ComboFix 08-09-15.02 - WinXp 2008-09-17 2:35:17.1 -
FAT32x86
Running from: C:\Documents and Settings\WinXp\My Documents\Downloads\Programs\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\WinXp\s\winxp@msn[2].txt
C:\WINDOWS\system32\Ultra.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Service_6to4
((((((((((((((((((((((((( Files Created from 2008-08-16 to 2008-09-16 )))))))))))))))))))))))))))))))
.
2008-09-16 23:57 . 2008-09-16 23:57 <DIR> d-------- C:\Program Files\The KMPlayer
2008-09-16 22:15 . 2008-09-16 22:15 7,168 --ahs---- C:\WINDOWS\Thumbs.db
2008-09-16 22:15 . 2008-09-16 22:15 5,632 --ahs---- C:\Thumbs.db
2008-09-16 01:04 . 2008-09-16 01:04 <DIR> d--hs---- C:\FOUND.002
2008-09-12 03:04 . 2008-09-12 03:04 <DIR> d-------- C:\Documents and Settings\WinXp\Application Data\TuneUp Software
2008-09-10 23:25 . 2008-09-10 23:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-10 16:07 . 1998-06-24 10:56 115,016 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-09-10 15:24 . 2008-09-10 15:24 <DIR> d-------- C:\Program Files\DirectVobSub
2008-09-10 14:22 . 2008-09-10 14:22 <DIR> d-------- C:\Program Files\Arafasoft
2008-09-09 03:47 . 2008-09-09 03:47 <DIR> d-------- C:\Documents and Settings\WinXp\Application Data\Symantec
2008-09-09 03:45 . 2008-09-09 03:45 <DIR> d-------- C:\Program Files\Norton 360
2008-09-09 03:43 . 2008-09-09 03:43 <DIR> d-------- C:\Program Files\Symantec
2008-09-09 03:43 . 2008-09-09 03:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-09-09 03:43 . 2008-09-09 04:25 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-09-09 03:43 . 2008-09-09 04:25 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-09-09 03:43 . 2008-09-09 04:25 10,671 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-09-09 03:43 . 2008-09-09 04:25 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-09-09 03:37 . 2008-09-09 03:37 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-09-08 21:43 . 2008-09-08 21:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-08 05:53 . 2008-09-08 05:53 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-09-08 05:11 . 2008-09-08 05:11 <DIR> d-------- C:\Program Files\Free Download Manager
2008-09-08 05:11 . 2008-09-08 05:11 <DIR> d-------- C:\Documents and Settings\WinXp\Application Data\Free Download Manager
2008-09-06 04:53 . 2008-09-06 04:53 <DIR> d-------- C:\Program Files\uTorrent
2008-09-06 04:53 . 2008-09-06 04:53 <DIR> d-------- C:\Documents and Settings\WinXp\Application Data\uTorrent
2008-09-06 04:40 . 2008-09-06 04:40 <DIR> d-------- C:\Program Files\LeapFTP
2008-09-06 04:40 . 1998-06-08 15:58 55,808 --a------ C:\WINDOWS\unleap.exe
2008-09-05 19:35 . 2008-09-05 19:35 <DIR> d-------- C:\Program Files\Intelore
2008-09-03 14:18 . 2008-09-03 14:18 <DIR> d--hs---- C:\FOUND.001
2008-09-03 13:21 . 2008-09-03 13:21 <DIR> d-------- C:\Program Files\Uniblue
2008-09-03 12:20 . 2008-09-03 12:20 1,555 --a------ C:\WINDOWS\ata live update.ini
2008-09-03 05:46 . 2008-07-15 20:22 2,703,456 --a------ C:\Program Files\idman514.exe
2008-09-03 02:58 . 2008-09-03 02:58 <DIR> d--hs---- C:\FOUND.000
2008-09-01 23:32 . 2008-09-01 23:32 <DIR> d-------- C:\Documents and Settings\WinXp\Application Data\CyberLink
2008-09-01 19:03 . 2008-09-11 05:58 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-09-01 18:42 . 2008-05-09 13:53 512,000 --------- C:\WINDOWS\system32\dllcache\jscript.dll
2008-09-01 18:42 . 2008-05-09 13:53 430,080 --------- C:\WINDOWS\system32\dllcache\vbscript.dll
2008-09-01 18:42 . 2008-05-09 13:53 180,224 --------- C:\WINDOWS\system32\dllcache\scrobj.dll
2008-09-01 18:42 . 2008-05-09 13:53 172,032 --------- C:\WINDOWS\system32\dllcache\scrrun.dll
2008-09-01 18:42 . 2008-05-08 14:24 155,648 --------- C:\WINDOWS\system32\dllcache\wscript.exe
2008-09-01 18:42 . 2008-05-09 11:45 135,168 --------- C:\WINDOWS\system32\dllcache\cscript.exe
2008-09-01 18:42 . 2008-05-09 13:53 90,112 --------- C:\WINDOWS\system32\dllcache\wshext.dll
2008-09-01 18:35 . 2008-09-15 04:00 3,218 --a------ C:\WINDOWS\system32\PerfStringBackup.TMP
2008-09-01 17:27 . 2008-09-01 17:27 <DIR> d-------- C:\Documents and Settings\WinXp\Application Data\FlashFXP
2008-09-01 15:56 . 2008-07-09 17:34 206,256 --a------ C:\WINDOWS\system32\idmmbc.dll
2008-08-22 19:08 . 2008-08-22 19:08 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-22 19:08 . 2008-08-22 19:08 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-22 19:08 . 2008-08-22 19:08 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-22 19:08 . 2008-08-22 19:08 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 19:05 . 2008-08-22 19:05 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-22 18:16 . 2008-08-22 18:16 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-08-22 16:18 . 2008-08-22 16:18 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-08-22 14:37 . 2008-06-13 14:05 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-22 13:17 . 2008-05-08 17:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-08-22 12:43 . 2008-04-11 22:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-22 06:45 . 2008-08-22 06:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt
2008-08-20 17:55 . 2008-08-20 17:55 <DIR> d-------- C:\Documents and Settings\WinXp\Application Data\SmartFTP
2008-08-19 20:35 . 2008-08-19 20:35 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-19 20:30 . 2008-04-14 03:12 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-08-19 20:29 . 2004-08-03 22:29 1,897,408 --------- C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-08-16 21:21 . 2008-08-16 21:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-08-16 21:17 . 2008-08-16 21:17 <DIR> d-------- C:\Program Files\Bonjour
