Hi john,
I did run the combofix again and here is the file that i could not find before.
ComboFix 08-10-06.01 - vali 2008-10-07 11:59:50.2 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2290 [GMT 1:00]
Running from: C:\Documents and Settings\vali\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\agxjkwcg.ini
C:\WINDOWS\system32\bhraspsi.ini
C:\WINDOWS\system32\fccaWOEW.dll
C:\WINDOWS\system32\knXyGfhk.ini
C:\WINDOWS\system32\knXyGfhk.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\refbrbcv.ini
C:\WINDOWS\system32\tbpgomms.ini
C:\WINDOWS\system32\upelejdv.ini
C:\WINDOWS\system32\vatpdchi.ini
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-09-07 to 2008-10-07 )))))))))))))))))))))))))))))))
.
2008-10-07 11:43 . 2008-10-07 11:43 324,564 --a------ C:\WINDOWS\system32\tuvTmMeE.dll
2008-10-06 21:29 . 2008-10-06 21:29 324,564 --a------ C:\WINDOWS\system32\ljJAQGxw.dll
2008-10-06 20:29 . 2008-10-06 20:29 324,564 --a------ C:\WINDOWS\system32\khfGwWOG.dll
2008-10-06 18:47 . 2008-10-06 18:47 <DIR> d-------- C:\Documents and Settings\vali\Application Data\OnlineArmor
2008-10-06 18:47 . 2008-10-06 18:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OnlineArmor
2008-10-06 18:47 . 2008-04-17 05:25 80,584 --a------ C:\WINDOWS\system32\drivers\OADriver.sys
2008-10-06 18:47 . 2008-04-17 05:25 32,456 --a------ C:\WINDOWS\system32\drivers\OAmon.sys
2008-10-06 18:47 . 2008-04-17 05:25 28,872 --a------ C:\WINDOWS\system32\drivers\oanet.sys
2008-10-06 16:36 . 2008-10-06 16:37 324,564 --a------ C:\WINDOWS\system32\ljjIaWOf.dll
2008-10-06 15:56 . 2008-10-06 15:56 <DIR> d-------- C:\Documents and Settings\vali\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-10-06 13:36 . 2008-10-06 13:36 324,564 --a------ C:\WINDOWS\system32\pMDuSMDu.dll
2008-10-05 22:00 . 2008-10-05 22:00 325,982 --a------ C:\WINDOWS\system32\urqPfgEx.dll
2008-10-05 21:00 . 2008-10-05 21:00 325,982 --a------ C:\WINDOWS\system32\geBqOHAQ.dll
2008-10-05 20:00 . 2008-10-05 20:00 325,982 --a------ C:\WINDOWS\system32\urqOHAQh.dll
2008-10-05 19:00 . 2008-10-05 19:00 325,982 --a------ C:\WINDOWS\system32\rqRIxwTN.dll
2008-10-05 16:00 . 2008-10-05 16:00 325,982 --a------ C:\WINDOWS\system32\urqOEwVo.dll
2008-10-05 15:00 . 2008-10-05 15:00 325,666 --a------ C:\WINDOWS\system32\efcAPICU.dll
2008-10-05 14:28 . 2008-10-05 14:28 <DIR> d-------- C:\Documents and Settings\vali\Application Data\dvdcss
2008-10-05 14:27 . 2008-10-05 14:27 <DIR> d-------- C:\Program Files\VideoLAN
2008-10-05 14:19 . 2008-10-05 14:19 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-10-05 14:09 . 2008-10-05 14:09 0 --a------ C:\WINDOWS\iPlayer.INI
2008-10-05 14:06 . 2008-10-05 14:06 <DIR> d-------- C:\Program Files\InterActual
2008-10-05 14:00 . 2008-10-05 14:00 325,982 --a------ C:\WINDOWS\system32\ddcCRHYr.dll
2008-10-04 19:26 . 2008-10-04 19:26 324,564 --a------ C:\WINDOWS\system32\jkkJaAqP.dll
2008-10-04 18:11 . 2008-10-04 18:11 324,564 --a------ C:\WINDOWS\system32\mlJAtQGa.dll
2008-10-01 21:18 . 2008-10-01 21:18 <DIR> d--hs---- C:\FOUND.003
2008-09-30 22:53 . 2008-09-30 22:53 <DIR> d-------- C:\Program Files\iPod
2008-09-30 22:53 . 2008-09-30 22:53 <DIR> d-------- C:\Documents and Settings\vali\Application Data\Apple Computer
2008-09-30 22:53 . 2008-09-30 22:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-30 22:53 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\system32\GEARAspi.dll
2008-09-30 22:53 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-09-30 22:52 . 2008-09-30 22:52 <DIR> d-------- C:\Program Files\QuickTime
2008-09-30 22:52 . 2008-09-30 22:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-30 22:51 . 2008-09-30 22:51 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-30 21:54 . 2008-09-30 21:54 <DIR> d--hs---- C:\FOUND.002
2008-09-30 19:09 . 2008-09-30 19:09 <DIR> d--hs---- C:\FOUND.001
2008-09-30 18:28 . 2008-09-30 18:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-30 17:23 . 2008-09-30 17:23 <DIR> d--hs---- C:\FOUND.000
