Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 10-03-20.01 - zero 03/20/2010 23:00:32.1.1 - x86
- Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.372 [GMT 1:00]
- Running from: c:\documents and settings\zero\Desktop\ComboFix.exe
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- c:\documents and settings\zero\csrss.exe
- D:\install.exe
- .
- ((((((((((((((((((((((((( Files Created from 2010-02-20 to 2010-03-20 )))))))))))))))))))))))))))))))
- .
- 2010-03-20 20:53 . 2010-03-20 20:53 -------- d-----w- c:\documents and settings\zero\DoctorWeb
- 2010-03-20 18:33 . 2010-03-20 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Autorun Eater
- 2010-03-20 18:19 . 2010-03-20 18:19 48 ----a-w- c:\documents and settings\zero\Application Data\svighost.dll
- 2010-03-16 16:00 . 2009-09-24 06:50 545 ----a-w- c:\windows\UC.PIF
- 2010-03-16 16:00 . 2009-09-24 06:50 545 ----a-w- c:\windows\RAR.PIF
- 2010-03-16 16:00 . 2009-09-24 06:50 545 ----a-w- c:\windows\PKZIP.PIF
- 2010-03-16 16:00 . 2009-09-24 06:50 545 ----a-w- c:\windows\PKUNZIP.PIF
- 2010-03-16 16:00 . 2010-03-16 16:01 -------- d-----w- C:\totalcmd
- 2010-03-16 16:00 . 2010-03-16 16:00 -------- d-----w- c:\documents and settings\zero\Application Data\GHISLER
- 2010-03-16 16:00 . 2009-09-24 06:50 545 ----a-w- c:\windows\NOCLOSE.PIF
- 2010-03-16 16:00 . 2009-09-24 06:50 545 ----a-w- c:\windows\LHA.PIF
- 2010-03-16 16:00 . 2009-09-24 06:50 545 ----a-w- c:\windows\ARJ.PIF
- 2010-03-15 22:56 . 2010-03-15 22:57 -------- d-----w- c:\program files\Recovery Toolbox for RAR
- 2010-03-15 09:53 . 2010-03-15 10:00 20833776 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\rp\RealPlayerSPGold.exe
- 2010-03-15 09:53 . 2010-03-15 09:53 8405312 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
- 2010-03-15 09:52 . 2010-03-15 09:52 149000 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\chr_helper\LaunchHelper.exe
- 2010-03-15 09:52 . 2010-03-15 09:52 10309448 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\chr\ChromeInstaller.exe
- 2010-03-15 09:50 . 2010-03-15 09:50 79368 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\RUP\vista.exe
- 2010-03-15 09:50 . 2010-03-15 09:50 64000 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
- 2010-03-15 09:50 . 2010-03-15 09:50 52288 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
- 2010-03-15 09:50 . 2010-03-15 09:50 50688 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
- 2010-03-15 09:50 . 2010-03-15 09:50 49152 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
- 2010-03-15 09:50 . 2010-03-15 09:50 118784 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\RUP\inst_config\compat.dll
- 2010-03-14 22:23 . 2010-03-14 22:23 439816 ----a-w- c:\documents and settings\zero\Application Data\Real\Update\setup3.10\setup.exe
- 2010-03-04 00:44 . 2010-03-04 00:44 -------- d-----w- c:\windows\G2Runner
- 2010-03-04 00:38 . 2010-03-04 00:38 -------- d-----w- c:\program files\Eidos Interactive
- 2010-02-27 15:49 . 2009-11-24 16:39 1093064 ----a-w- c:\documents and settings\zero\Application Data\Mozilla\Firefox\Profiles\i7wyvsa7.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2010-03-20 21:57 . 2009-06-02 17:21 -------- d-----w- c:\documents and settings\zero\Application Data\DNA
- 2010-03-20 20:20 . 2009-06-02 17:21 -------- d-----w- c:\program files\DNA
- 2010-03-20 18:25 . 2009-06-02 17:21 -------- d-----w- c:\documents and settings\zero\Application Data\BitTorrent
- 2010-03-04 00:51 . 2009-06-02 22:25 -------- d-----w- c:\program files\GameSpy Arcade
- 2010-03-04 00:38 . 2009-06-02 22:25 -------- d--h--w- c:\program files\InstallShield Installation Information
- 2010-02-07 23:21 . 2009-11-07 19:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
- 2010-02-03 02:00 . 2009-10-27 02:19 -------- d-----w- c:\documents and settings\zero\Application Data\mIRC
- 2010-02-01 23:14 . 2010-02-01 23:14 -------- d-----w- c:\program files\Webteh
- 2010-02-01 11:54 . 2009-06-07 05:11 12202 ----a-w- c:\documents and settings\zero\Application Data\Thinstall\BlazeDVD 5.0 Professional\%ProgramFilesDir%\BlazeVideo\BlazeDVD 5 Professional\BlazeDVD.dll
