| oh no... is it bad?? anyway this is the latest combofix:
ComboFix 09-02-06.04 - Administrator 2009-02-08 14:09:44.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1584 [GMT 8:00] Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt AV: AVG 7.5.552 *On-access scanning enabled* (Updated) * Created a new restore point
FILE :: c:\windows\system32\XDva195.sys c:\windows\system32\XDva204.sys c:\windows\system32\XDva208.sys .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
c:\windows\system\svhost.exe c:\windows\system32\drivers\sysdrv32.sys c:\windows\temp c:\windows\temp\77.exe H:\Autorun.inf
. ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) .
-------\Legacy_SYSDRV32 -------\Legacy_XDVA195 -------\Legacy_XDVA204 -------\Legacy_XDVA208 -------\Service_sysdrv32 -------\Service_XDva195 -------\Service_XDva204 -------\Service_XDva208
((((((((((((((((((((((((( Files Created from 2009-01-08 to 2009-02-08 ))))))))))))))))))))))))))))))) .
2009-02-08 13:47 . 2009-02-08 13:47 26,624 --a------ c:\windows\system32\56.scr 2009-02-08 12:38 . 2009-02-08 12:38 26,624 --a------ c:\windows\system32\10.scr 2009-02-07 00:03 . 2009-02-07 00:04 <DIR> d-------- c:\program files\view point killer 2009-02-07 00:01 . 2009-02-07 00:04 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-07 00:01 . 2009-02-07 00:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-07 00:01 . 2009-02-07 00:01 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes 2009-02-07 00:01 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-07 00:01 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-06 23:44 . 2009-02-06 23:44 <DIR> d-------- c:\program files\CCleaner 2009-02-02 14:45 . 2009-02-02 14:45 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Media Player Classic 2009-02-02 14:44 . 2009-02-02 14:44 <DIR> d-------- c:\program files\K-Lite Codec Pack 2009-02-02 14:44 . 2008-11-07 00:37 3,596,288 --a------ c:\windows\system32\qt-dx331.dll 2009-02-02 14:44 . 2008-09-25 02:41 839,680 --a------ c:\windows\system32\lameACM.acm 2009-02-02 14:44 . 2008-12-08 02:08 795,648 --a------ c:\windows\system32\xvidcore.dll 2009-02-02 14:44 . 2008-11-07 00:33 684,032 --a------ c:\windows\system32\divx.dll 2009-02-02 14:44 . 2004-01-26 00:18 217,088 --a------ c:\windows\system32\yv12vfw.dll 2009-02-02 14:44 . 2008-09-17 03:23 168,448 --a------ c:\windows\system32\unrar.dll 2009-02-02 14:44 . 2008-12-08 02:08 130,048 --a------ c:\windows\system32\xvidvfw.dll 2009-02-02 14:44 . 2007-09-21 08:52 118,784 --a------ c:\windows\system32\ac3acm.acm 2009-02-02 14:44 . 2008-12-11 08:33 86,016 --a------ c:\windows\system32\dpl100.dll 2009-02-02 14:44 . 2008-12-08 19:53 57,344 --a------ c:\windows\system32\ff_vfw.dll 2009-02-02 14:44 . 2007-07-11 00:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest 2009-02-02 14:44 . 2008-10-03 20:30 414 --a------ c:\windows\system32\lame_acm.xml 2009-01-29 09:34 . 2009-01-29 09:34 268 --ah----- C:\sqmdata13.sqm 2009-01-29 09:34 . 2009-01-29 09:34 244 --ah----- C:\sqmnoopt13.sqm 2009-01-21 16:05 . 2009-01-21 16:05 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Oberonv1001 2009-01-21 12:45 . 2009-02-07 16:41 <DIR> dr-h----- C:\$VAULT$.AVG 2009-01-14 23:26 . 2009-01-15 00:26 <DIR> d-------- c:\documents and settings\Administrator\Application Data\ForgottenRiddles2 2009-01-14 19:56 . 2009-01-14 19:56 410,984 --a------ c:\windows\system32\deploytk.dll 2009-01-11 23:22 . 2009-01-11 23:22 268 --ah----- C:\sqmdata12.sqm 2009-01-11 23:22 . 2009-01-11 23:22 244 --ah----- C:\sqmnoopt12.sqm 2009-01-11 19:29 . 2009-01-11 19:29 268 --ah----- C:\sqmdata11.sqm 2009-01-11 19:29 . 2009-01-11 19:29 244 --ah----- C:\sqmnoopt11.sqm 2009-01-11 18:28 . 2009-01-11 18:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Gogii 2009-01-11 18:27 . 2009-01-21 16:04 <DIR> d-------- c:\program files\Oberon Media 2009-01-11 15:32 . 2009-01-11 15:32 268 --ah----- C:\sqmdata10.sqm 2009-01-11 15:32 . 2009-01-11 15:32 244 --ah----- C:\sqmnoopt10.sqm 2009-01-10 11:51 . 2009-01-10 11:51 268 --ah----- C:\sqmdata09.sqm 2009-01-10 11:51 . 2009-01-10 11:51 244 --ah----- C:\sqmnoopt09.sqm 2009-01-10 11:08 . 2009-01-10 11:08 <DIR> d-------- C:\users 2009-01-09 21:25 . 2009-01-09 21:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Trymedia 2009-01-08 17:01 . 2009-01-08 17:01 268 --ah----- C:\sqmdata08.sqm 2009-01-08 17:01 . 2009-01-08 17:01 244 --ah----- C:\sqmnoopt08.sqm
