ComboFix 07-11-07.3 - Shahid Khalil 2007-11-07 15:17:35.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.50 [GMT 5:00]
Running from: D:\Documents and Settings\Shahid Khalil\Desktop\ComboFix.exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
D:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
D:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
D:\Documents and Settings\Shahid Khalil\Desktop\Live Safety Center.lnk
D:\Documents and Settings\Shahid Khalil\Desktop\Online Security Guide.lnk
D:\Documents and Settings\Shahid Khalil\Favorites\Online Security Guide.lnk
D:\WINDOWS\cookies.ini
D:\WINDOWS\svchost.ini
D:\WINDOWS\system32\del.bat
D:\WINDOWS\system32\nqtss.bak1
D:\WINDOWS\system32\nqtss.bak2
D:\WINDOWS\system32\nqtss.ini
D:\WINDOWS\system32\nqtss.ini2
D:\WINDOWS\system32\sstqn.dll
D:\WINDOWS\system32\xvifuwrp.dllbox
E:\Autorun.inf
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_NPF
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 )))))))))))))))))))))))))))))))
.
2007-11-07 15:33 <DIR> d--hs---- D:\FOUND.020
2007-11-07 15:13 79,936 --a------ D:\WINDOWS\system32\lqncrwkj.dll
2007-11-07 15:13 51,200 --a------ D:\WINDOWS\NirCmd.exe
2007-11-07 15:06 86,080 --a------ D:\WINDOWS\system32\iytxsecm.dll
2007-11-07 15:03 71,232 --a------ D:\WINDOWS\system32\tafmkrxp.exe
2007-11-07 15:02 145,984 --a------ D:\WINDOWS\system32\xvifuwrp.dll
2007-11-07 15:02 145,984 --a------ D:\WINDOWS\system32\lxwecspx.dll
2007-11-07 11:55 <DIR> d-------- D:\Documents and Settings\awais\Contacts
2007-11-06 23:19 36,352 --a------ D:\WINDOWS\system32\tuvtusp.dll
2007-11-06 17:05 81,472 --a------ D:\WINDOWS\system32\hvbgjeyp.dll
2007-11-06 13:04 81,472 --a------ D:\WINDOWS\system32\uvcqepix.dll
2007-11-06 13:03 87,104 --a------ D:\WINDOWS\system32\kwfttdoc.dll
2007-11-05 19:57 36,352 --a------ D:\WINDOWS\system32\iifdeee.dll
2007-11-05 19:55 36,352 --a------ D:\WINDOWS\system32\jkkkjgg.dll
2007-11-05 17:02 <DIR> d-------- D:\BackUpMSNCleaner
2007-11-02 22:43 <DIR> d-------- D:\Program Files\Trend Micro
2007-10-31 21:18 33,280 --a------ D:\WINDOWS\system32\cbxustu.dll
2007-10-31 21:04 10,752 -r-hs---- D:\WINDOWS\system32\asrsvc.exe
2007-10-30 17:56 <DIR> d-------- D:\Documents and Settings\Shahid Khalil\Application Data\AdobeUM
2007-10-30 16:51 <DIR> d-------- D:\Program Files\Common Files\Adobe
2007-10-30 16:39 <DIR> d-------- D:\WINDOWS\pss
2007-10-30 14:09 <DIR> d--hs---- D:\FOUND.019
2007-10-27 19:29 <DIR> d-------- D:\Program Files\Google
2007-10-27 13:14 <DIR> d-------- D:\Documents and Settings\awais\Application Data\SPAMfighter
2007-10-27 13:14 <DIR> d-------- D:\Documents and Settings\awais\Application Data\AVG7
2007-10-26 23:11 <DIR> d-------- D:\Program Files\Elcomsoft
2007-10-26 23:07 <DIR> d-------- D:\Program Files\Accent EXCEL Password Recovery
2007-10-26 21:35 <DIR> d--hs---- D:\FOUND.018
2007-10-26 15:20 <DIR> d--hs---- D:\FOUND.017
2007-10-25 18:23 <DIR> d-------- D:\Program Files\Common Files\Ankiro
2007-10-25 18:23 <DIR> d-------- D:\Documents and Settings\Shahid Khalil\Application Data\SPAMfighter
2007-10-25 18:22 <DIR> d-------- D:\Program Files\SPAMfighter
2007-10-25 18:22 <DIR> d-------- D:\Program Files\Common Files\Application
2007-10-25 18:12 <DIR> d-------- D:\Documents and Settings\Shahid Khalil\Application Data\AVG7
2007-10-25 18:11 <DIR> d-------- D:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-25 18:11 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-25 18:11 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\avg7
2007-10-22 17:32 <DIR> d--hs---- D:\FOUND.016
2007-10-18 17:09 <DIR> d--hs---- D:\FOUND.015
2007-10-08 09:28 <DIR> d--hs---- D:\FOUND.014
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-09-24 07:23 --------- d-----w D:\Program Files\Absolute MP3 Splitter
2007-09-24 07:05 --------- d-----w D:\Program Files\Cool MP3 Splitter
2007-09-21 04:22 --------- d-----w D:\Documents and Settings\awais\Application Data\eAcceleration
2007-09-17 13:11 --------- d-----w D:\Documents and Settings\Shahid Khalil\Application Data\LimeWire
2007-09-17 13:10 --------- d-----w D:\Program Files\LimeWire
2007-09-14 08:27 --------- d-----w D:\Documents and Settings\awais\Application Data\Teleca
2007-09-14 08:26 --------- d-----w D:\Documents and Settings\awais\Application Data\Sony Ericsson
2007-09-13 12:10 --------- d-----w D:\Documents and Settings\Shahid Khalil\Application Data\Teleca
2007-09-13 12:05 --------- d-----w D:\Documents and Settings\Shahid Khalil\Application Data\Sony Ericsson
2007-09-13 12:04 --------- d-----w D:\Program Files\Sony Ericsson
2007-09-13 12:04 --------- d-----w D:\Program Files\Common Files\Teleca Shared
2007-09-13 12:04 --------- d-----w D:\Program Files\Common Files\Sony Ericsson Shared
2007-09-13 12:03 --------- d-----w D:\Documents and Settings\All Users\Application Data\Teleca
2007-09-13 12:03 --------- d-----w D:\Documents and Settings\All Users\Application Data\Sony Ericsson
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1c43f756-9cda-409f-a57b-e06bf4546a8c}]
2007-11-07 15:13 79936 --a------ D:\WINDOWS\system32\lqncrwkj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{634BBAB7-3F60-4426-944F-A62B9007F67F}]
2007-11-05 19:55 36352 --a------ D:\WINDOWS\system32\jkkkjgg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-07 15:02 145984 --a------ D:\WINDOWS\system32\xvifuwrp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= D:\WINDOWS\system32\xvifuwrp.dll [2007-11-07 15:02 145984]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"vptray"="D:\Program Files\NavNT\vptray.exe" [2001-10-31 11:59]
"SPAMfighter Agent"="D:\Program Files\SPAMfighter\S***ent.exe" [2007-10-23 14:56]
"Application Layer Services"="asrsvc.exe" [2007-10-30 12:17 D:\WINDOWS\system32\asrsvc.exe]
"a0512da2"="D:\WINDOWS\system32\iytxsecm.dll" [2007-11-07 15:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MsnMsgr"="D:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"MSMSGS"="D:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:06]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:56]
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-07 14:08]
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks]
"{634BBAB7-3F60-4426-944F-A62B9007F67F}"= D:\WINDOWS\system32\jkkkjgg.dll [2007-11-05 19:55 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkkjgg]
jkkkjgg.dll 2007-11-05 19:55 36352 D:\WINDOWS\system32\jkkkjgg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xvifuwrp]
xvifuwrp.dll 2007-11-07 15:02 145984 D:\WINDOWS\system32\xvifuwrp.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
"Authentication Packages"= msv1_0 D:\WINDOWS\system32\sstqn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^Shahid Khalil^Start Menu^Programs^Startup^Encarta Dictionary Quickshelf.lnk]
path=D:\Documents and Settings\Shahid Khalil\Start Menu\Programs\Startup\Encarta Dictionary Quickshelf.lnk
backup=D:\WINDOWS\pss\Encarta Dictionary Quickshelf.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
D:\PROGRA~1\DAP\DAP.EXE /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"D:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
"D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
R2 SPAMfighter Update Service;SPAMfighter Update Service;"D:\Program Files\SPAMfighter\sfus.exe"
S3 s125bus;Sony Ericsson Device 125 driver (WDM);D:\WINDOWS\system32\DRIVERS\s125bus.sys
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;D:\WINDOWS\system32\DRIVERS\s125mdfl.sys
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;D:\WINDOWS\system32\DRIVERS\s125mdm.sys
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);D:\WINDOWS\system32\DRIVERS\s125mgmt.sys
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;D:\WINDOWS\system32\DRIVERS\s125obex.sys
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{587a6258-3479-11dc-8cc2-0002a5e36bb9}]
\Shell\AutoRun\command - RavMon.exe
\Shell\explore\Command - RavMon.exe -e
\Shell\open\Command - RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{587a6259-3479-11dc-8cc2-0002a5e36bb9}]
\Shell\AutoRun\command - fooool.exe
\Shell\explore\Command - fooool.exe
\Shell\open\Command - fooool.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{5b7b6158-cc02-11db-879c-806d6172696f}]
\Shell\AutoRun\command - RavMon.exe
\Shell\explore\Command - RavMon.exe -e
\Shell\open\Command - RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{d619ad7b-392b-11dc-a4de-806d6172696f}]
\Shell\AutoRun\command - RavMon.exe
\Shell\explore\Command - RavMon.exe -e
\Shell\open\Command - RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{d619ad7c-392b-11dc-a4de-806d6172696f}]
\Shell\AutoRun\command - RavMon.exe
\Shell\explore\Command - RavMon.exe -e
\Shell\open\Command - RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{d619ad7d-392b-11dc-a4de-806d6172696f}]
\Shell\AutoRun\command - RavMon.exe
\Shell\explore\Command - RavMon.exe -e
\Shell\open\Command - RavMon.exe
.
************************************************** ************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-07 15:37:44
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2007-11-07 15:39:43 - machine was rebooted
.
--- E O F ---