Hijackthis log
ComboFix 08-06-19.4 - Kirill 2008-06-20 13:59:49.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1446 [GMT -4:00]
Running from: C:\Documents and Settings\Kirill\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kirill\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\_004772_.tmp.dll
C:\WINDOWS\system32\_004773_.tmp.dll
C:\WINDOWS\system32\_004774_.tmp.dll
C:\WINDOWS\system32\_004775_.tmp.dll
C:\WINDOWS\system32\_004782_.tmp.dll
C:\WINDOWS\system32\_004783_.tmp.dll
C:\WINDOWS\system32\_004784_.tmp.dll
C:\WINDOWS\system32\_004785_.tmp.dll
C:\WINDOWS\system32\_004787_.tmp.dll
C:\WINDOWS\system32\_004788_.tmp.dll
C:\WINDOWS\system32\_004791_.tmp.dll
C:\WINDOWS\system32\_004792_.tmp.dll
C:\WINDOWS\system32\_004794_.tmp.dll
C:\WINDOWS\system32\_004795_.tmp.dll
C:\WINDOWS\system32\_004796_.tmp.dll
C:\WINDOWS\system32\_004798_.tmp.dll
C:\WINDOWS\system32\_004801_.tmp.dll
C:\WINDOWS\system32\_004802_.tmp.dll
C:\WINDOWS\system32\_004806_.tmp.dll
C:\WINDOWS\system32\_004807_.tmp.dll
C:\WINDOWS\system32\_004809_.tmp.dll
C:\WINDOWS\system32\_004812_.tmp.dll
C:\WINDOWS\system32\_004815_.tmp.dll
C:\WINDOWS\system32\_004816_.tmp.dll
C:\WINDOWS\system32\_004817_.tmp.dll
C:\WINDOWS\system32\_004818_.tmp.dll
C:\WINDOWS\system32\_004819_.tmp.dll
C:\WINDOWS\system32\_004822_.tmp.dll
C:\WINDOWS\system32\_004823_.tmp.dll
C:\WINDOWS\system32\_004824_.tmp.dll
C:\WINDOWS\system32\_004825_.tmp.dll
C:\WINDOWS\system32\_004826_.tmp.dll
C:\WINDOWS\system32\_004831_.tmp.dll
C:\WINDOWS\system32\_004833_.tmp.dll
C:\WINDOWS\system32\_004834_.tmp.dll
C:\WINDOWS\system32\CMMGR32.EXE
.
((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))
.
2008-06-20 04:58 . 2008-06-20 05:01 <DIR> d-------- C:\Program Files\DriftCity
2008-06-20 04:27 . 2008-06-20 04:27 <DIR> d--h----- C:\Documents and Settings\Kirill\Application Data\ijjigame
2008-06-20 04:17 . 2008-06-20 04:17 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\IJJIGame
2008-06-19 00:57 . 2008-06-19 01:00 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-18 21:57 . 2008-06-18 21:57 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-18 14:28 . 2008-06-18 21:46 1,905 --a------ C:\WINDOWS\diagwrn.xml
2008-06-18 14:28 . 2008-06-18 21:46 1,905 --a------ C:\WINDOWS\diagerr.xml
2008-06-16 18:09 . 2008-06-16 18:10 3,151 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-06-16 18:00 . 2008-06-16 18:00 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-06-16 17:59 . 2008-06-16 17:59 <DIR> d-------- C:\WINDOWS\system32\en
2008-06-16 17:59 . 2008-06-16 18:02 <DIR> d-------- C:\WINDOWS\system32\bits
2008-06-16 17:59 . 2008-06-16 17:59 <DIR> d-------- C:\WINDOWS\l2schemas
2008-06-16 17:46 . 2007-10-25 23:36 8,454,656 --a------ C:\WINDOWS\system32\dllcache\shell32.dll
2008-06-16 17:39 . 2008-04-13 20:12 507,904 --a------ C:\WINDOWS\system32\SET196.tmp
2008-06-16 17:38 . 2008-04-13 20:12 8,461,312 --a------ C:\WINDOWS\system32\SET210.tmp
2008-06-16 17:37 . 2008-04-13 20:11 2,113,536 --a------ C:\WINDOWS\system32\SET1255.tmp
2008-06-16 17:22 . 2008-06-16 18:00 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-06-16 16:36 . 2008-06-16 16:36 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7
2008-06-12 09:18 . 2008-06-12 09:18 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-06-11 10:59 . 2008-06-11 10:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
2008-06-10 08:47 . 2008-06-10 10:13 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Autodesk
2008-06-09 14:54 . 2008-06-09 14:54 <DIR> d-------- C:\Documents and Settings\Kirill\Application Data\Malwarebytes
2008-06-09 14:53 . 2008-06-09 14:53 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-06-09 14:48 . 2008-06-16 19:06 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-06-09 11:38 . 2007-02-22 20:50 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-06-09 11:38 . 2006-11-30 08:50 72,264 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-06-09 11:38 . 2006-11-30 08:50 64,360 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2008-06-09 11:38 . 2006-11-30 08:50 52,136 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2008-06-09 11:38 . 2006-11-30 08:50 34,152 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-06-09 11:38 . 2006-12-19 15:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-06-08 23:04 . 2008-06-20 05:05 <DIR> d-------- C:\QUARANTINE
2008-06-08 21:42 . 2008-06-08 21:42 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-06-08 21:42 . 2008-06-09 11:38 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2008-06-08 21:42 . 2006-12-19 15:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-06-08 21:39 . 2008-06-09 11:38 <DIR> d-------- C:\Program Files\McAfee
2008-06-08 21:39 . 2008-06-08 21:39 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-06-08 21:10 . 2008-06-19 01:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-08 10:04 . 2008-06-08 10:04 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-06 14:15 . 2008-06-06 14:15 <DIR> d-------- C:\Program Files\AmbiCom
2008-06-06 03:32 . 2008-06-08 11:13 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-06-05 23:53 . 2008-06-19 01:00 <DIR> d-------- C:\Gamigo Games
2008-06-05 23:14 . 2008-06-05 23:14 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
2008-05-27 23:11 . 2002-08-20 01:41 413,760 --a------ C:\WINDOWS\system32\MPG4c32.dll
2008-05-27 16:41 . 2008-05-27 21:26 <DIR> d-------- C:\Program Files\SpeedBit Video Accelerator
2008-05-27 16:38 . 2008-05-27 16:39 <DIR> d-------- C:\Documents and Settings\Kirill\Application Data\Software Informer
2008-05-27 16:37 . 2008-06-12 09:17 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-20 17:59 --------- d-----w C:\Documents and Settings\Kirill\Application Data\Skype
2008-06-20 17:54 --------- d-----w C:\Documents and Settings\Kirill\Application Data\DNA
2008-06-20 08:51 --------- d-----w C:\Documents and Settings\Kirill\Application Data\BitTorrent
2008-06-19 05:00 --------- d-----w C:\Documents and Settings\Kirill\Application Data\SUPERAntiSpyware.com
2008-06-16 22:59 --------- d-----w C:\Program Files\DIFX
2008-06-16 20:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 16:54 --------- d-----w C:\Documents and Settings\Kirill\Application Data\dvdcss
2008-06-13 13:42 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-06-11 23:59 --------- d-----w C:\Program Files\Sword of The New World
2008-06-10 22:55 --------- d-----w C:\Program Files\Common Files\Real
2008-06-10 14:13 --------- d-----w C:\Documents and Settings\Kirill\Application Data\Autodesk
2008-06-10 14:06 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-06-10 14:02 --------- d-----w C:\Program Files\Autodesk
2008-05-19 23:07 --------- d-----w C:\Documents and Settings\Kirill\Application Data\skypePM
2008-05-16 04:14 --------- d-----w C:\Program Files\DivX
2008-05-13 01:51 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-13 01:51 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 15:56 --------- d-----w C:\Program Files\Codemasters
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-05 09:49 --------- d-----w C:\Program Files\Netropa
2008-05-02 16:23 --------- d-----w C:\Program Files\DNA
2008-05-02 16:23 --------- d-----w C:\Program Files\BitTorrent
2008-05-02 07:21 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-04-24 16:30 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-04-24 16:05 --------- d-----w C:\Program Files\Sierra
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 11:01 272,128 ----a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-04-14 00:15 218,134 ----a-w C:\WINDOWS\AppPatch\SET540.tmp
2008-04-14 00:15 204,396 ----a-w C:\WINDOWS\AppPatch\SET53F.tmp
2008-04-14 00:15 1,202,774 ----a-w C:\WINDOWS\AppPatch\SET53E.tmp
2008-04-14 00:11 997,376 ----a-w C:\WINDOWS\system32\SET2EE.tmp
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\SET288.tmp
2008-04-14 00:10 177,152 ----a-w C:\WINDOWS\system32\SET121D.tmp
2008-04-14 00:09 3,584 ----a-w C:\WINDOWS\system32\SET36F.tmp
2008-04-14 00:09 290,816 ----a-w C:\WINDOWS\system32\SET336.tmp
2008-04-14 00:09 285,696 ----a-w C:\WINDOWS\system32\SET43D.tmp
2008-04-14 00:09 16,896 ----a-w C:\WINDOWS\system32\SET421.tmp
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\SET238.tmp
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\SET3A3.tmp
2008-04-13 17:26 94,208 ----a-w C:\WINDOWS\system32\SET289.tmp
