View Full Version : Probably another Bagle variant.
I recently downloaded a file which turned out to be infected, I have NOD32 Antivirus and Comodo Firewall as defences against viruses, malwares etc. When I launched this file the firewall made some blocks and ignorant of what they were I accepted the file to be executed, spiralling my computer into trouble. The logs from the firewall show that changes were made in the following folders and services:
LocalSecurityAuthority.Debug
C:\WINDOWS\system32\drivers\down HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA
\RPC Control\ntsvcs
\RPC Control\ntsvcs
C:\WINDOWS\explorer.exe
LocalSecurityAuthority.Debug
C:\Program Files\ESET\nod32kui.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\drivers\srosa.sys
I came across this link and it has proved useful:
http://forums.spybot.info/showthread.php?t=22682
Some of the changes made bear resemblance to features in this link:
http://www.bluetack.co.uk/forums/index.php?showtopic=18336
Unexpectedly, the NOD32 service has stopped functioning totally and the firewall only partially. I have deleted hldrrr.exe from System32\Drivers\ ,but am sure that the other changes made by this virus is certainly going to hamper the proper functioning of the pc.
I am doing the Kaspersky online scan (will post the log soon). Hijack and gmer logs are given below.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:05:12 PM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\eScan\TRAYSSER.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\eScan\TRAYICOS.EXE
C:\Program Files\COMODO\Firewall\cfp.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\AYUSH\Local Settings\Temp\wz9c45\gmer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [eScan Updater] C:\PROGRA~1\eScan\TRAYICOS.EXE /App
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6EB7939F-66B5-4441-9CFA-2ACB0A829CFF}: NameServer = 202.54.9.1,202.54.29.5
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: eScan Server-Updater (eScan-trayicos) - MicroWorld Technologies Inc. - C:\PROGRA~1\eScan\TRAYSSER.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5103 bytes
GMER 1.0.14.14205 - http://www.gmer.net
Rootkit scan 2008-03-16 19:16:25
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) ZwEnumerateKey [0xBA46D560]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) ZwEnumerateValueKey [0xBA46D610]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) ZwQuerySystemInformation [0xBA47B9B0]
Code \??\C:\WINDOWS\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \??\C:\WINDOWS\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) IoIsOperationSynchronous
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs klif.sys (spuper-ptor/Kaspersky Lab)
AttachedDevice \FileSystem\Ntfs \Ntfs amon.sys (Amon monitor/Eset )
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat klif.sys (spuper-ptor/Kaspersky Lab)
AttachedDevice \FileSystem\Fastfat \Fat amon.sys (Amon monitor/Eset )
AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
---- Threads - GMER 1.0.14 ----
Thread 4:132 81F38330
Thread 4:140 81F38330
Thread 4:144 81F09D30
Thread 4:148 81F09D30
Thread 4:152 81F09D30
---- EOF - GMER 1.0.14 ----
SmitFraudFix v2.305
Scan done at 21:39:42.43, Sun 03/16/2008
Run from C:\Documents and Settings\AYUSH\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\eScan\TRAYSSER.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\AYUSH
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\AYUSH\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\AYUSH\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\\WINDOWS\\system32\\guard32.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\adialhk.dll"
"LoadAppInit_DLLs"=dword:00000001
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Realtek RTL8139 Family PCI Fast Ethernet NIC - Packet Scheduler Miniport
DNS Server Search Order: 202.54.9.1
DNS Server Search Order: 202.54.29.5
HKLM\SYSTEM\CCS\Services\Tcpip\..\{6EB7939F-66B5-4441-9CFA-2ACB0A829CFF}: NameServer=202.54.9.1,202.54.29.5
HKLM\SYSTEM\CS1\Services\Tcpip\..\{F3336C18-5C6D-405A-97C1-F2B99ECC7C5B}: NameServer=202.54.9.1 202.54.29.5
HKLM\SYSTEM\CS2\Services\Tcpip\..\{6EB7939F-66B5-4441-9CFA-2ACB0A829CFF}: NameServer=202.54.9.1,202.54.29.5
HKLM\SYSTEM\CS3\Services\Tcpip\..\{6EB7939F-66B5-4441-9CFA-2ACB0A829CFF}: NameServer=202.54.9.1,202.54.29.5
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
KASPERSKY ONLINE SCANNER REPORT
