ComboFix 08-01-23.1C - raminder kaur 2008-01-27 13:22:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.82 [GMT -5:00]
Running from: C:\Documents and Settings\raminder kaur\Local Settings\Temporary Internet Files\Content.IE5\FPOYK7C1\ComboFix[1].exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp:/õj+|Cü¤Ì›v÷+È@™JŸ:®½‰NêGD_©½ºD˜QÄ{¶ÀzÎtçÒ»ÌHžG†.XóÆñ&ÍýGœ6þá<ôûøWU Client Download S-1-5-18`€HT4?? 6ÚVwoQZC¬¬D¢HÿóMVC:\WINDOWS\SoftwareDistribution\Download\ab59ac72525ea90a47679441587835c9\MAINSP3.CAB€
.
((((((((((((((((((((((((( Files Created from 2007-12-27 to 2008-01-27 )))))))))))))))))))))))))))))))
.
2008-01-27 13:21 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-27 11:12 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-27 11:12 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-26 22:18 . 2008-01-26 22:18 <DIR> d-------- C:\Program Files\CCleaner
2008-01-26 21:02 . 2005-08-22 15:07 1,035,008 --a------ C:\WINDOWS\system32\drivers\HSF_DPV.sys
2008-01-26 21:02 . 2005-08-18 11:13 133,528 --a------ C:\WINDOWS\system32\drivers\HSFProf.cty
2008-01-26 21:02 . 2005-09-16 13:14 110,592 --a------ C:\WINDOWS\system32\uci32101.dll
2008-01-26 21:01 . 2008-01-26 21:01 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-26 20:54 . 2008-01-26 20:54 7,518,568 --a------ C:\Program Files\R132395.EXE
2008-01-26 20:47 . 2008-01-26 20:47 <DIR> d-------- C:\Program Files\TechTracker
2008-01-26 19:59 . 2008-01-26 19:59 <DIR> d-------- C:\NV33122708.TMP
2008-01-26 19:59 . 2008-01-26 19:59 <DIR> d-------- C:\NV18642976.TMP
2008-01-26 19:58 . 2006-08-16 17:18 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-01-26 19:16 . 2008-01-26 19:16 <DIR> d-------- C:\Program Files\DellAutomatedPCTuneUp
2008-01-26 18:54 . 2008-01-27 13:13 <DIR> d-------- C:\Program Files\Uniblue
2008-01-26 18:42 . 2008-01-27 12:00 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-26 18:42 . 2008-01-26 18:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-26 18:36 . 2008-01-27 12:03 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-26 18:36 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-26 17:50 . 2007-10-10 18:55 6,065,664 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-26 17:50 . 2007-06-30 22:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-26 17:50 . 2007-06-30 22:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-26 17:50 . 2007-10-10 18:55 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-26 17:50 . 2007-10-10 18:55 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-26 17:50 . 2007-10-10 18:55 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-26 17:50 . 2007-10-10 18:55 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-26 17:50 . 2007-10-10 18:55 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-26 17:50 . 2007-10-10 05:59 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-26 17:07 . 2008-01-26 17:07 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-01-26 17:06 . 2008-01-26 17:53 <DIR> d-------- C:\Program Files\Norton Internet Security
2008-01-26 17:05 . 2008-01-26 18:10 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-26 17:05 . 2008-01-26 18:10 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-26 17:05 . 2008-01-26 17:05 4,128 --a------ C:\INFCACHE.1
2008-01-26 17:04 . 2008-01-27 12:35 <DIR> d-------- C:\Program Files\Symantec
2008-01-26 16:42 . 2006-03-16 23:03 8,452,096 --a------ C:\WINDOWS\system32\SETB05.tmp
2008-01-26 16:42 . 2007-10-10 05:34 350,720 --a------ C:\WINDOWS\system32\SETB06.tmp
2008-01-26 16:42 . 2006-08-16 04:37 225,664 --a------ C:\WINDOWS\system32\drivers\tcpip6.sys
2008-01-26 16:42 . 2004-08-10 05:00 100,352 --a------ C:\WINDOWS\system32\SETB00.tmp
2008-01-26 16:34 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\dllcache\custsat.dll
2008-01-26 16:14 . 2006-08-21 04:14 128,896 --------- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-01-26 16:14 . 2006-08-21 04:14 23,040 --------- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-01-26 16:14 . 2006-08-21 07:21 16,896 --------- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-01-26 15:58 . 2008-01-26 15:58 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-26 15:40 . 2008-01-26 15:40 <DIR> d-------- C:\Program Files\WebCyberCoach
