تقرير كومبو
ComboFix 08-05-25.4 - Administrator 05/26/2008 15:09:45.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.356 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\Celine Dion\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\All Users\Application Data\microsoft\pctools
C:\Documents and Settings\All Users\Application Data\microsoft\pctools\pctools.dll
C:\Program Files\Common Files\cpush
C:\Program Files\deskbar
C:\Program Files\deskbar\basis.xml
C:\Program Files\deskbar\but_close.gif
C:\Program Files\deskbar\but_maximize.gif
C:\Program Files\deskbar\but_next.gif
C:\Program Files\deskbar\channel.tmpl
C:\Program Files\deskbar\.tmpl
C:\Program Files\deskbar\deskbar.crc
C:\Program Files\deskbar\edit_rss.tmpl
C:\Program Files\deskbar\inv.gif
C:\Program Files\deskbar\minibrowser.swf
C:\Program Files\deskbar\null.swf
C:\Program Files\deskbar\toolbar.html
C:\Program Files\deskbar\uninst.exe
C:\Program Files\deskbar\version.txt
C:\Program Files\deskbar\yourlogo.gif
C:\Program Files\instant access
C:\Program Files\instant access\Center\Sevenline.lnk
C:\Program Files\instant access\Center\Sevenline.upd
C:\Program Files\instant access\Center\tray1.ico
C:\Program Files\instant access\DesktopIcons\Sevenline.lnk
C:\Program Files\instant access\Multi\20080418210452\Common\module.php
C:\Program Files\instant access\Multi\20080418210452\dialerexe.ini
C:\Program Files\instant access\Multi\20080418210452\instant access.exe
C:\Program Files\instant access\Multi\20080418210452\js\js_api_dialer.php
C:\Program Files\instant access\Multi\20080418210452\medias\4239_dialer.ico
C:\Program Files\instant access\Multi\20080418210452\medias\button1.gif
C:\Program Files\instant access\Multi\20080418210452\medias\button2.gif
C:\Program Files\instant access\Multi\20080418210452\medias\button3.gif
C:\Program Files\instant access\Multi\20080418210452\medias\button4.gif
C:\Program Files\Internet Explorer\IEXPLORE32.jmp
C:\Program Files\internet explorer\plugins\SysWin7s.Jmp
C:\Program Files\Zumie
C:\Program Files\Zumie\home.js
C:\Program Files\Zumie\uninstall.exe
C:\Program Files\Zumie\zumie.dll
C:\Program Files\Zumie\zumie.exe
C:\WINDOWS\dialerexe.ini
C:\WINDOWS\system32\d3d1caps.srg
C:\WINDOWS\system32\drivers\acpidisk.sys
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\gmnait.cfg
C:\WINDOWS\system32\hkunsxoi.dat
C:\WINDOWS\system32\hkunsxoi_nav.dat
C:\WINDOWS\system32\hkunsxoi_navps.dat
C:\WINDOWS\system32\lariytrz.cfg
C:\WINDOWS\system32\mprmsgse.axz
C:\WINDOWS\system32\mscpx32r.det
C:\WINDOWS\system32\nsinet.exe
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\TEMP\~my1.tmp
----- BITS: Possible infected sites -----
hxxp://download.microsoft.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ACPIDISK
-------\Legacy_MSEQSY
-------\Legacy_ZUMIE_SEARCH_SERVICE
-------\Service_acpidisk
-------\Service_Zumie Search Service
((((((((((((((((((((((((( Files Created from 2008-04-26 to 2008-05-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-26 13:12 671,744 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-26 13:12 60,824 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-26 13:12 175,760 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-26 13:12 11,096,096 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-25 18:43 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-05-24 14:00 12,288 ----a-w C:\WINDOWS\system32\impborl.dll
2008-05-24 00:23 --------- d-----w C:\Program Files\Pinedanet
2008-05-24 00:16 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TeraCopy
2008-05-17 16:32 --------- d-----w C:\Program Files\RivaTuner v2.08
2008-05-17 12:40 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-05-17 12:40 --------- d-----w C:\Program Files\Real
2008-05-17 12:40 --------- d-----w C:\Program Files\Common Files\Real
2008-05-17 07:58 --------- d-----w C:\Program Files\Free Offers from Freeze.com
2008-05-17 07:58 --------- d-----w C:\Program Files\Common Files\Winferno
2008-05-15 00:30 --------- d-----w C:\Program Files\Dream Aquarium
2008-05-14 23:28 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-14 20:45 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-14 20:44 --------- d-----w C:\Program Files\Windows Live
2008-05-14 20:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-13 20:07 --------- d-----w C:\Program Files\EMUpgrade
2008-05-10 22:09 --------- d-----w C:\Program Files\Upgrade
2008-05-10 13:16 --------- d-----w C:\Documents and Settings\Administrator\Application Data\phpDesigner 2008
2008-05-10 12:35 --------- d-----w C:\Program Files\Atmel
2008-05-08 20:37 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-05-08 20:37 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-05-07 21:34 --------- d-----w C:\Program Files\VID_0E8F&PID_0012
2008-05-07 18:06 --------- d-----w C:\Program Files\Conduit
2008-05-05 11:16 --------- d-----w C:\Program Files\Java
2008-05-05 10:49 --------- d-----w C:\Program Files\Common Files\Java
2008-05-04 12:00 --------- d-----w C:\Program Files\WinPcap
2008-05-03 22:25 --------- d-----w C:\Program Files\Yahoo!
2008-05-03 22:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2008-05-02 19:55 --------- d-----w C:\Program Files\Moyea
2008-05-02 19:55 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Moyea
2008-05-02 11:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Avant Profiles
2008-04-28 21:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-28 13:44 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CyberScrub
2008-04-28 13:43 --------- d-----w C:\Documents and Settings\Administrator\Application Data\cleaner
2008-04-27 18:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-26 23:18 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys.original.orbit
2008-04-26 20:00 96,645 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-04-26 20:00 87,941 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-04-21 17:19 --------- d-----w C:\Program Files\Bonjour
2008-04-21 17:19 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-04-21 17:18 --------- d-----w C:\Program Files\QuickTime
2008-04-21 17:18 --------- d-----w C:\Program Files\Apple Software Update
2008-04-21 17:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-21 17:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-04-16 11:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MobileAction
2008-04-16 11:30 --------- d-----w C:\Program Files\Nokia
2008-04-15 13:29 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Mobile Master
2008-04-15 13:19 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-13 18:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\This dog ping okay
2008-04-13 18:48 --------- d-----w C:\Program Files\PhoneJugs
2008-04-13 18:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PhoneJugs
2008-04-13 14:28 --------- d-----w C:\Program Files\vPlug Files Center
2008-04-13 10:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Auto Shutdown
2008-04-13 02:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-13 02:56 --------- d-----w C:\Program Files\Formosoft
2008-04-13 02:55 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-13 01:02 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-12 21:15 --------- d-----w C:\Program Files\Sony Ericsson
2008-04-12 20:21 --------- d-----w C:\Program Files\BitTorrent Fastest Tool
2008-04-12 14:19 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-04-11 20:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Thinstall
2008-04-11 03:33 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-04-11 03:33 --------- d-----w C:\Documents and Settings\Administrator\Application Data\skypePM
2008-04-11 03:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-04-11 03:29 --------- d-----w C:\Program Files\Skype
2008-04-11 03:29 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-11 03:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-04-10 17:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-04-10 17:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ashampoo
2008-04-10 16:33 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Orbit
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2008-03-28 17:41 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-20 16:32 4,716 ----a-w C:\WINDOWS\gdrv.sys
2008-03-20 15:46 155,995 ----a-w C:\WINDOWS\java\Packages\B31FDJR1.ZIP
2008-03-19 09:40 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:40 1,845,888 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 15:09 23,096 ----a-w C:\WINDOWS\system32\sremcon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF}]
C:\Program Files\Winferno\PC Confidential\PCCBHO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [12/31/2002 12:00 PM 15360]
"SpyEmergency"="C:\Program Files\NETGATE\Spy Emergency 2008\SpyEmergency.exe" [03/31/2008 11:13 AM 2071096]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [02/01/2008 05:22 PM 21898024]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/27/2008 08:56 PM 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 11:34 AM 5724184]
"eMuleAutoStart"="D:\Program Files\emule0.49\eMule\emule.exe" [05/13/2007 04:57 PM 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [11/11/2005 12:47 PM 7311360]
"nwiz"="nwiz.exe" [11/11/2005 12:47 PM 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [11/11/2005 12:47 PM 86016 C:\WINDOWS\system32\nvmctray.dll]
"RTHDCPL"="RTHDCPL.EXE" [11/10/2005 10:14 AM 15473664 C:\WINDOWS\RTHDCPL.EXE]
"LClock"="C:\Program Files\LClock\LClock.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50 AM 155648]
"DriverCD"="J:\Run.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [02/08/2008 06:36 PM 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [12/31/2002 12:00 PM 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Orbit.lnk - D:\Program Files\Orbitdownloader\Orbitdownloader\orbitdm.exe [2008-04-29 14:16:09 1678536]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}"= C:\WINDOWS\system32\wyrsdj.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Orbitdownloader\\Orbitdownloader\\orbitdm.exe"=
"D:\\Program Files\\Orbitdownloader\\Orbitdownloader\\orbitnet.exe"=
"D:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\kav\\kis7.0\\english\\setup.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"C:\\kav\\kav7.0\\english\\setup.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\Italian\\setup.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Italian\\setup.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\Program Files\\emule0.49\\eMule\\emule.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 SpyEmrg;Spy Emergency Driver;C:\WINDOWS\system32\Drivers\spyemrg.sys [02/05/2008 12:10 PM]
R1 tvtool;tvtool;D:\Program Files\TVTool\tvtool.sys [04/03/1996 08:33 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [12/13/2007 01:28 PM]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [03/13/2006 05:22 PM]
R3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver;C:\WINDOWS\system32\Drivers\spyemrg_guard.sys [02/05/2008 12:10 PM]
S1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\cinemsup.sys []
S1 VFILT;Outpost Firewall Kernel Driver;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\FILTNT.SYS []
S3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\ADBLOCK.DLL []
S3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\ARP.DLL []
S3 .DLL;Outpost Firewall PlugIn (.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\.DLL []
S3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\DNSCACHE.DLL []
S3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\FTPFILT.DLL []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [03/20/2008 06:32 PM]
S3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\HTMLFILT.DLL []
S3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\HTTPFILT.DLL []
S3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\IMAPFILT.DLL []
S3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\MAILFILT.DLL []
S3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\NNTPFILT.DLL []
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [11/06/2007 10:22 PM]
S3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\POP3FILT.DLL []
S3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\PROTECT.DLL []
S3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.359\SECRET.DLL []
S3 sys_ten;sys_ten;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~21.tmp []
S3 VPNET;DTVNet Ethernet Controller;C:\WINDOWS\system32\DRIVERS\DTVNet.sys [03/13/2006 09:59 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0789757c-071f-11dd-b9f4-00147f2ba1b7}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3aff6c89-0a36-11dd-ba07-00147f2ba1b7}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9164eb97-1169-11dd-ba53-00147f2ba1b7}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aba2ba50-0acc-11dd-ba09-00147f2ba1b7}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c421bbfb-0e2e-11dd-ba19-00147f2ba1b7}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f560202d-1f6f-11dd-a2dd-00147f2ba1b7}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
.
s of the 'Scheduled Tasks' folder
"2008-05-26 13:00:02 C:\WINDOWS\Tasks\AF26B71B91D12E43.job"
- c:\docume~1\admini~1\applic~1\phonej~1\SAVEONLINETHIS.exe
"2008-04-21 17:18:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-17 07:43:52 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
"2008-05-26 13:14:26 C:\WINDOWS\Tasks\PCConfidential.job"
- C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-05-26 15:14:45
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sys_ten]
"ImagePath"="\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~21.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\NETGATE\Spy Emergency 2008\SpyEmergencySrv.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 05/26/2008 15:17:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-26 13:16:56
Pre-Run: 3,644,014,592 bytes free
Post-Run: 3,583,115,264 bytes free
304 --- E O F --- 2008-05-25 22:02:59