Nordfaust | 12.07.2008 15:38 | Code:
ComboFix 08-07-11.1 - sam 2008-07-12 16:27:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.289 [GMT 2:00]
Running from: C:\Documents and Settings\sam\My Documents\Mozilla Downloads\ComboFix.exe
* Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\sam\Application Data\rhc1fqj0ev6c
C:\Program Files\rhc1fqj0ev6c
C:\WINDOWS\system32\blphc5fqj0ev6c.scr
C:\WINDOWS\system32\lphc5fqj0ev6c.exe
C:\WINDOWS\system32\phc5fqj0ev6c.bmp
C:\WINDOWS\system32\pphc5fqj0ev6c.exe
C:\WINDOWS\system32\richvideocodec.dll
C:\WINDOWS\system32\sysrest.sys
C:\WINDOWS\system32\sysrest32.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_sysrest.sys
((((((((((((((((((((((((( Files Created from 2008-06-12 to 2008-07-12 )))))))))))))))))))))))))))))))
.
2008-07-11 17:18 . 2008-07-11 17:18 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-11 17:18 . 2008-07-11 17:18 <DIR> d-------- C:\Documents and Settings\sam\Application Data\Malwarebytes
2008-07-11 17:18 . 2008-07-11 17:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-11 17:18 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-11 17:18 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-11 11:40 . 2008-07-11 11:47 94,208 --a------ C:\WINDOWS\system32\72.tmp
2008-07-11 11:40 . 2008-07-11 11:47 94,208 --a------ C:\WINDOWS\system32\71.tmp
2008-07-11 11:40 . 2008-07-11 11:47 94,208 --a------ C:\WINDOWS\system32\70.tmp
2008-07-11 11:40 . 2008-07-11 11:46 94,208 --a------ C:\WINDOWS\system32\6F.tmp
2008-07-11 11:40 . 2008-07-11 11:40 19,456 --a------ C:\WINDOWS\system32\navfilter.dll
2008-07-11 11:40 . 2008-07-11 11:40 19,456 --a------ C:\WINDOWS\system32\navf.dll
2008-07-11 11:39 . 2008-07-11 11:39 <DIR> d-------- C:\Program Files\RichVideoCodec
2008-07-11 11:39 . 2008-07-11 11:39 19,456 --a------ C:\WINDOWS\system32\nvgflt.dll
2008-07-11 10:48 . 2008-07-11 10:48 <DIR> d-------- C:\Documents and Settings\sam\Application Data\CyberLink
2008-07-11 10:43 . 2008-07-11 10:43 <DIR> d-------- C:\Program Files\Cyberlink
2008-07-11 10:43 . 2008-07-11 10:43 <DIR> d-------- C:\Program Files\Common Files\CyberLink
2008-07-11 10:43 . 2008-07-11 10:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-11 10:40 . 2008-07-11 10:41 <DIR> d-------- C:\Program Files\PowerDVD8
2008-07-11 10:40 . 2008-07-11 10:40 29,480 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-07-07 21:44 . 2008-07-07 21:44 <DIR> d-------- C:\WINDOWS\Sun
2008-07-06 22:33 . 2008-07-06 22:33 <DIR> d-------- C:\Documents and Settings\sam\Application Data\vlc
2008-07-06 22:27 . 2008-07-06 22:28 <DIR> d-------- C:\Program Files\VLC
2008-06-27 21:22 . 2008-06-27 21:22 <DIR> d-------- C:\Program Files\OpenSource Flash Video Splitter
2008-06-24 16:47 . 2008-06-25 00:35 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-06-23 15:29 . 2008-07-11 11:00 <DIR> d-------- C:\Documents and Settings\sam\Shared
2008-06-23 15:29 . 2008-07-11 11:47 <DIR> d-------- C:\Documents and Settings\sam\Incomplete
2008-06-23 15:28 . 2008-06-23 15:28 <DIR> d-------- C:\Program Files\LimeWire
2008-06-23 15:28 . 2008-06-27 18:03 <DIR> d-------- C:\Documents and Settings\sam\Application Data\LimeWire
2008-06-23 15:16 . 2008-06-23 15:16 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-06-22 22:28 . 2008-07-11 10:43 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-06-22 22:17 . 2008-06-22 22:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-06-22 22:10 . 2008-06-22 22:10 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-06-22 20:49 . 2008-06-23 15:27 17,856 --a------ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2008-06-22 20:45 . 2008-07-11 19:52 <DIR> d-------- C:\Program Files\Trillian
2008-06-22 15:27 . 2008-06-22 15:27 400 --a------ C:\WINDOWS\ODBC.INI
2008-06-22 15:26 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-06-22 15:17 . 2008-06-22 15:21 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-06-22 15:07 . 2008-06-22 15:07 <DIR> dr-h----- C:\MSOCache
2008-06-22 14:09 . 2008-06-22 14:09 <DIR> d-------- C:\Documents and Settings\sam\Application Data\DivX
2008-06-22 01:11 . 2008-06-22 01:40 2,328,704 --a------ C:\WINDOWS\system32\TUKernel.exe
2008-06-21 20:41 . 2008-06-21 20:41 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-06-21 20:41 . 2004-02-22 10:11 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-06-21 20:41 . 2006-10-07 17:43 502,784 --a------ C:\WINDOWS\x2.64.exe
2008-06-21 20:41 . 2008-02-07 16:15 408,576 --a------ C:\WINDOWS\system32\Smab.dll
2008-06-21 20:41 . 2007-05-17 17:30 318,976 --a------ C:\WINDOWS\system32\avisynth.dll
2008-06-21 20:41 . 2005-02-28 13:16 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2008-06-21 20:41 . 2006-04-12 09:47 217,073 --a------ C:\WINDOWS\meta4.exe
2008-06-21 20:41 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-06-21 20:41 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll
2008-06-21 20:41 . 2006-04-05 08:09 66,560 --a------ C:\WINDOWS\MOTA113.exe
2008-06-21 20:41 . 2005-07-14 12:31 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2008-06-21 16:18 . 2008-06-21 16:18 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-06-21 16:18 . 2008-06-21 16:18 <DIR> d-------- C:\WINDOWS\system32\custom matrices
2008-06-21 16:18 . 2008-06-21 16:18 <DIR> d-------- C:\WINDOWS\system32\C2MP
2008-06-21 16:09 . 2007-12-28 10:43 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-21 16:05 . 2007-12-27 18:54 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-06-21 16:05 . 2007-12-27 18:54 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-06-21 16:01 . 2005-02-25 00:00 46,080 --a------ C:\WINDOWS\system32\escimgd.dll
2008-06-21 16:01 . 2005-02-25 00:00 29,696 --a------ C:\WINDOWS\system32\escwiad.dll
2008-06-21 16:01 . 2005-02-25 00:00 22,016 --a------ C:\WINDOWS\system32\esccmd.dll
2008-06-21 15:53 . 2008-07-08 22:39 <DIR> d-------- C:\Documents and Settings\sam\dwhelper
2008-06-21 15:22 . 2007-12-27 18:56 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-06-21 15:22 . 2008-07-10 07:42 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-21 15:04 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-21 15:01 . 2008-06-21 15:04 <DIR> d-------- C:\Program Files\Java
2008-06-21 15:00 . 2008-06-21 15:00 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-21 14:35 . 2002-09-11 13:18 40,448 -ra------ C:\WINDOWS\system32\drivers\fetnd5b.sys
2008-06-21 14:32 . 2007-12-27 19:28 83,072 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-06-21 14:32 . 2007-12-27 19:28 83,072 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-06-21 14:32 . 2007-12-27 18:56 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-06-21 14:32 . 2007-12-27 18:56 52,864 --a--c--- C:\WINDOWS\system32\dllcache\dmusic.sys
2008-06-21 14:32 . 2007-12-27 18:56 6,272 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-06-21 14:32 . 2007-12-27 18:56 6,272 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-06-21 14:31 . 2008-06-21 14:31 <DIR> d-------- C:\Program Files\VIA Technologies, Inc
2008-06-21 14:25 . 2005-12-09 03:03 71,168 --a------ C:\WINDOWS\system32\E_FLBBEE.DLL
2008-06-21 14:25 . 2005-04-11 03:01 62,976 --a------ C:\WINDOWS\system32\E_FD4BBEE.DLL
2008-06-21 14:25 . 2004-09-10 22:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2008-06-21 14:25 . 2002-12-26 22:41 26,880 -ra------ C:\WINDOWS\system32\drivers\VIAAGP1.SYS
2008-06-21 14:24 . 2008-06-21 14:24 <DIR> d-------- C:\WINDOWS\system32\Tools
2008-06-21 14:24 . 2008-06-21 14:24 <DIR> d-------- C:\Documents and Settings\sam\WINDOWS
2008-06-21 14:24 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-06-21 14:23 . 2008-06-22 22:27 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-06-21 14:17 . 2008-06-21 16:01 <DIR> d-------- C:\Program Files\EPSON
2008-06-20 20:43 . 2008-06-20 20:43 <DIR> d-------- C:\Documents and Settings\sam\Application Data\Ahead
2008-06-20 20:39 . 2008-06-20 20:39 <DIR> d-------- C:\Program Files\Nero
2008-06-20 20:39 . 2008-06-20 20:39 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-06-20 20:32 . 2008-06-20 20:32 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-20 20:18 . 2008-06-20 20:30 <DIR> d-------- C:\Program Files\ICQLite
2008-06-20 20:18 . 2008-06-20 20:30 <DIR> d-------- C:\Documents and Settings\sam\Application Data\ICQLite
2008-06-20 20:17 . 2006-11-23 16:45 24,072 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-06-20 20:16 . 2008-06-20 20:17 <DIR> d-------- C:\Program Files\TuneUp 2007
2008-06-20 20:16 . 2008-06-20 20:16 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-20 20:16 . 2008-06-20 20:16 <DIR> d-------- C:\Documents and Settings\sam\Application Data\TuneUp Software
2008-06-20 20:16 . 2008-06-20 20:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-06-20 20:10 . 2008-06-28 11:14 <DIR> d-------- C:\Program Files\SUPER
2008-06-20 20:09 . 2008-06-20 20:09 4,444 --a------ C:\WINDOWS\system32\pid.PNF
2008-06-20 20:08 . 2004-08-04 21:00 66,082 --a--c--- C:\WINDOWS\system32\dllcache\c_1141.nls
2008-06-20 20:08 . 2004-08-04 21:00 66,082 --a------ C:\WINDOWS\system32\c_1141.nls
2008-06-20 20:03 . 2008-06-24 16:54 <DIR> d-------- C:\Program Files\Common Files\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 10:10 --------- d-----w C:\Documents and Settings\sam\Application Data\Skype
2008-06-28 08:52 --------- d-----w C:\Documents and Settings\sam\Application Data\skypePM
2008-06-20 17:53 --------- d-----w C:\Program Files\Skype
2008-06-20 17:53 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-20 17:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-06-20 17:36 --------- d-----w C:\Program Files\Avast4
2008-06-20 17:24 --------- d-----w C:\Program Files\microsoft frontpage
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 12:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"RemoteControl8"="C:\Program Files\PowerDVD8\PowerDVD8\PDVD8Serv.exe" [2008-03-20 20:23 83240]
"PDVD8LanguageShortcut"="C:\Program Files\PowerDVD8\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2008-07-11 01:09 91432]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-12-28 10:44 15360]
C:\Documents and Settings\sam\Start Menu\Programs\Startup\
Trillian.lnk - C:\Program Files\Trillian\trillian.exe [12/11/2007 1873280]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
"msacm.l3codec"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};C:\Program Files\PowerDVD8\PowerDVD8\000.fcl [2008-02-01 17:24]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 UxTuneUp;TuneUp Designerweiterung;C:\WINDOWS\System32\svchost.exe [2007-12-28 10:44]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-06-26 15:37:56 C:\WINDOWS\Tasks\1-Klick-Wartung.job"
- C:\Program Files\TuneUp 2007\SystemOptimizer.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-lphc5fqj0ev6c - C:\WINDOWS\system32\lphc5fqj0ev6c.exe
HKLM-Run-SMrhc1fqj0ev6c - C:\Program Files\rhc1fqj0ev6c\rhc1fqj0ev6c.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-12 16:31:20
Windows 5.1.2600 Service Pack 3, v.3282 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\C:\Program Files\PowerDVD8\PowerDVD8\000.fcl"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-07-12 16:36:19 - machine was rebooted [sam]
ComboFix-quarantined-files.txt 2008-07-12 14:36:12
Pre-Run: 63,937,757,184 bytes free
Post-Run: 63,946,579,968 bytes free
213 |