ComboFix 08-07-04.6 - MAJED 07/06/2008 1:10:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.2723 [GMT 3:00]
Running from: C:\Documents and Settings\MAJED\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\x64
----- BITS: Possible infected sites -----
hxxp://download.microsoft.com
.
((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-05 22:08 9,728 ----a-w C:\WINDOWS\AppPatch\AcSpecf.dll
2008-07-05 22:05 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-05 22:05 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-05 22:05 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-05 22:05 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-05 22:04 --------- d-----w C:\Documents and Settings\MAJED\Application Data\CyberScrub
2008-07-05 22:04 --------- d-----w C:\Documents and Settings\MAJED\Application Data\cleaner
2008-07-05 21:43 18,048 ----a-w C:\WINDOWS\system32\drivers\eth8023.sys
2008-07-05 21:43 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-05 21:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-05 21:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-05 20:46 27,136 ----a-w C:\WINDOWS\AppPatch\AcLue.dll
2008-07-05 20:12 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-02 10:33 82,432 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
2008-06-11 02:51 910,464 ----a-r C:\WINDOWS\system32\igmedkrn.dll
2008-05-29 06:35 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-05-23 15:21 81,920 ----a-w C:\WINDOWS\system32\404Fix.exe
2008-05-18 18:40 82,944 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-04-25 15:22 206,088 ----a-w C:\WINDOWS\system32\klogon.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/10/2004 02:02 AM 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06/11/2008 05:51 AM 142104]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06/11/2008 05:51 AM 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [06/11/2008 05:51 AM 138008]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/10/2004 02:02 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
"RTHDCPL"="RTHDCPL.EXE" [06/11/2008 05:52 AM 16126464 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/10/2004 02:02 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/22/2006 11:49 PM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
S0 klbg;KlBg;C:\WINDOWS\system32\drivers\klbg.sys []
S3 eth8023;eth8023;C:\WINDOWS\system32\drivers\eth8023.sys [07/06/2008 12:43 AM]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-06 01:11:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\linkinfo.dll 46592 bytes executable
C:\WINDOWS\system32\drivers\nvmini.sys 17152 bytes executable
C:\WINDOWS\system32\linkinfo.dll 18944 bytes executable
scan completed successfully
hidden files: 3
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\nvmini]
"ImagePath"="system32\DRIVERS\nvmini.sys"
.
Completion time: 07/06/2008 1:11:20
ComboFix-quarantined-files.txt 2008-07-05 22:11:17
Pre-Run: 27,572,609,024 bytes free
Post-Run: 27,565,633,536 bytes free
84