Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 11-06-17.02 - Admin 17/06/2011 19:53:02.1.1 - x86
- Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.948 [GMT 1:00]
- Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- c:\documents and settings\Admin\Application Data\inlog
- c:\documents and settings\Admin\Local Settings\Application Data\{D5C3971B-9E81-4074-B74B-E4A346395303}
- c:\documents and settings\Admin\Local Settings\Application Data\{D5C3971B-9E81-4074-B74B-E4A346395303}\chrome.manifest
- c:\documents and settings\Admin\Local Settings\Application Data\{D5C3971B-9E81-4074-B74B-E4A346395303}\chrome\content\_cfg.js
- c:\documents and settings\Admin\Local Settings\Application Data\{D5C3971B-9E81-4074-B74B-E4A346395303}\chrome\content\overlay.xul
- c:\documents and settings\Admin\Local Settings\Application Data\{D5C3971B-9E81-4074-B74B-E4A346395303}\install.rdf
- c:\windows\system32\install.exe
- .
- .
- ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- -------\Legacy_INPUT_MANAGER
- -------\Legacy_LOCAL_ACCOUNT_AUTHORITY_SERVICE
- -------\Legacy_MOUSEDRIVER
- -------\Legacy_PLUG_MANAGER
- .
- .
- ((((((((((((((((((((((((( Files Created from 2011-05-17 to 2011-06-17 )))))))))))))))))))))))))))))))
- .
- .
- 2011-06-17 18:36 . 2011-06-17 18:36 -------- d-----w- c:\program files\Hitman Pro 3.5
- 2011-06-17 18:21 . 2011-06-17 18:41 17480 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
- 2011-06-17 18:21 . 2011-06-17 18:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
- 2011-06-17 17:16 . 2011-05-29 08:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
- 2011-06-17 17:16 . 2011-06-17 17:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
- 2011-06-17 17:16 . 2011-05-29 08:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
- 2011-06-17 14:46 . 2011-06-17 14:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\AVG Security Toolbar
- 2011-06-17 14:05 . 2011-06-17 14:05 -------- d-----w- c:\documents and settings\Admin\Application Data\AVG10
- 2011-06-17 14:05 . 2011-06-17 14:05 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
- 2011-06-17 14:03 . 2011-06-17 17:50 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
- 2011-06-17 14:03 . 2011-06-17 14:03 -------- d-----w- c:\program files\AVG
- 2011-06-17 14:02 . 2011-06-17 17:44 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
- 2011-06-16 21:15 . 2011-06-17 08:26 -------- d-----w- C:\Downloads
- 2011-06-16 21:07 . 2011-06-16 21:07 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Mozilla
- 2011-06-16 20:27 . 2011-06-16 20:27 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
- 2011-06-16 20:27 . 2011-06-16 20:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
- 2011-06-15 22:44 . 2011-06-15 22:44 -------- d-----w- c:\documents and settings\Administrator
- 2011-06-10 22:32 . 2011-06-15 22:26 0 ----a-w- c:\windows\Hgoqoxubace.bin
- 2011-06-10 22:31 . 2011-06-10 22:31 144 ----a-w- c:\documents and settings\Admin\Application Data\phvoisznn.bat
- 2011-06-10 22:30 . 2011-06-10 22:30 166400 --sha-r- c:\windows\system32\normidna8.dll
- 2011-06-10 22:30 . 2011-06-10 22:30 166400 --sha-r- c:\windows\system32\atkctrs0.dll
- 2011-06-10 12:01 . 2011-06-10 12:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
- 2011-05-20 20:16 . 2011-05-20 20:16 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
- .
- .
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2011-05-16 12:57 . 2010-12-11 09:58 499712 ----a-w- c:\windows\system32\msvcp71.dll
- 2011-05-16 12:57 . 2010-12-11 09:58 348160 ----a-w- c:\windows\system32\msvcr71.dll
- 2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
- 2011-04-14 16:26 . 2011-06-16 21:06 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
- .
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- .
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-07-07 1753192]
- "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
- "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
- "HitmanPro35"="c:\program files\Hitman Pro 3.5\HitmanPro35.exe" [2011-06-17 6470464]
- .
