ComboFix 08-12-12.04 - just4u 12/13/2008 21:43:26.3 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.255.111 [GMT 2:00]
Running from: c:\documents and settings\just4u\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-13 to 2008-12-13 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-12 21:58 --------- d-----w c:\documents and settings\All Users\Application Data\19DA
2008-12-12 20:32 --------- d-----w c:\documents and settings\All Users\Application Data\26242
2008-12-11 21:26 --------- d-----w c:\documents and settings\All Users\Application Data\235B
2008-12-11 15:08 286,720 ----a-w c:\windows\iun506.exe
2008-12-11 15:08 --------- d-----w c:\program files\TurboPizza
2008-12-11 15:08 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Games
2008-12-11 11:12 --------- d-----w c:\program files\AnMing
2008-12-10 23:03 --------- d-----w c:\documents and settings\All Users\Application Data\3235B
2008-12-10 19:48 --------- d-----w c:\program files\Eusing Free Registry Cleaner
2008-12-09 22:04 --------- d-----w c:\documents and settings\All Users\Application Data\
029F
2008-12-09 20:17 --------- d-----w c:\program files\MP3Gain
2008-12-08 21:22 --------- d-----w c:\documents and settings\All Users\Application Data\14271
2008-12-08 17:37 --------- d-----w c:\program files\Common Files\TechSmith Shared
2008-12-08 17:37 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith
2008-12-08 09:22 --------- d-----w c:\program files\SWiSHmax
2008-12-07 20:35 --------- d-----w c:\documents and settings\All Users\Application Data\A203
2008-12-07 19:59 --------- d-----w c:\program files\Internet Download Manager
2008-12-07 19:59 --------- d-----w c:\documents and settings\just4u\Application Data\IDM
2008-12-07 19:59 --------- d-----w c:\documents and settings\just4u\Application Data\DMCache
2008-12-07 18:25 --------- d-----w c:\documents and settings\just4u\Application Data\Media Player Classic
2008-12-07 18:14 --------- d-----w c:\documents and settings\just4u\Application Data\Thinstall
2008-12-07 17:53 --------- d-----w c:\program files\RealDrawPro By Method
2008-12-07 17:53 --------- d-----w c:\program files\K-Lite Codec Pack
2008-12-07 17:52 --------- d-----w c:\program files\AIMP2
2008-12-07 17:52 --------- d-----w c:\documents and settings\just4u\Application Data\AIMP
2008-12-07 17:45 --------- d-----w c:\program files\Your Uninstaller 2008
2008-12-07 17:45 --------- d-----w c:\documents and settings\just4u\Application Data\URSoft
2008-12-07 17:45 --------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2008-12-07 17:44 --------- d-----w c:\program files\Yahoo!
2008-12-07 17:44 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-07 17:43 --------- d-----w c:\program files\BearShare Applications
2008-12-07 17:41 --------- d-----w c:\program files\Windows Live
2008-12-07 17:39 155,995 ----a-w c:\windows\java\Packages\1VXR17BP.ZIP
2008-12-07 17:25 --------- d-----w c:\program files\CCleaner
2008-12-07 17:25 --------- d-----w c:\documents and settings\just4u\Application Data\TuneUp Software
2008-12-07 17:07 --------- d-----w c:\documents and settings\just4u\Application Data\Avira
2008-12-07 17:01 --------- d-----w c:\program files\Avira
2008-12-07 17:01 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-12-07 16:53 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-07 16:53 --------- d-----w c:\program files\Realtek AC97
2008-12-07 16:53 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-04 11:27 --------- d-----w c:\program files\microsoft frontpage
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll
2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll
2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/03/2004 10:56 PM 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [12/05/2008 09:39 AM 1384880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [06/12/2008 01:28 PM 266497]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/03/2004 10:56 PM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/03/2004 10:56 PM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 12/05/2008 09:39 AM 1384880 c:\program files\Internet Download Manager\IDMan.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe" [2008-12-07 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE" [2008-12-07 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;"c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe" [2008-12-07 41217]
R3 slnt;Realtek RTL8139 Family PCI Fast Ethernet NIC;c:\windows\system32\DRIVERS\slnt.sys [2008-11-23 18004]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.eg/
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: avsda.dll
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\just4u\Application Data\Mozilla\Firefox\Profiles\li355h7x.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-13 21:44:27
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(716)
c:\windows\system32\avsda.dll
.
Completion time: 12/13/2008 21:44:57
ComboFix-quarantined-files.txt 2008-12-13 19:44:56
ComboFix2.txt 2008-12-13 19:42:14
Pre-Run: 2,756,677,632 bytes free
Post-Run: 2,749,292,544 bytes free
120