Voilà le rapport de combofix:
ComboFix 08-06-20.4 - Antonys 2008-06-24 11:59:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.659 [GMT 2:00]
Running from: C:\Documents and Settings\antonys\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\antonys\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\system32\1F6F.tmp
C:\WINDOWS\system32\1F72.tmp
C:\WINDOWS\system32\1F75.tmp
c:\windows\system32\audiohq.exe
C:\WINDOWS\system32\dllcache\winlogon.exe
C:\WINDOWS\system32\kdsyq.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\1F6F.tmp
C:\WINDOWS\system32\1F72.tmp
C:\WINDOWS\system32\1F75.tmp
C:\WINDOWS\system32\dllcache\winlogon.exe
C:\WINDOWS\system32\pskill.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-24 to 2008-06-24 )))))))))))))))))))))))))))))))
.
2008-06-17 18:24 . 2008-06-17 18:25 <DIR> d-------- C:\WINDOWS\ERUNT
2008-06-17 18:11 . 2008-06-17 13:12 <DIR> d-------- C:\SDFix
2008-06-17 10:13 . 2008-06-17 11:35 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-06-17 10:13 . 2008-06-17 11:35 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-06-17 10:12 . 2008-06-17 10:12 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-06-17 10:12 . 2008-06-24 11:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-16 19:58 . 2002-11-15 17:34 224,768 --a------ C:\WINDOWS\system32\dsquery.exe
2008-06-16 19:56 . 2008-06-24 12:04 1,290,272 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-16 19:56 . 2008-06-24 12:04 294,944 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-16 19:56 . 2008-06-24 12:04 12,208 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-16 19:56 . 2008-06-24 12:04 3,136 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-16 18:46 . 2008-06-16 18:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-06-16 18:12 . 2008-06-16 18:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-16 16:33 . 2008-06-16 16:33 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-16 16:33 . 2008-06-16 16:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-16 15:56 . 2008-06-16 19:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-16 15:16 . 2008-06-16 15:16 18,473,000 --a------ C:\Program Files\sdsetup.exe
2008-06-16 14:17 . 2008-06-16 14:17 19,153,264 --a------ C:\Program Files\Lavasoft_Adaware_multi.exe
2008-06-16 14:17 . 2008-06-16 14:17 104 --a------ C:\Recycle Bin.lnk
2008-06-16 14:15 . 2008-06-16 14:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-16 13:15 . 2008-06-16 13:15 586 --a------ C:\idxh2o.exe
2008-06-11 18:31 . 2008-06-11 18:31 <DIR> d-------- C:\WINDOWS\htmCache
2008-06-11 10:00 . 2008-06-16 13:29 <DIR> d-------- C:\Mes fichiers
2008-06-06 16:45 . 1998-06-17 18:07 57,344 --a------ C:\WINDOWS\system32\Mfc42loc.dll
2008-06-06 16:26 . 2008-05-18 13:10 4,096,056 --a------ C:\WINDOWS\ExpQAS_Wallpaper8x5.bmp
2008-06-06 16:26 . 2008-05-18 13:12 3,932,216 --a------ C:\WINDOWS\ExpQAS_Wallpaper5x3.bmp
2008-06-06 16:26 . 2008-05-18 13:09 3,686,456 --a------ C:\WINDOWS\ExpQAS_Wallpaper16x9.bmp
