Merci
tu es genial ca a marcher le cheval de troie n apparait plus c cool. voici le rapport:
ComboFix 08-07-15.4 - CHRISTIAN 2008-07-16 22:36:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.508 [GMT 1:00]
Running from: C:\Documents and Settings\CHRISTIAN\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
/b/color
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
C:\WINDOWS\system32\ckvo.exe
C:\WINDOWS\system32\ckvo0.dll
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-06-16 to 2008-07-16 )))))))))))))))))))))))))))))))
.
2008-07-16 21:25 . 2008-07-16 21:25 268 --ah----- C:\sqmdata05.sqm
2008-07-16 21:25 . 2008-07-16 21:25 244 --ah----- C:\sqmnoopt05.sqm
2008-07-16 21:22 . 2008-07-16 21:23 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-07-16 20:51 . 2008-07-16 20:51 268 --ah----- C:\sqmdata04.sqm
2008-07-16 20:51 . 2008-07-16 20:51 244 --ah----- C:\sqmnoopt04.sqm
2008-07-16 20:47 . 2008-07-16 20:47 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-07-16 20:47 . 2005-10-15 18:20 12,106 --a------ C:\WINDOWS\system32\drivers\OsaFsLoc.sys
2008-07-16 20:47 . 2005-06-30 16:58 7,296 --a------ C:\WINDOWS\system32\drivers\osaio.sys
2008-07-16 20:47 . 2005-09-13 15:34 4,392 --a------ C:\WINDOWS\system32\drivers\NdisFilt.sys
2008-07-16 20:47 . 2005-01-14 15:57 4,010 --a------ C:\WINDOWS\system32\drivers\osanbm.sys
2008-07-16 19:56 . 2008-07-16 19:57 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-07-16 19:56 . 2008-07-16 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-07-16 19:04 . 2008-07-16 19:04 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-07-16 19:03 . 2008-07-16 19:03 <DIR> d-------- C:\Program Files\Real
2008-07-16 19:03 . 2008-07-16 19:04 <DIR> d-------- C:\Program Files\Common Files\Real
2008-07-16 18:52 . 2008-07-16 18:53 <DIR> d-------- C:\Program Files\Google
2008-07-16 18:52 . 2008-07-16 19:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-16 18:34 . 2008-07-16 21:58 115,233 -r-hs---- C:\p83gjy.exe
2008-07-16 18:31 . 2008-07-16 18:31 268 --ah----- C:\sqmdata03.sqm
2008-07-16 18:31 . 2008-07-16 18:31 244 --ah----- C:\sqmnoopt03.sqm
2008-07-16 18:30 . 2008-07-16 18:30 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-07-16 18:25 . 2008-07-16 18:25 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-16 18:23 . 2008-07-16 18:23 <DIR> d-------- C:\Program Files\SuperCopier2
2008-07-16 18:20 . 2008-07-16 18:20 <DIR> d-------- C:\Program Files\MSECache
2008-07-16 12:44 . 2008-07-16 12:44 268 --ah----- C:\sqmdata02.sqm
2008-07-16 12:44 . 2008-07-16 12:44 244 --ah----- C:\sqmnoopt02.sqm
2008-07-16 10:25 . 2008-07-16 10:25 268 --ah----- C:\sqmdata01.sqm
2008-07-16 10:25 . 2008-07-16 10:25 244 --ah----- C:\sqmnoopt01.sqm
2008-07-16 00:53 . 2008-07-16 00:53 268 --ah----- C:\sqmdata00.sqm
2008-07-16 00:53 . 2008-07-16 00:53 244 --ah----- C:\sqmnoopt00.sqm
2008-07-16 00:38 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-16 00:38 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-07-16 00:38 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-16 00:16 . 2008-07-16 00:16 <DIR> d-------- C:\Documents and Settings\CHRISTIAN\Application Data\Yahoo!