2008-09-29 21:43 . 2008-09-29 21:43 <DIR> d-------- C:\Program Files\Kontiki
2008-09-29 11:33 . 2008-09-29 11:33 <DIR> d-------- C:\Documents and Settings\vali\Application Data\Uniblue
2008-09-27 18:43 . 2008-09-27 18:43 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-09-26 16:57 . 2008-09-26 16:57 <DIR> d-------- C:\WINDOWS\Bs350u2
2008-09-26 16:57 . 2004-12-02 20:23 605,312 --a------ C:\WINDOWS\system32\drivers\Bs350u2.sys
2008-09-26 16:57 . 2004-10-07 20:38 81,920 --a------ C:\WINDOWS\system\vfwExtC.dll
2008-09-26 16:57 . 2004-10-07 20:25 77,824 --a------ C:\WINDOWS\system\FiltProp.dll
2008-09-26 16:57 . 2004-11-29 12:36 40,960 --a------ C:\WINDOWS\Bs350u2r.exe
2008-09-26 16:57 . 2003-09-22 13:49 15,190 --a------ C:\WINDOWS\M1000Twn.ini
2008-09-26 16:57 . 2003-09-22 14:36 13,448 --a------ C:\WINDOWS\M1000Twn.src
2008-09-26 16:57 . 2004-06-17 22:23 12,537 --a------ C:\WINDOWS\system\S10H0110.csr
2008-09-26 16:57 . 2004-06-26 17:39 11,528 --a------ C:\WINDOWS\system\S10F0110.csr
2008-09-26 16:57 . 2004-06-16 20:38 3,031 --a------ C:\WINDOWS\system32\drivers\C10H0110.bin
2008-09-26 16:57 . 2004-06-16 20:38 3,031 --a------ C:\WINDOWS\system32\drivers\C10F0110.bin
2008-09-26 14:56 . 2008-09-26 14:56 <DIR> d-------- C:\Program Files\MagicDisc
2008-09-24 13:07 . 2008-09-24 13:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-05 13:19 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-10-05 13:19 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-09-04 13:03 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-09-04 12:58 --------- d-----w C:\Program Files\NOS
2008-09-04 12:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\NOS
2008-09-04 11:15 --------- d-----w C:\Program Files\PowerISO
2008-09-04 11:02 --------- d-----w C:\Documents and Settings\vali\Application Data\Canon
2008-09-03 23:49 --------- d-----w C:\Program Files\Apple Software Update
2008-09-03 23:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-09-03 14:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\ALM
2008-09-03 14:02 --------- d-----w C:\Program Files\Bonjour
2008-09-03 13:58 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-09-03 13:42 --------- d-----w C:\Program Files\MagicISO
2008-09-02 22:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-02 21:50 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-02 17:41 --------- d-----w C:\Program Files\DNA
2008-09-01 12:00 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-01 11:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-09-01 11:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Channel4
2008-08-29 21:09 --------- d-----w C:\Program Files\Real
2008-08-29 21:09 --------- d-----w C:\Program Files\Common Files\Real
2008-08-29 19:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-08-29 09:18 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 08:53 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
2008-08-28 22:46 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-08-28 22:43 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-28 22:42 --------- d-----w C:\Program Files\Windows Live
2008-08-28 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-28 22:38 --------- d-----w C:\Documents and Settings\vali\Application Data\skypePM
2008-08-28 22:37 --------- d-----w C:\Program Files\Skype
2008-08-28 22:37 --------- d-----w C:\Program Files\Google
2008-08-28 22:37 --------- d-----w C:\Program Files\Common Files\Skype
2008-08-28 22:37 --------- d-----w C:\Documents and Settings\vali\Application Data\Skype
2008-08-28 22:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-08-28 22:11 --------- d-----w C:\Program Files\ESET
2008-08-28 22:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-28 19:57 --------- d-----w C:\Program Files\WIDCOMM
2008-08-28 19:56 --------- d-----w C:\Program Files\Wlan
