combofix 09-03-25.02 - jjj 03/26/2009 8:30:41.1 - ntfsx86
microsoft windows xp professional 5.1.2600.2.1256.20.1033.18.1919.1472 [gmt 2:00]
running from: D:\progs\combofix.exe
* created a new restore point
warning -this machine does not have the recovery console installed !!
.
((((((((((((((((((((((((((((((((((((((( other deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\windows\system32\kr_done1
.
((((((((((((((((((((((((( files created from 2009-02-26 to 2009-03-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( find3m report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-26 06:32 7,534,624 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-26 06:32 --------- d-----w c:\documents and settings\jjj\application data\dmcache
2009-03-25 20:00 61,100 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-25 11:53 7,168 ----a-w c:\windows\system32\drivers\uti4mty3.sys
2009-03-25 03:28 --------- d-----w c:\documents and settings\jjj\application data\simply super software
2009-03-25 03:28 --------- d-----w c:\documents and settings\all users\application data\simply super software
2009-03-25 02:40 --------- d-----w c:\documents and settings\all users\application data\kaspersky lab setup files
2009-03-24 01:56 --------- d-----w c:\program files\yahoo!
2009-03-24 01:56 --------- d-----w c:\documents and settings\all users\application data\yahoo!
2009-03-23 19:11 --------- d-----w c:\program files\internet download manager
2009-03-23 19:10 --------- d-----w c:\documents and settings\jjj\application data\orbit
2009-03-19 13:09 73,216 ----a-w c:\windows\st6unst.exe
2009-03-19 00:54 286,720 ------w c:\windows\setup1.exe
2009-03-18 19:49 --------- d-----w c:\documents and settings\all users\application data\eset
2009-03-18 03:49 577,024 ----a-w c:\windows\system32\user32.dll
2009-03-18 03:49 32,256 ---h--w c:\documents and settings\jjj\peyscnr.exe
2009-03-18 03:49 32,256 ----a-w c:\windows\system32\hhnrab.exe
2009-03-18 03:49 163,840 ----a-w c:\windows\system32\nvtpm32.dll
2009-03-17 23:46 --------- d-----w c:\documents and settings\jjj\application data\idm
2009-03-17 05:02 --------- d-----w c:\program files\microsoft silverlight
2009-03-14 05:44 --------- d-----w c:\documents and settings\jjj\application data\yahoo!
2009-03-14 00:41 --------- d-----w c:\documents and settings\jjj\application data\grabpro
2009-03-12 03:14 --------- d-----w c:\documents and settings\jjj\application data\media player classic
2009-03-12 03:06 --------- d-----w c:\program files\windows doctor
2009-03-12 02:54 --------- d-----w c:\program files\k-lite codec pack
2009-03-08 21:02 155,995 ----a-w c:\windows\java\packages\mvjxjln1.zip
2009-03-06 04:37 --------- d-----w c:\program files\common files\xing shared
2009-03-06 04:37 --------- d-----w c:\program files\common files\real
2009-03-06 04:36 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-06 04:36 348,160 ----a-w c:\windows\system32\msvcr71.dll
2009-03-06 04:36 --------- d-----w c:\program files\real
2009-03-06 04:05 --------- d-----w c:\program files\shandidy ! Aimp2
2009-03-06 03:58 --------- d--h--w c:\program files\installshield installation information
2009-03-06 00:21 --------- d-----w c:\program files\realtek
2009-03-05 23:59 --------- d-----w c:\program files\common files\installshield
2009-03-05 23:52 315,392 ----a-w c:\windows\hidewin.exe
2009-03-05 23:40 --------- d-----w c:\program files\vista sidebar
.
c:\windows\system32\user32.dll ... Is infected !!
577,024 2009-03-18 03:49:30 c:\windows\system32\user32.dll
------- sigcheck -------
08/04/2004 01:56 am 17408 6ace0d8fead0927ce82a18493e41fcca c:\windows\system32\svchost.exe
03/18/2009 05:49 am 577024 97253f2f3e274d4a3b799f15d857f979 c:\windows\system32\user32.dll
08/04/2004 01:56 am 506368 fe13868409aeb29dc50c90c774fe5ace c:\windows\system32\winlogon.exe
01/09/2008 11:36 pm 2319232 cb8ecdb0f99b6e1dfdbcad13fafe727b c:\windows\system32\ntoskrnl.exe
01/09/2008 02:01 am 1697792 44fb497635839f782a0dab6eaab87443 c:\windows\explorer.exe
08/04/2004 01:56 am 110592 96bc5a64e37d8bd5764621c884f4dc49 c:\windows\system32\services.exe
08/04/2004 01:56 am 14848 855ec75a8a25647ca6215b4ea6162442 c:\windows\system32\lsass.exe
06/23/2006 05:50 am 58880 2a0742974a8ce6dad8469663493cbaec c:\windows\system32\spoolsv.exe
06/14/2006 02:49 am 112640 c6c281e916d12bf2eae49ec03d7435ee c:\windows\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( reg loading points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*note* empty entries & legit default entries are not shown
regedit4
[hkey_current_user\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 01:56 am 15360]
"idman"="c:\program files\internet download manager\idman.exe" [11/24/2008 06:45 pm 2745776]
"messenger (yahoo!)"="c:\program files\yahoo!\messenger\yahoomessenger.exe" [11/05/2008 09:59 pm 4347120]
[hkey_local_machine\software\microsoft\windows\currentversion\run]
"tkbellexe"="c:\program files\common files\real\update_ob\realsched.exe" [03/06/2009 06:36 am 185896]
"hhnrab"="c:\windows\system32\hhnrab.exe" [03/18/2009 05:49 am 32256]
"rthdcpl"="rthdcpl.exe" [08/10/2007 09:21 am 16384000 c:\windows\rthdcpl.exe]
[hkey_users\.default\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 01:56 am 15360]
[hkey_users\.default\software\microsoft\windows\currentversion\runonce]
"nlsf"="move" [x]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [08/03/2004 11:59 pm 44544]
c:\documents and settings\jjj\start menu\programs\startup\
is-3o9jl.lnk - c:\documents and settings\jjj\desktop\virus removal tool\is-3o9jl\startup.exe [2009-03-25 65536]
c:\documents and settings\all users\start menu\programs\startup\
sidebar.lnk - c:\program files\vista sidebar\sidebar.exe [2009-03-06 524288]
[hkey_local_machine\software\microsoft\windows\currentversion\policies\explorer]
"noresolvetrack"= 1 (0x1)
[hkey_current_user\software\microsoft\windows\currentversion\policies\explorer]
"nosmhelp"= 1 (0x1)
"noresolvetrack"= 1 (0x1)
[hkey_users\.default\software\microsoft\windows\currentversion\policies\explorer]
"nosmhelp"= 1 (0x1)
"noresolvetrack"= 1 (0x1)
[hklm\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"enablefirewall"= 0 (0x0)
[hklm\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"=
"c:\\documents and settings\\jjj\\peyscnr.exe"=
r1 is-3o9jldrv;is-3o9jldrv;c:\windows\system32\drivers\16660046.sys [2009-03-25 148496]
s2 systemntmi;systemntmi;\??\c:\windows\system32\drivers\systemntmi.sys --> c:\windows\system32\drivers\systemntmi.sys [?]
s3 uti4mty3;avz kernel driver;c:\windows\system32\drivers\uti4mty3.sys [2009-03-25 7168]
netsvcs requires repairs - current entries shown
6to4
appmgmt
audiosrv
browser
cryptsvc
dmserver
dhcp
eventsystem
fastuserswitchingcompatibility
hidserv
ias
iprip
irmon
lanmanserver
lanmanworkstation
messenger
netman
nla
nwcworkstation
nwsapagent
rasauto
rasman
remoteaccess
seclogon
sens
sharedaccess
srservice
tapisrv
themes
trkwks
w32time
wzcsvc
wmi
wmdmpmsp
winmgmt
xmlprov
bits
wuauserv
shellhwdetection
wmdmpmsn
hkey_local_machine\software\microsoft\windows nt\currentversion\svchost - netsvcs
.
- - - - orphans removed - - - -
ssodl-toyte-{4c102273-e6ba-88d9-7fe3-28566f9e140b} - (no file)
notify-wbsrv - (no file)
.
------- supplementary scan -------
.
Ustart page = about:blank
mstart page = hxxp://www.yahoo.com/
msearch bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
usearchurl,(default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
ie: تحميل الكل بواسطة internet download manager - c:\program files\internet download manager\iegetall.htm
ie: تحميل بواسطة internet download manager - c:\program files\internet download manager\ieext.htm
ie: تحميل محتوى flv بواسطة internet download manager - c:\program files\internet download manager\iegetvl.htm
lsp: C:\windows\system32\idmmbc.dll
dpf: Microsoft xml parser for java
dpf: {b7fdb0c3-4724-46d2-b8db-6fa1dc63f7ca} - hxxp://voice146.digivoice.net/readuid.cab
.
**************************************************************************
catchme 0.3.1367 w2k/xp/vista - rootkit/stealth malware detector by gmer,
rootkit scan 2009-03-26 08:32:31
windows 5.1.2600 service pack 2 ntfs
scanning hidden processes ...
Scanning hidden autostart entries ...
Scanning hidden files ...
Scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- locked registry keys ---------------------
[hkey_local_machine\software\classes\clsid\{5ed60779-4de2-4e07-b862-974ca4ff2e9c}]
@denied: (full) (everyone)
"scansk"=hex(0):18,7b,f9,71,3d,58,1e,86,fd,86,5f,9b,0e,b6,58,f3,a5,61,d6,44,dc,
10,10,0d,c2,99,51,46,12,64,d4,c2,ca,33,cb,e2,91,a8,a1,8f,00,00,00,00,00,00,\
[hkey_local_machine\software\classes\clsid\{fcd8ed9a-a08a-48ff-a911-fec31878e45a}]
@denied: (full) (everyone)
"model"=dword:00000054
"therad"=dword:0000000a
.
--------------------- dlls loaded under running processes ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\nvtpm32.dll
c:\windows\system32\ati2evxx.dll
c:\windows\system32\idmmbc.dll
- - - - - - - > 'lsass.exe'(828)
c:\windows\system32\idmmbc.dll
.
Completion time: 03/26/2009 8:34:16
combofix-quarantined-files.txt 2009-03-26 06:33:54
pre-run: 7,536,902,144 bytes free
post-run: 7,581,106,176 bytes free
198