Logfile: log.txtComboFix 08-03-08.2 - avishayb 2008-03-09 16:06:35.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1255.972.1033.18.2384 [GMT 2:00]
Running from: C:\Documents and Settings\avishayb\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\avishayb\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\WINDOWS\
003349_.tmp
C:\WINDOWS\asycfilt32.dll
C:\WINDOWS\didduid.ini
C:\WINDOWS\eSellerateEngine.dll
C:\WINDOWS\pss\findfast.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\system32\spoolvs.exe
C:\WINDOWS\system32\winav.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\180search assistant
C:\Program Files\180search assistant\180sa.exe
C:\Program Files\180search assistant\sau.exe
C:\Program Files\180searchassistant
C:\Program Files\180searchassistant\saap.exe
C:\Program Files\180searchassistant\sac.exe
C:\Program Files\180solutions
C:\Program Files\180solutions\sais.exe
C:\Program Files\seekmo
C:\Program Files\seekmo\seekmohook.dll
C:\Program Files\Sysmnt
C:\Program Files\Sysmnt\Ssmgr.exe
C:\Program Files\zango
C:\Program Files\zango\zango.exe
C:\WINDOWS\
003349_.tmp
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\asycfilt32.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\default.htm
C:\WINDOWS\didduid.ini
C:\WINDOWS\eSellerateEngine.dll
C:\WINDOWS\FLEOK
C:\WINDOWS\FLEOK\180ax.exe
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\wer8274.dll
C:\Windows\Temp\salm.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.
2008-03-09 16:05 . 2008-03-09 16:05 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\Malwarebytes
2008-03-09 16:04 . 2008-03-09 16:04 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-09 16:04 . 2008-03-09 16:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-09 15:23 . 2008-03-09 15:23 11,776 --a------ C:\WINDOWS\123messenger.per
2008-03-09 15:21 . 2008-03-09 15:21 <DIR> d-------- C:\Program Files\stc
2008-03-09 14:48 . 2008-03-09 14:48 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\Grisoft
2008-03-09 14:47 . 2008-03-09 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-09 14:47 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-09 14:43 . 2008-03-09 14:43 <DIR> d-------- C:\_OTMoveIt
2008-03-09 12:18 . 2008-03-09 12:19 312 --a------ C:\WINDOWS\wininit.ini
2008-03-09 11:42 . 2008-03-09 11:42 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-09 11:42 . 2008-03-09 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-09 11:38 . 2008-03-09 11:38 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Pandion
2008-03-09 10:22 . 2008-03-09 10:34 <DIR> d-------- C:\Program Files\Total Commander
2008-03-09 09:34 . 2008-03-09 09:34 <DIR> d-------- C:\Program Files\IE Extensions
2008-03-04 10:14 . 2008-03-04 10:14 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\Thinstall
2008-03-03 17:05 . 2008-03-03 17:05 <DIR> d-------- C:\Program Files\Pandion
2008-03-03 17:05 . 2008-03-03 17:56 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\Pandion
2008-03-03 14:54 . 2008-03-03 14:58 <DIR> d-------- C:\Program Files\ARS Server
2008-03-02 10:03 . 2008-03-02 10:03 <DIR> d-------- C:\Program Files\Salling Software AB
2008-03-02 10:03 . 2008-03-02 10:03 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-02 10:03 . 2008-03-02 10:03 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\Salling Software AB
2008-03-02 10:03 . 2008-03-02 10:03 385 --a------ C:\WINDOWS\{2158ED55-19D1-4C0C-B213-5EFF748248AC}_WiseFW.ini
2008-02-21 12:12 . 2008-02-21 12:59 <DIR> d-------- C:\Program Files\DJ Jukebox
2008-02-21 12:11 . 2008-02-21 12:13 <DIR> d-------- C:\Program Files\Common Files\System-G
2008-02-18 12:12 . 2008-02-18 12:12 <DIR> d-------- C:\Program Files\DFX
2008-02-18 12:12 . 2008-02-18 12:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DFX
2008-02-18 12:10 . 2008-02-18 12:14 <DIR> d-------- C:\Program Files\Winamp
2008-02-18 12:10 . 2008-02-18 12:14 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\Winamp
2008-02-18 11:55 . 2008-02-18 12:14 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\Quintessential Player
2008-02-14 15:24 . 2007-12-01 00:25 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-02-14 15:23 . 2008-02-14 15:23 <DIR> d-------- C:\WINDOWS\system32\en
2008-02-14 15:23 . 2008-02-14 15:23 <DIR> d-------- C:\WINDOWS\system32\bits
2008-02-14 15:23 . 2008-02-14 15:23 <DIR> d-------- C:\WINDOWS\l2schemas
2008-02-14 15:23 . 2007-12-01 00:26 32,866 --------- C:\WINDOWS\slrundll.exe
2008-02-14 15:18 . 2008-02-14 15:24 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-02-14 14:25 . 2006-02-20 20:25 17,536 --a------ C:\WINDOWS\system32\drivers\grmn0200.sys