2008-08-28 19:53 --------- d-----w C:\Program Files\Synaptics
2008-08-28 19:44 --------- d-----w C:\Program Files\Realtek
2008-08-28 19:41 --------- d-----w C:\Program Files\Intel
2008-08-28 19:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-28 19:40 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-28 19:32 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-18 12:27 34,312 ----a-w C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-08-18 12:19 53,256 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-08-18 12:18 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 21:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 21:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33AC7D18-DC35-4D1A-940E-AFD5FC5C3327}]
2006-01-26 16:39 38272 --a------ C:\WINDOWS\system32\cbXRKCvT.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-08-12 21741864]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-08-28 171448]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 1032640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-04-29 5898240]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-04-29 102490]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-04-29 708698]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 1447168]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2006-09-09 196608]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 1032640]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="D:\Programs\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"OnlineArmor GUI"="D:\Programs\Online Armor\oaui.exe" [2008-04-17 5545536]
"PtiuPbmd"="ptipbm.dll" [2005-01-14 C:\WINDOWS\system32\ptipbm.dll]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-08-12 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-29 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2005-04-29 C:\WINDOWS\ALCWZRD.EXE]
"nwiz"="nwiz.exe" [2005-04-29 C:\WINDOWS\system32\nwiz.exe]
"CHotkey"="mHotkey.exe" [2001-12-26 C:\WINDOWS\mHotkey.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WLAN Configuration Utility.lnk - C:\Program Files\Wlan\IPN2220\wlan_ui.exe [2004-11-08 454656]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-03-03 512061]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{33AC7D18-DC35-4D1A-940E-AFD5FC5C3327}"= "C:\WINDOWS\system32\cbXRKCvT.dll" [2006-01-26 38272]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXRKCvT]
2006-01-26 16:39 38272 C:\WINDOWS\system32\cbXRKCvT.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\System32\\USMT\\MIGWIZ.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\Programs\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-08-18 34312]
R1 OADevice;OADriver;C:\WINDOWS\system32\drivers\OADriver.sys [2008-04-17 80584]
R1 OAmon;OAmon;C:\WINDOWS\system32\drivers\OAmon.sys [2008-04-17 32456]
R1 OAnet;OAnet;C:\WINDOWS\system32\drivers\OAnet.sys [2008-04-17 28872]
R3 Slazldrv;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\SLDRV\slazldrv.sys [2005-04-29 230448]
S2 SvcOnlineArmor;Online Armor;D:\Programs\Online Armor\oasrv.exe [2008-04-17 5435968]
S3 CB54G3;Wireless CB54G3/MP54G3 Wireless LAN Card Driver;C:\WINDOWS\system32\DRIVERS\i2220ntx.sys [2004-04-27 148480]
.
Contents of the 'Scheduled Tasks' folder
2008-09-10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{4A1E7A41-7B76-4991-B5E7-8A1CBC2C808E} - C:\WINDOWS\system32\khfGyXnk.dll
HKCU-Run-Uniblue RegistryBooster 2009 - D:\Programs\Uniblue\RegistryBooster\RegistryBooster.exe
HKLM-Run-484c15da - C:\WINDOWS\system32\vdjelepu.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\vali\Application Data\Mozilla\Firefox\Profiles\ckajjtx5.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.grapevinejobs.com/home.asp.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-07 12:00:56
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\mchInjDrv]
"ImagePath"="\??\C:\WINDOWS\TEMP\mc21.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\cbXRKCvT.dll
.
