Computer running slow - Hijack Log file and combofix log
My computer is running very slow and also the internet. Lots of popups comes once i open any site. Not able to do google search or open any email sites. find below the hijackthis log and combofix log. Please help me. Thanks.:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:10, on 2008-09-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\AOL\1142915407\ee\AOLSoftware.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1142915407\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BM130cd580] Rundll32.exe "C:\WINDOWS\system32\hluvwuxo.dll",s
O4 - HKLM\..\Run: [103fe61c] rundll32.exe "C:\WINDOWS\system32\lpkyhmhp.dll",b
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/30.62/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 2313926812
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 2313919765
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol ... _en_dl.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager dmserverProtectedStorage (dmserverProtectedStorage) - Unknown owner - C:\WINDOWS\
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IMAPI CD-Burning COM Service ImapiServiceDefWatch (ImapiServiceDefWatch) - Unknown owner - .exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Uninterruptible Power Supply UPSCOMSysApp (UPSCOMSysApp) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcNla (WMPNetworkSvcNla) - Unknown owner - C:\WINDOWS\
--
End of file - 9813 bytes
ComboFix 08-09-03.01 - Rohit 2008-09-03 17:46:56.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.207 [GMT -4:00]
Running from: C:\ComboFix\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\#SharedObjects\8XSSJV7R\bin.clearspring.com
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\#SharedObjects\8XSSJV7R\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\#SharedObjects\8XSSJV7R\interclick.com
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\#SharedObjects\8XSSJV7R\interclick.com\ud.sol
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Rohit\Cookies\rohit@ad.yieldmanager[1].txt
C:\Documents and Settings\Rohit\Cookies\rohit@trafficmp[1].txt
C:\WINDOWS\BM130cd580.txt
C:\WINDOWS\BM130cd580.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bpoyqq.dll
C:\WINDOWS\system32\chvmrf.dll
C:\WINDOWS\system32\cmcehahj.dll
C:\WINDOWS\system32\ddcyvuVL.dll
C:\WINDOWS\system32\dyxfplpr.dll
C:\WINDOWS\system32\fewfbtwd.dll
C:\WINDOWS\system32\gdxpdpar.ini
C:\WINDOWS\system32\gkwaqf.dll
C:\WINDOWS\system32\hdohxedj.exe
C:\WINDOWS\system32\hhtsbhim.ini
C:\WINDOWS\system32\IkTwyGgh.ini
C:\WINDOWS\system32\IkTwyGgh.ini2
C:\WINDOWS\system32\inknumqv.ini
C:\WINDOWS\system32\jaflvvpg.dll
C:\WINDOWS\system32\jhxate.dll
C:\WINDOWS\system32\jwysxoda.ini
C:\WINDOWS\system32\lhdprdht.dll
C:\WINDOWS\system32\lvjhvuuc.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mihbsthh.dll
C:\WINDOWS\system32\ovfussrw.ini
C:\WINDOWS\system32\ppybku.dll
C:\WINDOWS\system32\pquslckv.exe
C:\WINDOWS\system32\saplupdk.dll
C:\WINDOWS\system32\scfeohpd.dll
C:\WINDOWS\system32\ssqNEtSi.dll
C:\WINDOWS\system32\thdrpdhl.ini
C:\WINDOWS\system32\tlguanne.dll
C:\WINDOWS\system32\upvdlnjn.dll
C:\WINDOWS\system32\wlaefxpk.dll
C:\WINDOWS\system32\wrssufvo.dll
C:\WINDOWS\system32\xebnza.dll
----- BITS: Possible infected sites -----
http://downloads.networkmagic.com
.
((((((((((((((((((((((((( Files Created from 2008-08-03 to 2008-09-03 )))))))))))))))))))))))))))))))
.
2008-08-27 20:10 . 2008-08-27 20:10 311,296 --a------ C:\WINDOWS\system32\hgGywTkI.dll
2008-08-22 18:56 . 2008-08-22 18:56 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-22 18:50 . 2004-08-04 03:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-08-22 18:39 . 2008-08-22 18:39 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-22 18:39 . 2008-08-22 18:39 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-22 18:39 . 2008-08-22 18:39 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 18:18 . 2008-04-13 20:12 276,992 --a------ C:\WINDOWS\system32\wmphoto.dll
2008-08-22 18:16 . 2008-04-13 20:11 650,752 --a------ C:\WINDOWS\system32\dot3ui.dll
2008-08-22 18:15 . 2008-04-13 20:11 233,472 --a------ C:\WINDOWS\system32\azroles.dll
2008-08-22 18:15 . 2008-04-13 20:11 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-08-22 18:15 . 2008-04-13 20:11 12,800 --a------ C:\WINDOWS\system32\credssp.dll
2008-08-22 18:15 . 2008-04-13 20:11 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-08-22 17:29 . 2008-08-22 17:29 0 --a------ C:\WINDOWS\VPC32.INI
2008-08-18 15:15 . 2008-08-18 15:15 <DIR> d-------- C:\Program Files\Lavasoft
2008-08-18 15:15 . 2008-08-18 15:15 <DIR> d-------- C:\Documents and Settings\Rohit\Application Data\Lavasoft
2008-08-18 12:12 . 2008-08-18 12:12 <DIR> d--h----- C:\WINDOWS\PIF
2008-08-18 12:09 . 2006-09-18 17:55 109,744 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-08-18 12:09 . 2006-09-18 17:55 48,816 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-18 12:08 . 2008-08-22 17:07 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2008-08-17 23:16 . 2008-08-17 23:16 32 --a-s---- C:\WINDOWS\system32\2289234671.dat
2008-08-14 11:11 . 2008-08-14 11:11 <DIR> d-------- C:\Documents and Settings\Default User.WINDOWS\Application Data\Juniper Networks
2008-08-13 18:16 . 2008-05-01 10:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-13 18:15 . 2008-04-11 15:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-13 07:47 . 2008-08-13 10:59 <DIR> d-------- C:\Documents and Settings\Rohit\Application Data\ICAClient
2008-08-13 07:46 . 2008-08-13 07:46 <DIR> d-------- C:\Program Files\Citrix
2008-08-09 22:05 . 2008-08-09 22:05 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Juniper Networks
2008-08-04 14:02 . 2008-08-04 14:02 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Juniper Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 17:12 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-08-25 19:39 --------- d-----w C:\Documents and Settings\Rohit\Application Data\Juniper Networks
2008-08-22 20:56 --------- d-----w C:\Documents and Settings\Rohit\Application Data\U3
2008-08-18 16:10 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-18 16:09 --------- d-----w C:\Program Files\Symantec
2008-08-18 16:08 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2008-08-06 22:19 16,552 ----a-w C:\Documents and Settings\Rohit\Application Data\wklnhst.dat
2008-07-25 15:32 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Juniper Networks
2008-07-25 15:32 --------- d-----w C:\Program Files\Juniper Networks
2008-07-06 13:17 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\TVU Networks
2006-04-08 19:07 28,552 ----a-w C:\Documents and Settings\Rohit\Application Data\GDIPFONTCACHEV1.DAT
2001-10-04 19:50 271 --sh--w C:\Program Files\desktop.ini
2001-10-04 19:50 21,952 ---ha-w C:\Program Files\folder.htt
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:10, on 2008-09-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\AOL\1142915407\ee\AOLSoftware.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1142915407\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BM130cd580] Rundll32.exe "C:\WINDOWS\system32\hluvwuxo.dll",s
O4 - HKLM\..\Run: [103fe61c] rundll32.exe "C:\WINDOWS\system32\lpkyhmhp.dll",b
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/30.62/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 2313926812
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 2313919765
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol ... _en_dl.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager dmserverProtectedStorage (dmserverProtectedStorage) - Unknown owner - C:\WINDOWS\
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IMAPI CD-Burning COM Service ImapiServiceDefWatch (ImapiServiceDefWatch) - Unknown owner - .exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Uninterruptible Power Supply UPSCOMSysApp (UPSCOMSysApp) - Unknown owner - C:\WINDOWS\
O23 - Service: Windows Media Player Network Sharing Service WMPNetworkSvcNla (WMPNetworkSvcNla) - Unknown owner - C:\WINDOWS\
--
End of file - 9813 bytes
ComboFix 08-09-03.01 - Rohit 2008-09-03 17:46:56.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.207 [GMT -4:00]
Running from: C:\ComboFix\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\#SharedObjects\8XSSJV7R\bin.clearspring.com
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\#SharedObjects\8XSSJV7R\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\#SharedObjects\8XSSJV7R\interclick.com
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\#SharedObjects\8XSSJV7R\interclick.com\ud.sol
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Rohit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Rohit\Cookies\rohit@ad.yieldmanager[1].txt
C:\Documents and Settings\Rohit\Cookies\rohit@trafficmp[1].txt
C:\WINDOWS\BM130cd580.txt
C:\WINDOWS\BM130cd580.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bpoyqq.dll
C:\WINDOWS\system32\chvmrf.dll
C:\WINDOWS\system32\cmcehahj.dll
C:\WINDOWS\system32\ddcyvuVL.dll
C:\WINDOWS\system32\dyxfplpr.dll
C:\WINDOWS\system32\fewfbtwd.dll
C:\WINDOWS\system32\gdxpdpar.ini
C:\WINDOWS\system32\gkwaqf.dll
C:\WINDOWS\system32\hdohxedj.exe
C:\WINDOWS\system32\hhtsbhim.ini
C:\WINDOWS\system32\IkTwyGgh.ini
C:\WINDOWS\system32\IkTwyGgh.ini2
C:\WINDOWS\system32\inknumqv.ini
C:\WINDOWS\system32\jaflvvpg.dll
C:\WINDOWS\system32\jhxate.dll
C:\WINDOWS\system32\jwysxoda.ini
C:\WINDOWS\system32\lhdprdht.dll
C:\WINDOWS\system32\lvjhvuuc.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mihbsthh.dll
C:\WINDOWS\system32\ovfussrw.ini
C:\WINDOWS\system32\ppybku.dll
C:\WINDOWS\system32\pquslckv.exe
C:\WINDOWS\system32\saplupdk.dll
C:\WINDOWS\system32\scfeohpd.dll
C:\WINDOWS\system32\ssqNEtSi.dll
C:\WINDOWS\system32\thdrpdhl.ini
C:\WINDOWS\system32\tlguanne.dll
C:\WINDOWS\system32\upvdlnjn.dll
C:\WINDOWS\system32\wlaefxpk.dll
C:\WINDOWS\system32\wrssufvo.dll
C:\WINDOWS\system32\xebnza.dll
----- BITS: Possible infected sites -----
http://downloads.networkmagic.com
.