2008-02-14 14:25 . 2003-09-23 16:42 17,024 --a------ C:\WINDOWS\system32\drivers\grmngen.sys
2008-02-14 14:25 . 2006-04-11 21:51 16,512 --a------ C:\WINDOWS\system32\drivers\grmn0400.sys
2008-02-14 14:25 . 2006-07-11 21:50 11,776 --a------ C:\WINDOWS\system32\drivers\grmn1200.sys
2008-02-14 14:25 . 2003-09-23 16:42 7,296 --a------ C:\WINDOWS\system32\drivers\grmnusb.sys
2008-02-14 11:37 . 2008-02-14 14:24 <DIR> d-------- C:\Garmin
2008-02-14 11:15 . 2008-03-04 18:14 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-14 11:09 . 2008-02-14 11:09 <DIR> d-------- C:\Program Files\Mobiola Remote Control
2008-02-14 11:09 . 2007-09-18 12:25 114,688 --a------ C:\WINDOWS\system32\BTCamVideoSource.dll
2008-02-13 17:50 . 2008-02-13 17:50 <DIR> d-------- C:\Program Files\NiiMe
2008-02-13 17:49 . 2008-02-13 17:49 <DIR> d-------- C:\Program Files\NiiMeWheel
2008-02-12 11:53 . 2008-02-18 10:43 1,893 --a------ C:\WINDOWS\mozver.dat
2008-02-12 11:46 . 2008-02-12 11:46 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\Talkback
2008-02-12 11:46 . 2008-02-12 11:46 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-11 12:08 . 2008-02-11 12:08 <DIR> d-------- C:\Documents and Settings\avishayb\Application Data\CheckPoint
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 14:06 12,204,682 ----a-w C:\WINDOWS\Internet Logs\tvDebug.Zip
2008-03-09 13:19 --------- d-----w C:\Program Files\Altiris
2008-03-09 12:21 --------- d-----w C:\Program Files\Trend Micro
2008-03-09 11:38 833,824 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-09 11:38 75,536 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-09 11:38 226,016 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-09 11:38 19,599,136 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-09 10:20 --------- d-----w C:\Program Files\pdf995
2008-03-09 09:21 --------- d-----w C:\Program Files\FlashGet
2008-03-05 12:15 3,582,464 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-03-05 12:14 2,499,072 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2008-03-04 14:16 --------- d-----w C:\Program Files\ICQ6
2008-03-03 15:41 --------- d-----w C:\Documents and Settings\avishayb\Application Data\SQLyog
2008-02-25 09:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-14 21:00 55,808 ----a-w C:\WINDOWS\system32\DevCon.exe
2008-02-14 21:00 3,072 ----a-w C:\WINDOWS\system32\Mswtif.dll
2008-02-14 21:00 24,576 ----a-w C:\WINDOWS\NOCLOSE.PIF
2008-02-14 09:10 2,758,656 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-02-11 10:07 --------- d-----w C:\Program Files\CheckPoint
2008-02-07 15:05 --------- d-----w C:\Documents and Settings\avishayb\Application Data\GUIB
2008-02-07 13:45 --------- d-----w C:\Documents and Settings\avishayb\Application Data\Wing IDE 3
2008-02-07 13:05 --------- d-----w C:\Program Files\Wing IDE 3.0
2008-02-07 08:30 --------- d-----w C:\Program Files\Common Files\Symbian
2008-02-07 08:04 --------- d-----w C:\Program Files\CSL Arm Toolchain
2008-02-07 08:04 --------- d-----w C:\Program Files\Common Files\SDK Descriptors
2008-02-06 12:11 --------- d-----w C:\Program Files\CLEAREVO.com
2008-02-05 15:17 22,016 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-02-05 15:17 2,216,448 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-02-05 15:14 80,384 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-02-05 13:16 --------- d-----w C:\Program Files\Microsoft Virtual PC
2008-02-05 12:45 2,087,424 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-02-05 07:52 51,716 ----a-w C:\WINDOWS\system32\pdf995mon.dll
2008-02-05 07:52 249,856 ----a-w C:\WINDOWS\system32\pdfmona.dll
2008-02-05 07:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-02-05 07:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-05 07:28 --------- d-----w C:\Program Files\Microsoft Works
2008-02-05 07:20 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-02-05 07:20 --------- d-----w C:\Documents and Settings\avishayb\Application Data\DAEMON Tools
2008-02-05 07:15 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-02-04 10:17 --------- d-----w C:\Documents and Settings\avishayb\Application Data\PC Suite
2008-02-03 09:06 0 ----a-w C:\Documents and Settings\granit\ISXAudit.DAT
2008-01-30 08:30 2,237,952 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-01-30 07:58 --------- d-----w C:\Program Files\Imprivata
2008-01-28 14:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-28 14:19 --------- d-----w C:\Program Files\FLV Player
2008-01-28 14:18 --------- d-----w C:\Program Files\Yahoo!