2008-07-16 00:16 . 2008-07-16 00:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-16 00:14 . 2008-07-16 00:14 <DIR> d-------- C:\Program Files\Windows Live Favorites
2008-07-16 00:13 . 2008-07-16 00:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-07-16 00:12 . 2008-07-16 00:15 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-07-16 00:10 . 2008-07-16 00:10 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-07-16 00:09 . 2008-07-16 00:10 <DIR> d-------- C:\Program Files\MSN Messenger
2008-07-15 23:52 . 2008-07-15 23:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-15 23:49 . 2008-07-15 23:50 <DIR> d-------- C:\Program Files\Yahoo!
2008-07-15 23:13 . 2008-07-15 23:13 162 --a------ C:\WINDOWS\ODBC.INI
2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Program Files\Microsoft Works
2008-07-15 23:03 . 2008-07-15 23:03 <DIR> d-------- C:\Program Files\MSBuild
2008-07-15 23:02 . 2008-07-15 23:02 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-07-15 23:00 . 2008-07-15 23:00 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-07-15 22:59 . 2008-07-15 23:03 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-07-15 22:59 . 2008-07-15 23:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-15 22:58 . 2008-07-15 22:58 <DIR> dr-h----- C:\MSOCache
2008-07-15 22:53 . 2008-07-16 21:28 77,312 -r-hs---- C:\WINDOWS\system32\ckvo1.dll
2008-07-15 22:52 . 2008-07-15 22:53 116,862 -r-hs---- C:\k.com
2008-07-15 21:55 . 2004-08-03 23:15 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-07-15 21:55 . 2004-08-03 23:15 82,944 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-07-15 21:55 . 2001-08-17 14:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-07-15 21:55 . 2001-08-17 14:00 54,272 --a--c--- C:\WINDOWS\system32\dllcache\swmidi.sys
2008-07-15 21:55 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-07-15 21:55 . 2004-08-03 23:07 52,864 --a--c--- C:\WINDOWS\system32\dllcache\dmusic.sys
2008-07-15 21:55 . 2004-08-03 23:07 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-07-15 21:55 . 2004-08-03 23:07 6,400 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-07-15 21:54 . 2004-08-03 23:07 171,776 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-07-15 21:54 . 2004-08-03 23:07 171,776 --a--c--- C:\WINDOWS\system32\dllcache\kmixer.sys
2008-07-15 21:54 . 2004-08-03 22:39 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-07-15 21:54 . 2004-08-03 22:39 142,464 --a--c--- C:\WINDOWS\system32\dllcache\aec.sys
2008-07-15 21:54 . 2004-08-03 23:15 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-07-15 21:54 . 2004-08-03 23:15 60,800 --a--c--- C:\WINDOWS\system32\dllcache\sysaudio.sys
2008-07-15 21:54 . 2004-08-03 22:58 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2008-07-15 21:54 . 2004-08-03 22:58 7,552 --a--c--- C:\WINDOWS\system32\dllcache\mskssrv.sys
2008-07-15 21:54 . 2004-08-03 23:07 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2008-07-15 21:54 . 2004-08-03 23:07 2,944 --a--c--- C:\WINDOWS\system32\dllcache\drmkaud.sys
2008-07-15 21:53 . 2008-07-15 21:53 <DIR> d-------- C:\Program Files\CONEXANT
2008-07-15 21:53 . 2004-08-03 22:58 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-07-15 21:53 . 2004-08-03 22:58 5,376 --a--c--- C:\WINDOWS\system32\dllcache\mspclock.sys
2008-07-15 21:53 . 2004-08-03 22:58 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2008-07-15 21:53 . 2004-08-03 22:58 4,992 --a--c--- C:\WINDOWS\system32\dllcache\mspqm.sys
2008-07-15 21:52 . 2008-07-15 21:52 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-07-15 21:51 . 2004-08-03 23:15 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-07-15 21:51 . 2004-08-03 23:15 145,792 --a--c--- C:\WINDOWS\system32\dllcache\portcls.sys
2008-07-15 21:51 . 2004-08-04 00:56 130,048 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-07-15 21:51 . 2004-08-04 00:56 130,048 --a--c--- C:\WINDOWS\system32\dllcache\ksproxy.ax
2008-07-15 21:51 . 2004-08-03 23:08 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-07-15 21:51 . 2004-08-03 23:08 60,288 --a--c--- C:\WINDOWS\system32\dllcache\drmk.sys
2008-07-15 21:51 . 2004-08-04 00:56 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-07-15 21:51 . 2004-08-04 00:56 4,096 --a--c--- C:\WINDOWS\system32\dllcache\ksuser.dll
2008-07-15 21:32 . 2008-07-15 21:32 <DIR> d-------- C:\WINDOWS\Options
2008-07-15 21:27 . 2008-07-15 21:27 <DIR> d-------- C:\Program Files\My Drivers
2008-07-15 21:09 . 2008-07-16 20:50 <DIR> d-------- C:\Program Files\InstallShield Installation Information
2008-07-15 21:08 . 2008-07-15 21:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-07-15 19:48 . 2008-07-02 18:21 113,731 -r-hs---- C:\xmnm2.cmd
2008-07-15 19:47 . 2008-07-15 19:53 <DIR> d-------- C:\Documents and Settings\CHRISTIAN\Application Data\U3
2008-07-15 13:05 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-15 00:45 . 2008-07-15 00:45 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-07-15 00:44 . 2008-07-15 00:44 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-07-15 00:44 . 2008-07-15 00:45 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-07-15 00:30 . 2008-07-16 21:28 15,778 --a------ C:\WINDOWS\system32\Config.MPF
2008-07-15 00:28 . 2008-07-16 20:53 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-07-15 00:28 . 2008-07-15 00:49 <DIR> d-------- C:\Documents and Settings\CHRISTIAN\Application Data\SiteAdvisor
2008-07-15 00:28 . 2005-04-20 19:22 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-07-15 00:28 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-07-15 00:27 . 2007-11-22 06:44 201,320 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-07-15 00:27 . 2007-11-22 06:44 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-07-15 00:27 . 2007-12-02 12:51 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-07-15 00:27 . 2007-11-22 06:44 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-07-15 00:27 . 2007-11-22 06:44 33,832 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-07-15 00:26 . 2008-07-15 00:26 <DIR> d-------- C:\Program Files\McAfee.com
2008-07-15 00:26 . 2008-07-15 21:59 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-07-15 00:26 . 2007-07-13 06:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-07-15 00:25 . 2008-07-15 22:22 <DIR> d-------- C:\Program Files\McAfee
2008-07-15 00:21 . 2008-07-15 00:21 <DIR> d--hs---- C:\Documents and Settings\CHRISTIAN\UserData
2008-07-15 00:20 . 2008-07-15 00:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-15 00:07 . 2008-06-13 14:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-15 00:07 . 2008-06-13 14:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-15 20:31 117,115 --sh--r C:\1yl2d.bat
2008-07-14 23:18 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-07-14 23:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-07-14 21:48 --------- d-----w C:\Program Files\Common Files\Softwin
2008-07-14 21:30 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-09-13 15:04 1,045,050 ----a-w C:\WINDOWS\inf\mydrivers.exe
2006-06-28 00:25 4,304,384 ----a-w C:\WINDOWS\inf\RtkHDAud.Sys
2006-06-16 03:57 119,808 ----a-w C:\WINDOWS\inf\Rtnic64.sys
2006-06-16 03:56 83,968 ----a-w C:\WINDOWS\inf\Rtnicxp.sys
2006-06-16 03:56 83,456 ----a-w C:\WINDOWS\inf\RTNIC.SYS
2006-06-12 01:00 990,592 ----a-w C:\WINDOWS\inf\HSF_DPV.sys
2006-06-12 00:59 727,808 ----a-w C:\WINDOWS\inf\HSF_CNXT.sys
2006-06-12 00:59 208,384 ----a-w C:\WINDOWS\inf\HSFHWAZL.sys
2006-05-24 18:19 74,752 ----a-w C:\WINDOWS\inf\ESM7SK.sys
2006-05-24 18:19 61,056 ----a-w C:\WINDOWS\inf\EMS7SK.sys
2006-05-24 18:19 40,064 ----a-w C:\WINDOWS\inf\ESD7SK.sys
2006-05-16 02:04 2,879,488 ----a-w C:\WINDOWS\inf\SkyTel.exe
2006-05-10 10:27 43,520 ----a-w C:\WINDOWS\inf\AmdK8.sys
2006-04-27 08:48 307,200 ----a-w C:\WINDOWS\inf\atiiiexx.dll
2006-04-27 08:47 258,048 ----a-w C:\WINDOWS\inf\ati2dvag.dll
2006-04-27 08:46 1,540,096 ----a-w C:\WINDOWS\inf\ati2mtag.sys
2006-04-27 08:41 77,824 ----a-w C:\WINDOWS\inf\Oemdspif.dll
2006-04-27 08:41 61,440 ----a-w C:\WINDOWS\inf\ati2evxx.dll
2006-04-27 08:41 41,984 ----a-w C:\WINDOWS\inf\ati2edxx.dll
2006-04-27 08:41 26,112 ----a-w C:\WINDOWS\inf\Ati2mdxx.exe
2006-04-27 08:41 114,688 ----a-w C:\WINDOWS\inf\atipdlxx.dll
2006-04-27 08:39 53,248 ----a-w C:\WINDOWS\inf\ATIDDC.DLL
2006-04-27 08:39 405,504 ----a-w C:\WINDOWS\inf\ati2evxx.exe
2006-04-27 08:31 2,693,280 ----a-w C:\WINDOWS\inf\ati3duag.dll
2006-04-27 08:25 1,408,000 ----a-w C:\WINDOWS\inf\ativvaxx.dll
2006-04-27 08:20 6,684,672 ----a-w C:\WINDOWS\inf\atioglx1.dll
2006-04-27 08:17 5,033,984 ----a-w C:\WINDOWS\inf\atioglxx.dll
2006-04-27 08:12 151,552 ----a-w C:\WINDOWS\inf\atikvmag.dll
2006-04-27 08:11 17,408 ----a-w C:\WINDOWS\inf\atitvo32.dll
2006-04-27 08:05 40,960 ----a-w C:\WINDOWS\inf\ati2erec.dll
2006-04-27 08:05 282,624 ----a-w C:\WINDOWS\inf\ati2cqag.dll
2006-03-16 01:06 118,784 ----a-w C:\WINDOWS\inf\Uci32105.dll
2006-03-14 16:01 16,010,752 ----a-w C:\WINDOWS\inf\RTHDCPL.EXE
2006-03-14 14:49 9,711,104 ----a-w C:\WINDOWS\inf\RTLCPL.EXE
2006-03-14 14:45 2,809,344 ----a-w C:\WINDOWS\inf\ALCWZRD.EXE
2006-03-10 18:32 2,158,592 ----a-w C:\WINDOWS\inf\MicCal.exe
2006-03-09 16:45 364,544 ----a-w C:\WINDOWS\inf\RtlUpd.exe
2006-03-03 12:11 81,920 ----a-w C:\WINDOWS\inf\InstNT.exe
2006-03-03 12:10 81,920 ----a-w C:\WINDOWS\inf\SynTPCo2.dll
2006-03-03 12:09 557,056 ----a-w C:\WINDOWS\inf\SynISDLL.dll
2006-03-03 12:09 225,280 ----a-w C:\WINDOWS\inf\Tutorial.exe
2006-03-03 12:08 86,106 ----a-w C:\WINDOWS\inf\SynTPLpr.exe
2006-03-03 12:08 69,722 ----a-w C:\WINDOWS\inf\SynTPFcs.dll
2006-03-03 12:07 761,946 ----a-w C:\WINDOWS\inf\SynTPEnh.exe
2006-03-03 11:59 6,135,898 ----a-w C:\WINDOWS\inf\SynTPCpl.dll
2006-03-03 11:56 41,063 ----a-w C:\WINDOWS\inf\SynTPCOM.dll
2006-03-03 11:55 94,298 ----a-w C:\WINDOWS\inf\SynTPAPI.dll
2006-03-03 11:55 82,013 ----a-w C:\WINDOWS\inf\SynCOM.dll
2006-03-03 11:55 114,688 ----a-w C:\WINDOWS\inf\SynCtrl.dll
2006-03-03 11:52 192,672 ----a-w C:\WINDOWS\inf\SynTP.sys
2006-03-03 11:51 163,840 ----a-w C:\WINDOWS\inf\SynZMetr.exe
2006-03-03 11:51 147,456 ----a-w C:\WINDOWS\inf\SynMood.exe
2006-02-24 15:32 266,240 ----a-w C:\WINDOWS\inf\RTCOMDLL.dll
2006-02-20 16:00 86,016 ----a-w C:\WINDOWS\inf\SOUNDMAN.EXE
2006-02-14 19:57 86,016 ----a-w C:\WINDOWS\inf\mdmxsdk.dll
2006-02-14 19:57 12,672 ----a-w C:\WINDOWS\inf\mdmxsdk.sys
2006-01-24 18:44 488,448 ----a-w C:\WINDOWS\inf\ar5211.sys
2005-12-13 09:32 577,536 ----a-w C:\WINDOWS\inf\HXFSetup.exe
2005-10-31 02:17 135,168 ----a-w C:\WINDOWS\inf\RtlCPAPI.dll
2005-05-03 02:43 69,632 ----a-w C:\WINDOWS\inf\Alcmtr.exe
2005-01-07 16:07 138,752 ----a-w C:\WINDOWS\inf\Hdaudbus.sys
2004-12-09 13:54 46,592 ----a-w C:\WINDOWS\inf\smcirda.sys
2004-12-08 20:04 5,120 ----a-w C:\WINDOWS\inf\FILTRCOI.DLL
2004-12-07 22:10 16,896 ----a-w C:\WINDOWS\inf\DKbFltr.SYS
2001-11-09 10:01 24,064 ----a-w C:\WINDOWS\inf\ativcoxx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 11:00 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 17:43 4670704]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [2006-07-07 17:45 1052672]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-16 18:52 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-07-16 19:03 185632]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2006-07-31 16:03 35416]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-14 17:01 16010752 C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f9931c0-5266-11dd-9642-0016d4670dd2}]
\Shell\AutoRun\command - H:\1yl2d.bat
\Shell\explore\Command - H:\1yl2d.bat
\Shell\open\Command - H:\1yl2d.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f9931c1-5266-11dd-9642-0016d4670dd2}]
\Shell\AutoRun\command - I:\1yl2d.bat
\Shell\explore\Command - I:\1yl2d.bat
\Shell\open\Command - I:\1yl2d.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9843b3de-5319-11dd-964c-0016d4670dd2}]
\Shell\AutoRun\command - H:\k.com
\Shell\explore\Command - H:\k.com
\Shell\open\Command - H:\k.com
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-07-16 21:09:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-07-15 00:01:44 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2008-07-14 23:26:30 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe.4158 0
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-kamsoft - C:\WINDOWS\system32\ckvo.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-16 22:38:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\mc21.tmp"
.
Completion time: 2008-07-16 22:39:00
ComboFix-quarantined-files.txt 2008-07-16 21:38:56
Pre-Run: 16,164,728,832 bytes free
Post-Run: 16,469,401,600 bytes free
288 --- E O F --- 2008-07-15 20:58:18