I m posting log file..
ComboFix 08-06-07.3 - Prateek 2008-06-08 16:54:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1619 [GMT 5.5:30]
Running from: C:\Documents and Settings\Prateek\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dKnpWyay.ini
C:\WINDOWS\system32\dKnpWyay.ini2
C:\WINDOWS\system32\hbhcbmsp.dll
C:\WINDOWS\system32\iiffDUkH.dll
C:\WINDOWS\system32\psmbchbh.ini
C:\WINDOWS\system32\urqOEtSl.dll
C:\WINDOWS\system32\yayWpnKd.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-08 to 2008-06-08 )))))))))))))))))))))))))))))))
.
2008-06-08 15:32 . 2008-06-08 15:45 <DIR> d-------- C:\Program Files\Yahoo!
2008-06-08 15:32 . 2008-06-08 15:33 <DIR> d-------- C:\Program Files\CCleaner
2008-06-08 15:08 . 2008-06-08 15:30 <DIR> d-------- C:\Documents and Settings\Prateek\Application Data\IDM
2008-06-08 15:07 . 2008-06-08 16:41 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-06-08 14:44 . 2008-06-08 14:44 1,169 --a------ C:\WINDOWS\mozver.dat
2008-06-08 13:16 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-08 13:15 . 2008-06-08 13:16 <DIR> d-------- C:\Program Files\Java
2008-06-08 13:07 . 2008-06-08 13:07 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-08 13:00 . 2008-06-08 13:00 <DIR> d-------- C:\Program Files\filehippo.com
2008-06-08 12:26 . 2008-06-08 12:26 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-06-08 12:26 . 2006-11-17 03:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-06-08 12:26 . 2006-11-17 03:06 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-06-08 12:26 . 2006-11-17 03:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-06-08 12:23 . 2008-06-08 12:23 <DIR> d-------- C:\Program Files\uTorrent
2008-06-08 12:23 . 2008-06-08 12:42 <DIR> d-------- C:\Documents and Settings\Prateek\Application Data\uTorrent
2008-06-08 12:21 . 2008-06-08 15:47 <DIR> d-------- C:\Documents and Settings\Prateek\Application Data\DMCache
2008-06-08 12:19 . 2008-06-08 12:19 <DIR> d-------- C:\Documents and Settings\Prateek\Application Data\Talkback
2008-06-08 12:18 . 2008-06-08 12:18 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-08 12:14 . 2008-06-08 12:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-05-12 18:26 . 2008-02-15 20:42 206,256 --a------ C:\WINDOWS\system32\idmmbc.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-08 11:27 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-08 06:16 --------- d-----w C:\Documents and Settings\Prateek\Application Data\Uniblue
2008-06-08 06:15 --------- d-----w C:\Program Files\Uniblue
2008-06-08 06:14 --------- d-----w C:\Documents and Settings\Prateek\Application Data\ATI
2008-06-08 06:12 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-08 06:12 --------- d-----w C:\Program Files\ATI Technologies
2008-06-08 06:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-08 06:06 16,608 ----a-w C:\WINDOWS\gdrv.sys
2008-06-08 06:01 --------- d-----w C:\Program Files\Realtek
2008-06-08 05:59 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-06-08 05:58 --------- d-----w C:\Program Files\AMD
2008-06-08 05:58 --------- d-----w C:\Documents and Settings\Prateek\Application Data\InstallShield
2008-04-28 19:29 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-04-28 19:29 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-28 19:29 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-04-28 19:29 140,288 ----a-w C:\WINDOWS\system32\sfc_os.dll
2008-04-14 10:42 74,752 ----a-w C:\WINDOWS\system32\storprop.dll
2008-04-14 10:42 74,240 ----a-w C:\WINDOWS\system32\usbui.dll
2008-04-14 10:42 29,184 ----a-w C:\WINDOWS\system32\sdhcinst.dll
2008-04-14 10:41 30,208 ----a-w C:\WINDOWS\system32\bthserv.dll
2008-04-14 10:41 20,992 ----a-w C:\WINDOWS\system32\bthci.dll
2008-04-14 05:13 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 05:12 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv
2008-04-14 05:11 4,096 ----a-w C:\WINDOWS\system32\ksuser.dll
2008-04-14 05:10 57,600 ----a-w C:\WINDOWS\system32\drivers\redbook.sys
2008-04-14 05:06 8,832 ----a-w C:\WINDOWS\system32\drivers\wmiacpi.sys
2008-04-14 03:55 1,804 ----a-w C:\WINDOWS\system32\Dcache.bin
2008-04-14 03:46 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 03:43 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 03:43 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 03:43 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 03:43 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 03:43 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 03:43 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 03:43 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 03:41 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 03:40 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 03:40 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 03:40 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-14 03:40 102,912 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-14 03:39 9,344 ----a-w C:\WINDOWS\system32\framebuf.dll
2008-04-14 03:39 7,168 ----a-w C:\WINDOWS\system32\kbdukx.dll
2008-04-14 03:39 566,784 ----a-w C:\WINDOWS\system32\gpedit.dll
2008-04-14 03:39 3,584 ----a-w C:\WINDOWS\system32\icmp.dll
2008-04-14 03:39 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll
2008-04-14 03:39 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll
2008-04-14 03:39 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll
2008-04-14 03:39 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
2008-04-14 03:39 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll
2008-04-14 00:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-14 00:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-14 00:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-14 00:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 23:45 60,160 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
2008-04-13 23:45 6,272 ----a-w C:\WINDOWS\system32\drivers\splitter.sys
2008-04-13 23:45 56,576 ----a-w C:\WINDOWS\system32\drivers\swmidi.sys
2008-04-13 23:45 52,864 ----a-w C:\WINDOWS\system32\drivers\DMusic.sys
2008-04-13 23:45 49,408 ----a-w C:\WINDOWS\system32\drivers\stream.sys
2008-04-13 23:45 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
2008-04-13 23:45 172,416 ----a-w C:\WINDOWS\system32\drivers\kmixer.sys
2008-04-13 23:32 196,224 ----a-w C:\WINDOWS\system32\drivers\rdpdr.sys
2008-04-13 23:00 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 22:58 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 22:54 2,145,280 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 22:51 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 22:50 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 22:50 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 22:49 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 22:49 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 22:49 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 22:49 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 22:48 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 22:47 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 22:47 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 22:46 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 22:45 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 22:45 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 22:45 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 22:44 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 22:44 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 22:30 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 22:30 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 22:27 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 22:27 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 22:27 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 22:27 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 22:27 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 22:27 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 22:27 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 22:26 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 22:26 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 22:26 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 22:26 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 22:26 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 22:26 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 22:25 202,624 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys
2008-04-13 22:24 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 22:23 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 22:23 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 22:23 36,608 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys
.
------- Sigcheck -------
2008-04-29 00:59 361344 68f06fe0021b01e670af37b8c5964fdf C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue SpyEraser"="C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" [2008-04-02 09:50 1424648]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-08-16 09:02 1877272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-12-20 14:17 16860672 C:\WINDOWS\RTHDCPL.exe]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-06 01:07 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"GEST"="=" []
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [ ]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-04-14 09:11 99840 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [2005-08-06 01:07:30 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
S3 ATICDSDr;ATICDSDr;H:\BIN\atiicdxx.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2008-06-08 11:36]
.
Contents of the 'Scheduled Tasks' folder
"2008-06-08 07:00:10 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-08 17:05:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 2008-06-08 17:06:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-08 11:36:07
Pre-Run: 39,074,598,912 bytes free
Post-Run: 39,042,699,264 bytes free
216