Completion time: 2008-10-07 12:01:19
ComboFix-quarantined-files.txt 2008-10-07 11:01:18
Pre-Run: 934,232,064 bytes free
Post-Run: 927,547,392 bytes free
241 --- E O F --- 2008-10-06 17:46:28
Plus
File iTunesHelper.exe received on 10.07.2008 05:18:40 (CET)
Current status: finished
Result: 0/36 (0.00%)
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2008.10.3.2 2008.10.06 -
AntiVir 7.8.1.34 2008.10.06 -
Authentium 5.1.0.4 2008.10.07 -
Avast 4.8.1248.0 2008.10.06 -
AVG 8.0.0.161 2008.10.06 -
BitDefender 7.2 2008.10.07 -
CAT-QuickHeal 9.50 2008.10.06 -
ClamAV 0.93.1 2008.10.07 -
DrWeb 4.44.0.09170 2008.10.06 -
eSafe 7.0.17.0 2008.10.07 -
eTrust-Vet 31.6.6132 2008.10.06 -
Ewido 4.0 2008.10.06 -
F-Prot 4.4.4.56 2008.10.06 -
F-Secure 8.0.14332.0 2008.10.07 -
Fortinet 3.113.0.0 2008.10.07 -
GData 19 2008.10.07 -
Ikarus T3.1.1.34.0 2008.10.07 -
K7AntiVirus 7.10.486 2008.10.06 -
Kaspersky 7.0.0.125 2008.10.06 -
McAfee 5398 2008.10.04 -
Microsoft 1.4005 2008.10.07 -
NOD32 3498 2008.10.07 -
Norman 5.80.02 2008.10.06 -
Panda 9.0.0.4 2008.10.06 -
PCTools 4.4.2.0 2008.10.06 -
Prevx1 V2 2008.10.07 -
Rising 20.65.02.00 2008.10.06 -
SecureWeb-Gateway 6.7.6 2008.10.06 -
Sophos 4.34.0 2008.10.07 -
Sunbelt 3.1.1707.1 2008.10.07 -
Symantec 10 2008.10.07 -
TheHacker 6.3.1.0.102 2008.10.07 -
TrendMicro 8.700.0.1004 2008.10.06 -
VBA32 3.12.8.6 2008.10.07 -
ViRobot 2008.10.6.1408 2008.10.06 -
VirusBuster 4.5.11.0 2008.10.06 -
Additional information
Tamano archivo: 289576 bytes
MD5...: a7fa648719063b234a434a089fc0f49d
SHA1..: 65b7190c139ad06092480bd502918eeb3115d94e
SHA256: 544edfeb784b4a77483c16130129fd43faa2a39042c86da09e17e1274c024862
SHA512: b7e309ed78a113cc8663711f401cbf4aeb169ace8b5c0eb4385f30aa505a0928
23299e5cceac38fc2668239b5fcd6d39a7281c1a9c06932749bfdd655ef6664e
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x411b41
timedatestamp.....: 0x48c5fda7 (Tue Sep 09 04:37:59 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1fa28 0x1fc00 6.62 f7606c21e6174c896f95ff2c5a8d1fd6
.rdata 0x21000 0x7d82 0x7e00 5.36 5c517f597e50fde9999a1f0e768a843a
.data 0x29000 0x3e40 0x2000 4.10 bc5c3a3808d2a1f868c9047a80c09764
.rsrc 0x2d000 0x16f68 0x17000 5.35 ab6b3268bd420eeb2a8cec8c7b24ee3b
.reloc 0x44000 0x46e2 0x4800 4.03 0ce68e73dd10d1fc63f58ccc3f6e11f3
( 9 imports )
> VERSION.dll: GetFileVersionInfoA, GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueA, GetFileVersionInfoSizeA
> WININET.dll: HttpSendRequestA, InternetCloseHandle, InternetConnectA, InternetOpenA, InternetReadFile, InternetQueryDataAvailable, HttpQueryInfoA, HttpOpenRequestA, InternetGetConnectedState
> SETUPAPI.dll: SetupDiDestroyDeviceInfoList, CM_Get_Device_IDW, SetupDiGetDeviceRegistryPropertyW, SetupDiGetClassDevsW, SetupDiEnumDeviceInfo
> KERNEL32.dll: LCMapStringW, LCMapStringA, HeapSize, GetStdHandle, ExitProcess, HeapCreate, HeapDestroy, GetConsoleMode, GetConsoleCP, MultiByteToWideChar, WideCharToMultiByte, lstrlenW, RaiseException, InitializeCriticalSection, DeleteCriticalSection, GetLastError, lstrlenA, lstrcmpiA, EnterCriticalSection, LeaveCriticalSection, GetCurrentThreadId, IsDBCSLeadByte, GetModuleFileNameA, InterlockedIncrement, InterlockedDecrement, FreeLibrary, SizeofResource, LoadResource, FindResourceA, LoadLibraryExA, GetModuleHandleA, ResetEvent, SetEvent, GetCommandLineA, CloseHandle, CreateEventA, CreateProcessA, Sleep, WaitForMultipleObjects, CreateEventW, WaitForSingleObject, CreateThread, FlushInstructionCache, GetCurrentProcess, Process32Next, Process32First, CreateToolhelp32Snapshot, SetLastError, WriteFile, SetFilePointer, CreateFileA, ProcessIdToSessionId, GetCurrentProcessId, TerminateThread, GetExitCodeThread, SetStdHandle, FlushFileBuffers, CreateFileW, OutputDebugStringA, GetModuleFileNameW, DebugBreak, GlobalFree, GlobalAlloc, GetLocaleInfoW, GetUserDefaultLCID, GetSystemDefaultLangID, LoadLibraryW, GetProcAddress, VerifyVersionInfoA, VerSetConditionMask, LoadLibraryA, CreateMutexW, HeapSetInformation, ReleaseMutex, CreateMutexA, GetSystemDirectoryA, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, IsValidCodePage, GetOEMCP, GetCPInfo, GetFileAttributesA, GetStartupInfoA, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetLocalTime, GetTickCount, ExitThread, GetSystemTimeAsFileTime, GetTimeZoneInformation, HeapReAlloc, RtlUnwind, VirtualQuery, GetSystemInfo, VirtualProtect, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, HeapAlloc, GetProcessHeap, HeapFree, InterlockedCompareExchange, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CompareStringA, CompareStringW, SetEnvironmentVariableA, FreeEnvironmentStringsA, QueryPerformanceCounter, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, CopyFileW, GetEnvironmentStrings, GetStringTypeW, GetStringTypeA, InterlockedExchange
> USER32.dll: SetPropA, GetDesktopWindow, MessageBeep, CreateDialogParamA, GetForegroundWindow, GetWindowThreadProcessId, AttachThreadInput, IsIconic, SetForegroundWindow, PostQuitMessage, ShowWindow, DefWindowProcA, DispatchMessageA, TranslateMessage, PostThreadMessageA, CharUpperA, SetWindowLongA, UnhookWindowsHookEx, SetWindowsHookExA, DestroyWindow, CallNextHookEx, CharNextA, SetDlgItemTextA, SendDlgItemMessageA, SetWindowTextA, PostMessageA, GetPropA, CreateWindowExA, RegisterClassA, KillTimer, LoadStringA, wsprintfA, GetMessageA, UnregisterClassA, SendMessageA
> ADVAPI32.dll: RegOpenKeyW, RegQueryValueExW, RegQueryValueExA, GetUserNameA, RegEnumKeyExA, RegQueryInfoKeyA, RegSetValueExA, RegOpenKeyExA, RegCreateKeyExA, RegCloseKey, RegDeleteValueA, RegDeleteKeyA, RegOpenKeyExW
> ole32.dll: CoInitialize, CoRegisterClassObject, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, StringFromGUID2, CoCreateInstance, CoRevokeClassObject, CoUninitialize, CoInitializeEx, GetRunningObjectTable, CreateClassMoniker
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -
> SHLWAPI.dll: PathFileExistsA
( 0 exports )
Thank you