Kaban
Topic Starter
Thank you to whomever helps in advance…
Last night I was browsing (firefox) and something poped up and installed a malware, my Antivir detected it and i hit access deny, however it messed with my system and left something as wallpaper
I was cautious not to log into anything important and tried to log into some NFL thing online, and antivir poped up again with same file
Virus or unwanted program 'VBS/Agent.1002 [virus]'
detected in file 'C:\Documents and Settings\Mike\Local Settings\Temp\.tt1.tmp.vbs.
Action performed: Move file to quarantine
I moved it to quarantine, and deleted everything in temp folder
later i searched the tt1.tmp and found following topic which looks like exact same:
http://forums.whatthetech.com/Unable_to_ru…his_t94050.html
I followed same instructions and here are the log files for Malwarebytes' anti-malware and combofix::
Malwarebytes' Anti-Malware 1.25
Database version: 1066
Windows 5.1.2600 Service Pack 2
5:58:40 PM 8/18/2008
mbam-log-08-18-2008 (17-58-40).txt
Scan type: Quick Scan
Objects scanned: 40932
Time elapsed: 2 minute(s), 57 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\blphcg0mj0eecl.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lphcg0mj0eecl.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\phcg0mj0eecl.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
———————————————————–>>>>>
ComboFix 08-08-18.01 - Mike 2008-08-18 18:08:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1683 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\#SharedObjects\6V8VSSWS\interclick.com
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\#SharedObjects\6V8VSSWS\interclick.com\ud.sol
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Mike\UserData
C:\Documents and Settings\Mike\UserData\index.dat
C:\Documents and Settings\Mike\UserData\K9EJS9UN\IsOnIE6tbPromo[1].xml
.
((((((((((((((((((((((((( Files Created from 2008-07-18 to 2008-08-18 )))))))))))))))))))))))))))))))
.
2008-08-18 18:03 . 2008-08-18 18:03 d——– C:\Program Files\Trend Micro
2008-08-18 17:52 . 2008-08-18 17:52 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-18 17:52 . 2008-08-18 17:52 d——– C:\Documents and Settings\Mike\Application Data\Malwarebytes
2008-08-18 17:52 . 2008-08-18 17:52 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-18 17:52 . 2008-08-17 15:01 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-18 17:52 . 2008-08-17 15:01 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-18 00:09 . 2008-08-18 00:09 d——– C:\Program Files\Lavasoft
2008-08-18 00:07 . 2008-08-18 00:08 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-15 20:44 . 2008-08-15 20:44 38 –a—— C:\WINDOWS\avisplitter.INI
2008-08-07 18:55 . 2008-08-07 18:55 d——– C:\WINDOWS\Sun
2008-08-07 09:52 . 2003-09-18 14:32 1,060,864 –a—— C:\WINDOWS\system32\MFC71.dll
2008-08-07 09:52 . 1998-10-29 16:45 306,688 –a—— C:\WINDOWS\IsUninst.exe
2008-08-07 09:52 . 2008-08-07 09:52 0 –a—— C:\WINDOWS\OpPrintServer.INI
2008-08-07 09:49 . 2008-08-07 09:49 d——– C:\WINDOWS\StartHtmico
2008-08-07 09:49 . 2008-08-07 09:49 d——– C:\WINDOWS\IP4000,3000
2008-08-07 09:49 . 2008-08-07 09:49 d–h—– C:\BJPrinter
2008-08-07 09:49 . 2004-06-15 01:00 116,736 –a—— C:\WINDOWS\system32\CNMLM61.DLL
2008-08-07 09:49 . 2004-06-04 11:34 86,016 -ra—— C:\WINDOWS\system32\CNMCP61.exe
2008-08-07 09:49 . 2004-06-15 01:00 7,680 –a—— C:\WINDOWS\system32\CNMVS61.DLL
