التقرير
ComboFix 08-06-08.7 - Administrator 06/09/2008 11:30:36.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.30 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\.IE5\RIUNPVVN\cnsminex_empty[1].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\.IE5\RIUNPVVN\cnsminex_empty[2].htm
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\.IE5\UT2W4ZG6\cnsminex_empty[1].htm
C:\Program Files\ActivationManager
C:\Program Files\ActivationManager\Uninstall.exe
C:\WINDOWS\system32\Npad.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-09 to 2008-06-09 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-08 19:31 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-08 19:31 74,760 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-08 19:31 12,424 ----a-w C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-08 19:31 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-06-08 19:31 --------- d-----w C:\Program Files\AVG
2008-06-08 19:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-06-08 19:31 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-06-07 20:07 --------- d-----w C:\Program Files\Remote Professional
2008-06-07 20:05 --------- d-----w C:\Program Files\Create-Ringtone
2008-06-06 20:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DivX
2008-06-06 20:56 --------- d-----w C:\Program Files\DivX
2008-06-06 20:49 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-06 20:48 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-06 20:48 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-06 20:47 --------- d-----w C:\Program Files\Common Files\Real
2008-06-06 20:40 --------- d-----w C:\Program Files\RichFX
2008-06-04 20:56 --------- d-----w C:\Program Files\Internet Download Manager
2008-06-01 11:29 --------- d-----w C:\Program Files\Stepok's Gigital Beauty
2008-05-29 22:19 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-05-29 22:18 --------- d-----w C:\Program Files\Common Files\Skype
2008-05-29 22:17 --------- d-----w C:\Program Files\Google
2008-05-29 22:16 --------- d-----w C:\Program Files\Skype
2008-05-29 22:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-05-29 22:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-29 22:11 --------- d-----w C:\Program Files\Yahoo!
2008-05-28 22:32 --------- d-----w C:\Program Files\Real
2008-05-28 22:31 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-05-28 22:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-05-27 11:48 --------- d-----w C:\Program Files\Reference Assemblies
2008-05-27 11:48 --------- d-----w C:\Program Files\MSBuild
2008-05-26 00:02 --------- d-----w C:\Program Files\MSXML 4.0
2008-05-25 21:53 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MozillaControl
2008-05-25 20:54 --------- d-----w C:\Program Files\'Full Speed' Internet Booster + Performance Tests
2008-05-25 20:37 --------- d-----w C:\Program Files\CCleaner
2008-05-25 11:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-24 18:27 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-05-24 18:27 249,856 ------w C:\WINDOWS\Setup1.exe
2008-05-20 23:57 --------- d-----w C:\Program Files\eBook Workshop
2008-05-20 22:26 --------- d-----w C:\Program Files\TechSmith
2008-05-20 22:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-05-20 22:24 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-20 22:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-20 22:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-20 22:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\GlobalSCAPE
2008-03-26 08:09 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-26 08:09 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-25 07:20 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
2008-03-25 07:20 219,936 ----a-w C:\WINDOWS\system32\dllcache\msltus40.dll
2008-03-19 09:40 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:40 1,845,888 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2002-12-31 21:42 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2002-12-31 21:42 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012003010120030102\index.dat
2002-12-31 21:42 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\.IE5\index.dat
2002-12-31 21:42 16,384 --sha-w C:\WINDOWS\system32\config\systemprofile\s\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{A057A204-BACC-4D26-9990-79A187E2698E}]
06/08/2008 10:31 PM 2041600 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [06/08/2008 10:31 PM 2041600]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [06/08/2008 10:31 PM 2041600]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:00 PM 15360]
"npad_ql"="C:\WINDOWS\system32\Npad.exe" [ ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [03/27/2007 04:22 PM 4670968]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [03/05/2007 02:28 PM 25776168]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="C:\Program Files\LClock\LClock.exe" [ ]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [05/06/2006 09:29 AM 6656]
"c0.exe"="C:\aidualc3\c0.exe" [07/29/2007 09:48 PM 292864]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/07/2008 12:47 AM 185896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [06/08/2008 11:31 PM 1172760]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:00 PM 15360]
"npad_ql"="C:\WINDOWS\system32\Npad.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WindowBlinds"="C:\Program Files\Stardock\ Desktop\Windowblinds\wbconfig.exe" [12/03/2005 03:03 AM 638976]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-05-01 11:11:48 6395464]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-25 14:10:20 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\ Desktop\Windowblinds\wbsrv.dll 12/06/2005 10:16 PM 176128 C:\Program Files\Stardock\ Desktop\Windowblinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [06/08/2008 10:31 PM]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [06/08/2008 10:31 PM]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [06/08/2008 11:31 PM]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [06/08/2008 11:31 PM]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [06/08/2008 10:31 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WudfServiceGroup REG_SZ hex(7):57,00,55,00,44,00,46,00,53,00,76,00,63,00,00,00,00,00
*Newly Created Service* - CATCHME
.
s of the 'Scheduled Tasks' folder
"2008-06-09 08:05:24 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-09 11:34:44
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfPf]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,57,00,75,00,64,00,66,00,50,00,66,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfRd]
"ImagePath"="hex(2):73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,00,49,00,56,00,45,00,52,00,53,00,5c,00,77,00,75,00,64,00,66,00,72,00,64,00,2e,00,73,00,79,00,73,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WudfSvc]
"ImagePath"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00"
"ServiceDll"="hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,57,00,55,00,44,00,46,00,53,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00"
.
Completion time: 06/09/2008 11:36:10
ComboFix-quarantined-files.txt 2008-06-09 08:36:04
Pre-Run: 701,026,304 bytes free
Post-Run: 699,424,768 bytes free
176 --- E O F --- 2008-06-08 20:07:27