My Combo Fix Log File...........
ComboFix 08-04-29.5 - selva kumar 2008-05-01 19:32:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.54 [GMT 5.5:30]
Running from: C:\Documents and Settings\selva kumar\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\selva kumar\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\WinData.cab . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-04-01 to 2008-05-01 )))))))))))))))))))))))))))))))
.
2008-05-01 19:34 . 2008-05-01 19:34 9,728 --a------ C:\WINDOWS\system32\WinNt32.dll
2008-05-01 12:12 . 2008-05-01 12:12 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\Talkback
2008-04-30 23:55 . 2008-04-30 23:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-30 23:44 . 2008-04-30 23:44 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-30 23:44 . 2008-05-01 19:04 1,024 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT.LOG
2008-04-30 23:39 . 2008-05-01 15:56 326 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-30 23:06 . 2008-05-01 18:19 192,512 --a------ C:\WINDOWS\system32\cbOCR.dll
2008-04-30 15:58 . 2008-05-01 19:04 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG
2008-04-30 09:44 . 2008-04-30 09:44 <DIR> d-------- C:\Program Files\Yamicsoft
2008-04-30 08:18 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-29 23:33 . 2008-04-29 23:33 58,880 --a------ C:\WINDOWS\system32\qelv.exe
2008-04-29 23:30 . 2008-04-30 17:29 14,976 --a------ C:\WINDOWS\system32\drivers\Tyo14.sys
2008-04-29 23:30 . 2008-04-30 17:29 9,728 --a------ C:\WINDOWS\system32\WinData.cab
2008-04-29 23:16 . 2008-04-29 23:18 350 --a------ C:\WINDOWS\CRedit.INI
2008-04-29 19:33 . 2008-04-29 20:15 <DIR> d-------- C:\Program Files\Winamp
2008-04-29 19:33 . 2008-04-29 20:18 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\Winamp
2008-04-28 08:19 . 2008-04-28 08:19 <DIR> d-------- C:\WINDOWS\Sun
2008-04-28 08:17 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-28 07:51 . 2008-04-28 07:51 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-25 13:47 . 2008-04-25 13:47 0 --a------ C:\WINDOWS\autorun.INI
2008-04-25 13:33 . 2007-12-19 11:06 172,032 --a------ C:\WINDOWS\system32\igfxres.dll
2008-04-25 12:32 . 2007-11-14 15:18 553 --a------ C:\WINDOWS\USetup.iss
2008-04-25 12:31 . 2005-05-03 18:43 69,632 --a------ C:\WINDOWS\Alcmtr.exe
2008-04-25 12:29 . 2007-12-19 11:40 147,456 --a------ C:\WINDOWS\system32\igfxCoIn_v4906.dll
2008-04-25 10:33 . 2008-04-25 10:33 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-04-25 08:51 . 2004-09-28 11:13 526,184 --a------ C:\WINDOWS\system32\XceedCry.dll
2008-04-25 08:51 . 2004-03-09 00:00 224,016 --a------ C:\WINDOWS\system32\Tabctl32.ocx
2008-04-25 08:51 . 2004-08-11 15:55 110,602 --a------ C:\WINDOWS\system32\xcdsfx32.bin
2008-04-24 23:08 . 2004-03-09 16:45 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-04-24 23:08 . 2005-01-12 11:19 456,536 --a------ C:\WINDOWS\system32\XCEEDZIP.DLL
2008-04-24 21:11 . 2008-04-24 21:11 1,532 --a------ C:\WINDOWS\mozver.dat
2008-04-23 21:13 . 2008-04-23 21:13 <DIR> d-------- C:\Program Files\Common Files\Cosmi
2008-04-23 21:13 . 2008-04-23 21:13 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2008-04-23 21:13 . 1997-07-10 10:36 299,008 --a------ C:\WINDOWS\system32\SKY32V3C.DLL
2008-04-23 21:13 . 1996-05-07 19:59 47,104 --a------ C:\WINDOWS\system32\D2HTLS32.DLL
2008-04-23 21:13 . 1996-02-28 15:47 28,976 --a------ C:\WINDOWS\system32\D2HTOOLS.DLL
2008-04-23 21:13 . 2008-04-23 21:13 0 --a------ C:\WINDOWS\PROTOCOL.INI
2008-04-23 21:12 . 2008-04-23 21:12 <DIR> d-------- C:\Documents and Settings\selva kumar\WINDOWS
2008-04-23 21:12 . 1998-02-06 22:37 299,520 --a------ C:\WINDOWS\uninst.exe
2008-04-23 17:42 . 2008-04-25 09:26 50 --a------ C:\WINDOWS\MegaManager.INI
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-04-23 12:37 . 2008-04-30 00:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-04-21 22:32 . 2008-04-21 22:32 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-21 22:30 . 2008-04-21 22:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-20 16:08 . 2008-04-20 16:08 <DIR> d-------- C:\Program Files\CyberLink
2008-04-19 17:10 . 2008-04-19 17:10 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-18 16:18 . 2008-04-18 16:18 <DIR> d--h----- C:\WINDOWS\PIF
