Combofix log:
(ksfvjxai appears as an entry as service in memory)
ComboFix 10-12-03.03 - Nashir 04/12/2010 18:31:23.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2006.1045 [GMT 0:00]
Running from: c:\users\Nashir\Desktop\ComboFixkl.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1EE8.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2255.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2609.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2D89.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3842.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3851.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3852.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3A16.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3B5D.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4C1F.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4CAC.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc59A6.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5ED4.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6B04.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6C3C.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6FC5.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc751F.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc762.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc76E6.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc77E1.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7CA1.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7F11.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc847D.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8C2B.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc92B0.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc92DF.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc97CE.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA305.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB4FF.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB55C.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB878.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBCE1.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBF3C.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC0C2.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC3AF.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC43B.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC90B.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCB9B.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCBE9.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCDE.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCE2A.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD4DE.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD5C8.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE320.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE3CC.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE4A6.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE4B6.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE561.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE89C.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEE1.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEF02.tmp
c:\users\Nashir\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF884.tmp
c:\users\Nashir\AppData\Roaming\l0wsec
c:\users\Nashir\AppData\Roaming\l0wsec\l0cal.ds
c:\users\Nashir\AppData\Roaming\l0wsec\us3r.ds
.
---- Previous Run -------
.
c:\users\Nashir\AppData\Roaming\Ugubg\vuipa.exe
c:\users\Nashir\AppData\Roaming\Ynkue\hoha.exe
.
((((((((((((((((((((((((( Files Created from 2010-11-04 to 2010-12-04 )))))))))))))))))))))))))))))))
.
2010-12-04 18:40 . 2010-12-04 18:41 -------- d-----w- c:\users\Nashir\AppData\Local\temp
2010-12-04 18:40 . 2010-12-04 18:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-03 13:07 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E5D07C6F-44E4-427D-9D8E-B7985FB9AA3D}\mpengine.dll
2010-11-25 09:14 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:23 . 2009-06-30 10:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2010-11-20 18:23 . 2010-11-20 18:23 -------- d-----w- c:\users\Nashir\AppData\Roaming\PCDr
2010-11-10 10:59 . 2010-10-07 11:37 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-11-06 11:37 . 2010-11-06 11:37 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 17:42 . 2010-07-16 19:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 17:42 . 2010-07-16 19:55 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-19 10:41 . 2009-10-04 18:05 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-09-13 13:56 . 2010-10-13 09:07 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-08 06:01 . 2010-10-13 09:06 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 05:57 . 2010-10-13 09:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 05:57 . 2010-10-13 09:06 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-08 05:56 . 2010-10-13 09:05 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-09-08 05:56 . 2010-10-13 09:05 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-09-08 05:04 . 2010-10-13 09:06 385024 ----a-w- c:\windows\system32\html.iec
2010-09-08 04:26 . 2010-10-13 09:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-09-08 04:25 . 2010-10-13 09:05 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-06 16:20 . 2010-10-13 09:06 125952 ----a-w- c:\windows\system32\srvsvc.dll
2010-09-06 16:19 . 2010-10-13 09:06 17920 ----a-w- c:\windows\system32\netevent.dll
2010-09-06 13:45 . 2010-10-13 09:06 304128 ----a-w- c:\windows\system32\drivers\srv.sys
2010-09-06 13:45 . 2010-10-13 09:06 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-09-06 13:45 . 2010-10-13 09:06 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-02-25 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-12-01 1422632]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-12-01 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-12-01 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-12-01 154136]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-22 3810304]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-11-11 442536]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"diagnostics"="c:\program files\Thomson\ST330\diagnostics\diagnostics.exe" [2009-06-23 557149]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [2009-09-14 1584640]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-11-29 963976]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-08-15 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
c:\users\Nashir\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-11-18 780840]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-09-22 13:58 16680 ----a-w- c:\program files\Citrix\GoToAssist\570\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=""
"FirewallOverride"=""
R1 rqmophar;rqmophar;c:\windows\system32\drivers\rqmophar.sys
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 135664]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2009-06-23 30464]
R3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2009-06-23 12672]
R3 stppp;Speedtouch PPP Adapter Adapter;c:\windows\system32\DRIVERS\stppp.sys [2009-06-23 35328]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-06-30 28552]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [2009-03-20 81920]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2010-05-20 88176]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-12-24 29736]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-10-28 135936]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-12-01 112128]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2008-10-08 212992]
S3 OA008Ufd;Creative Camera OA008 Upper Filter Driver;c:\windows\system32\DRIVERS\OA008Ufd.sys [2009-02-10 133472]
S3 OA008Vid;Creative Camera OA008 Function Driver;c:\windows\system32\DRIVERS\OA008Vid.sys [2009-02-10 271616]
--- Other Services/Drivers In Memory ---
*Deregistered* - ksfvjxai
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 20:12]
2010-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-25 20:12]
2010-05-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 11:22]
2009-07-31 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 11:22]
2010-12-04 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2009-10-12 05:01]
2010-10-27 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-10-12 05:01]
2010-12-03 c:\windows\Tasks\PC Health Advisor Defrag.job
- c:\program files\ParetoLogic\PCHA\PCHA.exe [2010-09-30 21:40]
2010-10-27 c:\windows\Tasks\PC Health Advisor.job
- c:\program files\ParetoLogic\PCHA\PCHA.exe [2010-09-30 21:40]
2010-12-04 c:\windows\Tasks\User_Feed_Synchronization-{E7640368-FDBF-4942-94A0-18CC59282571}.job
- c:\windows\system32\msfeedssync.exe [2010-10-13 04:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bbc.co.uk/
mWindow Title = Microsoft Internet Explorer Provided by Wanadoo
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -
Toolbar-BigBitmap - (no file)
Toolbar-SmallBitmap - (no file)
HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKLM-Run-SysTrayApp - %ProgramFiles%\IDT\WDM\sttray.exe
AddRemove-alotToolbar - c:\program files\alot\alotUninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-12-04 18:41
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\st330service]
"ImagePath"="C:\Program Files/Thomson/ST330/service/st330service.exe -service"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ksfvjxai]
.
Completion time: 2010-12-04 18:43:56
ComboFix-quarantined-files.txt 2010-12-04 18:43
Pre-Run: 166,878,900,224 bytes free
Post-Run: 167,412,301,824 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=18 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18
- - End Of File - - 339AAA4D7BEC25A46EB44B87E3991A06