2008-03-17 11:24
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/03/2008
Kaspersky Anti-Virus database records: 634673
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 70622
Number of viruses found 1
Number of infected objects 5
Number of suspicious objects 0
Duration of the scan process 02:05:41
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\comodo\Firewall Pro\cfplogdb.sdb Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\cert8.db Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\flashgot.log Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\history.dat Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\key3.db Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\parent.lock Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\search.sqlite Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\webappsstore.sqlite Object is locked skipped
C:\Documents and Settings\AYUSH\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-3-17-2008( 9-22-22 ).LOG Object is locked skipped
C:\Documents and Settings\AYUSH\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\Application Data\Mozilla\Firefox\Profiles\dk05o8v3.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\History\History.IE5\MSHist012008031720080318\index.dat Object is locked skipped
C:\Documents and Settings\AYUSH\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\AYUSH\My Documents\Ayush's\Scrap\Scanner logs from infection on 16.03.08\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\AYUSH\My Documents\Ayush's\Softwares & INLoads\Security\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\AYUSH\My Documents\Ayush's\Softwares & INLoads\Security\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\AYUSH\My Documents\Ayush's\Softwares & INLoads\Security\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\AYUSH\ntuser.dat Object is locked skipped
C:\Documents and Settings\AYUSH\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\ESET\cache\CACHE.NDB Object is locked skipped
C:\Program Files\ESET\logs\virlog.dat Object is locked skipped
C:\Program Files\ESET\logs\warnlog.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{3B304A43-30C2-4EBB-9A8F-FB7BB67BEF01}\RP1\A0000524.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{3B304A43-30C2-4EBB-9A8F-FB7BB67BEF01}\RP2\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
2008-03-17 11:52 . 2008-03-17 11:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-17 11:52 . 2008-03-17 11:52 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Malwarebytes
2008-03-17 11:52 . 2008-03-17 11:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-17 09:22 . 2008-03-17 09:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-17 09:21 . 2008-03-17 09:22 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-17 09:21 . 2008-03-17 09:21 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\SUPERAntiSpyware.com
2008-03-16 23:25 . 2008-03-16 23:24 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-03-16 23:25 . 2008-03-16 23:24 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-03-16 23:25 . 2008-03-16 23:24 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-03-16 21:40 . 2008-03-16 21:41 2,596 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-16 19:25 . 2008-03-16 19:25 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-16 19:03 . 2008-03-16 19:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-16 18:57 . 2008-03-16 22:49 250 --a------ C:\WINDOWS\gmer.ini
2008-03-16 17:33 . 2008-03-16 18:43 112,324 --a------ C:\WINDOWS\system32\FontInfo.bin
2008-03-16 17:33 . 2008-03-16 18:43 36,504 --a------ C:\WINDOWS\system32\GlyphInfo.bin
2008-03-16 17:33 . 2007-04-01 17:29 26,624 --a------ C:\WINDOWS\system32\AWRESX32.DLL
2008-03-16 17:33 . 2007-04-01 17:29 24,576 --a------ C:\WINDOWS\system32\AWCODC32.DLL
2008-03-16 17:33 . 2007-04-01 17:29 11,776 --a------ C:\WINDOWS\system32\AWDENC32.DLL
2008-03-16 17:33 . 2007-04-01 17:29 10,240 --a------ C:\WINDOWS\system32\AWVIEW32.DLL
2008-03-16 17:33 . 2007-04-01 17:29 6,144 --a------ C:\WINDOWS\system32\AWDCXC32.DLL
2008-03-16 17:32 . 2008-03-16 17:32 <DIR> d-------- C:\Program Files\LEAD Technologies
2008-03-16 09:05 . 2008-03-16 09:05 <DIR> d-------- C:\Program Files\Common Files\LizardTech Shared
2008-03-16 09:05 . 2005-11-22 21:10 774,144 --a------ C:\WINDOWS\system32\LTIFilter.dll
2008-03-16 09:00 . 2008-03-16 09:00 57,344 --a------ C:\WINDOWS\system32\RO82D7.tmp
2008-03-13 13:12 . 2008-03-13 13:12 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Systweak
2008-03-13 13:07 . 2008-03-13 13:22 <DIR> d-------- C:\Program Files\Advanced System Optimizer
2008-03-13 13:00 . 2008-03-13 13:00 <DIR> d-------- C:\Program Files\ToniArts
2008-03-13 12:40 . 2008-03-16 10:07 <DIR> d-------- C:\Program Files\File Renamer
2008-03-13 12:40 . 2008-03-13 12:40 120,499 --a------ C:\WINDOWS\File Renamer - Basic Uninstaller.exe
2008-03-13 12:39 . 2008-03-13 12:39 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Uniblue
2008-03-13 10:58 . 2008-03-13 11:00 6,869,187 --a------ C:\WINDOWS\REGBK16.ZIP
2008-03-09 17:32 . 2008-03-09 17:32 <DIR> d-------- C:\Program Files\FreeOCRnet
2008-03-06 19:20 . 2008-03-11 23:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-06 19:20 . 2008-03-06 19:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-05 20:28 . 2008-03-05 20:28 <DIR> d-------- C:\BVGPRES
2008-03-05 20:26 . 2008-03-05 20:26 0 --a------ C:\WINDOWS\asym.ini
2008-03-04 18:58 . 2008-03-04 19:05 <DIR> d-------- C:\Documents and Settings\AYUSH\dwhelper
2008-03-04 10:04 . 2008-03-04 10:05 6,854,994 --a------ C:\WINDOWS\REGBK15.ZIP
2008-02-28 16:07 . 2008-02-28 16:07 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Bitdefender
2008-02-28 16:07 . 2008-02-28 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-02-28 15:13 . 2008-02-28 15:13 85,520 --a------ C:\WINDOWS\system32\drivers\bdfndisf.sys.avxpnd
2008-02-28 14:43 . 2008-03-16 09:02 8,912,896 --a------ C:\WINDOWS\system32\RO82FF.bac
2008-02-28 14:43 . 2008-03-14 18:46 303,104 --a------ C:\WINDOWS\system32\RO8304.bac
2008-02-28 12:01 . 2008-02-28 15:44 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-02-28 11:58 . 2008-02-28 14:44 <DIR> d-------- C:\Program Files\BitDefender
2008-02-28 11:56 . 2008-02-28 14:44 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-02-28 11:16 . 2008-02-28 11:21 <DIR> d-------- C:\Program Files\Moyea
2008-02-28 11:16 . 2008-02-28 11:24 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Moyea
2008-02-27 23:49 . 2007-02-25 15:36 383,238 --a------ C:\WINDOWS\system32\libmp3lame-0.dll
2008-02-20 16:40 . 2008-02-20 16:40 <DIR> d-------- C:\Program Files\ShurikSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 06:34 986,400 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-17 06:33 --------- d-----w C:\Program Files\eScan
2008-03-17 06:32 95,492 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-17 06:32 102,412,832 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-17 06:32 1,376,852 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-17 03:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-16 17:55 --------- d-----w C:\Program Files\ESET
2008-03-16 17:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-16 16:55 --------- d-----w C:\Program Files\3D Maxs 7
2008-03-16 16:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-03-16 16:54 --------- d-----w C:\Program Files\backburner 2
2008-03-16 12:18 --------- d-----w C:\Program Files\eMule
2008-03-16 12:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-16 03:35 --------- d-----w C:\Program Files\LizardTech
2008-03-14 08:50 --------- d-----w C:\Program Files\FlashGet
2008-03-14 07:32 --------- d-----w C:\Program Files\Spyware Doctor
2008-03-14 06:38 --------- d-----r C:\Program Files\TypingMaster
2008-03-09 18:33 --------- d-----w C:\Documents and Settings\AYUSH\Application Data\Image Zone Express
2008-03-08 07:09 --------- d-----w C:\Program Files\Paint.NET
2008-02-25 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-02-16 18:05 --------- d-----w C:\Program Files\File Extension Changer
2008-02-11 04:36 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-09 05:50 --------- d-----w C:\Documents and Settings\AYUSH\Application Data\TrueCrypt
2008-02-09 05:40 225,344 ----a-w C:\WINDOWS\system32\drivers\truecrypt.sys
2008-02-09 05:40 --------- d-----w C:\Program Files\TrueCrypt
2008-02-06 04:51 83,064 ----a-w C:\WINDOWS\system32\drivers\cmdGuard.sys
2008-02-06 04:51 23,800 ----a-w C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-02-06 04:51 139,008 ----a-w C:\WINDOWS\system32\guard32.dll
2008-02-05 17:41 --------- d-----w C:\Documents and Settings\AYUSH\Application Data\BitTorrent
2008-02-05 17:40 --------- d-----w C:\Program Files\BitTorrent
2008-02-02 18:38 6,824,409 ----a-w C:\WINDOWS\REGBK14.ZIP
2008-01-25 05:42 6,812,213 ----a-w C:\WINDOWS\REGBK13.ZIP
2008-01-23 06:14 --------- d-----w C:\Program Files\NCH Swift Sound
2008-01-23 06:02 --------- d-----w C:\Documents and Settings\AYUSH\Application Data\NCH Swift Sound
2008-01-16 06:21 6,807,368 ----a-w C:\WINDOWS\REGBK12.ZIP
2008-01-02 17:05 38,824 ----a-w C:\Documents and Settings\AYUSH\Application Data\GDIPFONTCACHEV1.DAT
2007-10-31 16:16 24,192 ----a-w C:\Documents and Settings\AYUSH\usbsermptxp.sys
2007-10-31 16:16 22,768 ----a-w C:\Documents and Settings\AYUSH\usbsermpt.sys
2007-10-26 17:01 88,309 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_26_22_18_05_small.dmp.zip
2007-10-26 16:34 99,062 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_26_22_01_17_small.dmp.zip
2007-10-12 14:13 24,873,553 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_12_19_21_52_full.dmp.zip
2007-10-12 14:12 24,874,424 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_12_19_21_34_full.dmp.zip
2007-10-07 09:58 72,022 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_10_07_14_26_11_small.dmp.zip
2007-10-07 09:58 65,928 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_10_07_14_25_55_small.dmp.zip
2007-09-30 03:30 70,377 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_30_00_03_01_small.dmp.zip
2007-09-30 03:30 69,915 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_30_00_03_37_small.dmp.zip
2007-08-05 13:00 22,610,030 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_05_18_23_29_full.dmp.zip
.
------- Sigcheck -------
2006-04-20 17:21 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
2006-04-20 17:48 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2qfe\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\dllcache\tcpip.sys
2004-08-03 23:14 359040 6a603809f598332dbedd535bdbce313e C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eScan Updater"="C:\PROGRA~1\eScan\TRAYICOS.exe" [2006-07-30 16:53 1052160]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-02-06 10:19 5046016]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-03-16 23:24 949376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^AYUSH^Start Menu^Programs^Startup^ProcessTamer.lnk]
backup=C:\WINDOWS\pss\ProcessTamer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
--a------ 2007-06-28 12:51 218376 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\drvsyskit]
C:\WINDOWS\system32\drivers\hldrrr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-02-29 16:03 1481968 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Systweak Wallpaper Changer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"SDhelper"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"NPFMntor"=2 (0x2)
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"WebrootSpySweeperService"=2 (0x2)
"aawservice"=3 (0x3)
"KAVMonitorService"=2 (0x2)
"ScanWscS"=2 (0x2)
"MWAgent"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"sv"=2 (0x2)
"gusvc"=3 (0x3)
"AVP"=2 (0x2)
"Autodesk Licensing Service"=2 (0x2)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MailScan Dispatcher"="C:\Program Files\eScan\LAUNCH.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\PROGRA~1\\COMMON~1\\MICROW~1\\Agent\\MWAGENT.EXE"=
"C:\\PROGRA~1\\COMMON~1\\MICROW~1\\eScanRAD\\ESCANRAD.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\PROGRA~1\\eScan\\DOWNLOAD.EXE"=
"C:\\PROGRA~1\\eScan\\TRAYICOS.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Wolfram Research\\Mathematica Player\\6.0\\MathematicaPlayer.exe"=
"C:\\Program Files\\Wolfram Research\\Mathematica Player\\6.0\\MathKernel.exe"=
"C:\\Program Files\\backburner 2\\monitor.exe"=
"C:\\Program Files\\backburner 2\\manager.exe"=
"C:\\Program Files\\backburner 2\\server.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Java\\jdk1.5.0\\jre\\bin\\java.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-02-06 10:21]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-02-06 10:21]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;C:\Program Files\ASTRA32\ASTRA32.sys [2007-02-22 11:28]
R2 eScan-trayicos;eScan Server-Updater;C:\PROGRA~1\eScan\TRAYSSER.EXE [2006-07-31 04:08]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2007-11-18 00:50]
S4 KAVMonitorService;eScan Monitor Service;C:\PROGRA~1\eScan\avpm.exe [2003-12-24 17:16]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 12:04:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-03-17 12:08:00 - machine was rebooted [AYUSH]
ComboFix-quarantined-files.txt 2008-03-17 06:37:53
.
2007-08-07 13:05:23 --- E O F ---
ComboFix 08-03-14.4 - AYUSH 2008-03-17 11:56:10.2 - NTFSx86
Running from: C:\Documents and Settings\AYUSH\My Documents\Ayush's\Softwares & INLoads\Security\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((( Files Created from 2008-02-17 to 2008-03-17 )))))))))))))))))))))))))))))))
.
2008-03-17 11:52 . 2008-03-17 11:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-17 11:52 . 2008-03-17 11:52 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Malwarebytes
2008-03-17 11:52 . 2008-03-17 11:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-17 09:22 . 2008-03-17 09:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-17 09:21 . 2008-03-17 09:22 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-17 09:21 . 2008-03-17 09:21 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\SUPERAntiSpyware.com
2008-03-16 23:25 . 2008-03-16 23:24 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-03-16 23:25 . 2008-03-16 23:24 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-03-16 23:25 . 2008-03-16 23:24 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-03-16 21:40 . 2008-03-16 21:41 2,596 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-16 19:25 . 2008-03-16 19:25 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-16 19:03 . 2008-03-16 19:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-16 18:57 . 2008-03-16 22:49 250 --a------ C:\WINDOWS\gmer.ini
2008-03-16 17:33 . 2008-03-16 18:43 112,324 --a------ C:\WINDOWS\system32\FontInfo.bin
2008-03-16 17:33 . 2008-03-16 18:43 36,504 --a------ C:\WINDOWS\system32\GlyphInfo.bin
2008-03-16 17:33 . 2007-04-01 17:29 26,624 --a------ C:\WINDOWS\system32\AWRESX32.DLL
2008-03-16 17:33 . 2007-04-01 17:29 24,576 --a------ C:\WINDOWS\system32\AWCODC32.DLL
2008-03-16 17:33 . 2007-04-01 17:29 11,776 --a------ C:\WINDOWS\system32\AWDENC32.DLL
2008-03-16 17:33 . 2007-04-01 17:29 10,240 --a------ C:\WINDOWS\system32\AWVIEW32.DLL
2008-03-16 17:33 . 2007-04-01 17:29 6,144 --a------ C:\WINDOWS\system32\AWDCXC32.DLL
2008-03-16 17:32 . 2008-03-16 17:32 <DIR> d-------- C:\Program Files\LEAD Technologies
2008-03-16 09:05 . 2008-03-16 09:05 <DIR> d-------- C:\Program Files\Common Files\LizardTech Shared
2008-03-16 09:05 . 2005-11-22 21:10 774,144 --a------ C:\WINDOWS\system32\LTIFilter.dll
2008-03-16 09:00 . 2008-03-16 09:00 57,344 --a------ C:\WINDOWS\system32\RO82D7.tmp
2008-03-13 13:12 . 2008-03-13 13:12 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Systweak
2008-03-13 13:07 . 2008-03-13 13:22 <DIR> d-------- C:\Program Files\Advanced System Optimizer
2008-03-13 13:00 . 2008-03-13 13:00 <DIR> d-------- C:\Program Files\ToniArts
2008-03-13 12:40 . 2008-03-16 10:07 <DIR> d-------- C:\Program Files\File Renamer
2008-03-13 12:40 . 2008-03-13 12:40 120,499 --a------ C:\WINDOWS\File Renamer - Basic Uninstaller.exe
2008-03-13 12:39 . 2008-03-13 12:39 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Uniblue
2008-03-13 10:58 . 2008-03-13 11:00 6,869,187 --a------ C:\WINDOWS\REGBK16.ZIP
2008-03-09 17:32 . 2008-03-09 17:32 <DIR> d-------- C:\Program Files\FreeOCRnet
2008-03-06 19:20 . 2008-03-11 23:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-06 19:20 . 2008-03-06 19:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-05 20:28 . 2008-03-05 20:28 <DIR> d-------- C:\BVGPRES
2008-03-05 20:26 . 2008-03-05 20:26 0 --a------ C:\WINDOWS\asym.ini
2008-03-04 18:58 . 2008-03-04 19:05 <DIR> d-------- C:\Documents and Settings\AYUSH\dwhelper
2008-03-04 10:04 . 2008-03-04 10:05 6,854,994 --a------ C:\WINDOWS\REGBK15.ZIP
2008-02-28 16:07 . 2008-02-28 16:07 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Bitdefender
2008-02-28 16:07 . 2008-02-28 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-02-28 15:13 . 2008-02-28 15:13 85,520 --a------ C:\WINDOWS\system32\drivers\bdfndisf.sys.avxpnd
2008-02-28 14:43 . 2008-03-16 09:02 8,912,896 --a------ C:\WINDOWS\system32\RO82FF.bac
2008-02-28 14:43 . 2008-03-14 18:46 303,104 --a------ C:\WINDOWS\system32\RO8304.bac
2008-02-28 12:01 . 2008-02-28 15:44 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-02-28 11:58 . 2008-02-28 14:44 <DIR> d-------- C:\Program Files\BitDefender
2008-02-28 11:56 . 2008-02-28 14:44 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-02-28 11:16 . 2008-02-28 11:21 <DIR> d-------- C:\Program Files\Moyea
2008-02-28 11:16 . 2008-02-28 11:24 <DIR> d-------- C:\Documents and Settings\AYUSH\Application Data\Moyea
2008-02-27 23:49 . 2007-02-25 15:36 383,238 --a------ C:\WINDOWS\system32\libmp3lame-0.dll
2008-02-20 16:40 . 2008-02-20 16:40 <DIR> d-------- C:\Program Files\ShurikSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 06:34 986,400 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-17 06:33 --------- d-----w C:\Program Files\eScan
2008-03-17 06:32 95,492 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-17 06:32 102,412,832 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-17 06:32 1,376,852 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-17 03:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-16 17:55 --------- d-----w C:\Program Files\ESET
2008-03-16 17:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-16 16:55 --------- d-----w C:\Program Files\3D Maxs 7
2008-03-16 16:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-03-16 16:54 --------- d-----w C:\Program Files\backburner 2
2008-03-16 12:18 --------- d-----w C:\Program Files\eMule
2008-03-16 12:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-16 03:35 --------- d-----w C:\Program Files\LizardTech
2008-03-14 08:50 --------- d-----w C:\Program Files\FlashGet
2008-03-14 07:32 --------- d-----w C:\Program Files\Spyware Doctor
2008-03-14 06:38 --------- d-----r C:\Program Files\TypingMaster
2008-03-09 18:33 --------- d-----w C:\Documents and Settings\AYUSH\Application Data\Image Zone Express
2008-03-08 07:09 --------- d-----w C:\Program Files\Paint.NET
2008-02-25 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-02-16 18:05 --------- d-----w C:\Program Files\File Extension Changer
2008-02-11 04:36 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-09 05:50 --------- d-----w C:\Documents and Settings\AYUSH\Application Data\TrueCrypt
2008-02-09 05:40 225,344 ----a-w C:\WINDOWS\system32\drivers\truecrypt.sys
2008-02-09 05:40 --------- d-----w C:\Program Files\TrueCrypt
2008-02-06 04:51 83,064 ----a-w C:\WINDOWS\system32\drivers\cmdGuard.sys
2008-02-06 04:51 23,800 ----a-w C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-02-06 04:51 139,008 ----a-w C:\WINDOWS\system32\guard32.dll
2008-02-05 17:41 --------- d-----w C:\Documents and Settings\AYUSH\Application Data\BitTorrent
2008-02-05 17:40 --------- d-----w C:\Program Files\BitTorrent
2008-02-02 18:38 6,824,409 ----a-w C:\WINDOWS\REGBK14.ZIP
2008-01-25 05:42 6,812,213 ----a-w C:\WINDOWS\REGBK13.ZIP
2008-01-23 06:14 --------- d-----w C:\Program Files\NCH Swift Sound
2008-01-23 06:02 --------- d-----w C:\Documents and Settings\AYUSH\Application Data\NCH Swift Sound
2008-01-16 06:21 6,807,368 ----a-w C:\WINDOWS\REGBK12.ZIP
2008-01-02 17:05 38,824 ----a-w C:\Documents and Settings\AYUSH\Application Data\GDIPFONTCACHEV1.DAT
2007-10-31 16:16 24,192 ----a-w C:\Documents and Settings\AYUSH\usbsermptxp.sys
2007-10-31 16:16 22,768 ----a-w C:\Documents and Settings\AYUSH\usbsermpt.sys
2007-10-26 17:01 88,309 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_26_22_18_05_small.dmp.zip
2007-10-26 16:34 99,062 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_10_26_22_01_17_small.dmp.zip
