ComboFix 08-09-27.05 - Vlasnik 2008-09-28 23:07:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.1427 [GMT 2:00]
Running from: C:\Documents and Settings\Vlasnik\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.
2008-09-28 20:42 . 2008-09-28 20:49 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-09-28 20:42 . 2008-09-28 20:42 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-09-28 20:41 . 2008-09-28 23:13 2,021,408 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-28 20:41 . 2008-09-28 23:13 237,600 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-28 20:41 . 2008-09-28 23:13 17,920 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-28 20:41 . 2008-09-28 23:13 2,940 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-28 19:32 . 2008-09-28 19:32 <DIR> d-------- C:\Documents and Settings\Vlasnik\Application Data\ESET
2008-09-28 19:31 . 2008-09-28 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-09-22 00:54 . 2008-09-22 00:54 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-02 03:21 . 2008-09-06 12:31 <DIR> d-------- C:\Program Files\DVBViewer
2008-08-31 21:25 . 2008-08-31 21:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-08-31 21:20 . 2008-08-31 21:20 <DIR> d--h----- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2008-08-31 21:20 . 2008-08-31 21:20 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\CanonBJ
2008-08-31 21:20 . 2007-04-16 07:00 215,040 --a------ C:\WINDOWS\system32\CNMLM8V.DLL
2008-08-31 21:19 . 2008-08-31 21:19 <DIR> d--h----- C:\Program Files\CanonBJ
2008-08-31 21:19 . 2008-08-31 21:25 <DIR> d-------- C:\Program Files\Canon
2008-08-31 21:07 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-08-31 21:07 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-08-28 01:14 . 2008-08-28 01:14 <DIR> d-------- C:\Program Files\Winamp
2008-08-28 01:14 . 2008-08-28 01:16 <DIR> d-------- C:\Documents and Settings\Vlasnik\Application Data\Winamp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 21:14 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-09-28 20:56 --------- d-----w C:\Documents and Settings\Vlasnik\Application Data\Skype
2008-09-28 19:12 --------- d-----w C:\Program Files\Premiere TV Guide 1.0
2008-09-28 18:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-28 17:03 --------- d-----w C:\Documents and Settings\Vlasnik\Application Data\skypePM
2008-09-27 04:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-23 09:49 --------- d-----w C:\Program Files\ICQ6
2008-09-17 19:51 --------- d-----w C:\Documents and Settings\Vlasnik\Application Data\ICQ
2008-09-02 01:21 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-02 01:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-02 01:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\CMUV
2008-08-30 23:46 --------- d-----w C:\Program Files\Valve
2008-08-30 23:45 --------- d-----w C:\Program Files\sXe Injected
2008-07-29 18:20 24,774 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
2007-12-20 09:03 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2006-06-23 13:48 32,768 ----a-w C:\WINDOWS\inf\UpdateUSB.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-08-11 21741864]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"ICQ"="C:\Program Files\ICQ6\ICQ.exe" [2008-09-01 173304]
"ProvideSupportOperatorConsole[default]"="C:\PROGRA~1\PROVID~1\LIVESU~1\PROVID~1.EXE" [2007-01-29 19:37 3858432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"Ai Nap"="C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-01-28 1413120]
"CPU Power Monitor"="C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"ASUS Energy Saving"="C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe" [2008-01-28 1352704]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 86016]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]
"nwiz"="nwiz.exe" [2008-05-16 C:\WINDOWS\system32\nwiz.exe]
"P17Helper"="P17.dll" [2005-05-03 C:\WINDOWS\system32\P17.dll]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\totalcmd\\TOTALCMD.EXE"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Valve\\hl.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=
"C:\\Program Files\\Provide Support\\Live Support Chat for Web Site\\ProvideSupportConsole.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:wow
"6112:TCP"= 6112:TCP:wow1
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 101528]
R3 ArcCD;ArcCD Filter Driver Service;C:\WINDOWS\system32\drivers\ArcCD.sys [2007-04-24 36352]
R3 ASUSVRC;ASUSTeK Virtual Capture Device;C:\WINDOWS\system32\DRIVERS\AsusVRC.sys [2007-01-29 18432]
R3 Cap7146_DVB;TechnoTrend BDA/DVB Capture;C:\WINDOWS\system32\Drivers\TTCap46n.sys [2007-08-09 81024]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 PTDVB;TechnoTrend BDA/DVB Tuner;C:\WINDOWS\system32\Drivers\TTFEDVBn.sys [2007-08-09 253952]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2006-09-29 10752]
S3 genmcmnUSB;USB Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gflmouhid.sys [ ]
S3 p17filt;p17filt;C:\WINDOWS\system32\drivers\p17filt.sys [2006-03-20 1452032]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S4 ArcUdfs;ArcUdfs FileSystem Driver Service;C:\WINDOWS\system32\drivers\ArcUdfs.sys [2007-04-25 134912]
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Vlasnik\Application Data\Mozilla\Firefox\Profiles\olin6j6w.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 23:14:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\ASUS\AASP\1.00.59\aaCenter.exe
C:\Program Files\Provide Support\Live Support Chat for Web Site\ProvideSupportConsole.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-09-28 23:17:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-28 21:17:11
Pre-Run: 8.592.404.480 bytes free
Post-Run: 8,972,107,776 bytes free
152 --- E O F --- 2008-09-10 10:05:45
|