ComboFix 09-03-06.02 - RobSusan 2009-03-09 22:16:34.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1687 [GMT -6:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) FW: Kaspersky Internet Security *disabled* . ((((((((((((((((((((((((( Files Created from 2009-02-10 to 2009-03-10 ))))))))))))))))))))))))))))))) . 2009-03-09 22:15 . 2009-03-09 22:15 d-------- c:\windows\LastGood 2009-02-27 18:06 . 2009-02-27 18:06 d-------- c:\program files\Audible 2009-02-27 18:06 . 2001-08-17 22:43 24,576 --------- c:\windows\system32\msxml3a.dll 2009-02-27 17:44 . 2009-02-27 17:44 d-------- c:\program files\FreeRIP3 2009-02-27 17:44 . 2009-02-27 17:44 d-------- c:\documents and settings\All Users\Application Data\FreeRIP 2009-02-27 17:17 . 2009-02-27 18:02 378 --a------ c:\windows\cdplayer.ini 2009-02-27 16:49 . 2009-02-27 16:49 d-------- C:\f8c8832aea5bf442f1 2009-02-27 16:42 . 2009-02-27 18:52 d-------- c:\program files\Best Buy Rhapsody 2009-02-27 16:37 . 2009-02-27 16:37 d-------- c:\documents and settings\RobSusan\Application Data\ArcSoft 2009-02-27 16:36 . 2009-02-27 16:36 d-------- c:\program files\Common Files\ArcSoft 2009-02-27 16:36 . 2009-02-27 16:36 d-------- c:\program files\ArcSoft 2009-02-27 16:36 . 2006-01-24 10:20 1,645,320 --a------ c:\windows\system32\GdiPlus.dll 2009-02-27 16:36 . 2005-06-21 10:29 245,408 --a------ c:\windows\system32\unicows.dll 2009-02-27 14:36 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\65254764.sys 2009-02-26 19:45 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\96992922.sys 2009-02-26 14:17 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\88965794.sys 2009-02-26 13:35 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\97959155.sys 2009-02-26 13:33 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\49053800.sys 2009-02-26 13:22 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\[u]0[/u]1043849.sys 2009-02-26 12:41 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\64046267.sys 2009-02-26 09:10 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\17392811.sys 2009-02-26 08:52 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\63052452.sys 2009-02-26 08:41 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\24449345.sys 2009-02-25 21:34 . 2009-02-25 21:39 250 --a------ c:\windows\gmer.ini 2009-02-14 15:11 . 2009-02-14 15:11 d-------- c:\program files\File Shredder . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-10 04:14 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-03-10 04:13 368,672 --sha-w c:\windows\system32\drivers\fidbox2.dat 2009-03-10 04:13 2,340 --sha-w c:\windows\system32\drivers\fidbox2.idx 2009-03-10 04:13 13,288 --sha-w c:\windows\system32\drivers\fidbox.idx 2009-03-10 04:13 1,562,656 --sha-w c:\windows\system32\drivers\fidbox.dat 2009-02-28 00:53 --------- d-----w c:\program files\Real 2009-02-27 22:36 --------- d--h--w c:\program files\InstallShield Installation Information 2009-02-27 19:56 --------- d-----w c:\program files\Registry Easy 2009-02-06 02:18 33,808 ----a-w c:\windows\system32\drivers\klbg.sys 2009-02-04 00:39 89,601 ----a-w c:\windows\system32\drivers\klick.dat 2009-02-04 00:39 101,287 ----a-w c:\windows\system32\drivers\klin.dat 2009-01-30 03:02 410,984 ----a-w c:\windows\system32\deploytk.dll 2009-01-30 03:02 --------- d-----w c:\program files\Java 2009-01-26 12:37 --------- d-----w c:\program files\RegistryPatrol3.0 2009-01-19 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\STOPzilla! 