((((((((((((((((((((((((( Files Created from 2008-08-03 to 2008-09-03 )))))))))))))))))))))))))))))))
.
2008-08-27 20:10 . 2008-08-27 20:10 311,296 --a------ C:\WINDOWS\system32\hgGywTkI.dll
2008-08-22 18:56 . 2008-08-22 18:56 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-22 18:50 . 2004-08-04 03:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-08-22 18:39 . 2008-08-22 18:39 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-22 18:39 . 2008-08-22 18:39 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-22 18:39 . 2008-08-22 18:39 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 18:18 . 2008-04-13 20:12 276,992 --a------ C:\WINDOWS\system32\wmphoto.dll
2008-08-22 18:16 . 2008-04-13 20:11 650,752 --a------ C:\WINDOWS\system32\dot3ui.dll
2008-08-22 18:15 . 2008-04-13 20:11 233,472 --a------ C:\WINDOWS\system32\azroles.dll
2008-08-22 18:15 . 2008-04-13 20:11 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-08-22 18:15 . 2008-04-13 20:11 12,800 --a------ C:\WINDOWS\system32\credssp.dll
2008-08-22 18:15 . 2008-04-13 20:11 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-08-22 17:29 . 2008-08-22 17:29 0 --a------ C:\WINDOWS\VPC32.INI
2008-08-18 15:15 . 2008-08-18 15:15 <DIR> d-------- C:\Program Files\Lavasoft
2008-08-18 15:15 . 2008-08-18 15:15 <DIR> d-------- C:\Documents and Settings\Rohit\Application Data\Lavasoft
2008-08-18 12:12 . 2008-08-18 12:12 <DIR> d--h----- C:\WINDOWS\PIF
2008-08-18 12:09 . 2006-09-18 17:55 109,744 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-08-18 12:09 . 2006-09-18 17:55 48,816 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-18 12:08 . 2008-08-22 17:07 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2008-08-17 23:16 . 2008-08-17 23:16 32 --a-s---- C:\WINDOWS\system32\2289234671.dat
2008-08-14 11:11 . 2008-08-14 11:11 <DIR> d-------- C:\Documents and Settings\Default User.WINDOWS\Application Data\Juniper Networks
2008-08-13 18:16 . 2008-05-01 10:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-13 18:15 . 2008-04-11 15:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-13 07:47 . 2008-08-13 10:59 <DIR> d-------- C:\Documents and Settings\Rohit\Application Data\ICAClient
2008-08-13 07:46 . 2008-08-13 07:46 <DIR> d-------- C:\Program Files\Citrix
2008-08-09 22:05 . 2008-08-09 22:05 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Juniper Networks
2008-08-04 14:02 . 2008-08-04 14:02 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Juniper Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 17:12 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-08-25 19:39 --------- d-----w C:\Documents and Settings\Rohit\Application Data\Juniper Networks
2008-08-22 20:56 --------- d-----w C:\Documents and Settings\Rohit\Application Data\U3
2008-08-18 16:10 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-18 16:09 --------- d-----w C:\Program Files\Symantec
2008-08-18 16:08 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2008-08-06 22:19 16,552 ----a-w C:\Documents and Settings\Rohit\Application Data\wklnhst.dat
2008-07-25 15:32 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Juniper Networks
2008-07-25 15:32 --------- d-----w C:\Program Files\Juniper Networks
2008-07-06 13:17 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\TVU Networks
2006-04-08 19:07 28,552 ----a-w C:\Documents and Settings\Rohit\Application Data\GDIPFONTCACHEV1.DAT
2001-10-04 19:50 271 --sh--w C:\Program Files\desktop.ini
2001-10-04 19:50 21,952 ---ha-w C:\Program Files\folder.htt
.