ComboFix 08-07-05.1 - Administrator 07/06/2008 16:35:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1524 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\tazebama
C:\Documents and Settings\Administrator\Application Data\tazebama\tazebama.log
C:\Documents and Settings\Administrator\Application Data\tazebama\zPharaoh.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\AutoRun.inf
----- BITS: Possible infected sites -----
hxxp://download.microsoft.com
.
((((((((((((((((((((((((( Files Created from 2008-06-06 to 2008-07-06 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-06 13:38 3,050,016 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-06 13:38 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-07-06 13:37 48,140 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-06 13:37 19,652 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-06 13:37 176,160 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-06 13:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-05 18:13 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Suite
2008-07-04 17:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-07-04 11:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-07-04 10:58 --------- d-----w C:\Program Files\ma-config.com
2008-07-04 10:41 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IDM
2008-07-03 20:14 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-03 20:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nero
2008-07-03 19:48 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-07-03 19:48 --------- d-----w C:\Program Files\Nero
2008-07-03 19:48 --------- d-----w C:\Program Files\My Lockbox
2008-07-03 19:48 --------- d-----w C:\Program Files\mqreeb
2008-07-03 19:47 --------- d-----w C:\Program Files\Common Files\Nero
2008-07-03 19:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-07-03 19:46 --------- d-----w C:\Program Files\JetAudio
2008-07-03 19:46 --------- d-----w C:\Program Files\Common Files\xing shared
2008-07-03 19:45 --------- d-----w C:\Program Files\Common Files\Real
2008-07-03 19:42 --------- d-----w C:\Program Files\YouTube Downloader
2008-07-03 19:41 --------- d-----w C:\Program Files\Windows Live
2008-07-03 18:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-07-03 18:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-07-01 19:00 --------- d-----w C:\Program Files\SWiSHmax
2008-06-29 17:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-06-28 18:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-06-28 18:23 --------- d-----w C:\Program Files\HP
2008-06-28 18:15 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-28 18:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-06-28 13:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-06-27 19:37 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-27 19:37 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-06-27 19:32 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-06-27 19:30 43,488 ----a-w C:\WINDOWS\system32\drivers\AFS2K.SYS
2008-06-27 19:30 --------- d-----w C:\Program Files\Common Files\HP
2008-06-27 19:15 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-06-27 19:15 --------- d-----w C:\Program Files\Nokia
2008-06-27 19:15 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-06-27 19:15 --------- d-----w C:\Program Files\Common Files\Nokia
2008-06-27 11:02 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-06-27 11:02 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-06-27 11:02 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-06-27 10:38 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Creative
2008-06-27 09:52 155,995 ----a-w C:\WINDOWS\java\Packages\TBNB5B7P.ZIP
2008-06-27 09:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-27 09:49 --------- d-----w C:\Program Files\DIFX
2008-06-27 09:49 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nokia
2008-06-25 18:54 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-06-25 18:52 --------- d-----w C:\Program Files\Google
2008-06-25 18:49 --------- d-----w C:\Program Files\Real
2008-06-25 18:35 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-25 18:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-25 18:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-25 18:31 --------- d-----w C:\Program Files\Realtek
2008-06-25 18:30 16,608 ----a-w C:\WINDOWS\gdrv.sys
2008-06-25 18:30 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-06-25 18:29 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-06-25 18:26 --------- d-----w C:\Program Files\Intel
2008-06-25 18:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-06-25 18:20 --------- d-----w C:\Program Files\Creative
2008-06-25 18:19 --------- d--h--w C:\Program Files\Creative Installation Information
2008-06-25 18:19 --------- d-----w C:\Program Files\Common Files\Creative
2008-06-25 18:07 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-25 18:02 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"Creative MediaSource Go"="C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe" [11/09/2006 10:19 AM 204800]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [03/28/2008 11:20 AM 1079296]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [03/26/2008 06:41 PM 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [02/21/2008 01:59 PM 937392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m–|\ü" [X]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [06/28/2007 07:43 PM 8466432]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [06/28/2007 07:43 PM 81920]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [10/31/2005 10:51 AM 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [05/11/2000 01:00 AM 90112]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [07/03/2008 10:45 PM 185896]
"flockbox"="C:\Program Files\My Lockbox\flockbox.exe" [12/14/2007 04:59 PM 1071472]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [06/28/2007 12:51 PM 218376]
"nwiz"="nwiz.exe" [06/28/2007 07:43 PM 1626112 C:\WINDOWS\system32\nwiz.exe]
"P17Helper"="P17.dll" [05/03/2005 02:38 PM 64512 C:\WINDOWS\system32\P17.dll]
"RTHDCPL"="RTHDCPL.EXE" [02/13/2008 09:31 AM 16857600 C:\WINDOWS\RTHDCPL.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 12:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
"Resume copy"="copyfstq.exe" [03/24/2002 02:54 PM 46080 C:\WINDOWS\COPYFSTQ.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [03/26/2008 06:41 PM 1232896]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/22/2006 11:49 PM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 MPRIFL;MPRIFL;C:\WINDOWS\system32\DRIVERS\MPRIFL.SYS [12/13/2007 08:13 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [06/26/2008 09:13 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DXDllRegExe - dxdllreg.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-06 16:38:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\system32\WudfHost.exe
.
**************************************************************************
.
Completion time: 07/06/2008 16:39:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-06 13:39:44
Pre-Run: 42,685,083,648 bytes free
Post-Run: 43,201,236,992 bytes free
173 --- E O F --- 2008-07-01 15:13:12