2008-01-27 14:34 --------- d-----w C:\Program Files\Smallvideosoft
2008-01-27 08:22 --------- d-----w C:\Documents and Settings\avishayb\Application Data\NuSphere
2008-01-27 08:19 --------- d-----w C:\Program Files\MySQL
2008-01-27 08:18 --------- d-----w C:\Program Files\nusphere
2008-01-27 08:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\NuSphere
2008-01-27 08:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-01-27 08:13 --------- d-----w C:\Program Files\EasyPHP 2.0b1
2008-01-24 18:36 --------- d-----w C:\Program Files\SQLyog Community
2008-01-23 00:46 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-01-22 09:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-01-21 16:01 --------- d-----w C:\Program Files\ExamDiff
2008-01-20 08:16 --------- d-----w C:\Documents and Settings\avishayb\Application Data\skypePM
2008-01-17 16:23 2,516 ----a-w C:\WINDOWS\system32\drivers\sdboot.bin
2008-01-17 16:23 2,235,408 ----a-w C:\WINDOWS\system32\drivers\fw.sys
2008-01-17 16:22 106,592 ----a-w C:\WINDOWS\system32\fwnetcfg.dll
2008-01-15 08:00 --------- d-----w C:\Documents and Settings\avishayb\Application Data\Nokia
2008-01-14 13:26 --------- d-----w C:\Documents and Settings\avishayb\Application Data\Nokia Multimedia Player
2008-01-14 11:01 --------- d-----w C:\Documents and Settings\avishayb\Application Data\ICQ
2008-01-14 08:47 --------- d-----w C:\Program Files\Symbian OS Tools
2008-01-14 08:47 --------- d-----w C:\Documents and Settings\avishayb\Application Data\InstallShield
2008-01-13 08:44 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-10 16:44 --------- d-----w C:\Program Files\Nokia
2008-01-10 16:44 --------- d-----w C:\Program Files\Common Files\Nokia
2008-01-10 16:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-01-10 16:22 --------- d-----w C:\Program Files\NSS
2008-01-10 09:06 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-01-10 08:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-01-09 09:16 106,496 ----a-w C:\WINDOWS\system32\SSOCareFx.dll
2007-12-12 06:33 480,736 ----a-w C:\WINDOWS\system32\icslta.dll
2007-10-31 12:14 8 ----a-w C:\Documents and Settings\SAPServiceDAB\ISXAudit.DAT
2007-10-31 12:14 8 ----a-w C:\Documents and Settings\nwadmin\ISXAudit.DAT
2007-10-31 12:14 8 ----a-w C:\Documents and Settings\novadia\ISXAudit.DAT
2007-10-31 12:14 8 ----a-w C:\Documents and Settings\gadir\ISXAudit.DAT
2007-10-31 12:14 8 ----a-w C:\Documents and Settings\Default User\ISXAudit.DAT
2007-10-31 12:14 8 ----a-w C:\Documents and Settings\dabadm\ISXAudit.DAT
2007-10-31 12:14 8 ----a-w C:\Documents and Settings\avishayb\ISXAudit.DAT
2007-10-31 12:14 8 ----a-w C:\Documents and Settings\Administrator\ISXAudit.DAT
2004-10-27 18:40 331,776 ----a-w C:\Documents and Settings\nwadmin\sapinstevents.dll
.
------- Sigcheck -------
2007-06-27 16:40 824320 9226919fbb14f5ab12859c05e474dd77 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
2004-08-04 10:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB905915$\wininet.dll
2005-10-21 05:38 661504 af785c4947676a7fc1673fdc5c8d0b5b C:\WINDOWS\$NtUninstallKB925454$\wininet.dll
2006-10-23 17:34 664576 231ef4179acabe486376b5ca893f1076 C:\WINDOWS\$NtUninstallKB937143$\wininet.dll
2007-06-26 16:35 665600 e1a3dd68b5380b360a7310a64d9bb188 C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
2007-08-22 14:55 665600 a1bc17eb3758d73c3938b2318820f5b4 C:\WINDOWS\ie7\wininet.dll
2007-08-13 18:54 818688 a4a0fc92358f39538a6494c42ef99fe9 C:\WINDOWS\ie7updates\KB937143-IE7\wininet.dll
2007-12-01 00:26 666112 e7f441cde6e418bb68fc700872c004a0 C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2007-06-27 16:34 823808 8068cbb58fe60cc95aeb2cff70178208 C:\WINDOWS\system32\wininet.dll
2007-06-27 16:34 823808 8068cbb58fe60cc95aeb2cff70178208 C:\WINDOWS\system32\dllcache\wininet.dll
.
((((((((((((((((((((((((((((( snapshot@2008-03-09_13.54.11.20 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-09 11:40:13 4,212 ---ha-w C:\WINDOWS\system32\zllictbl.dat
+ 2008-03-09 13:39:38 4,212 ---ha-w C:\WINDOWS\system32\zllictbl.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
2008-01-28 18:27 390616 --a------ C:\Program Files\CheckPoint\ZAForceField\TrustChecker\Components\TrustCheckerIEPlugin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A683EEA9-ECFA-45A2-BCA9-7D9D54AD58AE}]
2008-01-09 11:16 262144 --a------ C:\Program Files\Imprivata\ISXBho.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}"= "C:\Program Files\CheckPoint\ZAForceField\TrustChecker\Components\TrustCheckerIEPlugin.dll" [2008-01-28 18:27 390616]
[HKEY_CLASSES_ROOT\clsid\{ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107}]
[HKEY_CLASSES_ROOT\CheckPoint.ForceFieldToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{80E552F9-F23B-4DD7-A1CD-80AA724529E6}]
[HKEY_CLASSES_ROOT\CheckPoint.ForceFieldToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107}"= C:\Program Files\CheckPoint\ZAForceField\TrustChecker\Components\TrustCheckerIEPlugin.dll [2008-01-28 18:27 390616]
[HKEY_CLASSES_ROOT\clsid\{ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107}]
[HKEY_CLASSES_ROOT\CheckPoint.ForceFieldToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{80E552F9-F23B-4DD7-A1CD-80AA724529E6}]
[HKEY_CLASSES_ROOT\CheckPoint.ForceFieldToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2007-05-09 22:33 106904]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-01 00:26 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-17 18:51 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 13:36 14854144 C:\WINDOWS\RTHDCPL.EXE]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 16:16 356352]
"SAPSMC"="C:\WINDOWS\system32\mmc.exe" [2007-12-01 00:26 1414656]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35 1294336]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Pandion.lnk - C:\Program Files\Pandion\Pandion.exe [2006-01-11 03:06:07 993792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SysAlrt"= {9839e66d-b275-49ef-8e42-0b5d4e906787} - C:\WINDOWS\Installer\{9839e66d-b275-49ef-8e42-0b5d4e906787}\SysAlrt.dll [2008-03-09 09:34 14374]
"zip"= {0543c7c4-fed3-4762-a10e-76559d1e6c20} - C:\WINDOWS\Installer\{0543c7c4-fed3-4762-a10e-76559d1e6c20}\zip.dll [2008-03-09 09:34 22686]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
ckpNotify.dll 2006-04-09 21:24 24674 C:\WINDOWS\system32\ckpNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3009975827-1942386155-3087368816-24128\Scripts\Logon\
0\
0]
"Script"=OneSignAgent_ver2.bat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, credssp.dll, wowfx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^avishayb^Start Menu^Programs^Startup^findfast.exe]
path=C:\Documents and Settings\avishayb\Start Menu\Programs\Startup\findfast.exe
backup=C:\WINDOWS\pss\findfast.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^avishayb^Start Menu^Programs^Startup^Mobiola Remote Control.lnk]
path=C:\Documents and Settings\avishayb\Start Menu\Programs\Startup\Mobiola Remote Control.lnk