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
- "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
- 2010-11-10 12:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
- 2010-11-10 12:49 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
- 2010-12-09 00:07 69632 ----a-w- c:\windows\Alcmtr.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
- 2008-04-14 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus D92 Series]
- 2006-09-27 04:00 139264 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBZE.EXE
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
- 2008-04-14 05:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
- 2010-07-09 16:24 13923432 ----a-w- c:\windows\system32\nvcpl.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
- 2010-07-09 16:24 110696 ----a-w- c:\windows\system32\nvmctray.dll
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
- 2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
- 2010-12-09 00:07 16208384 ----a-w- c:\windows\RTHDCPL.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
- 2010-12-09 00:07 2879488 ----a-w- c:\windows\SkyTel.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
- 2011-05-16 12:57 273544 ----a-w- c:\program files\Real\RealPlayer\Update\realsched.exe
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
- "WMPNetworkSvc"=3 (0x3)
- "Plug Manager"=2 (0x2)
- "ose"=3 (0x3)
- "MyWebSearchService"=2 (0x2)
- "MouseDriver"=2 (0x2)
- "Local Account Authority Service"=2 (0x2)
- "JavaQuickStarterService"=2 (0x2)
- "Input Manager"=2 (0x2)
- "idsvc"=3 (0x3)
- "IDriverT"=3 (0x3)
- "gusvc"=3 (0x3)
- "gupdatem"=3 (0x3)
- "gupdate"=2 (0x2)
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\security center]
- "AntiVirusOverride"=dword:00000001
- "FirewallOverride"=dword:00000001
- .
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
- "%windir%\\system32\\sessmgr.exe"=
- .
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
- "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
- .
- S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
- S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14/04/2008 13:00 14336]
- S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
- S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [22/03/2011 13:48 136176]
- S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [22/03/2011 13:48 136176]
- .
- --- Other Services/Drivers In Memory ---
- .
- *NewlyCreated* - WUAUSERV
- .
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
- WINRM REG_MULTI_SZ WINRM
- .
- Contents of the 'Scheduled Tasks' folder
- .
- 2011-06-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
- .
- 2011-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2011-03-22 12:48]
- .
- 2011-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2011-03-22 12:48]
- .
- 2011-06-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-602162358-448539723-1801674531-1004.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 09:47]
- .
- 2011-06-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-602162358-448539723-1801674531-1004.job
- - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 09:47]
- .
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://www.google.co.uk/
- IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
- IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
- IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
- TCP: DhcpNameServer = 192.168.0.97
- TCP: Interfaces\{12AD199B-99ED-4750-A343-5018CFF9EE0B}: NameServer = 8.8.8.8,8.8.4.4
- FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\qzokx1at.default\
- FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
- FF - prefs.js: network.proxy.type - 0
- .
- - - - - ORPHANS REMOVED - - - -
- .
- Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
- WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
- MSConfigStartUp-conhost - c:\documents and settings\Admin\Application Data\Microsoft\conhost.exe
- MSConfigStartUp-Gsinigowe - c:\windows\ezebeqixiwu.dll
- MSConfigStartUp-Input Manager - c:\documents and settings\Admin\Application Data\conima.exe
- MSConfigStartUp-Local Account Service - c:\documents and settings\Admin\Application Data\lssas.exe
- MSConfigStartUp-MSC - c:\program files\Microsoft Security Client\msseces.exe
- MSConfigStartUp-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe
- MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
- MSConfigStartUp-NtWqIVLZEWZU - c:\docume~1\Admin\LOCALS~1\Temp\Vlq.exe
- MSConfigStartUp-p2ie470 - c:\documents and settings\Admin\Application Data\kx0378r.exe
- MSConfigStartUp-Plug Manager - c:\documents and settings\Admin\Application Data\manager.exe
- MSConfigStartUp-QK9G0Z54EX - c:\windows\Vmalya.exe
- MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
- MSConfigStartUp-Tmijogiseyi - c:\windows\jtmthusu.dll
- MSConfigStartUp-YDZ1QVAGOJ - c:\docume~1\Admin\LOCALS~1\Temp\Vll.exe
- .
- .
- .
- **************************************************************************
- .
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2011-06-17 19:58
- Windows 5.1.2600 Service Pack 3 NTFS
- .
- scanning hidden processes ...
- .
- scanning hidden autostart entries ...
- .
- scanning hidden files ...
- .
- scan completed successfully
- hidden files: 0
- .
- **************************************************************************
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- .
- - - - - - - - > 'explorer.exe'(3716)
- c:\windows\system32\WININET.dll
- c:\windows\system32\ieframe.dll
- c:\windows\system32\webcheck.dll
- c:\windows\system32\WPDShServiceObj.dll
- c:\windows\system32\PortableDeviceTypes.dll
- c:\windows\system32\PortableDeviceApi.dll
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\windows\system32\nvsvc32.exe
- c:\windows\system32\rundll32.exe
- c:\windows\system32\rundll32.exe
- c:\windows\system32\rundll32.exe
- .
- **************************************************************************
- .
- Completion time: 2011-06-17 20:01:07 - machine was rebooted
- ComboFix-quarantined-files.txt 2011-06-17 19:01
- .
- Pre-Run: 23,217,901,568 bytes free
- Post-Run: 23,123,918,848 bytes free
- .
- WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
- [boot loader]
- timeout=2
- default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
- [operating systems]
- c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
- UnsupportedDebug="do not select this" /debug
- multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- .
- - - End Of File - - DCC3D0C8BAFE7029C99D2BB7B16D9D06
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement