Antivirus Version Last Update Result
AhnLab-V3 2008.5.30.1 2008.06.03 -
AntiVir 7.8.0.26 2008.06.03 -
Authentium 5.1.0.4 2008.06.03 -
Avast 4.8.1195.0 2008.06.03 -
AVG 7.5.0.516 2008.06.03 -
BitDefender 7.2 2008.06.04 -
CAT-QuickHeal 9.50 2008.06.03 -
ClamAV 0.92.1 2008.06.03 -
DrWeb 4.44.0.09170 2008.06.03 -
eSafe 7.0.15.0 2008.06.03 -
eTrust-Vet 31.4.5845 2008.06.03 -
Ewido 4.0 2008.06.03 -
F-Prot 4.4.4.56 2008.06.02 -
F-Secure 6.70.13260.0 2008.06.03 -
Fortinet 3.14.0.0 2008.06.04 -
GData 2.0.7306.1023 2008.06.03 -
Ikarus T3.1.1.26.0 2008.06.03 -
Kaspersky 7.0.0.125 2008.06.03 -
McAfee 5309 2008.06.03 -
Microsoft 1.3604 2008.06.03 -
NOD32v2 3156 2008.06.03 -
Norman 5.80.02 2008.06.03 -
Panda 9.0.0.4 2008.06.03 -
Prevx1 V2 2008.06.04 -
Rising 20.47.12.00 2008.06.03 -
Sophos 4.29.0 2008.06.03 -
Sunbelt 3.0.1143.1 2008.06.03 -
Symantec 10 2008.06.04 -
TheHacker 6.2.92.333 2008.06.03 -
VBA32 3.12.6.7 2008.06.03 -
VirusBuster 4.3.26:9 2008.06.03 -
Webwasher-Gateway 6.6.2 2008.06.03 BlockReason.0
Additional information
File size: 6144 bytes
MD5...: ac3dd1708b22761ebd7cbe14dcc3b5d7
SHA1..: c52920173dc8fedf42b99c71fda34c26c0a11317
SHA256: 395769c8daa505e261033b9ea0319a7ed56a6289bae11fdda49002e25d9d8698
SHA512: f25ad06d4a990f0eb805ea6a4407898c2f748988e86b7089789a647c79a4ec6a
e6dd2b65b3a26d70beada8bb1f4855e6dd6f4ebe20c72f38e23a5ff8c30be044
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x14005
timedatestamp.....: 0x4549b177 (Thu Nov 02 08:51:03 2006)
machinetype.......: 0x14c (I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x47a 0x600 4.96 cb5ce1bca5bd2f0773aedc1042abe435
.rdata 0x2000 0xad 0x200 1.52 7c799c2fc8ec7dbe3207581364f8c4d1
.data 0x3000 0x8 0x200 0.16 0b2e7741e0c0fc65af1542e370d89f53
INIT 0x4000 0x2de 0x400 4.17 c3d870f51e4c5c4499202658d592c5d5
.rsrc 0x5000 0x3d8 0x400 3.29 5ac209cf2f32fdf3280a1d2d64c626d2
.reloc 0x6000 0xd0 0x200 1.90 8863107c6e99e7fe3202bc3543d43045
( 2 imports )
> ntoskrnl.exe: IoStartPacket, MmLockPagableDataSection, KeCancelTimer, MmUnlockPagableImageSection, IoStartNextPacket, KeSetTimer, IoAcquireCancelSpinLock, IoDeleteDevice, KeInitializeTimer, KeInitializeDpc, IoCreateDevice, RtlInitUnicodeString, KeTickCount, KeRemoveDeviceQueue, IoReleaseCancelSpinLock, KeRemoveEntryDeviceQueue, IofCompleteRequest, _allmul, KeInitializeEvent
> HAL.dll: ExReleaseFastMutex, KfRaiseIrql, KfLowerIrql, HalMakeBeep, ExAcquireFastMutex
( 0 exports )
ComboFix 08-06-01.6 - FFM185 2008-06-03 17:12:53.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1206 [GMT -5:00]
Running from: C:\Users\FFM185\Desktop\ComboFix.exe
Command switches used :: C:\Users\FFM185\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Windows\444.470
C:\Windows\444.471
C:\Windows\mssys.exe
C:\Windows\msupdate.exe
C:\Windows\System32\hljwugsf.bin
C:\Windows\System32\vbpdtvdp.exe
D:\autorun.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\444.470
C:\Windows\444.471
C:\Windows\mssys.exe
C:\Windows\msupdate.exe
C:\Windows\RkZNMTg1
C:\Windows\System32\6026c
C:\Windows\System32\a053
C:\Windows\System32\a053\updatdll95.exe
C:\Windows\System32\Dev3
C:\Windows\System32\hljwugsf.bin
C:\Windows\System32\sTMP
C:\Windows\System32\sTMP\lutdtx2.exe
C:\Windows\System32\vbpdtvdp.exe
C:\Windows\System32\Vco1
C:\Windows\System32\vntiho06
C:\Windows\System32\vntiho06\vntiho061083.exe
D:\autorun.exe . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-05-03 to 2008-06-03 )))))))))))))))))))))))))))))))
.
2008-06-03 13:28 . 2008-06-03 13:28 <DIR> d-------- C:\Deckard
2008-06-03 13:23 . 2008-06-03 13:23 2,962 --a------ C:\Windows\System32\tmp.reg
2008-06-03 13:23 . 2008-06-03 13:23 691 --a------ C:\Users\FFM185\AppData\Roaming\GetValue.vbs
2008-06-03 13:23 . 2008-06-03 13:23 35 --a------ C:\Users\FFM185\AppData\Roaming\SetValue.bat
2008-06-02 23:23 . 2008-06-02 23:39 <DIR> d-------- C:\SDFix
2008-06-02 17:18 . 2008-06-02 17:20 <DIR> d-------- C:\ProgramData\Lavasoft
2008-06-02 17:18 . 2008-06-02 17:18 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-02 16:56 . 2008-06-02 16:56 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-02 00:35 . 2008-06-03 14:17 <DIR> d-------- C:\Temp
2008-06-02 00:35 . 2006-11-02 03:51 6,144 --a------ C:\Windows\System32\beep.sys
2008-06-02 00:33 . 2008-06-02 13:48 <DIR> d-------- C:\Users\FFM185\AppData\Roaming\IDM
2008-06-02 00:33 . 2008-06-03 17:16 <DIR> d-------- C:\Users\FFM185\AppData\Roaming\DMCache
2008-06-02 00:33 . 2008-06-02 00:34 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-06-02 00:25 . 2008-06-02 00:25 <DIR> d-------- C:\Program Files\Alwil Software
2008-06-02 00:19 . 2008-06-02 00:19 <DIR> dr-h----- C:\Users\FFM185\AppData\Roaming\SecuROM
2008-06-02 00:19 . 2008-06-02 00:19 <DIR> d-------- C:\Users\FFM185\AppData\Roaming\Command & Conquer 3 Tiberium Wars
2008-06-02 00:19 . 2008-06-02 00:19 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2008-06-01 23:48 . 2006-11-29 13:06 3,426,072 --a------ C:\Windows\System32\d3dx9_32.dll
2008-06-01 23:35 . 2008-06-01 23:35 <DIR> d-------- C:\Program Files\Electronic Arts
2008-06-01 22:38 . 2006-10-26 19:56 32,592 --a------ C:\Windows\System32\msonpmon.dll
2008-06-01 22:36 . 2008-06-01 22:36 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-01 22:34 . 2008-06-01 22:34 <DIR> d-------- C:\Windows\PCHEALTH
2008-06-01 22:34 . 2008-06-01 22:34 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-01 22:32 . 2008-06-01 22:32 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-06-01 22:31 . 2008-06-01 22:54 <DIR> d-------- C:\ProgramData\Microsoft Help
2008-06-01 18:43 . 2008-06-01 18:43 229,888 --a------ C:\Windows\System32\msshsq.dll
2008-06-01 18:42 . 2008-06-01 18:42 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-06-01 18:42 . 2008-06-01 18:42 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-06-01 18:42 . 2007-11-17 23:22 3,636 --a------ C:\Windows\System32\drivers\nvphy.bin
2008-05-31 21:10 . 2008-05-31 21:10 <DIR> d-------- C:\Program Files\Lavalys
2008-05-31 14:29 . 2008-05-31 14:29 <DIR> d-------- C:\Windows\nvtmpinst
2008-05-26 18:18 . 2008-05-26 18:18 <DIR> d-------- C:\Program Files\Combined Community Codec Pack
2008-05-26 18:15 . 2008-05-26 18:16 <DIR> d-------- C:\Program Files\DivX
2008-05-26 18:15 . 2008-05-26 18:15 <DIR> d-------- C:\Program Files\Common Files\PX Storage Engine
2008-05-22 09:25 . 2008-06-03 17:14 <DIR> d-------- C:\Users\FFM185\AppData\Roaming\uTorrent
2008-05-22 09:25 . 2008-05-22 09:25 <DIR> d-------- C:\Program Files\uTorrent
2008-05-21 03:27 . 2008-05-21 03:27 2,923,520 --a------ C:\Windows\explorer.exe
2008-05-21 03:26 . 2008-05-21 03:26 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-05-21 03:26 . 2008-05-21 03:26 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-05-21 03:25 . 2008-05-21 03:25 376,320 --a------ C:\Windows\System32\winsrv.dll
2008-05-21 03:25 . 2008-05-21 03:25 49,664 --a------ C:\Windows\System32\csrsrv.dll
2008-05-21 03:23 . 2008-05-21 03:23 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-05-21 03:23 . 2008-05-21 03:23 41,984 --a------ C:\Windows\System32\drivers\monitor.sys
2008-05-21 03:21 . 2008-05-21 03:21 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
2008-05-21 03:21 . 2008-05-21 03:21 414,208 --a------ C:\Windows\System32\msscp.dll
2008-05-21 03:21 . 2008-05-21 03:21 356,864 --a------ C:\Windows\System32\MediaMetadataHandler.dll
2008-05-21 03:21 . 2008-05-21 03:21 7,680 --a------ C:\Windows\System32\spwmp.dll
2008-05-21 03:21 . 2008-05-21 03:21 4,096 --a------ C:\Windows\System32\msdxm.ocx
2008-05-21 03:21 . 2008-05-21 03:21 4,096 --a------ C:\Windows\System32\dxmasf.dll
2008-05-21 03:20 . 2008-05-21 03:20 396,800 --a------ C:\Windows\System32\MPSSVC.dll
2008-05-21 03:20 . 2008-05-21 03:20 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
2008-05-21 03:20 . 2008-05-21 03:20 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
2008-05-21 03:20 . 2008-05-21 03:20 86,016 --a------ C:\Windows\System32\icfupgd.dll
2008-05-21 03:20 . 2008-05-21 03:20 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys
2008-05-21 03:20 . 2008-05-21 03:20 61,952 --a------ C:\Windows\System32\cmifw.dll
2008-05-21 03:20 . 2008-05-21 03:20 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys
2008-05-21 03:20 . 2008-05-21 03:20 16,896 --a------ C:\Windows\System32\wfapigp.dll
2008-05-21 03:20 . 2008-05-21 03:20 15,360 --a------ C:\Windows\System32\drivers\TUNMP.SYS
2008-05-21 03:19 . 2008-05-21 03:19 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-05-21 03:19 . 2008-05-21 03:19 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe
2008-05-21 03:19 . 2008-05-21 03:19 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-05-21 03:19 . 2008-05-21 03:19 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-05-21 03:19 . 2008-05-21 03:19 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-05-21 03:19 . 2008-05-21 03:19 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-05-21 03:19 . 2008-05-21 03:19 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-05-21 03:19 . 2008-05-21 03:19 15,928 --a------ C:\Windows\System32\drivers\pciide.sys
2008-05-21 03:18 . 2008-05-21 03:18 1,191,936 --a------ C:\Windows\System32\msxml3.dll
2008-05-21 03:18 . 2008-05-21 03:18 104,448 --a------ C:\Windows\System32\DWWIN.EXE
2008-05-21 03:18 . 2008-05-21 03:18 2,048 --a------ C:\Windows\System32\msxml3r.dll
2008-05-21 03:17 . 2008-05-21 03:17 224,768 --a------ C:\Windows\System32\drivers\usbport.sys
2008-05-21 03:17 . 2008-05-21 03:17 192,000 --a------ C:\Windows\System32\drivers\usbhub.sys
2008-05-21 03:17 . 2008-05-21 03:17 73,216 --a------ C:\Windows\System32\drivers\usbccgp.sys
2008-05-21 03:17 . 2008-05-21 03:17 38,400 --a------ C:\Windows\System32\drivers\usbehci.sys
2008-05-21 03:17 . 2008-05-21 03:17 19,456 --a------ C:\Windows\System32\drivers\usbohci.sys
2008-05-21 03:17 . 2008-05-21 03:17 8,704 --a------ C:\Windows\System32\hcrstco.dll
2008-05-21 03:17 . 2008-05-21 03:17 8,704 --a------ C:\Windows\System32\hccoin.dll
2008-05-21 03:17 . 2008-05-21 03:17 5,888 --a------ C:\Windows\System32\drivers\usbd.sys
2008-05-21 03:16 . 2008-05-21 03:16 1,327,104 --a------ C:\Windows\System32\quartz.dll
2008-05-21 03:16 . 2008-05-21 03:16 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-05-21 03:16 . 2008-05-21 03:16 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-05-21 03:16 . 2008-05-21 03:16 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-05-21 03:16 . 2008-05-21 03:16 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-05-21 03:16 . 2008-05-21 03:16 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-05-21 03:14 . 2008-05-21 03:14 1,585,664 --a------ C:\Windows\System32\setupapi.dll
2008-05-21 03:11 . 2008-05-21 03:11 2,027,008 --a------ C:\Windows\System32\win32k.sys
2008-05-21 03:11 . 2008-05-21 03:11 223,232 --a------ C:\Windows\System32\WMASF.DLL
2008-05-21 03:11 . 2008-05-21 03:11 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2008-05-21 03:11 . 2008-05-21 03:11 2,048 --a------ C:\Windows\System32\asferror.dll
