor Service;C:\Program Files\Maxtor\Sync\SyncServices.exe [2007-09-28 13:24]
.
Contents of the 'Scheduled Tasks' folder
2008-08-22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-27 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-08-09 16:04]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-08-09 16:04]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- C:\","D:\" []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-ares - C:\Program Files\Ares\Ares.exe
HKCU-Run-GGWallpaper - C:\Program Files\BeautifulEarth\Beautiful-Earth.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Anoop\Application Data\Mozilla\Firefox\Profiles\agvr6c6b.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-26 20:56:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Apoint\hidfind.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-08-26 21:19:13 - machine was rebooted [Anoop]
ComboFix-quarantined-files.txt 2008-08-27 01:18:18
Pre-Run: 83,000,745,984 bytes free
Post-Run: 84,958,871,552 bytes free
269 — E O F — 2008-08-26 19:33:38
HJT log :
Logfile of HijackThis v1.99.1
Scan saved at 21:24, on 2008-08-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\program files\dell\quickset\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "C:\WINDOWS\system32\rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\program files\dell\quickset\quickset.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] "C:\WINDOWS\system32\WLTRAY.exe"
O4 - HKLM\..\Run: [igfxtray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [igfxhkcmd] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [igfxpers] "C:\WINDOWS\system32\igfxpers.exe"
O4 - HKLM\..\Run: [DLA] "C:\WINDOWS\System32\DLA\DLACTRLW.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Norton Ghost 12.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?00b99e68afec4246b7144b56c0947f88
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?00b99e68afec4246b7144b56c0947f88
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) -
http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE