|
Registered User
Join Date: Apr 2008
Location: 3 Feet behide your car
Posts: 14
OS: xp home edition sp3
|
Am I infected?
this is my results from a combofix scan
Quote:
ComboFix 08-05-01.3 - Workspace 2008-05-03 18:56:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.110 [GMT -7:00]
Running from: C:\Documents and Settings\Workspace\My Documents\My Downloads\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Workspace\err.log
C:\install.exe
C:\WINDOWS\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((( Files Created from 2008-04-04 to 2008-05-04 )))))))))))))))))))))))))))))))
.
2008-05-03 17:54 . 2008-05-03 17:54 <DIR> d-------- C:\Program Files\Windows Defender
2008-05-03 17:45 . 2008-05-03 17:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-09 09:42 . 2008-02-12 14:59 1,306,624 --------- C:\WINDOWS\system32\dllcache\msxml6.dll
2008-04-09 09:42 . 2008-02-12 02:48 79,872 --------- C:\WINDOWS\system32\dllcache\msxml6r.dll
2008-04-09 09:39 . 2008-02-12 14:59 584,704 --a------ C:\WINDOWS\system32\RPCRT4.dll
2008-04-09 09:37 . 2008-04-09 09:42 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-04-09 09:37 . 2008-02-12 14:58 284,672 --a------ C:\WINDOWS\system32\gdi32.dll
2008-04-09 09:29 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\002955_.tmp
2008-04-09 09:23 . 2008-04-09 09:23 <DIR> d-------- C:\WINDOWS\EHome
2008-04-05 16:23 . 2008-04-05 16:23 <DIR> d-------- C:\Program Files\HyperCam
2008-04-05 16:23 . 2008-04-05 16:23 3,343 --a------ C:\WINDOWS\UnHyCam.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-19 19:52 1,175,552 ----a-w C:\WINDOWS\system32\XCoreLib.dll
2008-05-04 01:44 --------- d-----w C:\Program Files\Logitech
2008-05-04 01:41 --------- d-----w C:\Program Files\Common Files\Logitech
2008-05-04 01:39 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-05-04 01:35 --------- d-----w C:\Program Files\Microsoft Bootvis
2008-05-04 01:31 88,576 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-05-04 01:31 27,488 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-04 01:31 2,256,928 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-04 01:13 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-04 00:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-04 00:29 118,784 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-04-09 03:46 --------- d-----w C:\Program Files\Steam
2008-04-09 00:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-04-08 04:03 161,280 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2008-04-08 04:03 1,568,768 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-04-04 05:36 227,840 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-04-04 04:54 --------- d-----w C:\Documents and Settings\Workspace\Application Data\LimeWire
2008-04-03 20:59 --------- d-----w C:\Program Files\IEPro
2008-04-03 20:55 --------- d-----w C:\Documents and Settings\Workspace\Application Data\IEPro
2008-04-02 05:49 --------- d-----w C:\Program Files\Dell
2008-04-02 00:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-01 23:57 --------- d-----w C:\Program Files\Symantec
2008-04-01 23:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-01 21:11 97,792 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-04-01 21:11 1,500,160 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-04-01 20:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-04-01 20:51 --------- d-----w C:\Program Files\Alwil Software
2008-03-31 05:45 47,104 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-03-31 04:24 --------- d-----w C:\Program Files\InfraRecorder
2008-03-31 04:23 --------- d-----w C:\Documents and Settings\Workspace\Application Data\InfraRecorder
2008-03-31 03:29 49,152 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-03-31 03:11 --------- d-----w C:\Program Files\Roxio
2008-03-31 03:07 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-03-31 03:06 --------- d-----w C:\Program Files\7-Zip
2008-03-30 18:26 520,704 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-03-30 18:26 1,453,568 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-03-30 18:05 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-30 18:05 --------- d-----w C:\Documents and Settings\Workspace\Application Data\SUPERAntiSpyware.com
2008-03-20 03:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 03:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-19 03:35 --------- d-----w C:\Documents and Settings\Workspace\Application Data\iolo
2008-03-19 03:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\iolo
2008-03-17 03:44 --------- d-----w C:\Program Files\TweakNow RegCleaner Std
2008-03-17 03:43 --------- d-----w C:\Program Files\CCleaner
2008-03-16 03:50 --------- d-----w C:\Documents and Settings\Workspace\Application Data\SiteAdvisor
2008-03-14 06:11 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-03-14 06:11 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-03-14 05:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-14 05:14 --------- d-----w C:\Program Files\Zone Labs
2008-03-14 04:52 --------- d-----w C:\Program Files\Windows SteadyState
2008-03-14 04:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-14 04:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-10 03:44 --------- d-----w C:\Program Files\LimeWire
2008-03-08 06:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-03-07 21:47 --------- d-----w C:\Program Files\Java
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-12 23:12 1,788 ----a-w C:\WINDOWS\system32\dcache.bin
2008-02-12 23:04 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-02-12 21:59 997,376 ----a-w C:\WINDOWS\system32\msgina.dll
2008-02-12 21:58 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-02-12 21:57 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-02-12 21:55 3,072 ----a-w C:\WINDOWS\system32\dpnlobby.dll
2008-02-12 21:55 3,072 ----a-w C:\WINDOWS\system32\dpnaddr.dll
2008-02-12 21:55 285,696 ----a-w C:\WINDOWS\system32\atmfd.dll
2008-02-12 21:55 16,896 ----a-w C:\WINDOWS\system32\cfgmgr32.dll
2008-02-12 18:32 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-02-12 11:04 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-02-12 10:18 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-02-12 10:10 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
2008-02-12 10:05 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-02-12 10:05 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-02-12 10:05 2,065,792 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-02-12 09:48 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-02-12 09:47 94,208 ----a-w C:\WINDOWS\system32\odbcint.dll
2008-02-12 09:47 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-02-12 09:47 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-02-12 09:45 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll
2008-02-12 09:26 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-02-12 09:26 2,897,920 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-02-12 09:26 187,392 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-02-12 08:49 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-02-12 08:38 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-02-12 08:32 76,800 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-02-12 08:29 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
2008-02-12 08:28 549,376 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-02-12 08:10 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-02-12 08:06 216,064 ----a-w C:\WINDOWS\system32\moricons.dll
2008-02-12 08:04 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-02-12 08:04 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-02-12 08:03 48,128 ----a-w C:\WINDOWS\system32\inetres.dll
2008-02-12 07:59 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-02-12 07:06 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
2008-02-05 01:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2006-09-11 01:02 8 ----a-w C:\Documents and Settings\Workspace\Application Data\usb.dat.bin
2007-02-01 02:40 56 --sh--r C:\WINDOWS\system32\9F6FB99659.sys
2007-02-01 02:40 2,516 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-12 14:59 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-17 20:19 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 17:42 1404928]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 01:12 94208]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 14:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 14:50 81920]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 03:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 03:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 03:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 03:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 03:00 455168]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-02-03 11:25 36904]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36 114688]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 15:52 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-04-17 12:30 85184]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 17:38 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-07-15 05:28:52 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 01:15:54 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Documents and Settings\\Workspace\\Application Data\\Microsoft\\Installer\\{F99C5427-4D78-43E2-B97E-F4C4E622D612}\\MapleStory.exe21_F99C54274D7843E2B97EF4C4E622D612.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 13:33]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
R3 kbdcap;kbdcap;C:\WINDOWS\system32\drivers\kbdcap.sys [2007-09-02 12:44]
S3 BlackJoseph1;BlackJoseph1;C:\Documents and Settings\Workspace\Desktop\maplestory hacks\BlackJoseph_Engine\BlackJoseph Engine\BlackJ32.sys []
S3 cdrmkaun;cdrmkaun;C:\DOCUME~1\WORKSP~1\LOCALS~1\Temp\cdrmkaun.sys []
S3 CEDRIVER51;CEDRIVER51;G:\Gunz\TheBOUEngine\DBK32.sys []
S3 CEDRIVER53;CEDRIVER53;C:\Program Files\Cheat Engine\dbk32.sys []
S3 cheetah1;Cheetah1;C:\Documents and Settings\Workspace\Desktop\Cheetah Engine 2.0\Cheetah Engine 2.0\cheetahrules.sys []
S3 DADriv1;DADriv1;C:\Documents and Settings\Workspace\Desktop\Da_HackPack\DAK32.sys []
S3 geebers12;geebers12;C:\Documents and Settings\Workspace\Desktop\Wonka Engine V1.12\nvid888.sys []
S3 iCheat1;iCheat1;C:\Documents and Settings\Workspace\Desktop\Thinder_v41_Hack_Pax\iCheat Engine\nvid999.sys []
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\Documents and Settings\Workspace\Desktop\HackPAck\HackPackV4\IlvMoney1129.sys []
S3 KIKIDRIVER;KIKIDRIVER;C:\Documents and Settings\Workspace\Desktop\hack\kikiuce141\kiki.sys []
S3 MzBot.sys;MzBot.sys;C:\WINDOWS\system32\MzBot.sys [2007-04-01 04:41]
S3 MzBot;MzBot;C:\MzBot.sys []
S3 npkycryp;npkycryp;C:\Nexon\MapleStory\npkycryp.sys []
S3 puma1;puma1;C:\Documents and Settings\Workspace\Desktop\Puma Engine + [2].CT\Puma Engine + [2].CT\puma.sys []
S3 Revolution1;Revolution1;C:\Documents and Settings\Workspace\Desktop\SHAK3.sys []
S3 sejt1;sejt1;C:\Documents and Settings\Workspace\Desktop\Akuma+CT+Autolink+Bot+DXWnd\Akuma Engine\sejt.sys []
S3 SHAK31;SHAK31;C:\Documents and Settings\Workspace\Desktop\RE 4.2\RE 4.2\SHAK3.sys []
S3 SoRa01;SoRa01;C:\Documents and Settings\Workspace\Desktop\virus\SoRa Remake Engine 2.6\SoRa Remak Engine 2.6\SoRa.sys []
S3 spuce1;spuce1;C:\Documents and Settings\Workspace\Desktop\maplestory hacks\spuce\SPUCE 2.0\spuce.sys []
S3 spydetector;spydetector;C:\Program Files\Spyware Process Detector\spydetector.sys []
S3 TSHAK3T1;TSHAK3T1;C:\Documents and Settings\Workspace\Desktop\Re-Engine3.2\RE 3.2\spuce.sys []
S3 uzeil1;uzeil1;C:\Documents and Settings\Workspace\Desktop\Advanced_Hack_Pack\Advanced_Hack_Pack\Engines\Mini Engine\Mini Engine\uzeil.sys []
S3 XDva037;XDva037;C:\WINDOWS\system32\XDva037.sys []
S3 xp1;xp1;C:\Documents and Settings\Workspace\Desktop\Hack pack\xpengine\xpengine\xp.sys []
S3 Yakir1;Yakir1;C:\Documents and Settings\Workspace\Desktop\ZenXEngine v2(Beta Closed)\Log Evasion Engine\ZenX.Sys []
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-05 01:30:01 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DEREK-Workspace).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2008-05-04 01:35:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-03 19:05:52
Windows 5.1.2600 Service Pack 3, v.3311 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ImagePath"="\??\C:\Documents and Settings\Workspace\Desktop\Puma Engine +
[2].CT\Puma Engine + [2].CT\puma.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\puma1]
"ImagePath"="\??\C:\Documents and Settings\Workspace\Desktop\Puma Engine +
.
Completion time: 2008-05-03 19:09:22
ComboFix-quarantined-files.txt 2008-05-04 02:09:14
Pre-Run: 84,768,415,744 bytes free
Post-Run: 85,330,026,496 bytes free
233 --- E O F --- 2008-04-09 01 03
|
|