ComboFix 08-10-07.06 - User 10/08/2008 20:55:37.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.193 [GMT 3:00]
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ICON\_desktop.ini
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 10:29 --------- d-----w C:\Program Files\Zain USB-Connect
2008-10-08 01:05 --------- d-----w C:\Program Files\BitSpirit
2008-10-06 17:55 --------- d-----w C:\Program Files\CCleaner
2008-10-06 14:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-10-04 10:32 --------- d-----w C:\Program Files\Common Files\SolidDocuments
2008-10-04 10:32 --------- d-----w C:\Documents and Settings\User\Application Data\SolidDocuments
2008-10-04 10:31 --------- d-----w C:\Program Files\Soliddocuments
2008-10-04 10:05 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-10-04 10:05 172,032 ------w C:\WINDOWS\Setup1.exe
2008-10-04 10:05 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-09-27 14:07 --------- d-----w C:\Program Files\Huawei technologies
2008-09-26 20:46 --------- d-----w C:\Program Files\Megaupload
2008-09-26 20:46 --------- d-----w C:\Documents and Settings\User\Application Data\Megaupload
2008-09-26 20:15 --------- d-----w C:\Program Files\MegauploadToolbar
2008-09-26 20:15 --------- d-----w C:\Documents and Settings\User\Application Data\MegauploadToolbar
2008-09-26 20:15 --------- d-----w C:\Documents and Settings\User\Application Data\EmailNotifier
2008-09-26 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Megaupload
2008-09-26 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\EmailNotifier
2008-09-26 20:05 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-09-26 19:19 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-26 19:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-26 18:53 --------- d-----w C:\Program Files\Windows Live
2008-09-26 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-09-26 17:38 --------- d-----w C:\Program Files\Yahoo!
2008-09-26 08:25 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2008-09-26 08:25 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2008-09-26 08:25 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2008-09-26 08:25 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2008-09-26 08:25 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-09-26 08:25 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-09-26 08:25 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
2008-09-26 08:25 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-09-24 22:46 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2008-09-24 22:34 --------- d-----w C:\Program Files\DAP
2008-09-24 20:26 --------- d-----w C:\Program Files\Common Files\Vbox
2008-09-24 20:25 --------- d-----w C:\Program Files\Macromedia
2008-09-24 07:44 --------- d-----w C:\Program Files\D-Link
2008-09-24 07:44 --------- d-----w C:\Program Files\ANI
2008-09-21 02:28 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-21 02:28 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-21 02:28 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-09-21 02:28 --------- d-----w C:\Program Files\AVG
2008-09-21 02:28 --------- d-----w C:\Documents and Settings\User\Application Data\AVGTOOLBAR
2008-09-21 02:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-09-20 22:44 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-20 22:44 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-20 22:44 --------- d-----w C:\Program Files\Common Files\Real
2008-09-20 22:43 --------- d-----w C:\Program Files\Real
2008-09-20 05:45 --------- d-----w C:\Program Files\Alo RM Converter
2008-09-17 22:38 --------- d-----w C:\Program Files\Google
2008-09-17 22:37 --------- d-----w C:\Documents and Settings\User\Application Data\Application Data
2008-09-17 22:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Storm
2008-09-17 22:25 --------- d-----w C:\Program Files\StormII
2008-09-17 18:41 --------- d-----w C:\Documents and Settings\User\Application Data\DMCache
2008-09-14 22:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-14 22:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpeedBit
2008-09-14 18:12 --------- d-----w C:\Program Files\Hotspot Shield
2008-09-14 18:11 --------- d-----w C:\Program Files\mDSL
2008-09-14 18:11 --------- d-----w C:\Documents and Settings\User\Application Data\ZTEEVDO
2008-09-12 23:54 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-05 20:30 241,704 ------w C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-05 20:29 917,032 ------w C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-08-17 16:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-16 14:08 --------- d-----w C:\Documents and Settings\User\Application Data\Media Player Classic
2008-08-16 14:03 --------- d-----w C:\Program Files\Ringz Studio
2008-08-16 14:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-31 19:28 8,847,360 ----a-w C:\nc2mdf.sys
2008-07-31 19:28 20,532 ----a-w C:\nc2mdb.sys
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 19:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 19:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 19:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 19:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 19:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 19:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 19:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 19:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 19:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 19:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}]