2008-05-21 03:10 . 2008-05-21 03:10 2,605,568 --a------ C:\Windows\System32\SLsvc.exe
2008-05-21 03:10 . 2008-05-21 03:10 566,784 --a------ C:\Windows\System32\SLCommDlg.dll
2008-05-21 03:10 . 2008-05-21 03:10 351,232 --a------ C:\Windows\System32\SLUI.exe
2008-05-21 03:10 . 2008-05-21 03:10 296,448 --a------ C:\Windows\System32\gdi32.dll
2008-05-21 03:10 . 2008-05-21 03:10 268,288 --a------ C:\Windows\System32\mcbuilder.exe
2008-05-21 03:10 . 2008-05-21 03:10 223,232 --a------ C:\Windows\System32\SLC.dll
2008-05-21 03:10 . 2008-05-21 03:10 186,368 --a------ C:\Windows\System32\SLLUA.exe
2008-05-21 03:10 . 2008-05-21 03:10 57,856 --a------ C:\Windows\System32\SLUINotify.dll
2008-05-21 03:10 . 2008-05-21 03:10 39,936 --a------ C:\Windows\System32\slcinst.dll
2008-05-21 03:10 . 2008-05-21 03:10 33,280 --a------ C:\Windows\System32\slwmi.dll
2008-05-21 03:09 . 2008-05-21 03:09 1,335,296 --a------ C:\Windows\System32\msxml6.dll
2008-05-21 03:09 . 2008-05-21 03:09 2,048 --a------ C:\Windows\System32\msxml6r.dll
2008-05-21 03:07 . 2008-05-21 03:07 737,792 --a------ C:\Windows\System32\inetcomm.dll
2008-05-21 03:07 . 2008-05-21 03:07 84,480 --a------ C:\Windows\System32\INETRES.dll
2008-05-21 03:07 . 2008-05-21 03:07 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-05-21 03:06 . 2008-05-21 03:06 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
2008-05-21 03:06 . 2008-05-21 03:06 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
2008-05-21 03:05 . 2008-05-21 03:05 788,992 --a------ C:\Windows\System32\rpcrt4.dll
2008-05-21 03:05 . 2008-05-21 03:05 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2008-05-21 03:05 . 2008-05-21 03:05 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2008-05-21 03:05 . 2008-05-21 03:05 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2008-05-21 03:05 . 2008-05-21 03:05 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2008-05-21 03:03 . 2008-05-21 03:03 974,336 --a------ C:\Windows\System32\crypt32.dll
2008-05-21 03:03 . 2008-05-21 03:03 152,576 --a------ C:\Windows\System32\imagehlp.dll
2008-05-21 03:03 . 2008-05-21 03:03 12,800 --a------ C:\Windows\System32\drivers\fs_rec.sys
2008-05-21 03:03 . 2008-05-21 03:03 5,120 --a------ C:\Windows\System32\wmi.dll
2008-05-21 03:03 . 2008-05-21 03:03 2,048 --a------ C:\Windows\System32\tzres.dll
2008-05-21 03:01 . 2008-05-21 03:01 750,080 --a------ C:\Windows\System32\qmgr.dll
2008-05-21 03:01 . 2008-05-21 03:01 633,856 --a------ C:\Windows\System32\user32.dll
2008-05-21 03:00 . 2008-05-21 03:00 1,244,672 --a------ C:\Windows\System32\mcmde.dll
2008-05-20 22:18 . 2008-05-20 22:18 <DIR> d-------- C:\Users\FFM185\AppData\Roaming\Ventrilo
2008-05-20 17:26 . 2008-05-20 17:26 1,080 --a------ C:\Windows\System32\settingsbkup.sfm
2008-05-20 17:26 . 2008-05-20 17:26 1,080 --a------ C:\Windows\System32\settings.sfm
2008-05-20 12:55 . 2008-05-20 12:55 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-05-20 12:35 . 2008-05-21 02:38 <DIR> d-------- C:\Program Files\World of Warcraft
2008-05-20 12:35 . 2008-05-20 12:36 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-05-20 12:30 . 2008-05-20 12:30 <DIR> d-------- C:\Windows\System32\Macromed
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 18:40 9,216 ----a-w C:\Windows\searchword.dll
2008-06-02 03:36 --------- d-----w C:\Program Files\MSBuild
2008-06-01 23:42 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-06-01 23:42 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-06-01 23:42 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-06-01 23:42 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-06-01 23:42 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-05-21 08:39 174 --sha-w C:\Program Files\desktop.ini
2008-05-21 08:36 --------- d-----w C:\Program Files\Windows Mail
2008-05-21 08:36 --------- d-----w C:\Program Files\Windows Calendar
2008-05-21 08:35 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-21 08:35 --------- d-----w C:\Program Files\Windows Defender
2008-05-21 08:28 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2008-05-21 08:28 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2008-05-21 08:28 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2008-05-21 08:28 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2008-05-21 08:28 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2008-05-21 08:27 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-05-21 08:13 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-05-21 08:13 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-05-21 08:13 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-05-21 08:13 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-05-21 08:13 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
2008-05-21 08:13 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
2008-05-21 08:13 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-05-21 08:13 15,872 ----a-w C:\Windows\system32\drivers\kbdhid.sys
2008-05-21 08:04 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-05-15 23:18 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-05-03 03:46 7,460,320 ----a-w C:\Windows\system32\drivers\nvlddmkm.sys
2008-04-29 16:20 15,648 ----a-w C:\Windows\system32\drivers\NSDriver.sys
2008-04-29 16:19 15,648 ----a-w C:\Windows\system32\drivers\Awrtrd.sys
2008-04-29 16:19 12,960 ----a-w C:\Windows\system32\drivers\Awrtpd.sys
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot@2008-06-03_14.22.48.66 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-03 19:21:04 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-06-03 22:16:27 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-06-03 19:21:19 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-06-03 22:16:39 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-06-03 19:21:19 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-03 22:16:39 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-06-03 19:21:13 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-03 22:16:38 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-06-03 19:21:13 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-03 22:16:38 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-03 19:21:13 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-03 22:16:38 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-06-03 18:33:56 103,818 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-06-03 19:27:10 103,818 ----a-w C:\Windows\System32\perfc009.dat
- 2008-06-03 18:33:56 618,410 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-06-03 19:27:10 618,410 ----a-w C:\Windows\System32\perfh009.dat
- 2008-06-03 18:16:16 7,064 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-217085429-2072581838-3877441453-1000_UserData.bin
+ 2008-06-03 19:22:56 7,378 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-217085429-2072581838-3877441453-1000_UserData.bin
- 2008-06-03 18:28:19 58,716 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-06-03 19:22:55 58,904 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-06-03 22:14:47 2,470 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9B3F03D8-D903-400D-8B39-F75D09DA1AAB}]
C:\Windows\system32\fcccyVnk.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 07:34 2159104 C:\Windows\System32\oobefldr.dll]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36 201728]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-06-02 00:34 2594224]
"Microsoft Windows Installer"="C:\Users\FFM185\AppData\Roaming\Microsoft\dtsc\31534.exe" [2008-06-02 00:35 121856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 01:00 45056]
"RCSystem"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 18:07 49152]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 18:07 49152]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 11:01 122880]
"CtxfiReg"="CTXFIREG.exe" [2008-02-20 20:55 43520 C:\Windows\System32\CTXFIREG.EXE]
"UpdReg"="C:\Windows\UpdReg.EXE" [2000-05-11 01:00 90112]
"CTRegRun"="C:\Windows\CTRegRun.EXE" [1999-10-10 20:00 41984]
"CTHelper"="CTHELPER.EXE" [2008-02-20 20:58 19456 C:\Windows\System32\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2008-02-20 20:58 19968 C:\Windows\System32\CTXFIHLP.EXE]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-02 22:46 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-02 22:46 92704]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"MSServer"="C:\Windows\system32\cbXNFxyv.dll" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2488AE31-F3C7-4AE0-AA15-C478365BDBCB}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{03A6C4BC-5673-4D1E-91EC-2A9236E73574}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{1A0596B1-C8DD-4187-9421-F4255E8EF960}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D1DDE9B5-C4AE-4664-A3AD-16465CA64FEC}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{715EC48D-D914-4231-AB63-40FAA8FB1FB0}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{C0792028-5639-42DA-A954-ED01AA4C4235}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{15BC9E6F-E011-4B6C-A3E1-C0A157391A5D}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{0898D75D-6C5F-43F3-B4D9-0D3A54ECD32C}Q:\\westwood\\sun\\game.exe"= UDP:Q:\westwood\sun\game.exe:Main executable for Tiberian Sun
"UDP Query User{B26F5BB2-00AA-4767-97AF-CA855D73C5EF}Q:\\westwood\\sun\\game.exe"= TCP:Q:\westwood\sun\game.exe:Main executable for Tiberian Sun
"TCP Query User{5918945A-6E4C-4A34-AD4D-A384018BFF9D}Q:\\westwood\\ra2\\gamemd.exe"= UDP:Q:\westwood\ra2\gamemd.exe:Main executable for Yuri's Revenge
"UDP Query User{94E0B68B-9181-40F0-8CD7-42F969DE40F2}Q:\\westwood\\ra2\\gamemd.exe"= TCP:Q:\westwood\ra2\gamemd.exe:Main executable for Yuri's Revenge
"TCP Query User{B66BF8D1-1336-4744-BFD4-DFA5012F4385}C:\\users\\ffm185\\appdata\\local\\temp\\electronicarts_patcher_000.exe"= UDP:C:\users\ffm185\appdata\local\temp\electronicarts_patcher_000.exe:electronicarts_patcher_000.exe
"UDP Query User{2C164CCC-ACD0-4AE3-8B44-7AC46FEC229F}C:\\users\\ffm185\\appdata\\local\\temp\\electronicarts_patcher_000.exe"= TCP:C:\users\ffm185\appdata\local\temp\electronicarts_patcher_000.exe:electronicarts_patcher_000.exe
"{716FDA19-CF08-456C-8718-8F509FC6FBFC}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{37335827-8C0C-489F-9347-BEA0639ED82C}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-15 18:20]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-15 18:16]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-15 18:18]
R2 CTAudSvcService;Creative Audio Service;C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2008-03-07 19:24]
R3 ha20x2k;Creative 20X HAL Driver;C:\Windows\system32\drivers\ha20x2k.sys [2008-02-25 09:44]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187.sys [2007-11-19 06:59]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187.sys [2007-11-19 06:59]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-03 17:16:42
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\nvvsvc.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\CTXFISPI.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-06-03 17:18:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-03 22:18:30
ComboFix2.txt 2008-06-03 19:23:20
Pre-Run: 419,882,397,696 bytes free
Post-Run: 423,043,411,968 bytes free
316 --- E O F --- 2008-06-02 03:04:30
Everything still seems normal, but the clock is still in Military time.