Hi Dave! Really appreciate the help. I followed the steps and here are the results:
Results of screen317's Security Check version 0.99.5
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check: Windows Firewall Disabled!
AVG Free 9.0
Online Armor 4.0
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware
CCleaner
Adobe Flash Player 10.1.53.64
Adobe Reader 8.2.3
Out of date Adobe Reader installed! Mozilla Firefox (3.6.6)
Firefox Out of Date! ````````````````````````````````
Process Check:
objlist.exe by Laurent AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
Tall Emu Online Armor OAcat.exe
Tall Emu Online Armor oasrv.exe
Tall Emu Online Armor oaui.exe
Tall Emu Online Armor OAhlp.exe
````````````````````````````````
DNS Vulnerability Check: Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?) ``````````End of Log```````````` ComboFix 10-08-16.03 - Sunaina Ji 08/17/2010 11:31:29.1.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2039.1418 [GMT 5.5:30]
Running from: c:\documents and settings\Sunaina Ji\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\desktop
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\system.dat
c:\windows\system32\tmp.reg
----- BITS: Possible infected sites -----
hxxp://netxpert.airtelbroadband.in
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NDISRD
((((((((((((((((((((((((( Files Created from 2010-07-17 to 2010-08-17 )))))))))))))))))))))))))))))))
.
2010-08-15 05:12 . 2010-08-15 05:12 388096 ----a-r- c:\documents and settings\Sunaina Ji\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-15 05:12 . 2010-08-15 05:12 -------- d-----w- c:\program files\TrendMicro
2010-08-14 20:32 . 2010-08-14 20:32 -------- d-----w- c:\documents and settings\Sunaina Ji\Application Data\Malwarebytes
2010-08-14 20:31 . 2010-04-29 10:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-14 20:31 . 2010-08-14 20:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-14 20:31 . 2010-04-29 10:09 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-14 19:49 . 2010-08-14 19:49 -------- d-----w- C:\FOUND.008
2010-08-14 19:02 . 2010-08-14 19:02 63488 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-14 19:02 . 2010-08-14 19:02 52224 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-14 19:02 . 2010-08-14 19:02 117760 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-14 19:01 . 2010-08-14 19:01 -------- d-----w- c:\documents and settings\Sunaina Ji\Application Data\SUPERAntiSpyware.com
2010-08-14 19:01 . 2010-08-14 19:01 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-08-14 19:01 . 2010-08-14 19:01 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-08-14 17:38 . 2010-08-14 17:38 -------- d-----w- c:\documents and settings\Sunaina Ji\Application Data\OnlineArmor
2010-08-14 17:38 . 2010-08-14 17:38 -------- d-----w- c:\documents and settings\All Users\Application Data\OnlineArmor
2010-08-08 17:16 . 2010-08-08 17:16 -------- d-----w- c:\program files\TOEFL Official Guide
2010-08-08 17:16 . 2010-08-08 17:16 -------- d-----w- c:\documents and settings\Sunaina Ji\Application Data\M-HTOEFL
2010-08-07 17:19 . 2010-08-07 17:19 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-07 17:17 . 2010-08-07 17:17 -------- d-----w- c:\program files\QuickTime
2010-08-07 17:14 . 2010-08-07 17:14 -------- d-----w- c:\program files\Bonjour
2010-08-07 08:53 . 2010-08-07 08:53 503808 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-65bfe8db-n\msvcp71.dll
2010-08-07 08:53 . 2010-08-07 08:53 499712 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-65bfe8db-n\jmc.dll
2010-08-07 08:53 . 2010-08-07 08:53 12800 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-63bc1f3f-n\decora-d3d.dll
2010-08-07 08:53 . 2010-08-07 08:53 61440 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-63bc1f3f-n\decora-sse.dll
2010-08-07 08:53 . 2010-08-07 08:53 348160 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-65bfe8db-n\msvcr71.dll
2010-07-27 06:30 . 2010-07-27 06:30 8462336 ------w- c:\windows\system32\dllcache\shell32.dll
2010-07-23 12:13 . 2010-07-23 12:13 198448 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-07-21 11:00 . 2010-07-21 11:00 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-20 12:49 . 2010-07-20 12:49 -------- d-----w- c:\documents and settings\Sunaina Ji\Application Data\Logitech
2010-07-20 12:49 . 2010-07-20 12:49 -------- d-----w- c:\documents and settings\Sunaina Ji\Application Data\Leadertech
2010-07-20 12:49 . 2010-07-20 12:49 10134 ----a-r- c:\documents and settings\Sunaina Ji\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-07-20 12:49 . 2010-07-20 12:49 -------- d-----w- c:\program files\Common Files\LogiShared
2010-07-20 12:48 . 2010-07-20 12:48 10134 ----a-r- c:\documents and settings\Sunaina Ji\Application Data\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
