ComboFix 08-07-08.9 - o0oNooNEo0o 2008-07-09 21:33:40.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.20.1033.18.72 [GMT 3:00]
Running from: C:\Documents and Settings\o0oNooNEo0o\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
.
((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
.
2008-07-09 20:56 . 2008-07-09 20:56 <DIR> d-------- C:\Program Files\No-IP
2008-07-09 19:03 . 2008-07-09 19:03 <DIR> d-------- C:\Program Files\TeamViewer
2008-07-09 19:03 . 2008-07-09 19:03 <DIR> d-------- C:\Program Files\DynGate
2008-07-09 19:03 . 2008-07-09 19:03 <DIR> d-------- C:\Documents and Settings\o0oNooNEo0o\temp
2008-07-09 18:15 . 2008-07-09 18:15 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-07-09 17:59 . 2008-07-09 17:59 <DIR> d--hs---- C:\Recycled
2008-07-09 17:50 . 2008-07-09 17:50 25 --a------ C:\WINDOWS\cdplayer.ini
2008-07-09 17:46 . 2008-07-09 17:46 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-07-09 17:45 . 2008-07-09 17:45 <DIR> d-------- C:\Program Files\Real
2008-07-09 17:45 . 2008-07-09 17:45 <DIR> d-------- C:\Program Files\Common Files\Real
2008-07-09 17:45 . 2008-07-09 17:45 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-07-09 17:27 . 2008-07-09 20:02 836 --a------ C:\WINDOWS\bthservsdp.dat
2008-07-09 17:25 . 2004-08-03 23:10 274,304 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-07-09 17:25 . 2004-08-04 00:56 152,576 --a------ C:\WINDOWS\system32\irftp.exe
2008-07-09 17:25 . 2004-08-03 22:58 100,992 --a------ C:\WINDOWS\system32\drivers\bthpan.sys
2008-07-09 17:25 . 2004-08-03 23:10 59,648 --a------ C:\WINDOWS\system32\drivers\rfcomm.sys
2008-07-09 17:25 . 2004-08-04 00:56 27,136 --a------ C:\WINDOWS\system32\irmon.dll
2008-07-09 17:25 . 2004-08-03 23:10 18,944 --a------ C:\WINDOWS\system32\drivers\BTHUSB.SYS
2008-07-09 17:25 . 2004-08-03 23:10 17,024 --a------ C:\WINDOWS\system32\drivers\BthEnum.sys
2008-07-09 17:25 . 2004-08-04 00:56 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-07-09 17:02 . 2006-06-06 10:10 126,976 --a------ C:\WINDOWS\system32\igfxres.dll
2008-07-09 16:59 . 2008-07-09 16:59 <DIR> d-------- C:\Program Files\Foxit Software
2008-07-09 16:59 . 2008-07-09 16:59 <DIR> d-------- C:\Program Files\ADSoft
2008-07-09 16:59 . 2008-07-09 16:59 <DIR> d-------- C:\Documents and Settings\o0oNooNEo0o\Application Data\ADSoft
2008-07-09 16:59 . 2008-07-09 16:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ADSoft
2008-07-09 16:59 . 2008-07-09 16:59 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-09 16:04 . 2008-07-09 16:04 <DIR> d-------- C:\Program Files\Texas Instruments Inc
2008-07-09 16:03 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-07-09 16:02 . 2008-07-09 16:02 <DIR> d-------- C:\Program Files\HPQ
2008-07-09 16:02 . 2005-10-31 15:30 987,136 --a------ C:\WINDOWS\system32\BttnCmn.dll
2008-07-09 16:02 . 2005-09-19 13:24 9,344 --a------ C:\WINDOWS\system32\drivers\CPQBttn.sys
2008-07-09 16:02 . 2005-09-19 13:23 7,808 --a------ C:\WINDOWS\system32\drivers\eabfiltr.sys
2008-07-09 16:02 . 2005-09-19 13:24 5,760 --a------ C:\WINDOWS\system32\drivers\EabUsb.sys
2008-07-09 16:01 . 2008-07-09 16:01 <DIR> d-------- C:\Program Files\Synaptics
2008-07-09 16:01 . 2006-03-31 15:41 193,056 --a------ C:\WINDOWS\system32\drivers\SynTP.sys
2008-07-09 16:01 . 2006-03-31 15:47 114,688 --a------ C:\WINDOWS\system32\SynCtrl.dll