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-08 01:56 --------- d-----w c:\documents and settings\Administrator\Application Data\AVG7 2009-02-05 06:49 --------- d-----w c:\program files\Diablo II 2009-02-02 08:49 --------- d-----w c:\program files\StepMania 2009-01-21 08:35 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2009-01-19 04:58 --------- d-----w c:\program files\Common Files\Adobe 2009-01-16 00:53 --------- d--h--w c:\program files\InstallShield Installation Information 2009-01-16 00:48 --------- d-----w c:\documents and settings\Administrator\Application Data\Samsung 2009-01-14 11:56 --------- d-----w c:\program files\Java 2009-01-11 12:50 --------- d-----w c:\program files\Microsoft Silverlight 2008-12-28 11:35 --------- d-----w c:\program files\iTunes 2008-12-28 11:35 --------- d-----w c:\program files\iPod 2008-12-28 11:35 --------- d-----w c:\program files\Common Files\Apple 2008-12-28 11:35 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-12-28 11:34 --------- d-----w c:\program files\QuickTime 2008-12-26 02:54 --------- d-----w c:\program files\Ubisoft 2008-12-24 10:12 107,888 ----a-w c:\windows\system32\CmdLineExt.dll 2008-12-24 09:51 --------- d-----w c:\program files\CAPCOM 2006-05-12 15:19 60,518 ----a-w c:\program files\mozilla firefox\components\jar50.dll 2006-05-12 15:19 49,248 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll 2006-05-12 15:19 165,992 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll .
------- Sigcheck -------
2006-05-20 22:23 360448 9c515b8621d34478dfaa89b6b5434a54 c:\windows\system32\drivers\tcpip.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-02-04 62464] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-05-20 15360] "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-05-06 6656] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-05-20 208952] "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-05-20 59392] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-05-20 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-05-20 455168] "AVG7_CC"="c:\progra~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-10-17 590848] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-05-18 180269] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-14 136600] "mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-05-20 15360] "TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-02-04 62464] "AVG7_Run"="c:\progra~1\Grisoft\AVGFRE~1\avgw.exe" [2008-01-21 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "SynchronousMachineGroupPolicy"= 0 (0x0) "SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WindowsTelephony] @="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"= "c:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"= "c:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"= "c:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\WINDOWS\\System32\\10.scr"= "c:\\WINDOWS\\System32\\56.scr"=
S2 WindowsTelephony;Windows Telephony;"c:\windows\system\svhost.exe" --> c:\windows\system\svhost.exe [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe . Contents of the 'Scheduled Tasks' folder
2009-02-03 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com.sg/ uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 .
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-02-08 14:12:40 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . --------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(540) c:\windows\system32\Ati2evxx.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ati2evxx.exe c:\windows\system32\spool\drivers\w32x86\3\HP1006MC.EXE c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\progra~1\Grisoft\AVGFRE~1\avgamsvr.exe c:\progra~1\Grisoft\AVGFRE~1\avgupsvc.exe c:\progra~1\Grisoft\AVGFRE~1\avgemc.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Maxtor\Sync\SyncServices.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-02-08 14:14:05 - machine was rebooted ComboFix-quarantined-files.txt 2009-02-08 06:14:03 ComboFix2.txt 2009-02-07 06:33:49
Pre-Run: 86,359,105,536 bytes free Post-Run: 86,295,150,592 bytes free
210
|