Respital
Active Member
Hey cf... 
I just ran combofix.exe...
Can someone tell me what it did....
Here's the log file:
ComboFix 08-06-20.4 - mdg 06/26/2008 21:56:19.1 - NTFSx86
Running from: C:\Documents and Settings\mdg\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\sysdm.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 01:59 --------- d-----w C:\Program Files\PeerGuardian2
2008-06-27 01:56 --------- d-----w C:\Documents and Settings\mdg\Application Data\uTorrent
2008-06-27 00:00 --------- d-----w C:\Program Files\SiteAdvisor
2008-06-26 23:50 2,414 ----a-w C:\WINDOWS\system32\tmp.reg
2008-06-26 21:50 --------- d-----w C:\Documents and Settings\mdg\Application Data\OpenOffice.org2
2008-06-26 20:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-26 20:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-26 20:09 --------- d-----w C:\Program Files\CyberLink
2008-06-26 19:56 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-06-26 19:55 --------- d-----w C:\Program Files\Java
2008-06-26 19:40 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-06-26 02:58 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-26 02:58 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-26 02:58 --------- d-----w C:\Program Files\Real
2008-06-26 02:58 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-26 02:58 --------- d-----w C:\Program Files\Common Files\Real
2008-06-26 02:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-26 02:54 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-26 02:49 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-06-26 02:49 --------- d-----w C:\Documents and Settings\mdg\Application Data\Malwarebytes
2008-06-26 02:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-26 02:30 --------- d-----w C:\Program Files\Google Earth Pro 4.2
2008-06-26 02:01 --------- d-----w C:\Program Files\McAfee
2008-06-24 17:10 --------- d-----w C:\Program Files\Infogrames Interactive
2008-06-24 03:34 82,432 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
2008-06-23 17:38 --------- d-----w C:\Program Files\SpeedFan
2008-06-23 17:38 --------- d-----w C:\Program Files\ShortKeys2
2008-06-23 00:01 --------- d-----w C:\Documents and Settings\mdg\Application Data\SiteAdvisor
2008-06-19 21:48 34,296 ----a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-19 21:47 17,144 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-06-18 19:16 2,842 -c--a-w C:\Documents and Settings\Kuzniak\Application Data\wklnhst.dat
2008-06-18 18:30 --------- d-----w C:\Documents and Settings\Kuzniak\Application Data\Skype
2008-06-18 18:28 --------- d-----w C:\Documents and Settings\Kuzniak\Application Data\McAfee
2008-06-18 18:27 --------- d-----w C:\Documents and Settings\Kuzniak\Application Data\SiteAdvisor
2008-06-18 03:03 --------- d-----w C:\Program Files\Yahoo!
2008-06-18 02:48 --------- d-----w C:\Program Files\Lavasoft
2008-06-18 02:48 --------- d-----w C:\Documents and Settings\mdg\Application Data\Lavasoft
2008-06-18 02:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-18 02:47 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-17 17:26 --------- d-----w C:\Program Files\HammerHead
2008-06-17 00:06 10,942 -c--a-w C:\Documents and Settings\mdg\Application Data\wklnhst.dat
2008-06-11 22:42 --------- d-----w C:\Program Files\Steam
2008-06-01 00:44 --------- d-----w C:\Documents and Settings\mdg\Application Data\Nero
2008-06-01 00:41 --------- d-----w C:\Program Files\Common Files\Nero
2008-06-01 00:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-06-01 00:38 --------- d-----w C:\Program Files\Nero
2008-05-31 21:14 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-30 23:25 106 ----a-w C:\delete.bat
2008-05-30 15:02 --------- d-----w C:\Documents and Settings\mdg\Application Data\McAfee
2008-05-30 15:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-05-29 13:35 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-05-28 23:19 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-05-28 23:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-28 23:18 --------- d-----w C:\Program Files\Common Files\McAfee
2008-05-28 23:16 --------- d-----w C:\Program Files\McAfee.com
2008-05-28 23:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-05-26 02:52 --------- d-----w C:\Program Files\Paint.NET
2008-05-26 02:51 --------- d-----w C:\Program Files\QuickTime
2008-05-26 02:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-24 04:11 --------- d-----w C:\Documents and Settings\mdg\Application Data\HPAppData
2008-05-24 00:54 --------- d-----w C:\Program Files\7-Zip
2008-05-23 22:21 81,920 ----a-w C:\WINDOWS\system32\404Fix.exe
2008-05-22 17:33 --------- d-----w C:\Program Files\Trymedia
2008-05-20 23:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-05-20 21:11 --------- d-----w C:\Documents and Settings\mdg\Application Data\HP
2008-05-19 01:40 82,944 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-05-18 22:17 --------- d-----w C:\Program Files\nLite
2008-05-18 21:16 --------- d-----w C:\Documents and Settings\LocalService\Application Data\HP
2008-05-18 21:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-05-18 21:14 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\HPAppData
2008-05-18 21:14 --------- d-----w C:\Program Files\HP
2008-05-18 21:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-05-18 21:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-05-18 21:11 --------- d-----w C:\Program Files\Common Files\HP
2008-05-18 21:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-05-18 21:10 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-05-18 21:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-05-18 18:35 --------- d-----w C:\Program Files\Copysafe
2008-05-18 18:35 --------- d-----w C:\Program Files\ATITool
2008-05-18 17:58 --------- d-----w C:\Program Files\Incomplete
2008-05-18 02:19 --------- d-----w C:\Program Files\Lavalys
2008-05-18 01:48 --------- d-----w C:\Program Files\Electronic Arts
2008-05-16 21:59 --------- d-----w C:\Program Files\Common Files\ATI Technologies
2008-05-16 21:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-16 20:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-16 17:41 --------- d-----w C:\Documents and Settings\mdg\Application Data\Skype
2008-05-16 17:40 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-12 16:23 --------- d-----w C:\Documents and Settings\mdg\Application Data\Xfire
2008-05-11 20:47 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-05-11 20:47 --------- d-----w C:\Documents and Settings\mdg\Application Data\SUPERAntiSpyware.com
2008-05-11 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 20:41 --------- d-----w C:\Program Files\Trend Micro
2008-04-29 15:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2007-04-29 21:26 374 -c--a-w C:\Documents and Settings\mdg\Application Data\internaldb6334.dat
2007-04-29 21:25 18,432 ----a-w C:\Documents and Settings\mdg\Application Data\internaldb41.dat
2007-04-29 21:24 538 -c--a-w C:\Documents and Settings\mdg\Application Data\internaldb8467.dat
2006-12-06 03:57 59,952 -c--a-w C:\Documents and Settings\Kuzniak\Application Data\GDIPFONTCACHEV1.DAT
2007-10-17 00:35 56 --sh--r C:\WINDOWS\system32\CF7EBFD16D.sys
2007-10-17 00:38 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
06/13/2007 06:23 1617920 5411554c84b28fc522ca788aaf3d2e44 C:\WINDOWS\explorer.exe
06/13/2007 07:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
08/10/2004 08:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
06/13/2007 06:23 1617920 5411554c84b28fc522ca788aaf3d2e44 C:\WINDOWS\icon_TMP\explorer.exe
06/13/2007 06:23 4918784 a4d32bd82c68d8f1407064ad8d2b9ccb C:\WINDOWS\system_backup\explorer.exe
06/13/2007 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 2097488]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [09/18/2005 18:40 1421824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/10/2004 05:04 59392]
"RTHDCPL"="RTHDCPL.EXE" [02/26/2007 15:03 16125440 C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [05/03/2005 18:43 69632 C:\WINDOWS\Alcmtr.exe]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [08/12/2005 14:43 45056]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [03/11/2007 21:34 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 23:37 413696]
"Cleanup"="C:\DOCUME~1\mdg\LOCALS~1\Temp\2008528191321_mcappins.exe" [ ]
"msci"="C:\DOCUME~1\mdg\LOCALS~1\Temp\2008528191318_mcinfo.exe" [ ]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [06/21/2007 19:12 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [11/30/2007 05:42 1164576]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [01/16/2007 13:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [01/08/2007 11:22 20480]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 19:12 582992]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/25/2008 22:58 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 144784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^mdg^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\mdg\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 09/18/2007 10:16 171464 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps]
--a------ 03/15/2007 23:58 781992 C:\FRAPS\FRAPS.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iconcache]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder]
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 10/13/2004 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 12/03/2007 14:21 2213160 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 03/01/2007 14:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
--a------ 09/18/2005 18:40 1421824 C:\Program Files\PeerGuardian2\pg2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 03/28/2008 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 08/31/2007 17:40 22879528 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 05/16/2006 18:04 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 12/02/2007 14:58 1266936 c:\program files\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 09/25/2007 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 02/29/2008 16:03 1481968 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
--a------ 06/29/2006 19:55 707376 C:\WINDOWS\vVX3000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrB"=3 (0x3)
"PnkBstrA"=2 (0x2)
"NBService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Dcfssvc"=2 (0x2)
"BITS"=2 (0x2)
"ATI Smart"=2 (0x2)
"aspnet_state"=3 (0x3)
"AppMgmt"=3 (0x3)
"ALG"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\half-life 2 deathmatch\\hl2.exe"=
"C:\\Program Files\\KODAK\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\day of defeat source\\hl2.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
*Newly Created Service* - 0233271214445745MCINSTCLEANUP
*Newly Created Service* - CATCHME
*Newly Created Service* - KLIF
*Newly Created Service* - NPKCRYPT
*Newly Created Service* - NPPTNT2
*Newly Created Service* - PGFILTER
*Newly Created Service* - SITEADVISOR_SERVICE
.
Contents of the 'Scheduled Tasks' folder
"2008-05-28 23:16:37 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-05-28 23:16:36 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-26 22:00:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 06/26/2008 22:01:47
ComboFix-quarantined-files.txt 2008-06-27 02:01:37
Pre-Run: 155,036,164,096 bytes free
Post-Run: 155,401,019,392 bytes free
279 --- E O F --- 2008-05-11 20:00:11
I just ran combofix.exe...
Can someone tell me what it did....
Here's the log file:
ComboFix 08-06-20.4 - mdg 06/26/2008 21:56:19.1 - NTFSx86
Running from: C:\Documents and Settings\mdg\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\sysdm.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 01:59 --------- d-----w C:\Program Files\PeerGuardian2
2008-06-27 01:56 --------- d-----w C:\Documents and Settings\mdg\Application Data\uTorrent
2008-06-27 00:00 --------- d-----w C:\Program Files\SiteAdvisor
2008-06-26 23:50 2,414 ----a-w C:\WINDOWS\system32\tmp.reg
2008-06-26 21:50 --------- d-----w C:\Documents and Settings\mdg\Application Data\OpenOffice.org2
2008-06-26 20:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-26 20:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-26 20:09 --------- d-----w C:\Program Files\CyberLink
2008-06-26 19:56 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-06-26 19:55 --------- d-----w C:\Program Files\Java
2008-06-26 19:40 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-06-26 02:58 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-26 02:58 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-26 02:58 --------- d-----w C:\Program Files\Real
2008-06-26 02:58 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-26 02:58 --------- d-----w C:\Program Files\Common Files\Real
2008-06-26 02:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-26 02:54 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-26 02:49 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-06-26 02:49 --------- d-----w C:\Documents and Settings\mdg\Application Data\Malwarebytes
2008-06-26 02:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-26 02:30 --------- d-----w C:\Program Files\Google Earth Pro 4.2
2008-06-26 02:01 --------- d-----w C:\Program Files\McAfee
2008-06-24 17:10 --------- d-----w C:\Program Files\Infogrames Interactive
2008-06-24 03:34 82,432 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
2008-06-23 17:38 --------- d-----w C:\Program Files\SpeedFan
2008-06-23 17:38 --------- d-----w C:\Program Files\ShortKeys2
2008-06-23 00:01 --------- d-----w C:\Documents and Settings\mdg\Application Data\SiteAdvisor
2008-06-19 21:48 34,296 ----a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-19 21:47 17,144 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-06-18 19:16 2,842 -c--a-w C:\Documents and Settings\Kuzniak\Application Data\wklnhst.dat
2008-06-18 18:30 --------- d-----w C:\Documents and Settings\Kuzniak\Application Data\Skype
2008-06-18 18:28 --------- d-----w C:\Documents and Settings\Kuzniak\Application Data\McAfee
2008-06-18 18:27 --------- d-----w C:\Documents and Settings\Kuzniak\Application Data\SiteAdvisor
2008-06-18 03:03 --------- d-----w C:\Program Files\Yahoo!
2008-06-18 02:48 --------- d-----w C:\Program Files\Lavasoft
2008-06-18 02:48 --------- d-----w C:\Documents and Settings\mdg\Application Data\Lavasoft
2008-06-18 02:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-18 02:47 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-17 17:26 --------- d-----w C:\Program Files\HammerHead
2008-06-17 00:06 10,942 -c--a-w C:\Documents and Settings\mdg\Application Data\wklnhst.dat
2008-06-11 22:42 --------- d-----w C:\Program Files\Steam
2008-06-01 00:44 --------- d-----w C:\Documents and Settings\mdg\Application Data\Nero
2008-06-01 00:41 --------- d-----w C:\Program Files\Common Files\Nero
2008-06-01 00:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-06-01 00:38 --------- d-----w C:\Program Files\Nero
2008-05-31 21:14 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-30 23:25 106 ----a-w C:\delete.bat
2008-05-30 15:02 --------- d-----w C:\Documents and Settings\mdg\Application Data\McAfee
2008-05-30 15:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-05-29 13:35 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-05-28 23:19 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-05-28 23:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-28 23:18 --------- d-----w C:\Program Files\Common Files\McAfee
2008-05-28 23:16 --------- d-----w C:\Program Files\McAfee.com
2008-05-28 23:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-05-26 02:52 --------- d-----w C:\Program Files\Paint.NET
2008-05-26 02:51 --------- d-----w C:\Program Files\QuickTime
2008-05-26 02:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-24 04:11 --------- d-----w C:\Documents and Settings\mdg\Application Data\HPAppData
2008-05-24 00:54 --------- d-----w C:\Program Files\7-Zip
2008-05-23 22:21 81,920 ----a-w C:\WINDOWS\system32\404Fix.exe
2008-05-22 17:33 --------- d-----w C:\Program Files\Trymedia
2008-05-20 23:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-05-20 21:11 --------- d-----w C:\Documents and Settings\mdg\Application Data\HP
2008-05-19 01:40 82,944 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-05-18 22:17 --------- d-----w C:\Program Files\nLite
2008-05-18 21:16 --------- d-----w C:\Documents and Settings\LocalService\Application Data\HP
2008-05-18 21:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-05-18 21:14 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\HPAppData
2008-05-18 21:14 --------- d-----w C:\Program Files\HP
2008-05-18 21:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-05-18 21:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-05-18 21:11 --------- d-----w C:\Program Files\Common Files\HP
2008-05-18 21:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-05-18 21:10 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-05-18 21:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-05-18 18:35 --------- d-----w C:\Program Files\Copysafe
2008-05-18 18:35 --------- d-----w C:\Program Files\ATITool
2008-05-18 17:58 --------- d-----w C:\Program Files\Incomplete
2008-05-18 02:19 --------- d-----w C:\Program Files\Lavalys
2008-05-18 01:48 --------- d-----w C:\Program Files\Electronic Arts
2008-05-16 21:59 --------- d-----w C:\Program Files\Common Files\ATI Technologies
2008-05-16 21:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-16 20:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-16 17:41 --------- d-----w C:\Documents and Settings\mdg\Application Data\Skype
2008-05-16 17:40 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-12 16:23 --------- d-----w C:\Documents and Settings\mdg\Application Data\Xfire
2008-05-11 20:47 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-05-11 20:47 --------- d-----w C:\Documents and Settings\mdg\Application Data\SUPERAntiSpyware.com
2008-05-11 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 20:41 --------- d-----w C:\Program Files\Trend Micro
2008-04-29 15:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2007-04-29 21:26 374 -c--a-w C:\Documents and Settings\mdg\Application Data\internaldb6334.dat
2007-04-29 21:25 18,432 ----a-w C:\Documents and Settings\mdg\Application Data\internaldb41.dat
2007-04-29 21:24 538 -c--a-w C:\Documents and Settings\mdg\Application Data\internaldb8467.dat
2006-12-06 03:57 59,952 -c--a-w C:\Documents and Settings\Kuzniak\Application Data\GDIPFONTCACHEV1.DAT
2007-10-17 00:35 56 --sh--r C:\WINDOWS\system32\CF7EBFD16D.sys
2007-10-17 00:38 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
06/13/2007 06:23 1617920 5411554c84b28fc522ca788aaf3d2e44 C:\WINDOWS\explorer.exe
06/13/2007 07:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
08/10/2004 08:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
06/13/2007 06:23 1617920 5411554c84b28fc522ca788aaf3d2e44 C:\WINDOWS\icon_TMP\explorer.exe
06/13/2007 06:23 4918784 a4d32bd82c68d8f1407064ad8d2b9ccb C:\WINDOWS\system_backup\explorer.exe
06/13/2007 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 2097488]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [09/18/2005 18:40 1421824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/10/2004 05:04 59392]
"RTHDCPL"="RTHDCPL.EXE" [02/26/2007 15:03 16125440 C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [05/03/2005 18:43 69632 C:\WINDOWS\Alcmtr.exe]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [08/12/2005 14:43 45056]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [03/11/2007 21:34 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 23:37 413696]
"Cleanup"="C:\DOCUME~1\mdg\LOCALS~1\Temp\2008528191321_mcappins.exe" [ ]
"msci"="C:\DOCUME~1\mdg\LOCALS~1\Temp\2008528191318_mcinfo.exe" [ ]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [06/21/2007 19:12 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [11/30/2007 05:42 1164576]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [01/16/2007 13:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [01/08/2007 11:22 20480]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 19:12 582992]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/25/2008 22:58 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 144784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^mdg^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\mdg\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 09/18/2007 10:16 171464 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps]
--a------ 03/15/2007 23:58 781992 C:\FRAPS\FRAPS.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iconcache]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder]
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 10/13/2004 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 12/03/2007 14:21 2213160 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 03/01/2007 14:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
--a------ 09/18/2005 18:40 1421824 C:\Program Files\PeerGuardian2\pg2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 03/28/2008 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 08/31/2007 17:40 22879528 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 05/16/2006 18:04 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 12/02/2007 14:58 1266936 c:\program files\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 09/25/2007 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 02/29/2008 16:03 1481968 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
--a------ 06/29/2006 19:55 707376 C:\WINDOWS\vVX3000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrB"=3 (0x3)
"PnkBstrA"=2 (0x2)
"NBService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Dcfssvc"=2 (0x2)
"BITS"=2 (0x2)
"ATI Smart"=2 (0x2)
"aspnet_state"=3 (0x3)
"AppMgmt"=3 (0x3)
"ALG"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\half-life 2 deathmatch\\hl2.exe"=
"C:\\Program Files\\KODAK\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\day of defeat source\\hl2.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
*Newly Created Service* - 0233271214445745MCINSTCLEANUP
*Newly Created Service* - CATCHME
*Newly Created Service* - KLIF
*Newly Created Service* - NPKCRYPT
*Newly Created Service* - NPPTNT2
*Newly Created Service* - PGFILTER
*Newly Created Service* - SITEADVISOR_SERVICE
.
Contents of the 'Scheduled Tasks' folder
"2008-05-28 23:16:37 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-05-28 23:16:36 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-26 22:00:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 06/26/2008 22:01:47
ComboFix-quarantined-files.txt 2008-06-27 02:01:37
Pre-Run: 155,036,164,096 bytes free
Post-Run: 155,401,019,392 bytes free
279 --- E O F --- 2008-05-11 20:00:11