2008-07-09 16:01 . 2006-03-31 15:48 94,298 --a------ C:\WINDOWS\system32\SynTPAPI.dll
2008-07-09 16:01 . 2006-03-31 15:47 82,013 --a------ C:\WINDOWS\system32\SynCOM.dll
2008-07-09 16:01 . 2006-03-31 16:06 81,920 --a------ C:\WINDOWS\system32\SynTPCo2.dll
2008-07-09 16:01 . 2006-03-31 16:03 69,722 --a------ C:\WINDOWS\system32\SynTPFcs.dll
2008-07-09 16:00 . 2008-07-09 16:00 <DIR> d-------- C:\WINDOWS\Options
2008-07-09 16:00 . 2005-12-12 15:00 1,120,352 --a------ C:\WINDOWS\system32\drivers\AGRSM.sys
2008-07-09 16:00 . 2005-12-12 15:00 88,203 --a------ C:\WINDOWS\AGRSMMSG.exe
2008-07-09 16:00 . 2005-12-12 15:00 68,096 --------- C:\WINDOWS\system32\agrsmdel.exe
2008-07-09 16:00 . 2005-12-12 15:00 68,096 --a------ C:\WINDOWS\agrsmdel.exe
2008-07-09 16:00 . 2006-01-13 16:10 9,728 --------- C:\WINDOWS\HPModemVersion.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 14:45 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-07-09 12:58 --------- d-----w C:\Program Files\Intel
2008-07-09 12:55 --------- d-----w C:\Program Files\Analog Devices
2008-07-09 12:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-09 12:53 --------- d-----w C:\Program Files\Hewlett-Packard
2008-07-09 12:51 --------- d-----w C:\Program Files\AAQ
2008-07-09 12:49 --------- d-----w C:\Program Files\TechSmith
2008-07-09 12:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith
2008-07-09 12:48 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 12:40 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-09 12:38 --------- d-----w C:\Program Files\Internet Download Manager
2008-07-09 12:38 --------- d-----w C:\Documents and Settings\o0oNooNEo0o\Application Data\IDM
2008-07-09 12:38 --------- d-----w C:\Documents and Settings\o0oNooNEo0o\Application Data\DMCache
2008-07-09 12:20 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-09 12:19 --------- d-----w C:\Program Files\Broadcom
2008-07-09 12:14 --------- d-----w C:\Program Files\Windows Live
.
كود:
<pre>
----a-w 892,928 2008-07-09 15:52:20 C:\Documents and Settings\o0oNooNEo0o\Local Settings\Application Data\Microsoft\CD Burning\njoood\Undetector small stub 3x det .exe
</pre>
------- Sigcheck -------
2006-09-09 01:02 2198144 ba08992ecfb4b23b9204add12ab385ea C:\WINDOWS\system32\ntkrnlpa.exe
2006-09-08 23:01 2321024 ef63859e4fd9cb3ec31a111481f4b1b6 C:\WINDOWS\system32\ntoskrnl.exe
2006-09-09 00:48 1616896 7f9583eff8102bce8bd6716744018f83 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-08-16 16:19 5728112]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-07-09 15:38 932864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 09:11 925696]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-31 16:01 761946]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-06-06 10:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-06-06 10:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-06-06 10:10 118784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-07-09 17:45 185896]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 15:00 88203 C:\WINDOWS\AGRSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-05-01 11:11:48 6395464]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP110
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-09 21:34:40
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-09 21:34:59
ComboFix-quarantined-files.txt 2008-07-09 18:34:58
Pre-Run: 15,622,668,288 bytes free
Post-Run: 15,628,615,680 bytes free
148