2008-08-16 21:06 . 2008-08-16 21:06 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 03:20 2,138 ----a-w C:\Program Files\sas
2008-08-15 01:30 --------- d-----w C:\Program Files\MSN Messenger
2008-08-07 01:09 --------- d-----w C:\Documents and Settings\WinXp\Application Data\Uniblue
2008-08-07 00:36 --------- d-----w C:\Documents and Settings\WinXp\Application Data\Media Player Classic
2008-08-06 00:08 --------- d-----w C:\Documents and Settings\WinXp\Application Data\IDM
2008-08-06 00:08 --------- d-----w C:\Documents and Settings\WinXp\Application Data\DMCache
2008-08-06 00:07 --------- d-----w C:\Program Files\Internet Download Manager
2008-08-05 22:12 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-05 22:12 --------- d-----w C:\Program Files\Windows Live
2008-08-05 22:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-05 18:20 --------- d-----w C:\Documents and Settings\WinXp\Application Data\Ahead
2008-08-05 18:15 --------- d-----w C:\Documents and Settings\WinXp\Application Data\ACD Systems
2008-08-05 18:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-05 16:45 --------- d-----w C:\Program Files\Common Files\Cisco Systems
2008-08-05 16:38 --------- d-----w C:\Program Files\CONEXANT
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 15:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 07:57 3,592,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
.
------- Sigcheck -------
2008-04-14 03:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\system32\svchost.exe
2002-12-31 12:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2008-04-14 03:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-04-14 03:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\user32.dll
2002-12-31 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\SoftwareDistribution\Download\5652d934eec8bfa4dc68c4e256a23d5e\backup\sp2gdr\user32.dll
2002-12-31 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\SoftwareDistribution\Download\5652d934eec8bfa4dc68c4e256a23d5e\backup\sp2qfe\user32.dll
2002-12-31 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2008-04-14 03:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-04-14 03:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\system32\ws2_32.dll
2002-12-31 12:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2008-04-14 03:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2008-06-23 19:57 826368 8c13d4a7479fa0a026eda8abce82c0ed C:\WINDOWS\system32\wininet.dll
2008-06-23 19:57 826368 8c13d4a7479fa0a026eda8abce82c0ed C:\WINDOWS\system32\dllcache\wininet.dll
2008-04-23 06:35 827392 41546b396a526918da7995a02ea04e51 C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 19:01 827904 c66402a06b83b036c195242c0c8cf83c C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-04-14 03:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2002-12-31 15:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\ie7\wininet.dll
2007-08-13 18:54 818688 a4a0fc92358f39538a6494c42ef99fe9 C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
2008-04-23 07:16 826368 f6589be784647cfdbc22ea51ccb1a57a C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
2008-06-20 14:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 14:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\dllcache\tcpip.sys
2006-04-20 15:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\SP2QFE\tcpip.sys
2006-04-20 14:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\SP2GDR\tcpip.sys
2006-04-20 14:38 340480 b8158e2a6112c0a5ca67bc158fc70218 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\SP1QFE\tcpip.sys
2008-06-20 13:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 14:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 14:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2002-12-31 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-06-20 13:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2008-04-13 22:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-04-13 22:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2008-04-14 03:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\system32\winlogon.exe
2002-12-31 12:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-14 03:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 22:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\system32\drivers\ndis.sys
2002-12-31 12:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2008-04-13 22:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2008-04-13 21:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\system32\drivers\ip6fw.sys
2002-12-31 12:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 21:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2008-04-13 21:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\system32\ntkrnlpa.exe
2002-12-31 12:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\SoftwareDistribution\Download\5652d934eec8bfa4dc68c4e256a23d5e\backup\sp2gdr\ntkrnlpa.exe
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\SoftwareDistribution\Download\5652d934eec8bfa4dc68c4e256a23d5e\backup\sp2qfe\ntkrnlpa.exe
2002-12-31 12:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2008-04-13 21:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-04-13 22:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\system32\ntoskrnl.exe
2002-12-31 12:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\SoftwareDistribution\Download\5652d934eec8bfa4dc68c4e256a23d5e\backup\sp2gdr\ntoskrnl.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\SoftwareDistribution\Download\5652d934eec8bfa4dc68c4e256a23d5e\backup\sp2qfe\ntoskrnl.exe
2002-12-31 12:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2008-04-13 22:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-04-14 03:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\explorer.exe
2002-12-31 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2008-04-14 03:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2008-04-14 03:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\system32\services.exe
2002-12-31 12:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2008-04-14 03:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\ServicePackFiles\i386\services.exe
2008-04-14 03:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\system32\lsass.exe
2002-12-31 12:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2008-04-14 03:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2008-04-14 03:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\system32\ctfmon.exe
2002-12-31 12:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-14 03:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-14 03:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\system32\spoolsv.exe
2002-12-31 12:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2008-04-14 03:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-14 03:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\system32\userinit.exe
2002-12-31 12:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-14 03:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Uniblue SpeedUpMyPC"="C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [2008-05-02 9442584]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-09-09 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-05-28 86016]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-04 487424]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-10-27 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-10-27 118784]
"Athan"="C:\Program Files\Athan\Athan.exe" [2007-01-11 954368]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-05-18 49152]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 51048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 C:\WINDOWS\system32\bthprops.cpl]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 C:\WINDOWS\BCMSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\Dell\Bluetooth Software\BTTray.exe [2004-03-05 553021]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-12 06:55 110592 C:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
2006-07-22 23:49 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\LeapFTP\\LeapFTP.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
*Newly Created Service* - COMHOST
.
s of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-osCheck - C:\Program Files\Norton 360\osCheck.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\WinXp\Application Data\Mozilla\Firefox\Profiles\c4bh90up.default\
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-17 02:39:11
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\6to4]
"ServiceDll"="%SystemRoot%\System32\6to4svc.dll"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\CLTNetCnService]
"ImagePath"="\"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe\" /h ccCommon"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\COH_Mon]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\COH_Mon.sys"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\CO_Mon]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\CO_Mon.sys"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\eeCtrl]
"ImagePath"="\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EraserUtilRebootDrv]
"ImagePath"="\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\LiveUpdate Notice]
"ImagePath"="\"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe\" /h ccCommon"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NAVENG]
"ImagePath"="\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080916.003\NAVENG.SYS"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NAVEX15]
"ImagePath"="\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080916.003\NAVEX15.SYS"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SPBBCDrv]
"ImagePath"="\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SRTSP]
"ImagePath"="System32\Drivers\SRTSP.SYS"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SRTSPL]
"ImagePath"="System32\Drivers\SRTSPL.SYS"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SRTSPX]
"ImagePath"="System32\Drivers\SRTSPX.SYS"
--
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Symantec Core LC]
"ImagePath"="C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-09-17 2:42:23 - machine was rebooted [WinXp]
ComboFix-quarantined-files.txt 2008-09-16 23:42:20
Pre-Run: 6,688,423,936 bytes free
Post-Run: 7,164,231,680 bytes free
321 --- E O F --- 2008-09-16 21:21:02
والحين راح اشوف لك الفحص الجديد
Logfile of HijackThis v1.99.1
Scan saved at 2:43:06 AM, on 9/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Dell\Bluetooth Software\BTTray.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\DOCUME~1\WinXp\LOCALS~1\Temp\Rar$EX00.873\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: E?E - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash ) -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\system32\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe