——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, December 05, 2007 10:16:00 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/12/2007
Kaspersky Anti-Virus database records: 473506
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
J:\
K:\
Scan Statistics:
Total number of scanned objects: 170582
Number of viruses found: 3
Number of infected objects: 29
Number of suspicious objects: 0
Duration of the scan process: 03:16:47
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\ATI MMC\RemoteWonder.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\120c3c3b71f6f7dbfee143f3cac2cfb0_7afbb97e-90de-47c6-a5bf-1c0bdbd7fa74 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\132d6f3905a335484304fd221c1f2fe9_7afbb97e-90de-47c6-a5bf-1c0bdbd7fa74 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b11a2470a5045dd15f0f8a51a254caf_7afbb97e-90de-47c6-a5bf-1c0bdbd7fa74 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d3f60010ecc468b53a2bb3c5f609ff3_7afbb97e-90de-47c6-a5bf-1c0bdbd7fa74 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d1c1629ab94bc03e4d17f93abbc9382_7afbb97e-90de-47c6-a5bf-1c0bdbd7fa74 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6bf6ebde633f3cb0d57851b69c8158a1_7afbb97e-90de-47c6-a5bf-1c0bdbd7fa74 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ca3461f968a1fda05693dc8f43bdcc71_7afbb97e-90de-47c6-a5bf-1c0bdbd7fa74 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd140a497895d25b9ac1665e6cdfa33d_7afbb97e-90de-47c6-a5bf-1c0bdbd7fa74 Object is locked skipped
C:\Documents and Settings\josh\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\josh\Desktop\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen\WinAvi Ipod PSP 3GP MP4 Converter v3.1\winavi_ipod_video_converter.exe/data33 Infected: Trojan.Win32.Agent.csy skipped
C:\Documents and Settings\josh\Desktop\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen\WinAvi Ipod PSP 3GP MP4 Converter v3.1\winavi_ipod_video_converter.exe SIM: infected - 1 skipped
C:\Documents and Settings\josh\Desktop\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen.rar/WinAvi Ipod PSP 3GP MP4 Converter v3.1/winavi_ipod_video_converter.exe/data33 Infected: Trojan.Win32.Agent.csy skipped
C:\Documents and Settings\josh\Desktop\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen.rar/WinAvi Ipod PSP 3GP MP4 Converter v3.1/winavi_ipod_video_converter.exe Infected: Trojan.Win32.Agent.csy skipped
C:\Documents and Settings\josh\Desktop\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen.rar RAR: infected - 2 skipped
C:\Documents and Settings\josh\Desktop\software\DVD to DivX Advanced.zip/DivX Pro 5.02/DivX Pro 5.02.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
C:\Documents and Settings\josh\Desktop\software\DVD to DivX Advanced.zip/DivX Pro 5.02/DivX Pro 5.02.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
C:\Documents and Settings\josh\Desktop\software\DVD to DivX Advanced.zip ZIP: infected - 2 skipped
C:\Documents and Settings\josh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\josh\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\josh\Local Settings\History\History.IE5\MSHist012007120520071206\index.dat Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temp\~DF791C.tmp Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temp\~DF88A0.tmp Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temp\~DF88B6.tmp Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temp\~DF88D.tmp Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temp\~DF9456.tmp Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temp\~DFAB69.tmp Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temp\~DFDA0C.tmp Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\josh\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\josh\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\josh\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\CA\SharedComponents\PPRT\logs\2007-12-05.csv Object is locked skipped
C:\Program Files\WinAVI MP4 Converter\Skins\0\install.exe Infected: Trojan.Win32.Agent.csy skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir/backups/NTSpool.exe Infected: Trojan.Win32.Agent.csy skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir/backups/pics06.zip/pics06.exe Infected: Trojan.Win32.Agent.csy skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir/backups/pics06.zip Infected: Trojan.Win32.Agent.csy skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir/backups/pics08.zip/pics08.exe Infected: Trojan.Win32.Agent.csy skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir/backups/pics08.zip Infected: Trojan.Win32.Agent.csy skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir ZIP: infected - 5 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{E8F6C452-6735-41E5-B0C8-084A857B8CA1}\RP643\A0158460.exe Infected: Trojan.Win32.Agent.csy skipped
C:\System Volume Information\_restore{E8F6C452-6735-41E5-B0C8-084A857B8CA1}\RP643\A0158465.exe Infected: Trojan.Win32.Agent.csy skipped
C:\System Volume Information\_restore{E8F6C452-6735-41E5-B0C8-084A857B8CA1}\RP645\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
J:\System Volume Information\_restore{E8F6C452-6735-41E5-B0C8-084A857B8CA1}\RP645\change.log Object is locked skipped
J:\all folders\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen.rar/WinAvi Ipod PSP 3GP MP4 Converter v3.1/winavi_ipod_video_converter.exe/data33 Infected: Trojan.Win32.Agent.csy skipped
J:\all folders\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen.rar/WinAvi Ipod PSP 3GP MP4 Converter v3.1/winavi_ipod_video_converter.exe Infected: Trojan.Win32.Agent.csy skipped
J:\all folders\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen.rar RAR: infected - 2 skipped
J:\all folders\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen\WinAvi Ipod PSP 3GP MP4 Converter v3.1\winavi_ipod_video_converter.exe/data33 Infected: Trojan.Win32.Agent.csy skipped
J:\all folders\branden\WinAvi Ipod PSP 3GP MP4 Convert 3.1 + Keygen\WinAvi Ipod PSP 3GP MP4 Converter v3.1\winavi_ipod_video_converter.exe SIM: infected - 1 skipped
J:\all folders\software\DVD to DivX Advanced.zip/DivX Pro 5.02/DivX Pro 5.02.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
J:\all folders\software\DVD to DivX Advanced.zip/DivX Pro 5.02/DivX Pro 5.02.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
J:\all folders\software\DVD to DivX Advanced.zip ZIP: infected - 2 skipped
K:\old stuff from computer\desktop\Desktop\mirc\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
K:\old stuff from computer\desktop\Desktop\mirc\mirc616.exe mIRC: infected - 1 skipped
K:\old stuff from computer\desktop\Desktop\stuff\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
K:\old stuff from computer\desktop\Desktop\stuff\mirc616.exe mIRC: infected - 1 skipped
K:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
K:\System Volume Information\_restore{E8F6C452-6735-41E5-B0C8-084A857B8CA1}\RP645\change.log Object is locked skipped
Scan process completed.
ComboFix 07-12-04.3 - josh 2007-12-05 18:38:35.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1559 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\josh\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\73816E8FAA.sys
C:\WINDOWS\system32\NTInfos.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\drivers.exe
C:\SDFix\apps\dummy.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\moveex.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\regedit.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SecurityProviders.reg
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\zip.exe
C:\SDFix\backups\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups\find.exe
C:\SDFix\backups\findstr.exe
C:\SDFix\backups\HOSTS
C:\SDFix\backups\regedit.exe
C:\SDFix\catchme.exe
C:\SDFix\dummy.exe
C:\SDFix\dummy.sys
C:\SDFix\Report.txt
C:\SDFix\RunThis.cmd
C:\SDFix\SDFIX_ReadMe_Online.url
C:\WINDOWS\system32\73816E8FAA.sys
C:\WINDOWS\system32\NTInfos.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-06 to 2007-12-06 )))))))))))))))))))))))))))))))
.
2007-12-04 20:46 . 2007-12-04 20:46 d——– C:\WINDOWS\ERUNT
2007-12-03 04:29 . 2007-12-03 04:29 d——– C:\Documents and Settings\josh\Application Data\Grisoft
2007-12-03 04:27 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-03 04:11 . 2007-12-03 04:11 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-02 23:47 . 2007-12-02 23:47 d——– C:\Program Files\InterMute
2007-12-02 16:56 . 2007-12-02 16:56 d——– C:\Program Files\Trend Micro
2007-11-29 20:43 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2007-11-29 18:30 . 2007-12-05 13:51 60,862 –a—— C:\WINDOWS\system32\drivers\kmxcfg.u2k0
2007-11-29 18:30 . 2007-12-05 13:51 64 –a—— C:\WINDOWS\system32\drivers\kmxcfg.u2k7
2007-11-29 18:30 . 2007-12-05 13:51 64 –a—— C:\WINDOWS\system32\drivers\kmxcfg.u2k6
2007-11-29 18:30 . 2007-12-05 13:51 64 –a—— C:\WINDOWS\system32\drivers\kmxcfg.u2k5
2007-11-29 18:30 . 2007-12-05 13:51 64 –a—— C:\WINDOWS\system32\drivers\kmxcfg.u2k4
2007-11-29 18:30 . 2007-12-05 13:51 64 –a—— C:\WINDOWS\system32\drivers\kmxcfg.u2k3
2007-11-29 18:30 . 2007-12-05 13:51 64 –a—— C:\WINDOWS\system32\drivers\kmxcfg.u2k2
2007-11-29 18:30 . 2007-12-05 13:51 64 –a—— C:\WINDOWS\system32\drivers\kmxcfg.u2k1
2007-11-29 15:36 . 2007-08-20 13:42 879,784 –a—— C:\WINDOWS\system32\drivers\vetefile.sys
2007-11-29 15:36 . 2007-08-20 13:42 108,312 –a—— C:\WINDOWS\system32\drivers\veteboot.sys
2007-11-29 15:36 . 2007-08-20 13:42 99,592 –a—— C:\WINDOWS\system32\isafeif.dll
2007-11-29 15:36 . 2007-08-20 13:42 79,424 –a—— C:\WINDOWS\system32\vetredir.dll
2007-11-29 15:36 . 2007-08-20 13:42 75,016 –a—— C:\WINDOWS\system32\isafprod.dll
2007-11-29 15:36 . 2007-08-20 13:42 32,264 –a—— C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-11-29 15:36 . 2007-08-20 13:42 26,376 –a—— C:\WINDOWS\system32\drivers\vet-filt.sys
2007-11-29 15:36 . 2007-08-20 13:42 21,512 –a—— C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-11-29 15:36 . 2007-08-20 13:42 21,128 –a—— C:\WINDOWS\system32\drivers\vet-rec.sys
2007-11-29 15:35 . 2007-11-29 15:35 d——– C:\Program Files\Common Files\Scanner
2007-11-28 20:54 . 2007-11-28 20:54 244 –ah—– C:\sqmnoopt00.sqm
2007-11-28 20:54 . 2007-11-28 20:54 232 –ah—– C:\sqmdata00.sqm
2007-11-23 16:09 . 2007-12-03 04:10 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-20 03:15 . 2007-11-20 03:15 d——– C:\Program Files\MSN Messenger
2007-11-18 01:15 . 2007-11-18 01:15 d——– C:\Program Files\MSXML 4.0
2007-11-18 01:15 . 2005-05-26 15:34 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2007-11-15 18:53 . 2007-11-15 18:53 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-11-15 18:46 . 2007-11-15 18:46 d——– C:\Program Files\WinAVI MP4 Converter
2007-11-15 18:46 . 2007-12-04 19:53 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 04:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2007-12-02 20:56 ——— d—–w C:\Documents and Settings\josh\Application Data\ATI MMC
2007-11-30 02:43 ——— d—–w C:\Program Files\Java
2007-11-29 21:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\CA
2007-11-29 21:35 ——— d—–w C:\Program Files\CA
2007-11-22 06:49 ——— d—–w C:\Documents and Settings\josh\Application Data\BitTorrent
2007-11-20 22:28 ——— d—–w C:\Documents and Settings\josh\Application Data\AdobeUM
2007-11-18 08:36 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-16 00:53 ——— d—–w C:\Program Files\Apple Software Update
2007-10-19 00:16 ——— d—–w C:\Program Files\BitTorrent
2007-09-17 18:23 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 —-a-w C:\WINDOWS\system32\DivX.dll
2007-09-11 23:14 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"="C:\Program Files\ATI Multimedia\main\launchpd.exe" [2003-09-02 05:46]
"ATI Remote Control"="C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe" [2003-08-12 12:50]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ATI Scheduler"="C:\Program Files\ATI Multimedia\MAIN\ATISched.EXE" [2003-09-02 05:42]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 18:38]
"EPSON Stylus C80 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC2.exe" [2001-10-04 02:01]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-08-12 20:10]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickFinder Scheduler"="C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2006-04-05 23:55]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 15:30]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-20 03:01]
"P17Helper"="Rundll32 P17.dll" []
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 15:10]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 14:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"NWEReboot"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 11:45]
"EnableDCOM"="N" []
"restrictanonymous"="1 (0x1)" []
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-16 22:25]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2007-11-29 15:36]
"CAVRID"="C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe" [2007-08-20 13:42]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2007-08-14 10:06]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2007-08-14 10:06]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2007-08-14 10:01]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2007-05-18 14:30 79368 C:\WINDOWS\system32\UmxWNP.dll
R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe"
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe"
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe"
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys
R3 P17;Sound Blaster Audigy;C:\WINDOWS\system32\drivers\P17.sys
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe"
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310v.sys
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 00:53:58 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-29 22:37:17 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as josh at 3 36 PM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-05 18:42:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-05 18:43:23
C:\ComboFix2.txt … 2007-12-04 22:55
.
— E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:19 PM, on 12/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\ATI Multimedia\main\launchpd.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\ATI Multimedia\MAIN\ATISched.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\MAIN\ATISched.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [EPSON Stylus C80 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /P23 "EPSON Stylus C80 Series" /O5 "LPT1:" /M "Stylus C80"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1144886536953
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
–
End of file - 9982 bytes