2008-04-18 13:56 . 2008-04-18 13:56 66 --a------ C:\WINDOWS\system32\wmpcsauth.bin
2008-04-18 10:08 . 2008-04-18 10:08 <DIR> d-------- C:\Program Files\CONEXANT
2008-04-18 00:22 . 2008-04-30 00:01 <DIR> d-------- C:\Program Files\uTorrent
2008-04-18 00:22 . 2008-05-01 00:42 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\uTorrent
2008-04-17 21:39 . 2008-04-21 11:55 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-17 21:38 . 2008-04-17 21:38 479,298 --a------ C:\WINDOWS\system32\wbocx.ocx
2008-04-17 21:38 . 2008-04-17 21:38 172,032 --a------ C:\WINDOWS\system32\AniGIF.ocx
2008-04-17 21:38 . 2008-04-17 21:38 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2008-04-17 19:14 . 2008-04-17 19:14 144 --a------ C:\WINDOWS\Eudcedit.ini
2008-04-17 18:49 . 2008-04-23 16:33 <DIR> d-------- C:\Program Files\MegauploadToolbar
2008-04-17 18:49 . 2008-04-29 21:04 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\MegauploadToolbar
2008-04-17 18:26 . 2008-04-18 14:02 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-04-17 16:34 . 2008-04-17 18:19 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\Yahoo!
2008-04-17 16:22 . 2008-04-17 16:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-17 16:18 . 2008-04-17 18:19 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-17 15:54 . 2008-04-17 15:54 <DIR> d---s---- C:\Documents and Settings\selva kumar\UserData
2008-04-16 20:08 . 2008-04-17 15:44 <DIR> d-------- C:\Program Files\YOUConnect
2008-04-16 20:08 . 2006-05-27 12:11 929,844 --a------ C:\WINDOWS\system32\MFC42D.DLL
2008-04-16 20:08 . 2006-05-27 12:11 917,504 --a------ C:\WINDOWS\system32\Flash.ocx
2008-04-16 20:08 . 2006-05-27 12:11 798,773 --a------ C:\WINDOWS\system32\MFCO42D.DLL
2008-04-16 20:08 . 2006-05-27 12:11 434,252 --a------ C:\WINDOWS\system32\msvcrtd.dll
2008-04-16 20:08 . 2006-05-27 12:11 164,144 --a------ C:\WINDOWS\system32\COMCT232.OCX
2008-04-16 20:08 . 2006-05-27 12:11 143,360 --a------ C:\WINDOWS\system32\Unzip32.dll
2008-04-16 20:08 . 2006-05-27 12:11 109,248 --a------ C:\WINDOWS\system32\MSWinSck.ocx
2008-04-16 19:51 . 2004-09-30 02:06 15,360 -rah----- C:\WINDOWS\system32\drivers\NetMotCM.sys
2008-04-15 16:55 . 2008-04-15 16:56 1,024 --ah----- C:\Documents and Settings\Default User\NTUSER.DAT.LOG
2008-04-15 14:28 . 2008-04-30 18:09 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\dvdcss
2008-04-15 14:22 . 2008-04-21 20:46 <DIR> d-------- C:\Program Files\Total Video Converter
2008-04-15 09:23 . 2008-04-15 09:25 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-15 07:44 . 2008-04-15 07:44 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-04-15 07:44 . 2008-04-15 07:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-04-15 07:34 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-04-15 07:32 . 2008-04-15 07:32 <DIR> d-------- C:\Program Files\Microsoft Works
2008-04-15 07:31 . 2008-04-15 07:31 <DIR> d-------- C:\Program Files\MSBuild
2008-04-15 07:30 . 2008-04-15 07:30 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-04-15 07:28 . 2008-04-15 07:28 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-04-15 07:27 . 2008-04-15 07:31 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-04-15 07:26 . 2008-04-15 07:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-14 14:38 . 2008-04-14 14:38 223,128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2008-04-14 14:34 . 2008-04-14 14:34 642,560 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-04-14 14:34 . 2008-04-14 14:34 96,256 --a------ C:\WINDOWS\system32\drivers\sptd8893.sys
2008-04-13 18:00 . 2008-04-13 18:00 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\CyberLink
2008-04-13 17:59 . 2008-04-13 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-04-13 17:58 . 2008-04-13 17:58 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\vlc
2008-04-13 17:55 . 2008-04-13 17:55 <DIR> d-------- C:\Program Files\SRS Labs
2008-04-13 17:55 . 2008-04-13 17:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SRS Labs
2008-04-12 14:48 . 2008-04-12 14:48 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\ScanSoft