08/04/2008 11:44 PM 1947080 --a------ C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"= "C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL" [08/04/2008 11:44 PM 1947080]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"= "C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL" [08/04/2008 11:44 PM 1947080]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c39e-35f1d2a32ec8}]
[HKEY_CLASSES_ROOT\megauploadtoolbar.MEGAUPLOADTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 03:12 AM 15360]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" [09/25/2008 01:46 AM 3057152]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"Messenger (Yahoo!)"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [09/19/2008 05:34 PM 4347120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [01/12/2007 05:47 PM 131072]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [01/12/2007 05:47 PM 163840]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [01/12/2007 05:46 PM 135168]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/21/2008 01:44 AM 185896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [10/05/2008 08:21 PM 1234712]
"D-Link AirPlus XtremeG"="C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [06/16/2006 10:24 AM 1323008]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [06/01/2006 04:59 PM 49152]
"RTHDCPL"="RTHDCPL.EXE" [10/16/2007 02:30 AM 16855552 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [10/10/2007 07:04 PM 1826816 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 03:12 AM 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\User\\My Documents\\Downloads\\games\\Call of Duty 2\\CoDMP.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"C:\\Program Files\\BitSpirit\\BitSpirit.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [09/21/2008 05:28 AM 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [09/21/2008 05:28 AM 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [09/21/2008 05:28 AM 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [09/21/2008 05:28 AM 76040]
R2 ccosm;Contrl Center of Storm Media;C:\Program Files\StormII\stormliv.exe [03/11/2008 09:33 AM 473184]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [07/13/2006 04:11 AM 472096]
R3 nckbdsup;nckbdsup;C:\WINDOWS\system32\drivers\nckbdsup.sys [04/05/2006 09:53 PM 3584]
R3 ncvhook;ncvhook;C:\WINDOWS\system32\DRIVERS\ncvhook.sys [09/30/2007 04:54 PM 3200]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM 27136]
R3 zteusbser;ZTE USB Device for Legacy Serial Communication;C:\WINDOWS\system32\DRIVERS\ZTEUsbser.sys [02/06/2007 10:21 AM 97920]
S2 NetControl2Server;Net Control 2 Server;C:\Program Files\Net Control 2\ncserver.exe [10/26/2007 02:39 PM 365056]
S3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [08/08/2007 12:12 PM 101120]
S3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;C:\WINDOWS\system32\DRIVERS\ewusbser.sys [09/20/2006 10:23 AM 65152]
S3 NC2RemoteDesktop;Net Control 2 Remote Desktop Server Service;C:\Program Files\Net Control 2\ncvserver.exe [10/28/2007 12:28 PM 113152]
S3 OracleClientCache80;OracleClientCache80;C:\orant\BIN\ONRSD80.EXE [11/22/1999 04:13 PM 101136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ef2bb14-26eb-11dd-b8de-001b11158a65}]
\Shell\AutoRun\command - H:\xn1i9x.com
\Shell\explore\Command - H:\xn1i9x.com
\Shell\open\Command - H:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{64bb02e4-93bd-11dd-b9fb-001b11158a65}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{64bb02e5-93bd-11dd-b9fb-001b11158a65}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{73819ad6-938b-11dd-b9f9-001b11158a65}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7699c945-82b2-11dd-b967-001b11158a65}]
\Shell\AutoRun\command - I:\xn1i9x.com
\Shell\explore\Command - I:\xn1i9x.com
\Shell\open\Command - I:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b75fa728-8d2a-11dd-b9df-001b11158a65}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b75fa729-8d2a-11dd-b9df-001b11158a65}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db19d962-9523-11dd-ba04-001b11158a65}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db19d963-9523-11dd-ba04-001b11158a65}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb5a651a-ee6c-11dc-b8d8-001b11158a65}]
\Shell\AutoRun\command - H:\xn1i9x.com
\Shell\explore\Command - H:\xn1i9x.com
\Shell\open\Command - H:\xn1i9x.com
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKLM-Main,Search Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
O8 -: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 -: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 -: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 -: Download Using &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 -: تنزيل الارتباط باستخدام مدير ميغا... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 -: سأ±بجط¾«ءéدآشط(&B)
O18 -: Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - %~$path:i
O18 -: Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - %~$path:i
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-08 21:00:18
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\nclspnt.dll
.
Completion time: 10/08/2008 21:00:50
ComboFix-quarantined-files.txt 2008-10-08 18:00:48
Pre-Run: 3,161,780,224 bytes free
Post-Run: 3,167,657,984 bytes free
235 --- E O F --- 2008-10-03 23:42:10