2008-06-06 16:26 . 2008-05-18 13:08 3,145,784 --a------ C:\WINDOWS\ExpQAS_Wallpaper4x3.bmp
2008-06-06 16:26 . 2008-05-18 13:08 3,145,784 --a------ C:\WINDOWS\ExpQAS_Wallpaper.bmp
2008-06-03 19:16 . 2008-06-03 19:16 14 --a------ C:\WINDOWS\system32\SystemInfo32.sys
2008-06-03 19:15 . 2008-06-03 19:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD X Studios
2008-06-03 17:50 . 2008-06-03 17:50 <DIR> d-------- C:\Documents and Settings\antonys\Application Data\vlc
2008-06-03 17:49 . 2008-06-03 17:49 <DIR> d-------- C:\Program Files\VideoLAN
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-24 09:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\vulScan
2008-06-24 08:08 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-06-18 09:34 2,927 ----a-w C:\Program Files\qabwv010.ssn
2008-06-18 08:40 1,232,896 ----a-w C:\Program Files\qabwv010.idb
2008-06-17 08:28 504,320 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-06-16 17:45 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-11 07:07 --------- d-----w C:\Documents and Settings\antonys\Application Data\AdobeUM
2008-05-22 09:15 2,727 ----a-w C:\Program Files\qabwv009.ssn
2008-05-19 11:04 2,213,888 ----a-w C:\Program Files\qabwv009.idb
2008-05-16 09:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-13 09:33 27,008 ----a-w C:\WINDOWS\system32\drivers\Krx30.sys
2008-04-29 09:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 09:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 09:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-25 16:22 206,088 ----a-w C:\WINDOWS\system32\klogon.dll
2008-04-25 16:21 26,964 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
2008-04-24 09:18 --------- d-----w C:\Program Files\Experian Ltd
2008-04-24 07:36 202,827 ----a-w C:\WINDOWS\system32\atasnt40.dll
2007-10-12 10:10 602,112 ----a-w C:\Program Files\qabwv001.idb
2007-07-25 13:49 3,344 ----a-w C:\Program Files\qabwv001.ssn
2007-05-22 09:29 245,760 ----a-w C:\Program Files\qabwv008.idb
2007-05-22 09:29 2,664 ----a-w C:\Program Files\qabwv008.ssn
2007-03-15 11:23 2,201,600 ----a-w C:\Program Files\qabwv007.idb
2007-03-15 10:54 3,223 ----a-w C:\Program Files\qabwv007.ssn
2007-03-15 07:58 2,111,488 ----a-w C:\Program Files\qabwv006.idb
2007-03-14 18:09 2,571 ----a-w C:\Program Files\qabwv006.ssn
2007-02-28 11:45 1,415,168 ----a-w C:\Program Files\qabwv005.idb
2007-02-28 11:33 2,980 ----a-w C:\Program Files\qabwv005.ssn
2007-02-14 17:36 2,923 ----a-w C:\Program Files\qabwv004.ssn
2007-02-06 13:03 770,048 ----a-w C:\Program Files\qabwv004.idb
2007-01-23 10:36 245,760 ----a-w C:\Program Files\qabwv003.idb
2007-01-23 10:31 2,716 ----a-w C:\Program Files\qabwv003.ssn
2007-01-22 13:58 1,003,520 ----a-w C:\Program Files\qabwv000.idb
2007-01-22 13:54 3,244 ----a-w C:\Program Files\qabwv000.ssn
2007-01-22 13:28 921,600 ----a-w C:\Program Files\qabwv002.idb
2007-01-22 13:23 3,106 ----a-w C:\Program Files\qabwv002.ssn
.
