ComboFix 08-09-28.03 - Administrator 2008-10-07 11:44:13.2 - [color=red][b]FAT32[/b][/color]x86 Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.136 [GMT 2:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . ((((((((((((((((((((((((( Files Created from 2008-09-07 to 2008-10-07 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-07 09:47 35,872 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-10-07 09:47 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx 2008-10-07 09:47 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat 2008-10-07 09:47 1,360 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-10-07 07:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Premium 2008-09-29 12:57 --------- d-----w C:\Program Files\Exterminate It! 2008-09-28 11:54 --------- d-----w C:\Program Files\Free Hide Folder 2008-09-28 09:12 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat 2008-09-28 09:12 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat 2008-09-28 08:52 --------- d-----w C:\Program Files\Kaspersky Lab 2008-09-28 08:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-09-28 08:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files 2008-09-28 08:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7 2008-09-17 11:01 --------- d-----w C:\Program Files\Quick Batch File Compiler 2008-09-15 07:39 --------- d-----w C:\Program Files\No-IP 2008-09-14 09:58 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE 2008-09-14 09:58 249,856 ------w C:\WINDOWS\Setup1.exe 2008-09-13 12:57 --------- d-----w C:\Program Files\Clone Shareware 2008-09-11 10:22 --------- d-----w C:\Program Files\ScriptCryptor 2008-09-07 07:22 --------- d-----w C:\Program Files\Lavasoft 2008-09-07 07:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-09-01 09:19 --------- d-----w C:\DOCUME~1\user2\APPLIC~1\WinRAR 2008-08-27 08:21 --------- d-----w C:\Program Files\Apple Software Update 2008-08-27 08:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-08-25 09:34 --------- d-----w C:\Documents and Settings\user2\Application Data\Nero 2008-08-25 09:34 --------- d-----w C:\DOCUME~1\user2\APPLIC~1\Nero 2008-08-25 09:32 --------- d-----w C:\Documents and Settings\administrator.ELEGANTSERVICES\Application Data\Nero 2008-08-25 09:29 --------- d-----w C:\Program Files\Nero 2008-08-25 09:29 --------- d-----w C:\Program Files\Common Files\Nero 2008-08-25 09:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero 2008-08-19 13:30 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-08-19 13:30 --------- d-----w C:\Program Files\Windows Live 2008-08-19 13:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-08-17 05:19 --------- d-----w C:\Program Files\Trend Micro 2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll 2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll 2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe 2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe 2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll 2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll 2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll 2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll 2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll 2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll 2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll 2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll 2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll 2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll 2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll 2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll 2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll 2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll 2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll 2004-10-01 13:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [12/31/2002 12:00 PM 15360] "Nokia.PCSync"="C:\Nokia PC Suite 6\PCSync2.exe" [03/26/2008 06:41 PM 1232896] "PC Suite Tray"="C:\Nokia PC Suite 6\PCSuite.exe" [03/28/2008 11:20 AM 1079296] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM 5724184] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [06/24/2008 04:06 PM 1840424] "QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" [05/27/2008 10:50 AM 413696] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [09/20/2005 03:35 AM 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [09/20/2005 03:32 AM 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [09/20/2005 03:36 AM 114688] "OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [03/18/2005 12:18 PM 98304] "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [05/12/2004 03:18 PM 241664] "MSConfig"="C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe" [12/31/2002 01:00 PM 158208] "combofix"="C:\WINDOWS\system32\CF11248.exe" [10/07/2008 11:43 AM 388608] "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [04/25/2008 06:21 PM 201992] "SoundMan"="SOUNDMAN.EXE" [03/01/2006 09:22 AM 577536 C:\WINDOWS\soundman.