2009-01-19 03:10 --------- d-----w c:\documents and settings\All Users\Application Data\SITEguard 2009-01-19 03:08 --------- d-----w c:\program files\Common Files\iS3 2009-01-13 01:44 3,766 --sha-w c:\windows\system32\KGyGaAvL.sys 2009-01-13 01:42 --------- d-----w c:\documents and settings\RobSusan\Application Data\Corel Photo Album 2009-01-10 20:31 1,236,480 ----a-w c:\windows\system32\msxml3.dll 2009-01-10 20:31 1,236,480 ----a-w c:\windows\system32\dllcache\msxml3.dll 2009-01-05 01:45 0 ----a-w C:\register.bat . ------- Sigcheck ------- 2008-10-16 04:37 659456 6f1e4bfd78c4e0d05ff3725d59b72925 c:\windows\SoftwareDistributionOld1\Download\7bc58354ca50aa200544caaef7677c8a\SP2GDR\wininet.dll 2008-10-16 04:20 667648 93c9d0a216498ee14eb9b26119bb95ee c:\windows\SoftwareDistributionOld1\Download\7bc58354ca50aa200544caaef7677c8a\SP2QFE\wininet.dll 2008-10-15 19:00 666112 1576318bf08d28cc61d1278114ad8d5b c:\windows\SoftwareDistributionOld1\Download\7bc58354ca50aa200544caaef7677c8a\SP3GDR\wininet.dll 2008-10-15 19:04 667136 e8fce58a470999350f64c591557f9e42 c:\windows\SoftwareDistributionOld1\Download\7bc58354ca50aa200544caaef7677c8a\SP3QFE\wininet.dll 2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\system32\wininet.dll 2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\system32\dllcache\wininet.dll 2004-08-10 03:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\system32\drivers\tcpip.sys 2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntkrnlpa.exe 2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntkrnlpa.exe 2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntkrnlpa.exe 2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntkrnlpa.exe 2005-06-22 18:05 2015744 65f4b29a0793adb5d924fb3f47f1bca4 c:\windows\system32\ntkrnlpa.exe 2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntoskrnl.exe 2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntoskrnl.exe 2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntoskrnl.exe 2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntoskrnl.exe 2005-06-22 18:30 2136064 5611f453c6d20ab0552956f39bcddb88 c:\windows\system32\ntoskrnl.exe 2004-08-10 03:00 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe 2004-08-10 03:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe 2005-06-10 18:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe 2005-06-10 17:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\spoolsv.exe 2004-08-10 03:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe 2004-08-10 03:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll 2005-03-09 17:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-01 7561216] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264] "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920] "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-08-04 169984] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-05 206088] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-29 136600] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Billminder.lnk - c:\quickenw\BILLMIND.EXE [2009-01-17 30208] NETGEAR WG311v3 Wireless Assistant.lnk - c:\windows\Installer\{70014586-7BBA-4A92-A610-CDC896C48F8F}\NewShortcut1_1.exe [2009-01-01 2238] Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2009-01-17 27136] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) "NoThumbnailCache"= 1 (0x1) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ lsdelete [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe] --a------ 2005-07-12 17:05 1117184 c:\program files\McAfee\SpamKiller\MSKDetct.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\Program Files\\America Online 9.0\\waol.exe"= R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808] R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}] \Shell\AutoRun\command - E:\setup.exe . Contents of the 'Scheduled Tasks' folder 2009-02-27 c:\windows\Tasks\Schedule Task Weekly.job - c:\program files\Registry Easy\RE.exe [2008-12-31 15:15] . . ------- Supplementary Scan ------- . IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\RobSusan\Application Data\Mozilla\Firefox\Profiles\a2fw4277.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/|http://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true. ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-09 22:17:54 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-03-09 22:19:11 ComboFix-quarantined-files.txt 2009-03-10 04:19:08 Pre-Run: 233,347,084,288 bytes free Post-Run: 233,334,050,816 bytes free 157