2008-01-26 15:34 . 2005-07-04 16:03 1,650,688 --a------ C:\WINDOWS\system32\qdiagdwc.ocx
2008-01-26 15:34 . 2005-02-09 13:08 7,168 --a------ C:\WINDOWS\system32\DLPT64.sys
2008-01-26 15:34 . 2005-02-08 13:04 5,632 --a------ C:\WINDOWS\system32\GPCIEn64.sys
2008-01-26 15:34 . 2005-02-08 15:46 5,120 --a------ C:\WINDOWS\system32\GTKCMO64.sys
2008-01-26 15:34 . 2005-02-07 19:07 4,608 --a------ C:\WINDOWS\system32\DDMI64.sys
2008-01-26 15:30 . 2008-01-26 15:32 <DIR> d-------- C:\Program Files\Dell Support Center
2008-01-26 15:30 . 2008-01-26 15:30 <DIR> d-------- C:\Program Files\Common Files\supportsoft
2008-01-26 15:26 . 2007-10-25 22:34 8,460,288 --a------ C:\WINDOWS\system32\SETB02.tmp
2008-01-26 15:26 . 2007-10-29 05:04 350,720 --------- C:\WINDOWS\system32\SETB03.tmp
2008-01-26 15:17 . 2007-07-09 08:09 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-26 15:07 . 2006-03-20 22:23 23,040 --------- C:\WINDOWS\kb913800.exe
2008-01-26 15:05 . 2006-12-06 23:14 2,330,624 --------- C:\WINDOWS\system32\dllcache\wmvcore.dll
2008-01-26 14:42 . 2008-01-26 18:10 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-26 14:42 . 2008-01-26 18:10 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-26 14:13 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-01-26 14:13 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-26 14:13 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-27 18:27 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-27 05:27 --------- d-----w C:\Program Files\Yahoo!
2008-01-27 02:01 --------- d-----w C:\Program Files\Broadcom
2008-01-27 00:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-26 20:29 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2007-12-01 04:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2006-10-03 07:43 2,402,550 ----a-w C:\WINDOWS\inf\SETA4D.tmp
2004-08-10 10:00 1,431,144 ----a-w C:\WINDOWS\inf\SETABD.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 22:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-01-26 17:07 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 22:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-08-16 09:02 1877272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12 94208]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 12:12 7630848]
"nwiz"="nwiz.exe" [2006-08-23 14:12 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 14:12 86016]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"NortonAntiBot"="C:\Program Files\Symantec\Norton AntiBot\agent\bin\NortonAntiBot.exe" [2007-06-29 20:40 1727000]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-01 01:26:33 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
R2 datunidr;DellAutomatedPCTuneUp UniDriver;C:\WINDOWS\system32\DRIVERS\datunidr.sys [2007-08-23 18:29]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-25 00:07]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R2 SymantecAntiBotAgent;SymantecAntiBotAgent;"C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABAgent.exe" SymantecAntiBotAgent []
R2 SymantecAntiBotWatcher;SymantecAntiBotWatcher;C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABWatcher.exe [2007-06-29 20:40]
R3 SymantecAntiBotDriver;SymantecAntiBotDriver;C:\Program Files\Symantec\Norton AntiBot\agent\driver\platform_XP\AntiBotDriver.sys [2007-06-29 20:40]
R3 SymantecAntiBotFilter;SymantecAntiBotFilter;C:\Program Files\Symantec\Norton AntiBot\agent\driver\platform_XP\AntiBotFilter.sys [2007-06-29 20:40]
R3 SymantecAntiBotShim;SymantecAntiBotShim;C:\Program Files\Symantec\Norton AntiBot\agent\driver\platform_XP\AntiBotShim.sys [2007-06-29 20:40]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2007-05-29 15:55]
S3 DellAMBrokerService;DellAMBrokerService;"C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe" [2007-10-11 09:49]
S3 PTproct;PTproct;C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys [2006-10-05 16:07]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-01-26 22:21:22 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - raminder kaur.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-27 13:27:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-27 13:28:46
ComboFix-quarantined-files.txt 2008-01-27 18:28:39
.
2008-01-27 06:11:26 --- E O F ---
this is combo fix log