2010-07-20 12:48 . 2007-04-11 10:02 20496 ----a-w- c:\windows\system32\drivers\L8042Kbd.sys
2010-07-20 12:48 . 2007-04-11 10:02 36112 ----a-w- c:\windows\system32\drivers\LMouFilt.Sys
2010-07-20 12:48 . 2007-04-11 10:02 34832 ----a-w- c:\windows\system32\drivers\LHidFilt.Sys
2010-07-20 12:48 . 2007-04-11 10:02 56080 ----a-w- c:\windows\KHALMNPR.Exe
2010-07-20 12:47 . 2007-04-11 10:03 1419024 ----a-w- c:\windows\system32\WdfCoInstaller01005.dll
2010-07-20 12:47 . 2007-04-11 10:03 28688 ----a-w- c:\windows\system32\drivers\LUsbFilt.sys
2010-07-20 12:47 . 2007-04-22 22:30 69632 ----a-w- c:\windows\system32\KemXML.dll
2010-07-20 12:47 . 2007-04-22 22:30 163840 ----a-w- c:\windows\system32\kemutb.dll
2010-07-20 12:47 . 2007-04-22 22:30 135168 ----a-w- c:\windows\system32\KemUtil.dll
2010-07-20 12:47 . 2007-04-22 22:30 110592 ----a-w- c:\windows\system32\KemWnd.dll
2010-07-20 12:47 . 2010-07-20 12:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2010-07-20 12:47 . 2010-07-20 12:47 -------- d-----w- c:\program files\Logitech
2010-07-20 12:47 . 2010-07-20 12:47 10134 ----a-r- c:\documents and settings\Sunaina Ji\Application Data\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe
2010-07-20 12:47 . 2010-07-20 12:47 -------- d-----w- c:\program files\Common Files\Logitech
2010-07-20 12:46 . 2010-07-20 12:46 -------- d-----w- c:\documents and settings\Sunaina Ji\Application Data\InstallShield
2010-07-20 12:46 . 2010-07-20 12:46 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2010-07-20 12:45 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-07-20 12:45 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\dllcache\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-20 12:48 . 2010-07-20 12:48 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2010-07-20 12:48 . 2010-07-20 12:48 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2010-07-17 06:24 . 2009-06-18 16:14 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-17 06:24 . 2010-07-17 06:24 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-17 06:23 . 2008-07-11 17:23 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-16 23:30 . 2010-04-15 13:43 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-13 06:19 . 2010-07-13 06:19 -------- d-----w- c:\program files\Airtel NetXpert
2010-07-13 06:19 . 2010-07-13 06:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SupportSoft
2010-07-10 07:30 . 2010-07-01 10:07 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-10 07:30 . 2010-07-10 07:30 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-10 07:30 . 2010-07-10 07:30 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-10 07:29 . 2010-07-10 07:29 84054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-07-10 07:29 . 2010-07-10 07:29 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-10 07:19 . 2010-07-01 10:07 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-10 07:19 . 2010-07-01 10:07 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-07 06:55 . 2009-07-31 15:59 22600 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-07-07 06:55 . 2009-07-31 15:59 28232 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-07-07 06:55 . 2009-07-31 15:59 236104 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-07-01 13:04 . 2010-07-01 13:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-07-01 13:04 . 2010-07-01 13:04 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-07-01 10:06 . 2010-07-01 10:06 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-07-01 10:06 . 2010-07-01 10:06 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-07-01 10:06 . 2010-07-01 10:06 -------- d-----w- c:\documents and settings\Sunaina Ji\Application Data\DivX
2010-07-01 10:06 . 2010-07-01 10:06 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-07-01 10:06 . 2010-07-01 10:06 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-07-01 10:06 . 2010-07-01 10:06 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-07-01 10:06 . 2010-07-01 10:06 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-09 23:01 . 2006-03-16 11:05 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-06-09 23:01 . 2006-03-16 11:05 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-06-03 05:21 . 2008-07-11 17:23 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-31 08:57 . 2005-11-24 10:22 26736 ----a-w- c:\documents and settings\Sunaina Ji\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-29 05:48 . 2010-05-29 05:48 503808 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-59b3ccdc-n\msvcp71.dll
2010-05-29 05:48 . 2010-05-29 05:48 499712 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-59b3ccdc-n\jmc.dll
2010-05-29 05:48 . 2010-05-29 05:48 348160 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-59b3ccdc-n\msvcr71.dll
2010-05-29 05:48 . 2010-05-29 05:48 61440 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-63371cec-n\decora-sse.dll
2010-05-29 05:48 . 2010-05-29 05:48 12800 ----a-w- c:\documents and settings\Sunaina Ji\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-63371cec-n\decora-d3d.dll
2006-08-13 18:20 . 2006-08-13 18:20 774144 ----a-w- c:\program files\RngInterstitial.dll
2004-12-21 10:03 . 2007-12-23 10:53 86016 ----a-w- c:\program files\TATAUninstall.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Sunaina Ji\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-24 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe" [2006-03-31 28672]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2007-12-10 307200]
"AVG9_TRAY"="d:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-17 2065760]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-06-17 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"netxpert"="c:\program files\Airtel NetXpert\bin\sprtcmd.exe" [2009-12-22 206120]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"@OnlineArmor GUI"="d:\program files\Tall Emu\Online Armor\oaui.exe" [2010-07-07 6854984]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - d:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-8-29 610365]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-5-10 4456448]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-7-20 692224]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "d:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2010-07-07 924488]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-17 06:24 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Sunaina Ji^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Sunaina Ji\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Sunaina Ji^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=c:\documents and settings\Sunaina Ji\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=c:\windows\pss\PowerReg Scheduler V3.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-17 06:24 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-06-29 04:36 88363 ----a-w- c:\windows\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2004-12-07 08:53 57344 ----a-w- c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2004-12-10 10:08 2749440 ----a-w- c:\windows\ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
2006-03-31 02:17 28672 ----a-w- c:\windows\system32\Ati2mdxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-06-05 07:05 335872 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2005-12-10 14:27 133016 ----a-w- d:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 20:52 3739648 ----a-w- c:\program files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2004-08-12 12:15 61952 ------w- c:\windows\system32\Hdaudpropshortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-09-20 05:02 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydraVisionDesktopManager]
2003-09-15 15:30 270336 ----a-w- c:\program files\ATI Technologies\ATI HydraVision\HydraDM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydraVisionViewport]
2003-09-15 15:30 364544 ----a-w- c:\program files\ATI Technologies\ATI HydraVision\HydraMD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-20 05:02 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 05:06 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-09-20 05:05 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 16:46 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-11-02 09:23 77824 ----a-w- c:\windows\SoundMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2005-11-10 07:33 36975 ----a-w- c:\program files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-04-14 05:03 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\system32\\ccapp.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\StubInstaller.exe"=
"d:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\WINDOWS\\System32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"d:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\JAVA.EXE"=
"d:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"d:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"49152:TCP"= 49152:TCP:Azureus
"49152:UDP"= 49152:UDP:Azure
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/11/2008 10:53 PM 216400]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2009 9:44 PM 243024]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [7/31/2009 9:29 PM 236104]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [7/31/2009 9:29 PM 22600]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [7/31/2009 9:29 PM 28232]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:55 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/11/2010 12:11 AM 67656]
R2 avg9wd;AVG Free WatchDog;d:\program files\AVG\AVG9\avgwdsvc.exe [7/17/2010 11:54 AM 308136]
R2 OAcat;Online Armor Helper Service;d:\program files\Tall Emu\Online Armor\oacat.exe [7/31/2009 9:29 PM 1283400]