------- Sigcheck -------
2008-06-17 10:28 504320 50b7f5952fa2b0564596a454121a93e6 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-18_ 9.41.15.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-18 07:19:26 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-24 10:05:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2006-07-25 11:12:01 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-06-24 08:08:41 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2006-07-25 11:12:01 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-06-24 08:08:41 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-07-25 11:12:01 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-06-24 08:08:41 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2006-07-25 11:12:01 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-06-24 08:08:41 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2006-07-25 11:12:01 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-06-24 08:08:41 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-07-25 11:12:01 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-06-24 08:08:42 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-07-25 11:12:01 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-06-24 08:08:42 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2006-07-25 11:12:01 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-06-24 08:08:42 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-07-25 11:12:01 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-06-24 08:08:41 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-07-25 11:12:01 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-06-24 08:08:41 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-07-25 11:12:01 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-06-24 08:08:42 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-07-25 11:12:01 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-06-24 08:08:41 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-07-25 11:12:01 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-06-24 08:08:41 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2000-08-31 06:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 06:00:00 28,672 ----a-w C:\WINDOWS\Nircmd.exe
- 2008-06-18 07:22:11 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-24 10:08:06 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-06-18 07:22:11 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-06-24 10:08:06 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-06-18 07:22:11 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-24 10:08:08 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2002-11-15 13:34:46 218,624 ----a-w C:\WINDOWS\system32\dsget.exe
+ 2002-11-15 15:34:46 218,624 ----a-w C:\WINDOWS\system32\dsget.exe
- 2008-06-18 07:22:47 209,198 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
+ 2008-06-24 10:08:39 209,206 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
- 2008-06-16 14:32:51 72,744 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-06-24 08:11:29 72,744 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-06-16 14:32:51 441,616 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-06-24 08:11:29 441,616 ----a-w C:\WINDOWS\system32\perfh009.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
2008-04-25 18:22 62728 --a------ C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2002-01-11 22:47 401496]
"msnmsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 10:11 1388544]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-25 11:32 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-25 11:29 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-25 11:32 114688]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-13 11:12 88209 C:\WINDOWS\AGRSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 01:56 143360]
"IntelAPMClient"="C:\Program Files\LANDesk\LDClient\amclient.exe" [2005-08-30 08:05 307200]
"LANDeskInventoryClient"="C:\Program Files\LANDesk\LDClient\LDIScn32.exe" [2005-11-18 16:54 823296]
"LANDeskVulscanClient"="C:\Program Files\LANDesk\LDClient\vulScan.exe" [2006-01-06 02:00 892928]
"SDClientMonitor"="C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe" [2005-08-30 07:55 258048]
"Reg2Reg2"="C:\Program Files\LANDesk\LDClient\REG2REG2.EXE" [2005-12-12 09:47 77824]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-10-17 16:05 77824]
"C:\WINDOWS\system32\kdsyq.exe"="C:\WINDOWS\system32\kdsyq.exe" [ ]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 18:21 201992]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Firewall Client Connectivity Monitor.LNK - C:\Program Files\Microsoft Firewall Client\ISATRAY.EXE [2005-07-06 13:26:01 52496]
QuickAddress Pro (2).lnk - C:\Program Files\qas\QuickAddress Pro\KEEPPRO.exe [2008-04-14 15:22:43 176192]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisablePersonalDirChange"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"Intellimenus"= 1 (0x1)
"NoSimpleStartMenu"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoAutoUpdate"= 0 (0x0)
"NoStartMenuEjectPC"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoAutoTrayNotify"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\
0\
0]
"Script"=\\qas.com\SYSVOL\qas.com\scripts\shutdown_par.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\
0\
0]
"Script"=\\qas\sysvol\qas.com\scripts\startup_par.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2138838754-819666832-1349916565-16607\Scripts\Logon\
0\
0]
"Script"=\\qas.com\SysVol\qas.com\scripts\REVISED_login_paris_main.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2138838754-819666832-1349916565-24255\Scripts\Logon\
0\
0]
"Script"=\\qas.com\SysVol\qas.com\scripts\REVISED_login_lon_main.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2138838754-819666832-1349916565-25650\Scripts\Logon\
0\
0]
"Script"=\\qas.com\SysVol\qas.com\scripts\REVISED_login_paris_main.bat
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ciO63.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Iqy86.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Coordialis 2.0 PADI.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Coordialis 2.0 PADI.lnk
backup=C:\WINDOWS\pss\Coordialis 2.0 PADI.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DialMessenger]
C:\Program Files\DialMessenger\dialmessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\MsnMsgr.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\CBA\\pds.exe"=
"C:\\Program Files\\LANDesk\\LDClient\\tmcsvc.exe"=
"%windir%\\system32\\msgsys.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\LANDesk\\Shared Files\\residentagent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"137:UDP"= 137:UDP:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:@xpsp2res.dll,-22002
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"67:TCP"= 67:TCP:LANDesk(R) PXE TCP Port
"67:UDP"= 67:UDP:LANDesk(R) PXE UDP Port
"9535:TCP"= 9535:TCP:LANDesk(R) Remote Control Agent TCP Port
"9535:UDP"= 9535:UDP:LANDesk(R) Remote Control Agent UDP Port
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29]
R2 CBA8;LANDesk(R) Management Agent;"C:\Program Files\LANDesk\Shared Files\residentagent.exe" [2006-01-11 10:32]
R2 ProWeb;ProWeb;D:\QAS\WORLDP~1\ProWeb5.17\QASWVDN.EXE [2007-03-23 12:26]
R2 testwrapper;Test Wrapper Sample Application;C:\TGJSERVER\bin\windows\wrapper.exe [2004-10-01 13:24]
R2 VPN-1;VPN-1 Module;C:\WINDOWS\system32\drivers\vpn.sys [2004-04-01 17:48]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-04 00:26]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2004-09-02 12:30]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07]
R3 ldblank;Screen Blanking driver for Remote Control;C:\WINDOWS\system32\DRIVERS\ldblank.sys [2005-07-01 19:48]
R3 ldmirror;ldmirror;C:\WINDOWS\system32\DRIVERS\ldmirror.sys [2005-07-01 19:48]
R3 mirrorflt;Mirror Filter Driver for Uninstall;C:\WINDOWS\system32\DRIVERS\mirrorflt.sys [2005-07-01 19:48]
R3 OMVA;VPN-1 SecureClient Adapter;C:\WINDOWS\system32\DRIVERS\OMVA.sys [2004-04-01 17:48]
S0 Iqy86;Iqy86;C:\WINDOWS\system32\Drivers\Iqy86.sys []
S0 Sai18;Sai18;C:\WINDOWS\system32\Drivers\Sai18.sys []
S1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys []
S1 kbd;kbd;C:\WINDOWS\system32\drivers\kbd.sys []
S2 Softmon;LANDesk(R) Software Monitoring Service;"C:\Program Files\LANDesk\LDClient\softmon.exe" []
S3 QAPWWActiveX 4.02;QuickAddress Pro Web ActiveX Adaptor 4.02;D:\QAS\ids\proweb4.03\QAPWWSV.EXE [2003-12-18 13:30]
S3 wampapache;wampapache;"c:\wamp\apache2\bin\httpd.exe" -k runservice []
S3 wampmysqld;wampmysqld;c:\wamp\mysql\bin\mysqld-nt.exe [2007-07-06 13:14]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d74ba08-3d11-11dd-9f3d-545543445200}]
\Shell\AutoRun\command - jfvkcsy.bat
\Shell\explore\Command - jfvkcsy.bat
\Shell\open\Command - jfvkcsy.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7beab8d5-8217-11dc-9ec9-00166f7929a7}]
\Shell\AutoRun\command - F:\FRA_GUI.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-24 12:09:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\scardsvr.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\LANDesk\LDClient\LocalSch.EXE
C:\WINDOWS\system32\cba\pds.exe
C:\Program Files\LANDesk\LDClient\tmcsvc.exe
C:\PROGRA~1\LANDesk\LDClient\issuser.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe
C:\TGJSERVER\jre\bin\java.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\qas\QuickAddress Pro\QAPROWN.EXE
.
**************************************************************************
.
Completion time: 2008-06-24 12:12:36 - machine was rebooted [Antonys]
ComboFix-quarantined-files.txt 2008-06-24 10:12:30
ComboFix2.txt 2008-06-18 07:41:42
Pre-Run: 5,621,186,560 bytes free
Post-Run: 5,608,665,088 bytes free
300 --- E O F --- 2008-02-06 16:01:58