THe results of the Panda Antirootkit san
Items scanned 4020
Rootkits detected 0
known rootkits 0
unknown rootkits 0
Rootkits removed 0
Rootkits sent to PAnda 0
ComboFix 08-02.05.3 - edgar 2008-02-10 21:40:24.1 - NTFSx86
Running from: C:\Documents and Settings\edgar\Desktop\Techspot computer repair software\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\crap.1201817014.old
C:\Program Files\WinBudget\bin\matrix.dat
C:\Program Files\WinBudget\bin\matrix.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-11 to 2008-02-11 )))))))))))))))))))))))))))))))
.
2008-02-10 19:47 . 2008-02-10 19:47 <DIR> d-------- C:\VundoFix Backups
2008-02-10 18:10 . 2008-02-10 18:25 2,844 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-10 18:05 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-10 18:05 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-10 18:05 . 2008-02-08 23:55 85,504 --a------ C:\WINDOWS\system32\VACFix.exe
2008-02-10 18:05 . 2008-02-08 10:37 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-10 18:05 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-02-10 18:05 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-10 18:05 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-10 18:02 . 2008-02-10 18:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-10 17:57 . 2008-02-10 17:57 <DIR> d-------- C:\Program Files\Yahoo!
2008-02-10 17:57 . 2008-02-10 17:59 <DIR> d-------- C:\Program Files\CCleaner
2008-02-10 17:52 . 2008-02-10 17:52 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-10 17:52 . 2008-02-10 17:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-10 17:51 . 2008-02-10 17:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-10 17:44 . 2008-02-10 17:44 <DIR> d-------- C:\Documents and Settings\edgar\Application Data\Grisoft
2008-02-10 17:42 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-10 14:28 . 2008-02-10 14:26 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-10 14:26 . 2008-02-10 14:29 <DIR> d-------- C:\Documents and Settings\edgar\.housecall6.6
2008-02-10 13:48 . 2008-02-10 21:45 313,376 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-10 13:48 . 2008-02-10 20:40 5,456 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-10 13:43 . 2008-02-10 13:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-02-10 13:42 . 2007-11-14 16:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-02-10 13:42 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-02-10 13:42 . 2008-02-10 13:46 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-02-10 13:41 . 2008-02-10 13:41 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-10 13:39 . 2008-02-10 20:51 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-10 13:34 . 2008-02-10 13:35 <DIR> d-------- C:\Documents and Settings\edgar\Application Data\AVG7
2008-02-10 13:33 . 2008-02-10 13:33 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-10 13:32 . 2008-02-10 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-10 13:32 . 2008-02-10 14:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-09 19:33 . 2008-02-09 19:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-03 04:02 . 2008-02-03 04:02 13 --a------ C:\WINDOWS\C3EA-41F7-BFAC-EBF8.dat
2008-01-30 20:11 . 2008-01-30 20:11 <DIR> d-------- C:\WINDOWS\system32\bak
2008-01-27 14:23 . 2008-02-08 21:08 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-27 14:23 . 2008-01-27 14:23 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 23:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 22:49 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 22:37 --------- d-----w C:\Program Files\BitTorrent_DNA
2008-02-10 16:37 --------- d-----w C:\Documents and Settings\edgar\Application Data\Lavasoft
2008-02-09 02:08 --------- d-----w C:\Program Files\QuickTime
2008-02-03 04:27 --------- d-----w C:\Documents and Settings\edgar\Application Data\LimeWire
2008-01-24 13:42 --------- d-----w C:\Documents and Settings\edgar\Application Data\U3
2008-01-12 19:29 --------- d-----w C:\Documents and Settings\edgar\Application Data\BitTorrent
2008-01-09 03:00 --------- d-----w C:\Program Files\MP3 Player Utilities 4.15
2007-12-26 00:58 --------- d-----w C:\Program Files\USBToolbox
2007-12-26 00:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-11-14 21:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"Aim6"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2002-10-15 17:00 1818624 C:\WINDOWS\mixer.exe]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [ ]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\bak\qttask.exe" [2007-10-26 16:56 77824]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-10 14:09 579072]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-10 13:33 219136]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-04 00:31]
*Newly Created Service* - PHOOKS
*Newly Created Service* - PUTGOMFOPCIB
*Newly Created Service* - SDTHOOK
.
********************************************************************** ****
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-10 21:45:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************** ****
.
Completion time: 2008-02-10 21:48:44
ComboFix-quarantined-files.txt 2008-02-11 02:47:53
.
2008-01-10 04:21:59 --- E O F ---
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:45:13 PM 2/12/2008
+ Scan result:
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc201.txt -> TrackingCookie.Burstbeacon : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc202.txt -> TrackingCookie.Burstnet : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc35.txt -> TrackingCookie.Burstnet : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc56.txt -> TrackingCookie.Dealtime : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc157.txt -> TrackingCookie.Information : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc150.txt -> TrackingCookie.Liveperson : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc155.txt -> TrackingCookie.Msn : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc88.txt -> TrackingCookie.Msn : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc50.txt -> TrackingCookie.Overture : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc171.txt -> TrackingCookie.Tacoda : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc26.txt -> TrackingCookie.Tacoda : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc27.txt -> TrackingCookie.Tacoda : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc106.txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\edgar\Cookies\edgar@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc112.txt -> TrackingCookie.Webtrends : Cleaned.
F:\RECYCLER\S-1-5-21-1482476501-1580436667-1202660629-1003\Dc14.txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end