ComboFix 08-06-16.5 - admin 2008-06-19 14:15:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.527 [GMT 3:00]
Running from: C:\Documents and Settings\admin\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000012_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-19 to 2008-06-19 )))))))))))))))))))))))))))))))
.
2008-06-19 13:18 . 2008-06-19 13:18 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-06-13 14:45 . 2008-06-13 14:45 579,464 --a------ C:\WINDOWS\system32\SymNeti.dll
2008-06-13 14:45 . 2008-06-13 14:45 207,240 --a------ C:\WINDOWS\system32\SymRedir.dll
2008-06-13 14:14 . 2008-06-13 14:14 13,093 --a------ C:\WINDOWS\system32\drivers\SymRedir.cat
2008-06-13 14:14 . 2008-06-13 14:14 1,611 --a------ C:\WINDOWS\system32\drivers\SymRedir.inf
2008-06-13 14:13 . 2008-06-13 14:13 184,240 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
2008-06-13 14:13 . 2008-06-13 14:13 96,432 --a------ C:\WINDOWS\system32\drivers\symfw.sys
2008-06-13 14:13 . 2008-06-13 14:13 41,008 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
2008-06-13 14:13 . 2008-06-13 14:13 38,576 --a------ C:\WINDOWS\system32\drivers\symids.sys
2008-06-13 14:13 . 2008-06-13 14:13 37,424 --a------ C:\WINDOWS\system32\drivers\symndis.sys
2008-06-13 14:13 . 2008-06-13 14:13 22,320 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
2008-06-13 14:13 . 2008-06-13 14:13 13,616 --a------ C:\WINDOWS\system32\drivers\symdns.sys
2008-06-13 07:28 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\
03371726.sys
2008-06-13 05:18 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\32712334.sys
2008-06-13 05:11 . 2008-06-19 14:27 21,225,504 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-13 05:11 . 2008-06-19 14:24 249,248 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-20 13:54 . 2008-05-20 13:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-05-20 13:54 . 2008-05-20 13:54 <DIR> d-------- C:\Documents and Settings\admin\Application Data\HP
2008-05-20 13:49 . 2008-05-20 13:49 3,834 --a------ C:\WINDOWS\hpbvnstp.his
2008-05-20 13:49 . 2008-05-20 13:49 1,271 --a------ C:\WINDOWS\hpbvnstp.ini
2008-05-20 13:49 . 2008-05-20 13:49 731 --a------ C:\WINDOWS\hpbvspst.his
2008-05-20 13:49 . 2008-05-20 13:49 390 --a------ C:\WINDOWS\hpbvspst.ini
2008-05-20 13:44 . 2008-05-20 13:44 <DIR> d-------- C:\Program Files\HP
2008-05-20 13:42 . 2008-05-20 13:55 92,601 --a------ C:\WINDOWS\hppins05.dat
2008-05-20 13:42 . 2006-04-25 00:57 1,016 --------- C:\WINDOWS\hppmdl05.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-19 11:22 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-19 10:08 --------- d-----w C:\Program Files\Yahoo!
2008-06-19 03:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-20 10:51 --------- d-----w C:\Program Files\Hewlett-Packard
2008-05-13 11:05 --------- d-----w C:\Program Files\Quranzu1
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 06:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Symantec
2008-05-07 06:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Share-to-Web Upload Folder
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 05:54 0 ---ha-w C:\Documents and Settings\admin\hpothb07.dat
2008-04-30 05:54 0 ---ha-w C:\Documents and Settings\admin\Application Data\hpothb07.dat
2008-04-26 11:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-20 02:43 102,464 ----a-w C:\WINDOWS\HarfDeleteFont.exe
2008-04-20 02:43 --------- d-----w C:\Program Files\Harf
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-25 06:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-02-01 09:33 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-07-27 15:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-28 08:55 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-28 08:52 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-28 08:55 118784]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 10:42 69632]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-31 13:15 51048]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-08-25 07:53 714608]
"SkyTel"="SkyTel.EXE" [2006-05-16 18:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 15:03 16125440 C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 18:43 69632 C:\WINDOWS\Alcmtr.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2007-07-27 15:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-15 09:26 185896]
"ToolBoxFX"="C:\Program Files\Hewlett-Packard\ToolBoxFX\bin\HPTLBXFX.exe" [2006-06-15 08:43 49152]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"combofix"="C:\WINDOWS\system32\CF23956.exe" [2007-07-27 15:00 388608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-07-27 15:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Server4PC.lnk - C:\Program Files\TechniSat DVB\bin\Server4PC.exe [2007-11-18 20:00:52 430080]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Mobily Connect Card\\Mobily Connect Card.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 is-4CLC1drv;is-4CLC1drv;C:\WINDOWS\system32\drivers\
03371726.sys [2008-03-05 11:41]
R1 is-LOA4Ldrv;is-LOA4Ldrv;C:\WINDOWS\system32\drivers\32712334.sys [2008-03-05 11:41]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 HPFXBULK;HPFXBULK;C:\WINDOWS\system32\drivers\hpfxbulk.sys [2006-06-12 13:36]
R3 SKYNET;B2C2 Broadband Receiver PCI Adapter;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [2004-01-06 01:42]
S2 is-4CLC1;is-4CLC1;"C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-4CLC1\is-4CLC1.exe" -r []
S2 is-LOA4L;is-LOA4L;"C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-LOA4L\is-LOA4L.exe" -r []
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a7e34f2-1cc7-11dd-9c41-00d0d70ad711}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{734598cc-0139-11dd-9bd3-00d0d70ad711}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc1849a2-95f4-11dc-9a74-e9818e40da75}]
\Shell\AutoRun\command - F:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc1849a6-95f4-11dc-9a74-e9818e40da75}]
\Shell\AutoRun\command - F:\AutoRun.exe
*Newly Created Service* - COMHOST
.
s of the 'Scheduled Tasks' folder
"2008-06-16 17:03:00 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - admin.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-19 14:27:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
.
**************************************************************************
.
Completion time: 2008-06-19 14:30:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-19 11:30:36
Pre-Run: 29,463,846,912 bytes free
Post-Run: 29,419,388,928 bytes free
163 --- E O F --- 2008-06-16 17:06:49