backup=C:\WINDOWS\pss\Mobiola Remote Control.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^avishayb^Start Menu^Programs^Startup^Total Commander.lnk]
path=C:\Documents and Settings\avishayb\Start Menu\Programs\Startup\Total Commander.lnk
backup=C:\WINDOWS\pss\Total Commander.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2007-12-01 00:26 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Exodus]
--a------ 2003-07-02 18:39 2738688 C:\Program Files\Exodus\Exodus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExodusLoader]
--a------ 2004-10-17 09:50 49152 c:\progra~1\exodusloader\exodusloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 2007-09-25 10:10 2007088 C:\Program Files\FlashGet\flashget.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2005-01-07 19:07 61952 C:\WINDOWS\system32\hdashcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
--a------ 2008-03-03 14:08 172280 C:\Program Files\ICQ6\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-09-20 09:32 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-09-20 09:36 114688 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-09-20 09:35 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
--a------ 2004-08-04 15:00 44032 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-04 15:00 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW]
--a------ 2008-01-28 18:23 200781 C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISXAgent]
--a------ 2008-01-09 11:16 1290240 C:\Program Files\Imprivata\ISXAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JSPEdit]
C:\Documents and Settings\avishayb\Desktop\projvisualstudio\Solution1.sln
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 2004-08-04 15:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeScanNT Monitor]
--a------ 2006-02-07 16:16 356352 C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2007-12-10 10:12 695808 C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-04 15:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-04 15:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetRefresh]
--a------ 2003-11-20 20:01 525824 C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-10-10 07:28 36352 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinClicker.exe]
--a------ 2007-05-11 11:25 1150976 C:\Program Files\Salling Software AB\Salling Clicker\WinClicker.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
--a------ 2008-01-23 02:47 939496 C:\Program Files\CheckPoint\Integrity Client\iclient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
--a------ 2008-01-23 02:47 939496 C:\Program Files\Checkpoint\Integrity Client\iclient.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 r_server;Remote Administrator Service;"C:\WINDOWS\system32\r_server.exe" /service []
R2 SAPDAB_00;SAPDAB_00;D:\usr\sap\DAB\JC00\exe\sapstartsrv.exe pf=D:\usr\sap\DAB\SYS\profile\START_JC00_avishayb-7100 []
R2 SAPDAB_01;SAPDAB_01;D:\usr\sap\DAB\SCS01\exe\sapstartsrv.exe pf=D:\usr\sap\DAB\SYS\profile\START_SCS01_avishayb-7100 []
R2 SAPDBWWW;SAP DB WWW;d:\sapdb\programs\web\pgm\wahttp.exe [2005-06-16 12:14]
R2 SSOManHost;SSO Manager Host;"C:\Program Files\Imprivata\SSOManHost.exe" [2008-01-09 11:09]
R2 XServer;XServer;d:\sapdb\programs\pgm\serv.exe [2007-04-10 22:19]
R2 XyLoc Security System;XyLoc Security System;"C:\Program Files\Imprivata\XyLoc.exe" [2007-06-13 11:38]
R3 FW1;SecuRemote Miniport;C:\WINDOWS\system32\DRIVERS\fw.sys [2008-01-17 18:23]
S2 MailService;Rational ClearQuest Mail Service;"C:\Program Files\Rational\ClearQuest\mailservice.exe" [2005-06-08 11:02]
S3 icsak;icsak;C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys [2008-01-28 18:25]
S3 SAP DBTech-.M750044 (quick);SAPDB: .M750044 (quick);c:\sapdb\dab\db\pgm\quickknl.exe [2007-04-11 01:16]
S3 SAP DBTech-.M750044 (slow);SAPDB: .M750044 (slow);c:\sapdb\dab\db\pgm\slowknl.exe [2007-04-11 02:11]
S3 SAP DBTech-.M750044 (test);SAPDB: .M750044 (omststknl.exe);c:\sapdb\dab\db\pgm\omststknl.exe []
S3 SAP DBTech-.M750044;SAPDB: .M750044;c:\sapdb\dab\db\pgm\kernel.exe [2007-04-10 23:25]
S3 SAP DBTech-DAB (quick);SAPDB: DAB (quick);c:\sapdb\dab\db\pgm\quickknl.exe [2007-04-11 01:16]
S3 SAP DBTech-DAB (slow);SAPDB: DAB (slow);c:\sapdb\dab\db\pgm\slowknl.exe [2007-04-11 02:11]
