1) deleted \bitlord folder
2) uploaded c:\windows\system32\xa.tmp just said:
0 bytes size received / Se ha recibido un archivo vacio
3) ran systemlook:
SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 01:33 on 17/08/2009 by John Doe (Administrator - Elevation successful)
========== filefind ==========
Searching for "c:\windows\system32\drivers\beep.sys"
No files found.
Searching for "c:\windows\system32\msgsvc.dll"
No files found.
Searching for "c:\windows\system32\wscntfy.exe"
No files found.
Searching for "c:\windows\system32\ntmssvc.dll"
No files found.
-=End Of File=-
4) extracted XPSP2_netsvcs.zip sucessfully
5) ComboFix w/ script:
ComboFix 09-08-10.06 - John Doe 08/17/2009 1:42.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.614 [GMT -7:00]
Running from: k:\security\ComboFix.exe
Command switches used :: c:\documents and settings\John Doe\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2009-07-17 to 2009-08-17 )))))))))))))))))))))))))))))))
.
2009-08-16 10:46 . 2009-08-16 10:46 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-08-16 10:46 . 2009-02-16 07:10 69000 ----a-w- c:\windows\system32\zlcomm.dll
2009-08-16 10:46 . 2009-02-16 07:10 103816 ----a-w- c:\windows\system32\zlcommdb.dll
2009-08-16 10:46 . 2009-08-16 10:46 -------- d-----w- c:\windows\system32\ZoneLabs
2009-08-16 10:46 . 2009-08-16 10:46 -------- d-----w- c:\program files\Zone Labs
2009-08-16 10:46 . 2009-02-16 07:10 1221512 ----a-w- c:\windows\system32\zpeng25.dll
2009-08-16 10:45 . 2009-08-17 08:43 -------- d-----w- c:\windows\Internet Logs
2009-08-16 10:36 . 2009-07-28 23:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-16 10:36 . 2009-03-30 17:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-08-16 10:36 . 2009-02-13 19:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-08-16 10:36 . 2009-02-13 19:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-08-16 10:36 . 2009-08-16 10:36 -------- d-----w- c:\program files\Avira
2009-08-16 10:36 . 2009-08-16 10:36 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Avira
2009-08-16 08:13 . 2009-08-16 08:13 -------- d-----w- c:\windows\system32\wbem\snmp
2009-08-16 08:13 . 2009-08-16 08:13 -------- d-----w- c:\windows\system32\xircom
2009-08-16 08:13 . 2009-08-16 08:13 -------- d-----w- c:\windows\srchasst
2009-08-16 08:13 . 2009-08-16 08:13 -------- d-----w- c:\program files\microsoft frontpage
2009-08-09 07:28 . 2009-08-09 07:29 -------- d-----w- c:\program files\IZArc
2009-08-08 06:11 . 2009-08-08 12:08 -------- d-----w- C:\ILLUSION
2009-08-08 06:02 . 2009-08-08 06:04 -------- d-----w- c:\windows\system32\URTTemp
2009-07-24 09:48 . 2009-07-24 09:48 -------- d-----w- c:\documents and settings\John Doe\Local Settings\Application Data\Ascaron Entertainment
2009-07-24 09:32 . 2009-07-24 09:32 -------- d--h--r- c:\documents and settings\John Doe\Application Data\SecuROM
2009-07-24 09:32 . 2009-07-24 09:32 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-24 09:21 . 2009-07-24 09:21 -------- d-----w- c:\windows\Logs
2009-07-24 09:21 . 2009-07-24 09:21 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-07-24 09:21 . 2009-07-24 09:21 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-07-24 09:00 . 2009-07-24 09:00 -------- d-----w- c:\program files\Deep Silver
2009-07-24 09:00 . 2009-07-24 09:00 -------- d-----w- c:\windows\system32\AGEIA
2009-07-24 09:00 . 2009-07-24 09:00 -------- d-----w- c:\program files\AGEIA Technologies
2009-07-24 08:59 . 2009-07-24 08:59 -------- d-----w- c:\documents and settings\John Doe\Application Data\DAEMON Tools Pro
2009-07-24 08:05 . 2009-07-24 08:05 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\DAEMON Tools Lite
2009-07-24 08:04 . 2009-07-24 08:04 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-07-24 08:04 . 2009-07-24 08:04 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-07-24 08:01 . 2009-07-24 08:01 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-07-24 08:01 . 2009-07-24 08:05 -------- d-----w- c:\documents and settings\John Doe\Application Data\DAEMON Tools Lite
2009-07-22 18:00 . 2009-07-22 18:00 97792 ----a-w- c:\windows\system32\drivers\ACEDRV05.sys
2009-07-22 17:47 . 2009-07-22 17:47 -------- d-----w- c:\documents and settings\Karma\Local Settings\Application Data\Mozilla
2009-07-21 16:13 . 2009-07-21 16:13 -------- d-----w- c:\program files\Ascaron Entertainment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-16 10:09 . 2009-06-09 10:17 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-13 07:52 . 2009-05-19 16:55 -------- d---a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-08-11 18:57 . 2009-06-09 10:00 -------- d-----w- c:\program files\Trojan Remover
2009-08-08 12:08 . 2009-04-16 22:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-08 10:55 . 2009-04-21 21:22 10808 ----a-w- c:\documents and settings\John Doe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-25 15:21 . 2009-04-17 09:15 98304 ----a-w- c:\windows\DUMP76e5.tmp
2009-07-24 09:00 . 2009-04-16 22:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-12 17:47 . 2009-04-17 19:36 -------- d-----w- c:\documents and settings\John Doe\Application Data\Move Networks
2009-07-02 00:55 . 2009-04-17 09:15 90112 ----a-w- c:\windows\DUMP853d.tmp
2009-06-27 15:14 . 2009-06-06 16:38 2048 ----a-w- c:\windows\system32\Tr_sttool.dat
2009-06-18 18:12 . 2009-04-17 18:14 -------- d-----w- c:\program files\DivX
2009-06-09 08:47 . 2009-06-09 08:47 40576 ----a-w- c:\windows\system32\drivers\vrtaucbl.sys
2009-06-06 16:38 . 2009-06-06 16:38 692224 ----a-w- c:\windows\system32\bsrmgcv.dll
2009-06-06 16:38 . 2009-06-06 16:38 192512 ----a-w- c:\windows\system32\bsrmgps.dll
2009-06-06 16:38 . 2009-06-06 16:38 585728 ----a-w- c:\windows\system32\bsratswf.dll
2009-06-06 16:38 . 2009-06-06 16:38 147456 ----a-w- c:\windows\system32\bsratwmv.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
------- Sigcheck -------
[-] 2007-07-24 20:09 360704 A11391BE25035570AE4B8970920F2C74 c:\windows\system32\drivers\tcpip.sys
c:\windows\system32\drivers\beep.sys ... is missing !!
c:\windows\system32\msgsvc.dll ... is missing !!
c:\windows\system32\wscntfy.exe ... is missing !!
c:\windows\system32\ntmssvc.dll ... is missing !!
.
((((((((((((((((((((((((((((( SnapShot@2009-08-16_08.14.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 09:19 . 2007-11-07 09:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2009-08-16 16:43 . 2009-08-16 16:43 16384 c:\windows\Temp\Perflib_Perfdata_80.dat
+ 2009-08-16 10:46 . 2009-02-16 07:10 97672 c:\windows\system32\ZoneLabs\zlquarantine.dll
+ 2009-08-16 10:46 . 2008-11-17 09:24 51688 c:\windows\system32\ZoneLabs\srescan.sys
+ 2009-08-16 10:46 . 2009-02-16 07:10 94088 c:\windows\system32\ZoneLabs\lib\zvpn.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 20360 c:\windows\system32\ZoneLabs\lib\zsys.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 59272 c:\windows\system32\ZoneLabs\lib\zpdp.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 14216 c:\windows\system32\ZoneLabs\lib\zmenu.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 24968 c:\windows\system32\ZoneLabs\lib\zic.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 84872 c:\windows\system32\ZoneLabs\lib\ZAlert.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 34696 c:\windows\system32\ZoneLabs\lib\UpdateUI.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 17800 c:\windows\system32\ZoneLabs\lib\oem_1466.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 10120 c:\windows\system32\ZoneLabs\lib\oem_1454.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 10632 c:\windows\system32\ZoneLabs\lib\oem_1445.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 13704 c:\windows\system32\ZoneLabs\lib\oem_1440.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 11656 c:\windows\system32\ZoneLabs\lib\oem_1413.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 11144 c:\windows\system32\ZoneLabs\lib\oem_1010.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 29576 c:\windows\system32\ZoneLabs\lib\NavBar.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 12168 c:\windows\system32\ZoneLabs\lib\MainLoop.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 35720 c:\windows\system32\ZoneLabs\lib\Alert.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 38280 c:\windows\system32\ZoneLabs\featuremap.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 98184 c:\windows\system32\ZoneLabs\fbl.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 74632 c:\windows\system32\ZoneLabs\camupd.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 35208 c:\windows\system32\vswmi.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 58248 c:\windows\system32\vsregexp.dll
- 2009-04-16 21:52 . 2009-04-16 21:52 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-04-16 21:52 . 2009-08-16 15:20 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-08-16 10:36 . 2009-05-11 17:12 28520 c:\windows\system32\drivers\ssmdrv.sys
+ 2009-08-16 10:45 . 2009-08-16 10:45 62464 c:\windows\Installer\8bb047.msi
+ 2009-08-16 10:46 . 2009-02-16 07:10 9608 c:\windows\system32\ZoneLabs\lib\oem_1460.zip.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 10:54 . 2008-07-29 10:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2008-07-29 12:23 . 2008-07-29 12:23 626688 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcr90.dll
+ 2008-07-29 12:23 . 2008-07-29 12:23 856576 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcp90.dll
+ 2008-07-29 10:51 . 2008-07-29 10:51 245760 c:\windows\WinSxS\amd64_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_a17e7c1e\msvcm90.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 108424 c:\windows\system32\ZoneLabs\zlupdate.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 302472 c:\windows\system32\ZoneLabs\zlsre.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 178568 c:\windows\system32\ZoneLabs\zlparser.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 172936 c:\windows\system32\ZoneLabs\vsvault.dll
+ 2009-08-16 10:45 . 2009-02-16 07:10 108424 c:\windows\system32\ZoneLabs\vsdb.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 176520 c:\windows\system32\ZoneLabs\updclient.exe
+ 2009-08-16 10:46 . 2007-10-11 23:51 832984 c:\windows\system32\ZoneLabs\updating.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 431496 c:\windows\system32\ZoneLabs\ssleay32.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 134536 c:\windows\system32\ZoneLabs\scheduler.dll
+ 2009-08-16 10:46 . 2008-11-17 09:23 796128 c:\windows\system32\ZoneLabs\qrsrecl.dll
+ 2009-08-16 10:46 . 2008-11-17 09:23 722400 c:\windows\system32\ZoneLabs\qrbase.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 118664 c:\windows\system32\ZoneLabs\lib\zui.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 151944 c:\windows\system32\ZoneLabs\lib\ztv.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 188808 c:\windows\system32\ZoneLabs\lib\Overview.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 344968 c:\windows\system32\ZoneLabs\lib\LicenseUI.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 136584 c:\windows\system32\ZoneLabs\lib\DashBoard.zip.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 344456 c:\windows\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2009-08-16 10:45 . 2009-02-05 01:27 548128 c:\windows\system32\ZoneLabs\icslta.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 159112 c:\windows\system32\ZoneLabs\httpblocker.dll
+ 2009-08-16 10:46 . 2008-03-17 23:52 813568 c:\windows\system32\ZoneLabs\dbghelp.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 109960 c:\windows\system32\vsxml.dll
+ 2009-08-16 10:45 . 2009-02-16 07:10 482184 c:\windows\system32\vsutil.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 309128 c:\windows\system32\vspubapi.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 107912 c:\windows\system32\vsmonapi.dll
+ 2009-08-16 10:45 . 2009-02-16 07:10 229256 c:\windows\system32\vsinit.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 353672 c:\windows\system32\vsdatant.sys
+ 2009-08-16 10:45 . 2009-02-16 07:10 110472 c:\windows\system32\vsdata.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-08-16 10:35 . 2009-08-16 10:35 228352 c:\windows\Installer\823b6e.msi
+ 2008-07-29 15:05 . 2008-07-29 15:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 1648520 c:\windows\system32\ZoneLabs\vsruledb.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 2402184 c:\windows\system32\ZoneLabs\vsmon.exe
+ 2009-08-16 10:46 . 2008-11-17 09:23 1512928 c:\windows\system32\ZoneLabs\srescan.dll
+ 2009-08-16 10:46 . 2009-02-16 07:10 1536392 c:\windows\system32\ZoneLabs\lib\zpy.zip.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-08-16 10:46 . 2008-12-15 08:11 10465257 c:\windows\system32\ZoneLabs\zlasdbup.dat
+ 2009-08-16 10:46 . 2008-12-15 08:11 10465257 c:\windows\system32\ZoneLabs\spyware.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-03-09 37888]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-18 148888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-06-09 1059720]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-03-27 17567744]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2007-07-22 124928]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Linksys Wireless Network Monitor.lnk - c:\program files\Linksys\WUSBF54G\wlMonitor.exe [2009-6-14 3205632]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Deep Silver\\Sacred 2 - Fallen Angel\\system\\s2gs.exe"=
"c:\\Program Files\\Deep Silver\\Sacred 2 - Fallen Angel\\system\\sacred2.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/16/2009 3:36 AM 108289]
R2 NICSer_WUSBF54G;NICSer_WUSBF54G;c:\program files\Linksys\WUSBF54G\NICServ.exe [6/14/2009 1:06 PM 529920]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\drivers\vrtaucbl.sys [6/9/2009 1:47 AM 40576]
R3 usbvm328;HP Camera;c:\windows\system32\drivers\usbvm326.sys [5/5/2009 9:18 AM 219648]
R3 vmfilter323;VC0326 filter service for Serome;c:\windows\system32\drivers\vmfilter323.sys [5/5/2009 9:19 AM 475264]
R3 ZD1211U(Linksys);Linksys Wireless-G USB Network Adapter Driver(Linksys);c:\windows\system32\drivers\ZD1211U.sys [6/14/2009 1:06 PM 278528]
S2
FAH@C:+DOCUME~1+JOHNDO~1+LOCALS~1+Temp+IXP001.TMP+FAH.exe;FAH@C:+DOCUME~1+JOHNDO~1+LOCALS~1+Temp+IXP001.TMP+FAH.exe;c:\docume~1\JOHNDO~1\LOCALS~1\Temp\IXP001.TMP\FAH.exe -svcstart --> c:\docume~1\JOHNDO~1\LOCALS~1\Temp\IXP001.TMP\FAH.exe -svcstart [?]
S2 gupdate1c9bf8863d9adfc;Google Update Service (gupdate1c9bf8863d9adfc);c:\program files\Google\Update\GoogleUpdate.exe [4/17/2009 11:14 AM 133104]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
FF - ProfilePath - c:\docume~1\JOHNDO~1\APPLIC~1\Mozilla\Firefox\Profiles\g8ttv7fh.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - component: c:\documents and settings\John Doe\Application Data\Mozilla\Firefox\Profiles\g8ttv7fh.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\documents and settings\John Doe\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\documents and settings\John Doe\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-17 01:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ServiceDll"="c:\windows\system32\es.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\FAH@C:+DOCUME~1+JOHNDO~1+LOCALS~1+Temp+IXP001.TMP+FAH.exe]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-725345543-73586283-2147019285-1001\Software\SecuROM\License information*]
"datasecu"=hex:d6,69,a9,ab,f9,d8,98,45,66,82,74,9d,ad,9f,a8,42,86,c8,5b,16,9d,
dc,32,d7,a3,87,86,f8,ef,84,28,4c,1b,c0,de,e2,89,80,2b,f8,8a,ec,a7,a0,1c,d8,\
"rkeysecu"=hex:69,47,ec,71,f6,de,af,cf,2b,90,e4,90,fe,0e,c4,20
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3920)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2009-08-17 1:46
ComboFix-quarantined-files.txt 2009-08-17 08:46
ComboFix2.txt 2009-08-16 08:16
Pre-Run: 99,527,376,896 bytes free
Post-Run: 99,550,138,368 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
265