- 2010-01-27 18:10 . 2010-01-27 18:09 -------- d-----w- c:\program files\Common Files\Real
- 2010-01-27 18:10 . 2010-01-27 18:10 -------- d-----w- c:\program files\Common Files\xing shared
- 2010-01-27 18:09 . 2009-06-02 16:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
- 2010-01-27 18:09 . 2009-06-02 16:14 348160 ----a-w- c:\windows\system32\msvcr71.dll
- 2010-01-27 18:09 . 2010-01-27 18:09 -------- d-----w- c:\program files\Real
- 2010-01-26 08:07 . 2009-06-01 22:08 22144 ----a-w- c:\documents and settings\zero\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
- 2010-01-19 23:47 . 2009-06-02 16:30 -------- d-----w- c:\program files\Common Files\InstallShield
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
- "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
- "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-05 148888]
- "QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
- "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-01-27 198160]
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
- "ShowDeskFix"="shell32" [X]
- [HKEY_LOCAL_MACHINE\software\microsoft\security center]
- "AntiVirusOverride"=dword:00000001
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\Program Files\\DNA\\btdna.exe"=
- "c:\\Program Files\\BitTorrent\\bittorrent.exe"=
- "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
- "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
- "d:\\Program Files\\mIRC\\mirc.exe"=
- "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
- "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
- "c:\\Program Files\\Eidos Interactive\\Hothouse Creations\\Gangsters 2\\Gangsters2.exe"=
- R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [6/1/2008 8:13 AM 34064]
- S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/2/2009 6:33 PM 691696]
- .
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://www.google.com/
- IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
- DPF: {028C3B99-F9B0-4188-8C2C-D71CA84824D5} - hxxp://media.inecco.net/program/SonySncCs1011View.cab
- DPF: {66D393D5-4D80-497C-9F4F-F3839E090202} - hxxp://www.pysoft.com/Downloads/WebCamPlayerOCX.cab
- FF - ProfilePath - c:\documents and settings\zero\Application Data\Mozilla\Firefox\Profiles\i7wyvsa7.default\
- FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
- FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=
- FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
- FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
- FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin.dll
- FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin2.dll
- FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin3.dll
- FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin4.dll
- FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin5.dll
- FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin6.dll
- FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin7.dll
- .
- - - - - ORPHANS REMOVED - - - -
- HKCU-Run-cbvcs - c:\windows\system32\urretnd.exe
- ShellExecuteHooks-{68101905-D80F-4788-96F6-98618116178A} - c:\windows\system32\flashadgmn32.dll
- AddRemove-WinZip - c:\program files\WinZip\WINZIP32.EXE
- **************************************************************************
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2010-03-20 23:04
- Windows 5.1.2600 Service Pack 2 NTFS
- scanning hidden processes ...
- scanning hidden autostart entries ...
- scanning hidden files ...
- scan completed successfully
- hidden files: 0
- **************************************************************************
- .
- Completion time: 2010-03-20 23:05:49
- ComboFix-quarantined-files.txt 2010-03-20 22:05
- Pre-Run: 1,405,808,640 bytes free
- Post-Run: 1,494,953,984 bytes free
- WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
- [boot loader]
- timeout=2
- default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
- [operating systems]
- c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
- multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - - End Of File - - 97BD99A400B27D855A3B463F576B2743
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement