ComboFix 07-11-01.1 - Administrator 2007-11-01 12:46:40.1 -
FAT32x86
Running from: E:\Documents and Settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\WINDOWS\mywinsys.ini
E:\WINDOWS\system32\AlxRes061230.exe
E:\WINDOWS\system32\scrsys061230.scr
E:\WINDOWS\system32\scrsys16_061230.scr
E:\WINDOWS\system32\xydzyh.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Indexingbox
((((((((((((((((((((((((( Files Created from 2007-10-01 to 2007-11-01 )))))))))))))))))))))))))))))))
.
2007-11-01 11:22 <DIR> d-------- E:\Program Files\Spyware Doctor
2007-11-01 11:22 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\TEMP
2007-11-01 11:22 <DIR> d-------- E:\Documents and Settings\Administrator\Application Data\PC Tools
2007-11-01 11:22 626,688 --a------ E:\WINDOWS\system32\msvcr80.dll
2007-11-01 11:22 499,712 --a------ E:\WINDOWS\system32\msvcp71.dll
2007-11-01 11:22 348,160 --a------ E:\WINDOWS\system32\msvcr71.dll
2007-11-01 11:22 79,688 --a------ E:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-01 11:22 62,280 --a------ E:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-01 11:22 41,288 --a------ E:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-01 11:22 29,000 --a------ E:\WINDOWS\system32\drivers\kcom.sys
2007-11-01 11:03 51,200 --a------ E:\WINDOWS\NirCmd.exe
2007-11-01 10:41 <DIR> d-------- E:\Documents and Settings\Administrator\Application Data\Talkback
2007-11-01 10:41 0 --a------ E:\WINDOWS\nsreg.dat
2007-11-01 10:37 512,096 --a------ E:\WINDOWS\system32\drivers\amon.sys
2007-11-01 10:37 299,392 --a------ E:\WINDOWS\system32\imon.dll
2007-11-01 10:37 15,424 --a------ E:\WINDOWS\system32\drivers\nod32drv.sys
2007-11-01 10:17 <DIR> d-------- E:\Documents and Settings\Administrator\Application Data\Hewlett-Packard
2007-11-01 10:17 82,380 --a------ E:\WINDOWS\system32\drivers\AFS2K.SYS
2007-11-01 10:15 <DIR> d-------- E:\Program Files\Common Files\Hewlett-Packard
2007-11-01 10:15 31,616 --a------ E:\WINDOWS\system32\drivers\usbccgp.sys
2007-11-01 10:15 31,616 --a------ E:\WINDOWS\system32\dllcache\usbccgp.sys
2007-11-01 10:15 15,104 --a------ E:\WINDOWS\system32\drivers\usbscan.sys
2007-11-01 10:15 15,104 --a------ E:\WINDOWS\system32\dllcache\usbscan.sys
2007-11-01 10:14 <DIR> d-------- E:\Program Files\Hewlett-Packard
2007-11-01 10:13 20,724 --a------ E:\WINDOWS\hpoins01.dat
2007-11-01 10:13 16,618 --------- E:\WINDOWS\hpomdl01.dat
2007-11-01 01:41 22,016 --a------ E:\WINDOWS\system32\dllcache\agt0408.dll
2007-11-01 01:41 19,968 --a------ E:\WINDOWS\system32\dllcache\agt040e.dll
2007-11-01 01:41 19,456 --a------ E:\WINDOWS\system32\dllcache\agt041f.dll
2007-11-01 01:41 19,456 --a------ E:\WINDOWS\system32\dllcache\agt0419.dll
2007-11-01 01:41 19,456 --a------ E:\WINDOWS\system32\dllcache\agt0415.dll
2007-11-01 01:41 19,456 --a------ E:\WINDOWS\system32\dllcache\agt0405.dll
2007-11-01 01:41 8,704 --a------ E:\WINDOWS\system32\dllcache\batt.dll
2007-10-31 21:23 17,920 --a------ E:\WINDOWS\system32\mdimon.dll
2007-10-31 21:22 <DIR> d-------- E:\WINDOWS\SHELLNEW
2007-10-31 21:22 <DIR> d-------- E:\Program Files\Symbian OS Tools
2007-10-31 21:22 <DIR> d-------- E:\Program Files\SignSIS-GUI
2007-10-31 21:22 <DIR> d-------- E:\Program Files\Microsoft.NET
2007-10-31 21:22 <DIR> d-------- E:\Program Files\Microsoft ActiveSync
2007-10-31 21:22 <DIR> d-------- E:\Program Files\Common Files\Symbian
2007-10-31 21:19 <DIR> d-------- E:\Program Files\Yahoo!
2007-10-31 21:19 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-31 21:11 <DIR> d-------- E:\Program Files\Java
2007-10-31 21:11 <DIR> d-------- E:\Program Files\Common Files\Java
2007-10-31 21:09 <DIR> d-------- E:\Program Files\Codec Pack - All In 1
2007-10-31 21:09 737,280 --a------ E:\WINDOWS\iun6002.exe
2007-10-31 21:06 <DIR> d-------- E:\Program Files\TATA Indicom Web Accelerator
2007-10-31 21:06 86,016 --a------ E:\WINDOWS\system32\sliprt.dll
2007-10-31 21:02 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\WinZip
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-10-31 15:35 502,272 ----a-w E:\WINDOWS\system32\winlogon.exe
2007-10-31 15:29 --------- d-----w E:\Program Files\D-Link
2007-10-31 15:27 --------- d-----w E:\Program Files\Netropa
2007-10-31 15:27 --------- d-----w E:\Program Files\iBall
2007-10-31 15:22 --------- d-----w E:\Program Files\Analog Devices
2007-10-31 15:20 --------- d--h--w E:\Program Files\InstallShield Installation Information
2007-10-31 15:20 --------- d-----w E:\Program Files\Intel
2007-10-31 15:20 --------- d-----w E:\Program Files\Common Files\InstallShield
2007-10-31 15:02 --------- d-----w E:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Smapp"="E:\Program Files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 17:36]
"IgfxTray"="E:\WINDOWS\system32\igfxtray.exe" [2002-09-09 00:18]
"HotKeysCmds"="E:\WINDOWS\system32\hkcmd.exe" [2002-09-09 00:05]
"IMONTRAY"="C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe" [2002-09-19 17:33]
"LWBMOUSE"="E:\Program Files\iBall\2.2\LWBWHEEL.exe" [2002-09-05 10:47]
"MULTIMEDIA KEYBOARD"="E:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2001-11-08 23:10]
"SlipStream"="E:\Program Files\TATA Indicom Web Accelerator\TATA_Indicom_Accelerator.exe" [2006-04-06 04:53]
"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"CoolSwitch"="E:\WINDOWS\system32\taskswitch.e xe" [2002-03-19 17:30]
"nod32kui"="E:\Program Files\Eset\nod32kui.exe" [2007-11-01 10:36]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Yahoo! Pager"="E:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43]
E:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - E:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-02 20

10]
hp psc 1000 series.lnk - E:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-02 21:08:34]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
DcomLaunch DcomLaunch
.
Contents of the 'Scheduled Tasks' folder
"2007-11-01 04:47:54 E:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1193892449.job"
- E:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
.
************************************************** ************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-01 12:49:13
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2007-11-01 12:49:44 - machine was rebooted
.
--- E O F ---
my virus is deleted?
i dunno bt sypware doctor is still sayin some adware in my pc and it removes it but again wen i scan it still shows