Advertisement
Advertisement
| 01.29.2008 at 01:29AM PST, ID: 23118719 |
|
[x]
Attachment Details
|
||
|
[x]
The Solution Rating System
|
||
With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.
Your Input Matters If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support. Thank you! |
||
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41: 42: 43: 44: 45: 46: 47: 48: 49: 50: 51: 52: 53: 54: 55: 56: 57: 58: 59: 60: 61: 62: 63: 64: 65: 66: 67: 68: 69: 70: 71: 72: 73: 74: 75: 76: 77: 78: 79: 80: 81: 82: 83: 84: 85: 86: 87: 88: 89: 90: 91: 92: 93: 94: 95: 96: 97: 98: 99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: |
ComboFix 08-01-29.3 - Senad 2008-01-29 10:00:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1053.18.174 [GMT 1:00]
Running from: E:\Geocon\övrigt\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\drivers\fad.sys
----- BITS: Possible infected sites -----
hxxp://apps.corel.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-29 09:38 . 2008-01-29 09:38 <KAT> d-------- C:\WINDOWS\system32\backuped
2008-01-29 09:38 . 2008-01-29 09:48 <KAT> d-------- C:\Program\True Sword 4
2008-01-29 09:38 . 2008-01-29 09:38 <KAT> d-------- C:\Documents and Settings\Senad\Application Data\True Sword
2008-01-29 09:21 . 2008-01-29 09:21 <KAT> d-------- C:\Program\Trend Micro
2008-01-17 16:59 . 2008-01-17 16:59 <KAT> d-------- C:\Program\Lavasoft
2008-01-17 16:59 . 2008-01-17 17:00 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-17 16:50 . 2008-01-18 07:14 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-17 15:55 . 2008-01-17 15:55 <KAT> dr------- C:\Documents and Settings\All Users\Application Data\systemerrorfixer
2008-01-17 15:54 . 2008-01-17 16:32 <KAT> d-------- C:\Program\Delade filer\SystemErrorFixer
2008-01-17 15:54 . 2008-01-17 15:54 <KAT> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-01-17 15:50 . 19,584 C:\WINDOWS\system32\drivers\xgduasdf.dat
2008-01-17 15:45 . 2004-08-04 12:00 84,480 --a------ C:\WINDOWS\system32\d3dxo.dll
2008-01-17 15:45 . 2005-01-11 19:18 84,480 --a------ C:\WINDOWS\system32\ati2dva.dll
2008-01-11 09:19 . 2008-01-11 09:19 <KAT> d-------- C:\Program\AutoDWG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-22 14:04 17,408 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
2008-01-17 15:58 --------- d-----w C:\Program\Delade filer\Wise Installation Wizard
2008-01-11 08:52 --------- d--h--w C:\Program\InstallShield Installation Information
2007-12-12 15:12 --------- d-----w C:\Program\Chaos systems
2007-12-11 08:48 --------- d-----w C:\Program\Crystal Decisions
2007-12-10 16:16 --------- d-----w C:\Program\Delade filer\Chaos systems
2007-05-10 15:07 456,272 ----a-w C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
2007-07-11 18:50 88 --sh--r C:\WINDOWS\system32\38720B8E88.sys
1997-07-21 17:30 1,045,776 --sha-w C:\WINDOWS\system32\Msjet35.dll
1997-06-23 01:00 123,664 --sha-w C:\WINDOWS\system32\Msjint35.dll
1997-06-23 10:06 24,848 --sha-w C:\WINDOWS\system32\Msjter35.dll
1997-06-23 10:06 252,176 --sha-w C:\WINDOWS\system32\Msrd2x35.dll
1997-06-23 10:06 287,504 --sha-w C:\WINDOWS\system32\Msxbse35.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39CA37DA-3EA2-4B58-B6CD-1D2A3D2E4EB4}]
2005-01-11 19:18 84480 --a------ C:\WINDOWS\system32\ati2dva.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
"H/PC Connection Agent"="E:\Program\ACTIVE~1\wcescomm.exe" [2005-11-15 20:54 1204224]
"MSMSGS"="C:\Program\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"swg"="C:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-10 07:31 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program\Apoint\Apoint.exe" [2004-09-13 16:33 155648]
"SunJavaUpdateSched"="C:\Program\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"ATIPTA"="C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-01-11 12:45 344064]
"Dell QuickSet"="C:\Program\Dell\QuickSet\quickset.exe" [2005-03-04 11:26 606208]
"DVDLauncher"="C:\Program\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 08:04 53248]
"UpdateManager"="C:\Program\Delade filer\Sonic\Update Manager\sgtray.exe" [2004-01-07 01:01 110592]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05 127035]
"Easy-PrintToolBox"="C:\Program\Canon\Easy-PrintToolBox\BJPSMAIN.exe" [2004-01-14 02:10 409600]
"EPSON Stylus C48 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.exe" [2005-05-17 05:00 99840]
"PCSuiteTrayApplication"="C:\Program\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 12:20 227328]
"QuickTime Task"="C:\Program\QuickTime\qttask.exe" [2007-06-29 05:24 286720]
"ISUSPM Startup"="C:\Program\Delade filer\InstallShield\UpdateService\isuspm.exe" [2005-08-11 15:30 249856]
"ISUSScheduler"="C:\Program\Delade filer\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920]
"AVG7_CC"="C:\Program\Grisoft\AVGFRE~1\avgcc.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 12:00 15360]
"Nokia.PCSync"="C:\Program\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58 1744896]
C:\Documents and Settings\All Users\Start-meny\Program\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
AutoCAD Startup Accelerator.lnk - C:\Program\Delade filer\Autodesk Shared\acstart17.exe [2006-03-05 03:43:54 11000]
Digital Line Detect.lnk - C:\Program\Digital Line Detect\DLG.exe [2005-05-27 20:50:24 24576]
WinZip Quick Pick.lnk - C:\Program\WinZip\WZQKPICK.EXE [2007-04-11 10:10:00 394856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dit]
--a------ 2004-08-05 18:28 90112 C:\WINDOWS\Dit.exe
R0 mhqpytoe;mhqpytoe;C:\WINDOWS\system32\drivers\xgduasdf.dat []
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 08:26]
S3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-01-22 15:04]
S3 memcard;Drivrutin för PCMCIA-minneskort;C:\WINDOWS\system32\DRIVERS\memcard.sys [2001-08-17 21:58]
S3 TrmbTS;TrimbleTS Driver (TrmbTS.sys);C:\WINDOWS\system32\Drivers\TrmbTS.sys [2004-09-28 11:41]
S3 TRMUSB5K;Trimble USB GPS Driver;C:\WINDOWS\system32\drivers\TRMUSB5K.sys [2000-06-20 05:33]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc023545-5f61-11dc-b625-0012f07696e4}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-09-23 20:33:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 10:04:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program\Delade filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program\Delade filer\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\Program\Apoint\Apoint.exe
C:\Program\Apoint\Apntex.exe
C:\Program\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program\Dell\QuickSet\quickset.exe
C:\Program\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program\Delade filer\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I091.EXE
C:\Program\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program\Delade filer\InstallShield\UpdateService\issch.exe
E:\Program\ACTIVE~1\wcescomm.exe
C:\Program\PC Connectivity Solution\ServiceLayer.exe
C:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program\Digital Line Detect\DLG.exe
C:\Program\WinZip\WZQKPICK.EXE
e:\Program\ACTIVE~1\rapimgr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-01-29 10:05:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 09:05:20
|