ComboFix 08-10-12.01 - Administrator 12/26/2008 23:29:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.101 [GMT 3:00]
Running from: C:\Downloads\Programs\ComboFix.exe
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
- REDUCED FUNCTIONALITY MODE -
.
[i] ADS - svchost.exe: deleted 25088 bytes in 1 streams. [/i]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\file.bat
C:\WINDOWS\msauc.exe
C:\WINDOWS\services.exe
C:\WINDOWS\system32\rs32net.exe
C:\WINDOWS\system32\WinCtrl32.dl_
C:\WINDOWS\system32\WinCtrl32.dll
C:\WINDOWS\wiaservb.log
.
((((((((((((((((((((((((( Files Created from 2008-11-26 to 2008-12-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-26 20:30 73,728 ----a-w C:\WINDOWS\system32\806B932E.DLL
2008-12-26 20:30 32,256 ----a-w C:\WINDOWS\system32\drivers\ati6wcxx.sys
2008-12-26 20:30 118,784 ----a-w C:\WINDOWS\system32\blphc76vj0er1c.scr
2008-12-13 19:37 102,400 ----a-w C:\WINDOWS\system32\pphc76vj0er1c.exe
2008-12-13 16:22 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
2008-12-13 16:21 21,504 ----a-w C:\WINDOWS\system32\tzitvfsb32.dll
2008-12-13 16:08 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CyberScrub
2008-12-13 16:04 --------- d-----w C:\Documents and Settings\Administrator\Application Data\rhc36vj0er1c
2008-12-13 16:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\cleaner
2008-12-13 15:43 21,504 ----a-w C:\WINDOWS\system32\tzitvfsb.dll
2008-12-13 12:39 186,880 ----a-w C:\WINDOWS\system32\lphc76vj0er1c.exe
2008-12-13 01:12 13,312 ----a-w C:\Documents and Settings\Administrator\drwvas.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"Internet Download Accelerator"="C:\Program Files\IDA\ida.exe" [02/05/2008 05:49 PM 2200576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vistadrv"="C:\Program Files\VIPhd\vsdrv.exe" [07/30/2006 01:37 AM 121089]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 39792]
"lphc76vj0er1c"="C:\WINDOWS\system32\lphc76vj0er1c.exe" [12/13/2008 03:39 PM 186880]
"inrhc36vj0er1c"="C:\Documents and Settings\Administrator\Local Settings\temp\.tt7.tmp.exe" [12/26/2008 11:31 PM 1641505]
"BluetoothAuthenticationAgent"="bthprops.cpl" [08/04/2004 12:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-01 113664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)
"NoDispScrSavPage"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe "
"Userinit"="userinit.exe "
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tzitvfsb]
12/13/2008 07:21 PM 21504 C:\WINDOWS\system32\tzitvfsb32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WinCtrl32]
12/26/2008 11:31 PM 16384 C:\WINDOWS\system32\WinCtrl32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.3iv2"= C:\PROGRA~1\K-LITE~1\codecs\3IVXVF~1.DLL
"VIDC.VP60"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP61"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP62"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP70"= C:\PROGRA~1\K-LITE~1\codecs\vp7vfw.dll
"VIDC.VP31"= C:\PROGRA~1\K-LITE~1\codecs\vp31vfw.dll
"VIDC.FFDS"= C:\PROGRA~1\K-LITE~1\ffdshow\ff_vfw.dll
"msacm.ac3acm"= C:\PROGRA~1\K-LITE~1\codecs\ac3acm.acm
"msacm.l3fhg"= C:\PROGRA~1\K-LITE~1\codecs\l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6wcxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winms84.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 ati6wcxx;ati6wcxx;C:\WINDOWS\system32\Drivers\ati6wcxx.sys [12/26/2008 11:30 PM 32256]
R0 Winms84;Winms84;C:\WINDOWS\system32\Drivers\Winms84.sys [08/23/2001 03:00 PM 31104]
R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe [12/26/2008 11:32 PM 14336]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [08/04/2004 01:29 AM 327040]
R3 tcpsr;tcpsr;C:\WINDOWS\System32\drivers\tcpsr.sys [ ]
S2 D9ED12EA;D9ED12EA;C:\WINDOWS\system32\FF8BCE0E.EXE [07/17/2008 10:15 AM 19597]
S2 ICF;ICF;C:\WINDOWS\system32\svchost.exe:ext.exe [12/26/2008 11:32 PM 25088]
S3 BthEnum;Bluetooth Request Block Driver;C:\WINDOWS\system32\DRIVERS\BthEnum.sys [08/03/2004 11:10 PM 17024]
S3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys [08/03/2004 10:58 PM 100992]
S3 BTHPORT;Bluetooth Port Driver;C:\WINDOWS\system32\Drivers\BTHport.sys [08/03/2004 11:10 PM 274304]
S3 BTHUSB;Bluetooth Radio USB Driver;C:\WINDOWS\system32\Drivers\BTHUSB.sys [08/03/2004 11:10 PM 18944]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys [08/03/2004 11:10 PM 59648]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{37bdcd3a-7abd-11dd-8edf-0050fc8e0a1a}]
\Shell\Auto\command - I:\auto.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b750b16-7816-11dd-8ed1-0050fc8e0a1a}]
\Shell\Auto\command - I:\auto.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b750b18-7816-11dd-8ed1-0050fc8e0a1a}]
\Shell\Auto\command - auto.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
\Shell\Open\command - SSCVIHOST.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6871027e-96cf-11dd-8f07-0050fc8e0a1a}]
\Shell\Auto\command - I:\auto.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-services - C:\WINDOWS\services.exe
HKLM-Explorer_Run-services - C:\WINDOWS\services.exe
HKCU-Explorer_Run-services - C:\WINDOWS\services.exe
Notify-mohtxro - mohtxro.dll
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.sa/
R0 -: HKLM-Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
O8 -: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 -: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 -: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 -: Download ALL with IDA - C:\Program Files\IDA\idaieall.htm
O8 -: Download with IDA - C:\Program Files\IDA\idaie.htm
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [URL]http://www.gmer.net[/URL]
Rootkit scan 2008-12-26 23:31:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\svchost.exe:ext.exe 25088 bytes executable
C:\WINDOWS\system32\WinCtrl32.dll 16384 bytes executable
scan completed successfully
hidden files: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ICF]
"ImagePath"="C:\WINDOWS\system32\svchost.exe:ext.exe"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tzitvfsb32.dll
-> C:\WINDOWS\system32\WinCtrl32.dll
-> C:\WINDOWS\system32\806B932E.DLL
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\806B932E.DLL
PROCESS: C:\WINDOWS\system32\csrss.exe
-> C:\WINDOWS\system32\806B932E.DLL
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Local Settings\temp\.tt7.tmp
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 12/26/2008 23:34:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-26 20:34:31
Pre-Run: 13,972,856,832 bytes free
Post-Run: 14,281,670,656 bytes free
177