ComboFix 08-12-02.02 - WAEL 12/03/2008 22:41:33.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.102 [GMT 2:00]
Running from: c:\documents and settings\WAEL\Desktop\Download archive\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\dumass.exe
c:\windows\win32dll.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-03 to 2008-12-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 01:30 --------- d-----w c:\documents and settings\WAEL\Application Data\TuneUp Software
2008-11-26 20:33 9,914 ----a-w c:\windows\system32\mswentoue.dll
2008-11-16 16:57 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-04 13:53 --------- d-----w c:\program files\MIKSOFT
2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll
2008-10-28 14:46 --------- d-----w c:\documents and settings\WAEL\Application Data\IDM
2008-10-22 15:43 15,784 ----a-w c:\documents and settings\WAEL\Application Data\GDIPFONTCACHEV1.DAT
2008-10-22 06:33 --------- d-----w c:\program files\ZD Soft
2008-10-22 02:17 --------- d-----w c:\program files\Quick Screen Recorder
2008-10-20 07:48 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-10-18 03:02 --------- d-----w c:\documents and settings\WAEL\Application Data\FairStars Recorder
2008-10-16 15:18 --------- d-----w c:\program files\MP3 Splitter & Joiner Pro
2008-10-15 19:03 --------- d-----w c:\program files\Microsoft ActiveSync
2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
2008-09-19 04:41 155,995 ----a-w c:\windows\java\Packages\O9RZ9RNJ.ZIP
2008-09-12 11:44 206,256 ----a-w c:\windows\system32\idmmbc.dll
2008-09-08 22:03 51,712 ----a-w c:\windows\system32\sirenacm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [08/18/2008 01:23 PM 1447168]
"AntiARPStandalone"="c:\program files\ColorSoft\AntiARP\AntiARP.exe" [12/10/2007 02:49 PM 7176704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/03/2004 11:56 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/03/2004 11:56 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 09/15/2008 09:30 PM 2606512 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
--a------ 05/27/2008 09:58 PM 4269296 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
-ra------ 03/20/2008 06:58 PM 53248 c:\windows\system32\SiSPower.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 04/16/2007 03:28 PM 577536 c:\windows\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R2 AntiARPClientLoader;AntiARP Client Loader;"c:\program files\ColorSoft\AntiARP\AntiARPClientLoader.exe" [2007-10-17 40960]
R2 AntiArpNdisProt;AntiARP NDIS Protocol Driver;c:\windows\system32\DRIVERS\AntiArpNdisProt.sys [2007-10-17 21120]
R2 ekrn;Eset Service;"c:\program files\ESET\ESET Smart Security\ekrn.exe" [2008-08-18 468224]
R3 xAntiArp;xAntiArpSpoof Service;c:\windows\system32\DRIVERS\xAntiArp.sys [2007-12-06 375296]
S0 sensorsview;sensorsview;c:\windows\system32\drivers\sensorsview.sys [2008-11-02 4224]
S3 scrcap;scrcap;c:\windows\system32\DRIVERS\scrcap.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dca08d4c-87e7-11dd-b7a1-00016cb9d64c}]
\Shell\AutoRun\command - h:\.system\S-1-6-21-2434476501-1644491937-600003330-1213\Autorun.exe
\Shell\open\command - h:\.system\S-1-6-21-2434476501-1644491937-600003330-1213\Autorun.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-MSCenter update - win32dll.exe
HKU-Default-Run-VisualTask - Windows\\system32\\VisualTask\\VisualTask.exe
MSConfigStartUp-MsnMsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_07\bin\jusched.exe
MSConfigStartUp-VisualTask - Windows\\system32\\VisualTask\\VisualTask.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\WAEL\Application Data\Mozilla\Firefox\Profiles\vl5c9pxj.default\
FF -: plugin - c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF -: plugin - c:\program files\Minefield\plugins\npnul32.dll
FF -: plugin - c:\program files\Opera\program\plugins\NP_IDM1.dll
FF -: plugin - c:\program files\Opera\program\plugins\NP_IDM2.dll
FF -: plugin - c:\program files\Opera\program\plugins\NP_IDM3.dll
FF -: plugin - c:\program files\Opera\program\plugins\NP_IDM4.dll
FF -: plugin - c:\program files\Opera\program\plugins\NP_IDM5.dll
FF -: plugin - c:\program files\Opera\program\plugins\NP_IDM6.dll
FF -: plugin - c:\program files\Opera\program\plugins\nppl3260.dll
FF -: plugin - c:\program files\Opera\program\plugins\nprpjplug.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-03 22:43:25
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 12/03/2008 22:44:14
ComboFix-quarantined-files.txt 2008-12-03 20:44:14
Pre-Run: 2,813,964,288 bytes free
Post-Run: 2,816,909,312 bytes free
136