2008-08-07 09:48 . 2008-08-07 09:52 d——– C:\Program Files\Canon
2008-08-06 21:31 . 2008-08-06 21:31 d——– C:\Documents and Settings\Mike\Application Data\acccore
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Program Files\Viewpoint
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Program Files\Common Files\AOL
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-06 21:30 . 2008-08-06 21:31 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Documents and Settings\All Users\Application Data\AOL
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Documents and Settings\All Users\Application Data\acccore
2008-08-06 21:29 . 2008-08-06 21:30 d——– C:\Program Files\AIM6
2008-08-06 21:29 . 2008-08-06 21:30 409 –ah—– C:\IPH.PH
2008-08-06 16:39 . 2008-08-06 16:39 d——– C:\Program Files\Common Files\Adobe AIR
2008-08-06 16:38 . 2008-08-06 16:38 d——– C:\Program Files\Common Files\Adobe
2008-08-05 10:27 . 2008-08-05 10:27 d——– C:\Documents and Settings\Mike\Application Data\DivX
2008-08-04 11:17 . 2008-08-04 11:17 d——– C:\Program Files\Jasc Software Inc
2008-08-03 00:15 . 2007-12-11 18:34 120,056 ——— C:\WINDOWS\system32\pxcpyi64.exe
2008-08-03 00:15 . 2007-12-11 18:34 118,520 ——— C:\WINDOWS\system32\pxinsi64.exe
2008-08-03 00:14 . 2008-08-03 00:15 d——– C:\Program Files\DivX
2008-08-03 00:12 . 2008-08-03 00:12 d——– C:\Program Files\Java
2008-08-03 00:12 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-08-03 00:11 . 2008-08-03 00:11 d——– C:\Program Files\Common Files\Java
2008-08-01 12:14 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-08-01 12:14 . 2004-08-03 23:01 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2008-07-31 00:26 . 2004-08-03 23:08 26,496 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-31 00:13 . 2008-07-31 00:13 d——– C:\Program Files\SanDisk
2008-07-31 00:13 . 2008-07-31 00:13 d——– C:\Program Files\Common Files\ArcSoft
2008-07-31 00:13 . 2008-07-31 00:13 d——– C:\Documents and Settings\Mike\Application Data\ArcSoft
2008-07-31 00:13 . 2004-05-04 11:53 1,645,320 –a—— C:\WINDOWS\system32\gdiplus.dll
2008-07-31 00:13 . 2003-03-18 22:14 499,712 -ra—— C:\WINDOWS\system32\msvcp71.dll
2008-07-31 00:13 . 2005-06-21 10:29 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2008-07-30 20:22 . 2008-07-30 20:22 d——– C:\WINDOWS\system32\LogFiles
2008-07-30 20:22 . 2008-08-17 19:08 136,888 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-30 20:22 . 2008-08-17 19:07 111,928 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2008-07-30 20:22 . 2008-07-30 20:22 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2008-07-30 15:02 . 2008-07-30 15:02 d——– C:\Program Files\Ventrilo
2008-07-30 15:02 . 2008-08-18 00:09 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-07-30 15:02 . 2008-07-30 15:02 d——– C:\Documents and Settings\Mike\Application Data\Ventrilo
2008-07-30 14:09 . 2008-07-30 14:09 d——– C:\Program Files\Veoh Networks
2008-07-30 14:08 . 2008-07-30 14:08 d——– C:\WINDOWS\Downloaded Installations
2008-07-30 00:56 . 2008-07-30 00:56 d——– C:\Documents and Settings\Mike\Application Data\Media Player Classic
2008-07-30 00:45 . 2008-07-30 00:45 d——– C:\Program Files\K-Lite Codec Pack
2008-07-29 21:58 . 2008-07-29 21:59 d——– C:\Program Files\RivaTuner v2.09
2008-07-29 21:16 . 2008-07-29 21:16 d——– C:\Logs
2008-07-29 19:34 . 2008-07-30 14:19 d——– C:\World of Warcraft
2008-07-29 19:34 . 2008-07-29 19:34 d——– C:\Program Files\Common Files\Blizzard Entertainment
2008-07-29 01:40 . 2003-06-18 17:31 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2008-07-29 01:40 . 2008-07-29 01:40 376 –a—— C:\WINDOWS\ODBC.INI
2008-07-29 01:39 . 2008-07-29 01:39 d——– C:\WINDOWS\SHELLNEW
2008-07-29 01:39 . 2008-07-29 01:39 d——– C:\Program Files\Microsoft.NET
2008-07-29 01:39 . 2008-07-29 01:39 d——– C:\Program Files\Microsoft ActiveSync
2008-07-29 01:35 . 2008-08-17 19:07 d——– C:\Program Files\Steam
2008-07-29 01:21 . 2008-07-29 01:22 d——– C:\Program Files\Winamp
2008-07-29 01:21 . 2008-07-29 22:42 d——– C:\Documents and Settings\Mike\Application Data\Winamp
2008-07-29 01:17 . 2008-07-29 01:17 d——– C:\Program Files\Avira
2008-07-29 01:17 . 2008-07-29 01:17 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-07-29 01:09 . 2008-07-29 01:09 0 –a—— C:\WINDOWS\nsreg.dat
2008-07-29 01:08 . 2008-08-18 18:05 d——– C:\downloads
2008-07-29 01:05 . 2008-07-29 01:05 d——– C:\Program Files\Razer
2008-07-29 01:05 . 2001-01-04 10:12 162,900 ——— C:\WINDOWS\system32\drivers\USBICP.sys
2008-07-29 01:05 . 2005-07-22 15:01 69,632 –a—— C:\WINDOWS\system32\razer.cpl
2008-07-29 01:05 . 2005-08-12 10:11 19,020 –a—— C:\WINDOWS\system32\drivers\Razerlow.sys
2008-07-29 01:03 . 2008-07-29 01:05 810 –a—— C:\WINDOWS\system\Cmicnfgp.ini
2008-07-29 01:02 . 2008-07-29 01:02 d——– C:\Program Files\Razer Barracuda AC-1 Gaming Audio Card
2008-07-29 01:02 . 2008-07-29 01:02 d——– C:\Program Files\OpenAL
2008-07-29 00:57 . 2008-07-29 00:57 d——– C:\Program Files\ATI
2008-07-29 00:51 . 2008-07-29 00:51 d——– C:\Documents and Settings\Mike\Application Data\ATI
2008-07-29 00:51 . 2008-07-29 00:51 d——– C:\Documents and Settings\All Users\Application Data\ATI
2008-07-29 00:50 . 2008-07-29 00:50 0 –a—— C:\WINDOWS\ativpsrm.bin
2008-07-29 00:49 . 2005-01-17 01:43 295,424 -ra—— C:\WINDOWS\system32\idecoi.dll
2008-07-29 00:49 . 2004-12-16 04:32 176,128 -ra—— C:\WINDOWS\system32\nvusmb.exe
2008-07-29 00:49 . 2004-12-16 16:32 176,128 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2008-07-29 00:49 . 2004-12-16 04:32 176,128 -ra—— C:\WINDOWS\system32\nvuide.exe
2008-07-29 00:49 . 2005-01-17 01:43 88,576 -ra—— C:\WINDOWS\system32\drivers\nvatabus.sys
2008-07-29 00:49 . 2004-11-30 14:30 3,507 -ra—— C:\WINDOWS\system32\nvide.nvu
2008-07-29 00:49 . 2004-11-09 22:35 1,231 -ra—— C:\WINDOWS\system32\nvsmb.nvu
2008-07-29 00:48 . 2004-12-28 23:25 810,056 -ra—— C:\WINDOWS\system32\SATA.bmp
2008-07-29 00:48 . 2008-07-31 00:16 6,125 –a—— C:\WINDOWS\Ascd_tmp.ini
2008-07-29 00:48 . 2000-03-29 10:17 5,824 –a—— C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-07-29 00:48 . 2004-08-12 22:56 5,810 -ra—— C:\WINDOWS\system32\drivers\ASACPI.sys
2008-07-29 00:48 . 2004-12-29 03:47 264 -ra—— C:\WINDOWS\system32\raidmgmt.ini
2008-07-29 00:38 . 2008-07-29 00:38 d——– C:\Program Files\Common Files\ATI Technologies
2008-07-29 00:35 . 2008-05-14 21:05 593,920 ——— C:\WINDOWS\system32\ati2sgag.exe
2008-07-29 00:35 . 2008-05-20 19:53 93,696 -ra—— C:\WINDOWS\system32\drivers\AtiHdmi.sys
2008-07-29 00:34 . 2008-07-31 00:13 d–h—– C:\Program Files\InstallShield Installation Information
2008-07-29 00:34 . 2008-07-29 00:41 d——– C:\Program Files\ATI Technologies
2008-07-29 00:34 . 2008-05-14 21:37 3,107,788 -ra—— C:\WINDOWS\system32\ativvaxx.dat
2008-07-29 00:34 . 2008-05-14 21:37 3,107,788 -ra—— C:\WINDOWS\system32\ativva5x.dat
2008-07-29 00:34 . 2008-05-14 21:37 887,724 -ra—— C:\WINDOWS\system32\ativva6x.dat
2008-07-29 00:34 . 2008-05-14 22:12 413,696 -ra—— C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-29 00:34 . 2008-05-14 21:57 307,200 -ra—— C:\WINDOWS\system32\atiiiexx.dll
2008-07-29 00:34 . 2008-04-28 17:09 172,033 -ra—— C:\WINDOWS\system32\atiicdxx.dat
2008-07-29 00:34 . 2008-05-06 13:41 12,787 -ra—— C:\WINDOWS\atiogl.xml
2008-07-29 00:34 . 2007-08-31 09:20 7,167 -ra—— C:\WINDOWS\system32\atifglpf.xml
2008-07-29 00:33 . 2008-07-29 00:35 d——– C:\Program Files\Common Files\InstallShield
2008-07-29 00:31 . 2008-07-29 00:31 d—s—- C:\WINDOWS\system32\Microsoft
2008-07-29 00:28 . 2008-07-29 01:21 316,640 –a—— C:\WINDOWS\WMSysPr9.prx
2008-07-29 00:28 . 2004-08-04 00:56 96,768 —–c— C:\WINDOWS\system32\dllcache\dpcdll.dll
2008-07-29 00:26 . 2004-08-04 00:56 2,897,920 ——— C:\WINDOWS\system32\xpsp2res.dll
2008-07-29 00:25 . 2004-11-18 10:42 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-07-29 00:25 . 2004-07-17 11:40 19,528 –a—— C:\WINDOWS\002253_.tmp
2008-07-29 00:24 . 2008-07-29 00:24 d——– C:\WINDOWS\EHome
2008-07-29 00:20 . 2008-07-29 00:20 d——– C:\c3b6e45e03ee90ea6f7f45ac
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-29 05:02 86,016 —-a-w C:\WINDOWS\system32\OpenAL32.dll
2008-07-29 05:02 409,600 —-a-w C:\WINDOWS\system32\wrap_oal.dll
2008-07-29 03:31 ——— d—–w C:\Program Files\microsoft frontpage
2008-07-26 05:00 ——— d—–w C:\Program Files\THQ
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"ATICustomerCare"="C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" [2007-10-04 18:38 307200]
"razer"="C:\Program Files\Razer\Copperhead\razerhid.exe" [2005-10-08 16:27 155648]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 00:56 158208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-06-19 13:51 50528 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2008-07-29 01:36 1271032 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
–a—— 2008-06-19 15:15 3664944 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-07-09 17:33 36352 C:\Program Files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 22:31]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-05-20 19:53]
R3 cmudaxp;Razer Barracuda AC-1 Gaming Interface;C:\WINDOWS\system32\drivers\cmudaxp.sys [2006-12-07 11:23]
R3 Razerlow;Razer Copperhead Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-08-12 10:11]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae3cc804-5cfa-11dd-b447-806d6172696f}]
\Shell\AutoRun\command - E:\ASUSACPI.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-lphcg0mj0eecl - C:\WINDOWS\system32\lphcg0mj0eecl.exe
MSConfigStartUp-Cmaudio8788 - cmicnfgp.cpl
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\k8r7mxyn.default\
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-18 18:10:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-18 18:11:25
ComboFix-quarantined-files.txt 2008-08-18 22:11:21
Pre-Run: 94,031,294,464 bytes free
Post-Run: 94,019,883,008 bytes free
220
Last night I was browsing (firefox) and something poped up and installed a malware, my Antivir detected it and i hit access deny, however it messed with my system and left something as wallpaper
I was cautious not to log into anything important and tried to log into some NFL thing online, and antivir poped up again with same file
Virus or unwanted program 'VBS/Agent.1002 [virus]'
detected in file 'C:\Documents and Settings\Mike\Local Settings\Temp\.tt1.tmp.vbs.
Action performed: Move file to quarantine
I moved it to quarantine, and deleted everything in temp folder
later i searched the tt1.tmp and found following topic which looks like exact same:
http://forums.whatthetech.com/Unable_to_ru…his_t94050.html
I followed same instructions and here are the log files for Malwarebytes' anti-malware and combofix::
Malwarebytes' Anti-Malware 1.25
Database version: 1066
Windows 5.1.2600 Service Pack 2
5:58:40 PM 8/18/2008
mbam-log-08-18-2008 (17-58-40).txt
Scan type: Quick Scan
Objects scanned: 40932
Time elapsed: 2 minute(s), 57 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\blphcg0mj0eecl.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lphcg0mj0eecl.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\phcg0mj0eecl.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
———————————————————–>>>>>
ComboFix 08-08-18.01 - Mike 2008-08-18 18:08:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1683 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\#SharedObjects\6V8VSSWS\interclick.com
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\#SharedObjects\6V8VSSWS\interclick.com\ud.sol
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Mike\UserData
C:\Documents and Settings\Mike\UserData\index.dat
C:\Documents and Settings\Mike\UserData\K9EJS9UN\IsOnIE6tbPromo[1].xml
.
((((((((((((((((((((((((( Files Created from 2008-07-18 to 2008-08-18 )))))))))))))))))))))))))))))))
.
2008-08-18 18:03 . 2008-08-18 18:03 d——– C:\Program Files\Trend Micro
2008-08-18 17:52 . 2008-08-18 17:52 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-18 17:52 . 2008-08-18 17:52 d——– C:\Documents and Settings\Mike\Application Data\Malwarebytes
2008-08-18 17:52 . 2008-08-18 17:52 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-18 17:52 . 2008-08-17 15:01 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-18 17:52 . 2008-08-17 15:01 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-18 00:09 . 2008-08-18 00:09 d——– C:\Program Files\Lavasoft
2008-08-18 00:07 . 2008-08-18 00:08 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-15 20:44 . 2008-08-15 20:44 38 –a—— C:\WINDOWS\avisplitter.INI
2008-08-07 18:55 . 2008-08-07 18:55 d——– C:\WINDOWS\Sun
2008-08-07 09:52 . 2003-09-18 14:32 1,060,864 –a—— C:\WINDOWS\system32\MFC71.dll
2008-08-07 09:52 . 1998-10-29 16:45 306,688 –a—— C:\WINDOWS\IsUninst.exe
2008-08-07 09:52 . 2008-08-07 09:52 0 –a—— C:\WINDOWS\OpPrintServer.INI
2008-08-07 09:49 . 2008-08-07 09:49 d——– C:\WINDOWS\StartHtmico
2008-08-07 09:49 . 2008-08-07 09:49 d——– C:\WINDOWS\IP4000,3000
2008-08-07 09:49 . 2008-08-07 09:49 d–h—– C:\BJPrinter
2008-08-07 09:49 . 2004-06-15 01:00 116,736 –a—— C:\WINDOWS\system32\CNMLM61.DLL
2008-08-07 09:49 . 2004-06-04 11:34 86,016 -ra—— C:\WINDOWS\system32\CNMCP61.exe
2008-08-07 09:49 . 2004-06-15 01:00 7,680 –a—— C:\WINDOWS\system32\CNMVS61.DLL
2008-08-07 09:48 . 2008-08-07 09:52 d——– C:\Program Files\Canon
2008-08-06 21:31 . 2008-08-06 21:31 d——– C:\Documents and Settings\Mike\Application Data\acccore
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Program Files\Viewpoint
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Program Files\Common Files\AOL
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-06 21:30 . 2008-08-06 21:31 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Documents and Settings\All Users\Application Data\AOL
2008-08-06 21:30 . 2008-08-06 21:30 d——– C:\Documents and Settings\All Users\Application Data\acccore
2008-08-06 21:29 . 2008-08-06 21:30 d——– C:\Program Files\AIM6
2008-08-06 21:29 . 2008-08-06 21:30 409 –ah—– C:\IPH.PH
2008-08-06 16:39 . 2008-08-06 16:39 d——– C:\Program Files\Common Files\Adobe AIR
2008-08-06 16:38 . 2008-08-06 16:38 d——– C:\Program Files\Common Files\Adobe
2008-08-05 10:27 . 2008-08-05 10:27 d——– C:\Documents and Settings\Mike\Application Data\DivX
2008-08-04 11:17 . 2008-08-04 11:17 d——– C:\Program Files\Jasc Software Inc
2008-08-03 00:15 . 2007-12-11 18:34 120,056 ——— C:\WINDOWS\system32\pxcpyi64.exe
2008-08-03 00:15 . 2007-12-11 18:34 118,520 ——— C:\WINDOWS\system32\pxinsi64.exe
2008-08-03 00:14 . 2008-08-03 00:15 d——– C:\Program Files\DivX
2008-08-03 00:12 . 2008-08-03 00:12 d——– C:\Program Files\Java
2008-08-03 00:12 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-08-03 00:11 . 2008-08-03 00:11 d——– C:\Program Files\Common Files\Java
2008-08-01 12:14 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-08-01 12:14 . 2004-08-03 23:01 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2008-07-31 00:26 . 2004-08-03 23:08 26,496 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-31 00:13 . 2008-07-31 00:13 d——– C:\Program Files\SanDisk
2008-07-31 00:13 . 2008-07-31 00:13 d——– C:\Program Files\Common Files\ArcSoft
2008-07-31 00:13 . 2008-07-31 00:13 d——– C:\Documents and Settings\Mike\Application Data\ArcSoft
2008-07-31 00:13 . 2004-05-04 11:53 1,645,320 –a—— C:\WINDOWS\system32\gdiplus.dll
2008-07-31 00:13 . 2003-03-18 22:14 499,712 -ra—— C:\WINDOWS\system32\msvcp71.dll
2008-07-31 00:13 . 2005-06-21 10:29 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2008-07-30 20:22 . 2008-07-30 20:22 d——– C:\WINDOWS\system32\LogFiles
2008-07-30 20:22 . 2008-08-17 19:08 136,888 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-30 20:22 . 2008-08-17 19:07 111,928 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2008-07-30 20:22 . 2008-07-30 20:22 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2008-07-30 15:02 . 2008-07-30 15:02 d——– C:\Program Files\Ventrilo
2008-07-30 15:02 . 2008-08-18 00:09 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-07-30 15:02 . 2008-07-30 15:02 d——– C:\Documents and Settings\Mike\Application Data\Ventrilo
2008-07-30 14:09 . 2008-07-30 14:09 d——– C:\Program Files\Veoh Networks
2008-07-30 14:08 . 2008-07-30 14:08 d——– C:\WINDOWS\Downloaded Installations
2008-07-30 00:56 . 2008-07-30 00:56 d——– C:\Documents and Settings\Mike\Application Data\Media Player Classic
2008-07-30 00:45 . 2008-07-30 00:45 d——– C:\Program Files\K-Lite Codec Pack
2008-07-29 21:58 . 2008-07-29 21:59 d——– C:\Program Files\RivaTuner v2.09
2008-07-29 21:16 . 2008-07-29 21:16 d——– C:\Logs
2008-07-29 19:34 . 2008-07-30 14:19 d——– C:\World of Warcraft
2008-07-29 19:34 . 2008-07-29 19:34 d——– C:\Program Files\Common Files\Blizzard Entertainment
2008-07-29 01:40 . 2003-06-18 17:31 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2008-07-29 01:40 . 2008-07-29 01:40 376 –a—— C:\WINDOWS\ODBC.INI
2008-07-29 01:39 . 2008-07-29 01:39 d——– C:\WINDOWS\SHELLNEW
2008-07-29 01:39 . 2008-07-29 01:39 d——– C:\Program Files\Microsoft.NET
2008-07-29 01:39 . 2008-07-29 01:39 d——– C:\Program Files\Microsoft ActiveSync
2008-07-29 01:35 . 2008-08-17 19:07 d——– C:\Program Files\Steam
2008-07-29 01:21 . 2008-07-29 01:22 d——– C:\Program Files\Winamp
2008-07-29 01:21 . 2008-07-29 22:42 d——– C:\Documents and Settings\Mike\Application Data\Winamp
2008-07-29 01:17 . 2008-07-29 01:17 d——– C:\Program Files\Avira
2008-07-29 01:17 . 2008-07-29 01:17 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-07-29 01:09 . 2008-07-29 01:09 0 –a—— C:\WINDOWS\nsreg.dat
2008-07-29 01:08 . 2008-08-18 18:05 d——– C:\downloads
2008-07-29 01:05 . 2008-07-29 01:05 d——– C:\Program Files\Razer
2008-07-29 01:05 . 2001-01-04 10:12 162,900 ——— C:\WINDOWS\system32\drivers\USBICP.sys
2008-07-29 01:05 . 2005-07-22 15:01 69,632 –a—— C:\WINDOWS\system32\razer.cpl
2008-07-29 01:05 . 2005-08-12 10:11 19,020 –a—— C:\WINDOWS\system32\drivers\Razerlow.sys
2008-07-29 01:03 . 2008-07-29 01:05 810 –a—— C:\WINDOWS\system\Cmicnfgp.ini
2008-07-29 01:02 . 2008-07-29 01:02 d——– C:\Program Files\Razer Barracuda AC-1 Gaming Audio Card
2008-07-29 01:02 . 2008-07-29 01:02 d——– C:\Program Files\OpenAL
2008-07-29 00:57 . 2008-07-29 00:57 d——– C:\Program Files\ATI
2008-07-29 00:51 . 2008-07-29 00:51 d——– C:\Documents and Settings\Mike\Application Data\ATI
2008-07-29 00:51 . 2008-07-29 00:51 d——– C:\Documents and Settings\All Users\Application Data\ATI
2008-07-29 00:50 . 2008-07-29 00:50 0 –a—— C:\WINDOWS\ativpsrm.bin
2008-07-29 00:49 . 2005-01-17 01:43 295,424 -ra—— C:\WINDOWS\system32\idecoi.dll
2008-07-29 00:49 . 2004-12-16 04:32 176,128 -ra—— C:\WINDOWS\system32\nvusmb.exe
2008-07-29 00:49 . 2004-12-16 16:32 176,128 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2008-07-29 00:49 . 2004-12-16 04:32 176,128 -ra—— C:\WINDOWS\system32\nvuide.exe
2008-07-29 00:49 . 2005-01-17 01:43 88,576 -ra—— C:\WINDOWS\system32\drivers\nvatabus.sys
2008-07-29 00:49 . 2004-11-30 14:30 3,507 -ra—— C:\WINDOWS\system32\nvide.nvu
2008-07-29 00:49 . 2004-11-09 22:35 1,231 -ra—— C:\WINDOWS\system32\nvsmb.nvu
2008-07-29 00:48 . 2004-12-28 23:25 810,056 -ra—— C:\WINDOWS\system32\SATA.bmp
2008-07-29 00:48 . 2008-07-31 00:16 6,125 –a—— C:\WINDOWS\Ascd_tmp.ini
2008-07-29 00:48 . 2000-03-29 10:17 5,824 –a—— C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-07-29 00:48 . 2004-08-12 22:56 5,810 -ra—— C:\WINDOWS\system32\drivers\ASACPI.sys
2008-07-29 00:48 . 2004-12-29 03:47 264 -ra—— C:\WINDOWS\system32\raidmgmt.ini
2008-07-29 00:38 . 2008-07-29 00:38 d——– C:\Program Files\Common Files\ATI Technologies
2008-07-29 00:35 . 2008-05-14 21:05 593,920 ——— C:\WINDOWS\system32\ati2sgag.exe
2008-07-29 00:35 . 2008-05-20 19:53 93,696 -ra—— C:\WINDOWS\system32\drivers\AtiHdmi.sys
2008-07-29 00:34 . 2008-07-31 00:13 d–h—– C:\Program Files\InstallShield Installation Information
2008-07-29 00:34 . 2008-07-29 00:41 d——– C:\Program Files\ATI Technologies
2008-07-29 00:34 . 2008-05-14 21:37 3,107,788 -ra—— C:\WINDOWS\system32\ativvaxx.dat
2008-07-29 00:34 . 2008-05-14 21:37 3,107,788 -ra—— C:\WINDOWS\system32\ativva5x.dat
2008-07-29 00:34 . 2008-05-14 21:37 887,724 -ra—— C:\WINDOWS\system32\ativva6x.dat
2008-07-29 00:34 . 2008-05-14 22:12 413,696 -ra—— C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-29 00:34 . 2008-05-14 21:57 307,200 -ra—— C:\WINDOWS\system32\atiiiexx.dll
2008-07-29 00:34 . 2008-04-28 17:09 172,033 -ra—— C:\WINDOWS\system32\atiicdxx.dat
2008-07-29 00:34 . 2008-05-06 13:41 12,787 -ra—— C:\WINDOWS\atiogl.xml
2008-07-29 00:34 . 2007-08-31 09:20 7,167 -ra—— C:\WINDOWS\system32\atifglpf.xml
2008-07-29 00:33 . 2008-07-29 00:35 d——– C:\Program Files\Common Files\InstallShield
2008-07-29 00:31 . 2008-07-29 00:31 d—s—- C:\WINDOWS\system32\Microsoft
2008-07-29 00:28 . 2008-07-29 01:21 316,640 –a—— C:\WINDOWS\WMSysPr9.prx
2008-07-29 00:28 . 2004-08-04 00:56 96,768 —–c— C:\WINDOWS\system32\dllcache\dpcdll.dll
2008-07-29 00:26 . 2004-08-04 00:56 2,897,920 ——— C:\WINDOWS\system32\xpsp2res.dll
2008-07-29 00:25 . 2004-11-18 10:42 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-07-29 00:25 . 2004-07-17 11:40 19,528 –a—— C:\WINDOWS\002253_.tmp
2008-07-29 00:24 . 2008-07-29 00:24 d——– C:\WINDOWS\EHome
2008-07-29 00:20 . 2008-07-29 00:20 d——– C:\c3b6e45e03ee90ea6f7f45ac
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-29 05:02 86,016 —-a-w C:\WINDOWS\system32\OpenAL32.dll
2008-07-29 05:02 409,600 —-a-w C:\WINDOWS\system32\wrap_oal.dll
2008-07-29 03:31 ——— d—–w C:\Program Files\microsoft frontpage
2008-07-26 05:00 ——— d—–w C:\Program Files\THQ
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"ATICustomerCare"="C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" [2007-10-04 18:38 307200]
"razer"="C:\Program Files\Razer\Copperhead\razerhid.exe" [2005-10-08 16:27 155648]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 00:56 158208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-06-19 13:51 50528 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2008-07-29 01:36 1271032 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
–a—— 2008-06-19 15:15 3664944 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2008-07-09 17:33 36352 C:\Program Files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 22:31]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-05-20 19:53]
R3 cmudaxp;Razer Barracuda AC-1 Gaming Interface;C:\WINDOWS\system32\drivers\cmudaxp.sys [2006-12-07 11:23]
R3 Razerlow;Razer Copperhead Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-08-12 10:11]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae3cc804-5cfa-11dd-b447-806d6172696f}]
\Shell\AutoRun\command - E:\ASUSACPI.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-lphcg0mj0eecl - C:\WINDOWS\system32\lphcg0mj0eecl.exe
MSConfigStartUp-Cmaudio8788 - cmicnfgp.cpl
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\k8r7mxyn.default\
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-18 18:10:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-18 18:11:25
ComboFix-quarantined-files.txt 2008-08-18 22:11:21
Pre-Run: 94,031,294,464 bytes free
Post-Run: 94,019,883,008 bytes free
220