R2 sprtsvc_netxpert;SupportSoft Sprocket Service (netxpert);c:\program files\Airtel NetXpert\bin\sprtsvc.exe [7/13/2010 11:49 AM 206120]
R2 tgsrvc_netxpert;SupportSoft Repair Service (netxpert);c:\program files\Airtel NetXpert\bin\tgsrvc.exe [7/13/2010 11:49 AM 185640]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [5/10/2010 11:33 AM 110592]
R2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [5/10/2010 11:32 AM 1858048]
R2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [5/10/2010 11:32 AM 482304]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [3/24/2009 8:11 PM 33792]
R3 SvcOnlineArmor;Online Armor;d:\program files\Tall Emu\Online Armor\oasrv.exe [7/31/2009 9:29 PM 3364680]
S2 gupdate1c8e7d52f7d6ca;Google Update Service (gupdate1c8e7d52f7d6ca);c:\program files\Google\Update\GoogleUpdate.exe [7/17/2008 11:48 AM 133104]
S3 autorun;autorun;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 DUSBCamera;IBM UltraPort Camera;c:\windows\system32\drivers\IBM_501B.SYS [1/30/2002 9:44 PM 122388]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys --> c:\windows\system32\DRIVERS\ivusb.sys [?]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [7/26/2006 9:04 PM 223128]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/31/2010 11:12 PM 11520]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [7/26/2006 9:00 PM 643072]
.
Contents of the 'Scheduled Tasks' folder
2010-08-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1935655697-1580436667-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 16:39]
2010-08-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1935655697-1580436667-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 16:39]
2010-08-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1935655697-1580436667-725345543-1003Core1cb0ca4aa6ed070.job
- c:\documents and settings\Sunaina Ji\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-01 18:43]
2010-08-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 06:20]
2010-08-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-17 11:57]
2010-08-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-17 11:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.in/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 204.51.174.152:80
uInternet Settings,ProxyOverride = local;*.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
TCP: {2169162C-B377-4C9F-815E-617F58AF797D} = 202.56.215.54,202.56.215.55
FF - ProfilePath - c:\documents and settings\Sunaina Ji\Application Data\Mozilla\Firefox\Profiles\ze72yu61.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.in/
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\Sunaina Ji\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Lively\nplively.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: d:\program files\DivX\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: d:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_
everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a
s_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKCU-Run-EA Core - d:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-AVG7_CC - c:\progra~1\Grisoft\AVGFRE~1\avgcc.exe
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-DSLAGENTEXE - c:\program files\GlobespanVirata\Adsl\dslagent.exe
MSConfigStartUp-DSLSTATEXE - c:\program files\GlobespanVirata\Adsl\dslstat.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
MSConfigStartUp-PWRISOVM - d:\program files\PowerISO\PWRISOVM.EXE
MSConfigStartUp-SemanticInsight - c:\program files\RXToolBar\Semantic Insight\SemanticInsight.exe
MSConfigStartUp-SmcService - c:\progra~1\Sygate\SPF\smc.exe
MSConfigStartUp-SWN2 - d:\program files\Spyware Nuker\swnxt.exe
MSConfigStartUp-UpdateManager - c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
MSConfigStartUp-Yahoo! Pager - c:\progra~1\YAHOO!\MESSEN~1\ypager.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-17 11:36
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\autorun]
"ImagePath"="\??\c:\huadio.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(496)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(1740)
c:\windows\system32\WININET.dll
d:\program files\Tall Emu\Online Armor\OAwatch.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\program files\AVG\AVG9\avgchsvx.exe
d:\program files\AVG\AVG9\avgrsx.exe
d:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
d:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
d:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\documents and settings\Sunaina Ji\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
d:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-08-17 11:42:35 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-17 06:12
Pre-Run: 4,017,504,256 bytes free
Post-Run: 4,041,031,680 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - BA87B2125ACD84F99D3B2F00259FE7F8