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "combofix"="C:\WINDOWS\system32\CF11248.exe" [10/07/2008 11:43 AM 388608] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [12/31/2002 12:00 PM 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.3iv2"= C:\PROGRA~1\K-LITE~1\codecs\3IVXVF~1.DLL "VIDC.VP60"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll "VIDC.VP61"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll "VIDC.VP62"= C:\PROGRA~1\K-LITE~1\codecs\vp6vfw.dll "VIDC.VP70"= C:\PROGRA~1\K-LITE~1\codecs\vp7vfw.dll "VIDC.VP31"= C:\PROGRA~1\K-LITE~1\codecs\vp31vfw.dll "VIDC.FFDS"= C:\PROGRA~1\K-LITE~1\ffdshow\ff_vfw.dll "msacm.ac3acm"= C:\PROGRA~1\K-LITE~1\codecs\ac3acm.acm "msacm.l3fhg"= C:\PROGRA~1\K-LITE~1\codecs\l3codecp.acm [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 02/19/2006 02:41 AM 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] --------- 03/14/2006 03:06 AM 1397760 C:\Program Files\Ahead\InCD\InCD.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] --a------ 06/24/2008 04:06 PM 1840424 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU] --a------ 01/12/2008 02:44 PM 249856 C:\Program Files\lg_fwupdate\fwupdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan] --a------ 06/08/2008 09:31 AM 2221352 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 06/19/2008 09:53 AM 570664 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync] --a------ 03/26/2008 06:41 PM 1232896 C:\Nokia PC Suite 6\PcSync2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray] --a------ 03/28/2008 11:20 AM 1079296 C:\Nokia PC Suite 6\PCSuite.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 05/27/2008 10:50 AM 413696 C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] --a------ 11/02/2004 08:24 PM 32768 C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] --a------ 02/20/2008 08:02 AM 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784] R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM 24592] S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [11/06/2007 10:22 PM 34064] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{184a8020-41d1-11dd-8607-00167681890e}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL nircmd.exe execmd CALL fun\A.bat [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45169f64-77d8-11dc-8507-00167681890e}] \Shell\AutoRun\command - RavMon.exe \Shell\explore\Command - RavMon.exe -e \Shell\open\Command - RavMon.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e2da0be-0f7b-11dd-85d0-00167681890e}] \Shell\AutoRun\command - F:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0d198e8-6301-11dd-8631-00167681890e}] \Shell\AutoRun\command - F:\fun\b.exe \Shell\open\command - F:\fun\b.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fee7499f-222c-11dc-846b-00167681890e}] \Shell\AutoRun\command - .\Recycled\Driveinfo.exe \Shell\Open\Command - .\Recycled\Driveinfo.exe . Contents of the 'Scheduled Tasks' folder . - - - - ORPHANS REMOVED - - - - HKCU-Run-PowerBar - (no file) . ------- Supplementary Scan ------- . FireFox -: Profile - C:\DOCUME~1\user2\APPLIC~1\Mozilla\Firefox\Profiles\ldjtldih.default\ FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-10-07 11:48:25 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... HKCU\Software\Microsoft\Windows\CurrentVersion\Run PowerBar = ???????????????????????????????????????????????????????????????|p??|????m??|?`?w??????????????@?8?@?????????c"?s???s??????@?????N'?sdX2?L|?s????????????u??s????????c"?s???s??????@?8?@?N'?s?{2??$@?8?@?8?@??????????{2? D2????s???s?W2??C2? D2?0i?s????????pX2???? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TlntSvr] "ImagePath"="C:\WINDOWS\system32\tlntsvr.exe" . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\CF11248.exe [1440] C:\WINDOWS\system32\igfxtray.exe [2156] C:\WINDOWS\system32\hkcmd.exe [2180] C:\WINDOWS\system32\igfxpers.exe [2240] C:\WINDOWS\SOUNDMAN.EXE [2320] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [2492] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2664] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2880] C:\WINDOWS\system32\ctfmon.exe [2908] C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3316] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [3920] C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe [4016] C:\Program Files\Microsoft Office\OFFICE11\MSACCESS.EXE [2476] C:\WINDOWS\explorer.exe [1312] C:\ComboFix\catchme.cfexe [3836] . ************************************************************************** . Completion time: 10/07/2008 11:54:28 - machine was rebooted [user2] ComboFix-quarantined-files.txt 2008-10-07 09:54:26 Pre-Run: 8,462,221,312 bytes free Post-Run: 9,146,646,528 bytes free 207 --- E O F --- 2008-10-06 10:12:18