2008-04-13 17:26 90,112 ----a-w C:\WINDOWS\system32\SET1F3.tmp
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\SET2FC.tmp
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\SET286.tmp
2008-04-13 17:24 20,480 ----a-w C:\WINDOWS\system32\SET2DC.tmp
2008-04-13 17:03 63,488 ----a-w C:\WINDOWS\system32\SET431.tmp
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\SET2D8.tmp
2008-04-13 16:22 48,128 ----a-w C:\WINDOWS\system32\SET35E.tmp
2008-04-13 15:42 16,896 ----a-w C:\WINDOWS\system32\SET1E2.tmp
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\SET2E4.tmp
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-10 09:23 32 ----a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\ezsid.dat
2007-09-18 23:31 4,300,800 ----a-w C:\Program Files\mplayerc.exe
2008-03-09 22:48 8 --sha-r C:\WINDOWS\system32\8B6FE28B0E.sys
2008-03-09 22:48 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-19_20.49.25.48 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-20 00:44:57 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-20 08:52:43 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-06-20 00:45:28 26,921 ----a-w C:\WINDOWS\system32\tablet.dat
+ 2008-06-20 08:53:30 26,921 ----a-w C:\WINDOWS\system32\tablet.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-09-02 14:58 495616]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 21:22 21898024]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2008-03-13 11:12 5724184]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 14:44 196608]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 13:39 1289000]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-02 12:23 289088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-03-16 19:10 1392640]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 12:19 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 12:17 970752]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-23 00:32 7561216]
"nwiz"="nwiz.exe" [2006-03-23 00:32 1519616 C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2006-03-23 00:32 73728 C:\WINDOWS\system32\nvhotkey.dll]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 19:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 19:30 81920]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-07 18:08 185896]
"NvMediaCenter"="NvMCTray.dll" [2006-03-23 00:32 86016 C:\WINDOWS\system32\nvmctray.dll]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 15:24 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 15:14 217088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"DellTouch"="C:\WINDOWS\MMKeybd.exe" [2002-01-16 23:49 163840]
"SpeedBitVideoAccelerator"="C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe" [ ]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-22 20:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 11:27 136768]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
TabUserW.exe.lnk - C:\WINDOWS\system32\WTablet\TabUserW.exe [2008-03-08 12:34:20 114688]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\GALA-NET\\Rappelz_USA\\Launcher.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Common Files\\Autodesk Shared\\DirectConnect2.0\\java\\jre1.5.0_08\\bin\\javaw.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"C:\\Program Files\\Autodesk\\Showcase2009\\bin\\Showcase.exe"=
"C:\\Program Files\\Common Files\\Autodesk Shared\\DirectConnect2009\\java\\jre1.6.0_03\\bin\\javaw.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 Nhksrv;Netropa NHK Server;C:\WINDOWS\Nhksrv.exe [2002-01-16 23:49]
R3 Msikbd2k;DellTouch;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2002-01-16 23:49]
S3 ATIXPGAA;ATIXPGAA;C:\Dell\Drivers\R101351\ATIXPGAA.SYS [2004-02-20 13:31]
S3 XDva090;XDva090;C:\WINDOWS\system32\XDva090.sys []
S3 XDva134;XDva134;C:\WINDOWS\system32\XDva134.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{73a94b35-037f-11dd-b970-00123fd10501}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-20 14:01:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-20 14:03:06
ComboFix-quarantined-files.txt 2008-06-20 18:02:53
ComboFix2.txt 2008-06-20 00:50:01
Pre-Run: 20,782,108,672 bytes free
Post-Run: 20,752,842,752 bytes free
245 --- E O F --- 2008-06-13 07:04:42