S3 SAP DBTech-DAB (test);SAPDB: DAB (omststknl.exe);c:\sapdb\dab\db\pgm\omststknl.exe []
S3 SAP DBTech-DAB;SAPDB: DAB;c:\sapdb\dab\db\pgm\kernel.exe [2007-04-10 23:25]
S3 SAPDBXIE;SAPDBXIE;d:\sapdb\programs\web\pgm\sapdbxie.exe [2005-06-16 12:18]
S3 vsinstdv;vsinstdv;C:\DOCUME~1\avishayb\LOCALS~1\Temp\{CF20E9E4-4933-40D2-B305-CA9EDB585CA7}\vsinstdv.sys []
S4 IswSvc;ForceField IswSvc;"C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe" [2008-01-28 18:17]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
*Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
*Newly Created Service* - AVG_ANTI-SPYWARE_GUARD
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-09 16:12:19
Windows 5.1.2600 Service Pack 3, v.3264 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL]
"ImagePath"="\"C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"C:\Program Files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
Completion time: 2008-03-09 16:14:09
ComboFix-quarantined-files.txt 2008-03-09 14:14:04
ComboFix2.txt 2008-03-09 13:41:55
ComboFix3.txt 2008-03-09 12:30:18
Logfile BEFORE REBOOTING: mbam-log-3-9-2008(17-46-41).txtMalwarebytes' Anti-Malware 1.07
Database version: 470
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 298096
Time elapsed: 1 hour(s), 24 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 6
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 5
Files Infected: 13
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\Installer\{9839e66d-b275-49ef-8e42-0b5d4e906787}\SysAlrt.dll (Trojan.Alphabet) -> Unloaded module successfully.
C:\WINDOWS\Installer\{0543c7c4-fed3-4762-a10e-76559d1e6c20}\zip.dll (Trojan.Alphabet) -> Unloaded module successfully.
C:\Program Files\IE Extensions\cj.v2.dll (Trojan.BHO) -> Unloaded module successfully.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{9839e66d-b275-49ef-8e42-0b5d4e906787} (Trojan.Alphabet) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{0543c7c4-fed3-4762-a10e-76559d1e6c20} (Trojan.Alphabet) -> Delete on reboot.
HKEY_CLASSES_ROOT\cj.cjmgr (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\cj.cjmgr.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CJ.cjmgr (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CJ.cjmgr.1 (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SysAlrt (Trojan.Alphabet) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\zip (Trojan.Alphabet) -> Delete on reboot.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Trojan.Qhost) -> Data: wowfx.dll -> Quarantined and deleted successfully.
Folders Infected:
C:\WINDOWS\Installer\{9839e66d-b275-49ef-8e42-0b5d4e906787} (Trojan.Alphabet) -> Delete on reboot.
C:\WINDOWS\Installer\{0543c7c4-fed3-4762-a10e-76559d1e6c20} (Trojan.Alphabet) -> Delete on reboot.
C:\Program Files\SystemDefender (Rogue.SystemDefender) -> Quarantined and deleted successfully.
C:\Program Files\SysCleaner (Rogue.SysCleaner) -> Quarantined and deleted successfully.
C:\Program Files\IE Extensions (Trojan.BHO) -> Delete on reboot.
Files Infected:
C:\WINDOWS\Installer\{9839e66d-b275-49ef-8e42-0b5d4e906787}\SysAlrt.dll (Trojan.Alphabet) -> Delete on reboot.
C:\WINDOWS\Installer\{0543c7c4-fed3-4762-a10e-76559d1e6c20}\zip.dll (Trojan.Alphabet) -> Delete on reboot.
C:\QooBox\Quarantine\C\Program Files\ucleaner_setup.exe.vir (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D0D4C289-1775-4E84-B8F1-E8133151EDAF}\RP157\A0058352.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wowfx.dll (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\Program Files\IE Extensions\cj.v2.dll (Trojan.BHO) -> Delete on reboot.
C:\Program Files\tmp11175734.exe (Trojan.Alphabet) -> Quarantined and deleted successfully.
C:\Program Files\tmp11176265.exe (Trojan.Alphabet) -> Quarantined and deleted successfully.
C:\Program Files\tmp11181218.exe (Trojan.Alphabet) -> Quarantined and deleted successfully.
C:\Program Files\ucleaner_setup.exe (Adware.UCleaner) -> Quarantined and deleted successfully.
C:\Program Files\udefender_setup.exe (Adware.UDefender) -> Quarantined and deleted successfully.
C:\Documents and Settings\avishayb\Application Data\printer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\etc\services.1 (Heuristic.Reserved.Word.Exploit) -> Quarantined and deleted successfully.