ComboFix 09-03-06.02 - RobSusan 2009-03-09 22:16:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1687 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
.
((((((((((((((((((((((((( Files Created from 2009-02-10 to 2009-03-10 )))))))))))))))))))))))))))))))
.
2009-03-09 22:15 . 2009-03-09 22:15
d-------- c:\windows\LastGood
2009-02-27 18:06 . 2009-02-27 18:06 d-------- c:\program files\Audible
2009-02-27 18:06 . 2001-08-17 22:43 24,576 --------- c:\windows\system32\msxml3a.dll
2009-02-27 17:44 . 2009-02-27 17:44 d-------- c:\program files\FreeRIP3
2009-02-27 17:44 . 2009-02-27 17:44 d-------- c:\documents and settings\All Users\Application Data\FreeRIP
2009-02-27 17:17 . 2009-02-27 18:02 378 --a------ c:\windows\cdplayer.ini
2009-02-27 16:49 . 2009-02-27 16:49 d-------- C:\f8c8832aea5bf442f1
2009-02-27 16:42 . 2009-02-27 18:52 d-------- c:\program files\Best Buy Rhapsody
2009-02-27 16:37 . 2009-02-27 16:37 d-------- c:\documents and settings\RobSusan\Application Data\ArcSoft
2009-02-27 16:36 . 2009-02-27 16:36 d-------- c:\program files\Common Files\ArcSoft
2009-02-27 16:36 . 2009-02-27 16:36 d-------- c:\program files\ArcSoft
2009-02-27 16:36 . 2006-01-24 10:20 1,645,320 --a------ c:\windows\system32\GdiPlus.dll
2009-02-27 16:36 . 2005-06-21 10:29 245,408 --a------ c:\windows\system32\unicows.dll
2009-02-27 14:36 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\65254764.sys
2009-02-26 19:45 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\96992922.sys
2009-02-26 14:17 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\88965794.sys
2009-02-26 13:35 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\97959155.sys
2009-02-26 13:33 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\49053800.sys
2009-02-26 13:22 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\[u]0[/u]1043849.sys
2009-02-26 12:41 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\64046267.sys
2009-02-26 09:10 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\17392811.sys
2009-02-26 08:52 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\63052452.sys
2009-02-26 08:41 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\24449345.sys
2009-02-25 21:34 . 2009-02-25 21:39 250 --a------ c:\windows\gmer.ini
2009-02-14 15:11 . 2009-02-14 15:11 d-------- c:\program files\File Shredder
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-10 04:14 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-10 04:13 368,672 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-10 04:13 2,340 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-10 04:13 13,288 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-10 04:13 1,562,656 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-28 00:53 --------- d-----w c:\program files\Real
2009-02-27 22:36 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-27 19:56 --------- d-----w c:\program files\Registry Easy
2009-02-06 02:18 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-04 00:39 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-04 00:39 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-01-30 03:02 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-30 03:02 --------- d-----w c:\program files\Java
2009-01-26 12:37 --------- d-----w c:\program files\RegistryPatrol3.0
2009-01-19 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\STOPzilla!
2009-01-19 03:10 --------- d-----w c:\documents and settings\All Users\Application Data\SITEguard
2009-01-19 03:08 --------- d-----w c:\program files\Common Files\iS3
2009-01-13 01:44 3,766 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-01-13 01:42 --------- d-----w c:\documents and settings\RobSusan\Application Data\Corel Photo Album
2009-01-10 20:31 1,236,480 ----a-w c:\windows\system32\msxml3.dll
2009-01-10 20:31 1,236,480 ----a-w c:\windows\system32\dllcache\msxml3.dll
2009-01-05 01:45 0 ----a-w C:\register.bat
.
------- Sigcheck -------
2008-10-16 04:37 659456 6f1e4bfd78c4e0d05ff3725d59b72925 c:\windows\SoftwareDistributionOld1\Download\7bc58354ca50aa200544caaef7677c8a\SP2GDR\wininet.dll
2008-10-16 04:20 667648 93c9d0a216498ee14eb9b26119bb95ee c:\windows\SoftwareDistributionOld1\Download\7bc58354ca50aa200544caaef7677c8a\SP2QFE\wininet.dll
2008-10-15 19:00 666112 1576318bf08d28cc61d1278114ad8d5b c:\windows\SoftwareDistributionOld1\Download\7bc58354ca50aa200544caaef7677c8a\SP3GDR\wininet.dll
2008-10-15 19:04 667136 e8fce58a470999350f64c591557f9e42 c:\windows\SoftwareDistributionOld1\Download\7bc58354ca50aa200544caaef7677c8a\SP3QFE\wininet.dll
2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\system32\wininet.dll
2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\system32\dllcache\wininet.dll
2004-08-10 03:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\system32\drivers\tcpip.sys
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntkrnlpa.exe
2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntkrnlpa.exe
2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntkrnlpa.exe
2005-06-22 18:05 2015744 65f4b29a0793adb5d924fb3f47f1bca4 c:\windows\system32\ntkrnlpa.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntoskrnl.exe
2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntoskrnl.exe
2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe c:\windows\SoftwareDistributionOld1\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntoskrnl.exe
2005-06-22 18:30 2136064 5611f453c6d20ab0552956f39bcddb88 c:\windows\system32\ntoskrnl.exe
2004-08-10 03:00 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
2004-08-10 03:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe
2005-06-10 18:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 17:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\spoolsv.exe
2004-08-10 03:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2004-08-10 03:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
2005-03-09 17:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-01 7561216]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-08-04 169984]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-05 206088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-29 136600]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2009-01-17 30208]
NETGEAR WG311v3 Wireless Assistant.lnk - c:\windows\Installer\{70014586-7BBA-4A92-A610-CDC896C48F8F}\NewShortcut1_1.exe [2009-01-01 2238]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2009-01-17 27136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoThumbnailCache"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ lsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a------ 2005-07-12 17:05 1117184 c:\program files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-27 c:\windows\Tasks\Schedule Task Weekly.job
- c:\program files\Registry Easy\RE.exe [2008-12-31 15:15]
.
.
------- Supplementary Scan -------
.
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\RobSusan\Application Data\Mozilla\Firefox\Profiles\a2fw4277.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/|http://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-09 22:17:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-03-09 22:19:11
ComboFix-quarantined-files.txt 2009-03-10 04:19:08
Pre-Run: 233,347,084,288 bytes free
Post-Run: 233,334,050,816 bytes free
157