2008-04-12 14:48 . 2008-04-12 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-04-12 14:48 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-04-12 14:48 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-04-12 14:48 . 2008-04-12 14:48 416 --a------ C:\WINDOWS\MAXLINK.INI
2008-04-12 14:47 . 2008-04-12 14:47 <DIR> d-------- C:\Program Files\Common Files\ScanSoft Shared
2008-04-12 14:47 . 2008-04-12 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-04-12 14:40 . 2008-04-12 14:40 <DIR> d-------- C:\Program Files\ArcSoft
2008-04-12 14:40 . 1995-07-31 13:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-04-12 14:39 . 1998-10-29 15:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-12 14:38 . 2008-04-12 14:38 <DIR> d--h----- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2008-04-12 14:38 . 2008-04-12 14:38 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\CanonBJ
2008-04-12 14:38 . 2006-07-20 21:21 1,298,432 --a------ C:\WINDOWS\system32\CNCC160.DLL
2008-04-12 14:38 . 2006-09-13 10:30 197,632 --a------ C:\WINDOWS\system32\CNMLM83.DLL
2008-04-12 14:38 . 2006-05-26 16:24 135,168 --a------ C:\WINDOWS\system32\CNCL160.DLL
2008-04-12 14:38 . 2006-06-29 19:59 106,496 --a------ C:\WINDOWS\system32\cnco160.dll
2008-04-12 14:38 . 2006-07-20 21:21 57,344 --a------ C:\WINDOWS\system32\CNCI160.DLL
2008-04-12 14:37 . 2008-04-12 14:37 <DIR> d--h----- C:\Program Files\CanonBJ
2008-04-12 14:36 . 2008-04-12 14:39 <DIR> d-------- C:\Program Files\Canon
2008-04-12 14:34 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-12 14:34 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-12 14:34 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-12 14:34 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-12 10:14 . 2008-04-12 10:14 <DIR> d-------- C:\Program Files\Smart Projects
2008-04-12 06:15 . 2008-04-12 06:15 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-04-11 20:17 . 2008-04-11 20:18 <DIR> d-------- C:\Program Files\AnswerWorks 4.0
2008-04-11 20:12 . 2008-04-11 20:12 <DIR> d-------- C:\Program Files\Autodesk
2008-04-11 18:28 . 2008-04-11 20:22 <DIR> d-------- C:\Documents and Settings\selva kumar\Application Data\Autodesk
2008-04-11 18:28 . 2008-04-11 20:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-04-11 18:26 . 2008-04-11 20:19 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-04-10 21:16 . 2007-05-22 11:02 163,840 --a------ C:\WINDOWS\system32\unrar.dll
2008-04-10 21:12 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 11:03 4,707,328 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-04-10 15:24 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-10 11:22 16,861,184 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-04-02 03:57 1,196,032 ----a-w C:\WINDOWS\RtlUpd.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-01_19.11.49.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-01 13:37:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-01 14:04:57 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SRS Audio Sandbox"="C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" [2008-04-13 17:57 3158016]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-08-19 19:34 3084288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Tyo14.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RemoteControl"="d:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
R0 Tyo14;Tyo14;C:\WINDOWS\system32\Drivers\Tyo14.sys [2008-04-30 17:29]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-30 00:01]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-30 00:05]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS [2002-10-03 00:09]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bf4656c2-0714-11dd-816c-a2b01ac0a9b1}]
\Shell\AutoRun\command - f.exe
\Shell\explore\Command - f.exe
\Shell\open\Command - f.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-26 18:43:00 C:\WINDOWS\Tasks\WinXP Manager Live Update.job"
- C:\Program Files\Yamicsoft\WinXP Manager\LiveUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-01 19:35:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-05-01 19:38:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-01 14:08:17
ComboFix2.txt 2008-05-01 13:42:06
Pre-Run: 4,597,854,208 bytes free
Post-Run: 4,572,155,904 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
231 --- E O F --- 2008-04-17 14:18:28