2007-10-12 14:13 24,873,553 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_12_19_21_52_full.dmp.zip
2007-10-12 14:12 24,874,424 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_12_19_21_34_full.dmp.zip
2007-10-07 09:58 72,022 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_10_07_14_26_11_small.dmp.zip
2007-10-07 09:58 65,928 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_10_07_14_25_55_small.dmp.zip
2007-09-30 03:30 70,377 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_30_00_03_01_small.dmp.zip
2007-09-30 03:30 69,915 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_09_30_00_03_37_small.dmp.zip
2007-08-05 13:00 22,610,030 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_05_18_23_29_full.dmp.zip
.
------- Sigcheck -------
2006-04-20 17:21 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
2006-04-20 17:48 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2qfe\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\dllcache\tcpip.sys
2004-08-03 23:14 359040 6a603809f598332dbedd535bdbce313e C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eScan Updater"="C:\PROGRA~1\eScan\TRAYICOS.exe" [2006-07-30 16:53 1052160]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-02-06 10:19 5046016]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-03-16 23:24 949376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^AYUSH^Start Menu^Programs^Startup^ProcessTamer.lnk]
backup=C:\WINDOWS\pss\ProcessTamer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
--a------ 2007-06-28 12:51 218376 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\drvsyskit]
C:\WINDOWS\system32\drivers\hldrrr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-02-29 16:03 1481968 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Systweak Wallpaper Changer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"SDhelper"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"NPFMntor"=2 (0x2)
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"WebrootSpySweeperService"=2 (0x2)
"aawservice"=3 (0x3)
"KAVMonitorService"=2 (0x2)
"ScanWscS"=2 (0x2)
"MWAgent"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"sv"=2 (0x2)
"gusvc"=3 (0x3)
"AVP"=2 (0x2)
"Autodesk Licensing Service"=2 (0x2)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MailScan Dispatcher"="C:\Program Files\eScan\LAUNCH.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\PROGRA~1\\COMMON~1\\MICROW~1\\Agent\\MWAGENT.EXE"=
"C:\\PROGRA~1\\COMMON~1\\MICROW~1\\eScanRAD\\ESCANRAD.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\PROGRA~1\\eScan\\DOWNLOAD.EXE"=
"C:\\PROGRA~1\\eScan\\TRAYICOS.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Wolfram Research\\Mathematica Player\\6.0\\MathematicaPlayer.exe"=
"C:\\Program Files\\Wolfram Research\\Mathematica Player\\6.0\\MathKernel.exe"=
"C:\\Program Files\\backburner 2\\monitor.exe"=
"C:\\Program Files\\backburner 2\\manager.exe"=
"C:\\Program Files\\backburner 2\\server.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Java\\jdk1.5.0\\jre\\bin\\java.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-02-06 10:21]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-02-06 10:21]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;C:\Program Files\ASTRA32\ASTRA32.sys [2007-02-22 11:28]
R2 eScan-trayicos;eScan Server-Updater;C:\PROGRA~1\eScan\TRAYSSER.EXE [2006-07-31 04:08]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2007-11-18 00:50]
S4 KAVMonitorService;eScan Monitor Service;C:\PROGRA~1\eScan\avpm.exe [2003-12-24 17:16]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 12:04:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-03-17 12:08:00 - machine was rebooted [AYUSH]
ComboFix-quarantined-files.txt 2008-03-17 06:37:53
.
2007-08-07 13:05:23 --- E O F ---