Ohh ... Sorry about that. I think now the links should work.
There were hits on the winlogon.exe and lsass.exe
winlogon.exe
http://www.virustotal.com/analisis/...7dbf7199117afb3652ebf100d5f0429b1e-1250907547
services.exe
http://www.virustotal.com/analisis/...e2373b5d15a6ed1c8a71673aa1ce7d9530-1250854410
lsass.exe
http://www.virustotal.com/analisis/...2aa80426ad07cb221799cf941c682ab501-1250907687
svchost.exe
http://www.virustotal.com/analisis/...6d324a276d5f165f874f3fb1b6c613cdd5-1250921492
Comboxfix Log
ComboFix 09-08-22.06 - Administrator 24/08/2009 5:46.6.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.226 [GMT 4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFscript.txt
AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 )))))))))))))))))))))))))))))))
.
2009-08-22 03:12 . 2009-08-22 03:12 -------- d-----w- c:\program files\Java
2009-08-22 02:57 . 2009-08-22 03:02 -------- d-----w- c:\documents and settings\Administrator\.SunDownloadManager
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 09:46 . 2009-08-07 09:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec
2009-07-29 01:35 . 2009-07-29 01:35 -------- d-----w- c:\program files\Trend Micro
2009-07-29 01:34 . 2009-07-29 01:34 -------- d-----w- c:\program files\ERUNT
2009-07-27 01:23 . 2009-07-28 01:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 09:12 . 2008-11-09 11:18 -------- d-----w- c:\program files\Etisalat Modem Protector
2009-08-22 03:13 . 2009-03-26 07:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-22 03:07 . 2008-11-13 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-22 03:07 . 2008-11-13 13:24 -------- d-----w- c:\program files\NOS
2009-07-20 19:00 . 2008-10-09 17:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 08:54 . 2009-07-20 08:54 -------- d-----w- c:\program files\BFG
2009-07-20 08:54 . 2009-07-20 08:54 737280 ----a-w- c:\windows\iun6002.exe
2009-07-19 18:41 . 2009-07-18 15:57 -------- d-----w- c:\program files\GameShadow
2009-07-19 18:37 . 2009-07-19 18:37 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-17 14:32 . 2008-11-09 16:08 -------- d-----w- c:\program files\DivX
2009-07-17 14:31 . 2009-04-10 09:54 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-16 02:00 . 2008-11-09 11:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-16 01:57 . 2009-07-16 01:52 -------- d-----w- c:\program files\DIFX
2009-07-16 01:56 . 2009-07-16 01:56 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-16 01:56 . 2009-02-05 02:02 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-16 01:56 . 2008-12-18 14:11 -------- d-----w- c:\program files\Nokia
2009-07-16 01:52 . 2009-07-16 01:52 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-16 01:49 . 2009-07-16 01:49 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-16 01:49 . 2009-07-16 01:49 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-16 01:48 . 2008-12-18 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-07-16 01:48 . 2009-07-16 01:50 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-01_15.57.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-22 03:14 . 2009-08-22 03:14 16384 c:\windows\Temp\Perflib_Perfdata_ffc.dat
+ 2008-11-09 16:08 . 2009-08-22 02:49 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-11-09 16:08 . 2009-06-11 19:27 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-05-05 15:38 . 2009-08-22 02:46 88589 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 149280 c:\windows\system32\javaws.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 145184 c:\windows\system32\javaw.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 145184 c:\windows\system32\java.exe
+ 2009-08-22 02:43 . 2009-08-22 02:43 802304 c:\windows\Installer\4668ea6.msi
+ 2009-08-22 02:43 . 2009-08-22 02:43 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe
+ 2009-08-15 08:07 . 2005-10-20 08:02 163328 c:\windows\ERDNT\15-08-2009\ERDNT.EXE
+ 2009-06-12 09:05 . 2009-06-12 09:05 296336 c:\windows\Downloaded Program Files\rufsi.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-08-22 03:13 . 2009-08-22 03:13 1757696 c:\windows\Installer\5c435.msi
+ 2009-08-03 13:34 . 2009-08-03 13:34 1697792 c:\windows\Installer\4668e9f.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-14 4608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Etisalat Modem Protector"="c:\program files\Etisalat Modem Protector\Modem Protector.exe" [2006-06-05 446464]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2007-08-30 714608]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2008-07-07 4891472]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\WECPUpdate.exe" [2009-01-25 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Symantec Shared\\NPC\\npcLUStb.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/30/2007 4:45 AM 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\Etisalat Modem Protector\ModemProtectorService.exe [5/22/2006 5:33 PM 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 6:35 AM 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [8/30/2007 4:46 AM 23888]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - JAVAQUICKSTARTERSERVICE
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-08-22 c:\windows\Tasks\Norton AntiVirus Online - Run Full System Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]
2009-08-21 c:\windows\Tasks\Norton AntiVirus Online - Weekly Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-24 05:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2560)
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Symantec Shared\NPC\2.0\NPCEXT.dll
.
Completion time: 2009-08-24 5:54
ComboFix-quarantined-files.txt 2009-08-24 01:54
ComboFix2.txt 2009-08-22 09:22
ComboFix3.txt 2009-08-22 02:32
ComboFix4.txt 2009-08-21 06:23
ComboFix5.txt 2009-08-24 01:45
Pre-Run: 2,128,572,416 bytes free
Post-Run: 2,103,812,096 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
179 --- E O F --- 2009-01-18 12:53
There were hits on the winlogon.exe and lsass.exe
winlogon.exe
http://www.virustotal.com/analisis/...7dbf7199117afb3652ebf100d5f0429b1e-1250907547
services.exe
http://www.virustotal.com/analisis/...e2373b5d15a6ed1c8a71673aa1ce7d9530-1250854410
lsass.exe
http://www.virustotal.com/analisis/...2aa80426ad07cb221799cf941c682ab501-1250907687
svchost.exe
http://www.virustotal.com/analisis/...6d324a276d5f165f874f3fb1b6c613cdd5-1250921492
Comboxfix Log
ComboFix 09-08-22.06 - Administrator 24/08/2009 5:46.6.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.226 [GMT 4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFscript.txt
AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 )))))))))))))))))))))))))))))))
.
2009-08-22 03:12 . 2009-08-22 03:12 -------- d-----w- c:\program files\Java
2009-08-22 02:57 . 2009-08-22 03:02 -------- d-----w- c:\documents and settings\Administrator\.SunDownloadManager
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 09:46 . 2009-08-07 09:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec
2009-07-29 01:35 . 2009-07-29 01:35 -------- d-----w- c:\program files\Trend Micro
2009-07-29 01:34 . 2009-07-29 01:34 -------- d-----w- c:\program files\ERUNT
2009-07-27 01:23 . 2009-07-28 01:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 09:12 . 2008-11-09 11:18 -------- d-----w- c:\program files\Etisalat Modem Protector
2009-08-22 03:13 . 2009-03-26 07:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-22 03:07 . 2008-11-13 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-22 03:07 . 2008-11-13 13:24 -------- d-----w- c:\program files\NOS
2009-07-20 19:00 . 2008-10-09 17:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 08:54 . 2009-07-20 08:54 -------- d-----w- c:\program files\BFG
2009-07-20 08:54 . 2009-07-20 08:54 737280 ----a-w- c:\windows\iun6002.exe
2009-07-19 18:41 . 2009-07-18 15:57 -------- d-----w- c:\program files\GameShadow
2009-07-19 18:37 . 2009-07-19 18:37 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-17 14:32 . 2008-11-09 16:08 -------- d-----w- c:\program files\DivX
2009-07-17 14:31 . 2009-04-10 09:54 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-16 02:00 . 2008-11-09 11:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-16 01:57 . 2009-07-16 01:52 -------- d-----w- c:\program files\DIFX
2009-07-16 01:56 . 2009-07-16 01:56 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-16 01:56 . 2009-02-05 02:02 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-16 01:56 . 2008-12-18 14:11 -------- d-----w- c:\program files\Nokia
2009-07-16 01:52 . 2009-07-16 01:52 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-16 01:49 . 2009-07-16 01:49 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-16 01:49 . 2009-07-16 01:49 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-16 01:48 . 2008-12-18 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-07-16 01:48 . 2009-07-16 01:50 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-01_15.57.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-22 03:14 . 2009-08-22 03:14 16384 c:\windows\Temp\Perflib_Perfdata_ffc.dat
+ 2008-11-09 16:08 . 2009-08-22 02:49 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-11-09 16:08 . 2009-06-11 19:27 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-05-05 15:38 . 2009-08-22 02:46 88589 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 149280 c:\windows\system32\javaws.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 145184 c:\windows\system32\javaw.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 145184 c:\windows\system32\java.exe
+ 2009-08-22 02:43 . 2009-08-22 02:43 802304 c:\windows\Installer\4668ea6.msi
+ 2009-08-22 02:43 . 2009-08-22 02:43 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe
+ 2009-08-15 08:07 . 2005-10-20 08:02 163328 c:\windows\ERDNT\15-08-2009\ERDNT.EXE
+ 2009-06-12 09:05 . 2009-06-12 09:05 296336 c:\windows\Downloaded Program Files\rufsi.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-08-22 03:13 . 2009-08-22 03:13 1757696 c:\windows\Installer\5c435.msi
+ 2009-08-03 13:34 . 2009-08-03 13:34 1697792 c:\windows\Installer\4668e9f.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-14 4608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Etisalat Modem Protector"="c:\program files\Etisalat Modem Protector\Modem Protector.exe" [2006-06-05 446464]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2007-08-30 714608]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2008-07-07 4891472]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\WECPUpdate.exe" [2009-01-25 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Symantec Shared\\NPC\\npcLUStb.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/30/2007 4:45 AM 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\Etisalat Modem Protector\ModemProtectorService.exe [5/22/2006 5:33 PM 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 6:35 AM 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [8/30/2007 4:46 AM 23888]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - JAVAQUICKSTARTERSERVICE
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-08-22 c:\windows\Tasks\Norton AntiVirus Online - Run Full System Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]
2009-08-21 c:\windows\Tasks\Norton AntiVirus Online - Weekly Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-24 05:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2560)
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Symantec Shared\NPC\2.0\NPCEXT.dll
.
Completion time: 2009-08-24 5:54
ComboFix-quarantined-files.txt 2009-08-24 01:54
ComboFix2.txt 2009-08-22 09:22
ComboFix3.txt 2009-08-22 02:32
ComboFix4.txt 2009-08-21 06:23
ComboFix5.txt 2009-08-24 01:45
Pre-Run: 2,128,572,416 bytes free
Post-Run: 2,103,812,096 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
179 --- E O F --- 2009-01-18 12:53