ComboFix 07-11-19.3 - King of Kings 2007-11-23 10:46:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.110 [GMT 6:00]
Running from: F:\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.
2007-11-22 11:25 <DIR> d-------- C:\Documents and Settings\King of Kings\Application Data\vlc
2007-11-21 23:12 0 --a------ C:\WINDOWS\system32\h323log.txt
2007-11-21 23:09 171,776 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-11-21 23:09 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-11-21 23:07 130,048 --a------ C:\WINDOWS\system32\ksproxy.ax
2007-11-21 23:07 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-11-21 23:07 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys
2007-11-21 23:04 <DIR> d--hs---- C:\WINDOWS\Installer
2007-11-21 23:04 <DIR> dr------- C:\Program Files
2007-11-21 23:04 <DIR> dr------- C:\Documents and Settings\All Users\Documents
2007-11-21 23:04 69,120 --a------ C:\WINDOWS\NOTEPAD.EXE
2007-11-21 23:04 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2007-11-21 23:04 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-11-21 23:03 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-11-21 23:03 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2007-11-21 23:02 261 --a------ C:\WINDOWS\system32\$winnt$.inf
2007-11-21 21:02 <DIR> d-------- C:\Documents and Settings\King of Kings\Application Data\DivX
2007-11-21 20:21 <DIR> d-------- C:\Program Files\MegauploadToolbar
2007-11-21 20:20 <DIR> d-------- C:\Documents and Settings\King of Kings\Application Data\MegauploadToolbar
2007-11-21 19:08 <DIR> d-------- C:\Downloads
2007-11-21 19:08 61,491 --a------ C:\WINDOWS\system32\wbemdisp.TLB
2007-11-21 18:38 <DIR> d-------- C:\Program Files\Java
2007-11-21 18:36 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-21 18:08 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-21 18:08 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-21 18:08 <DIR> d-------- C:\Documents and Settings\King of Kings\Application Data\SUPERAntiSpyware.com
2007-11-21 18:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-21 18:06 <DIR> d-------- C:\Program Files\Avira
2007-11-21 18:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-11-21 18:03 0 --a------ C:\WINDOWS\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-21 12:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-21 11:47 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-21 11:24 --------- d-----w C:\Program Files\microsoft frontpage
2007-10-20 00:56 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 09:06 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2004-08-04 04:56 568,832 --sh--r C:\WINDOWS\system32\WinUpdater.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-11-21 18:18]
"Windows Updater"="WinUpdater.exe" [2004-08-04 10:56 C:\WINDOWS\system32\WinUpdater.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Windows Updater"="WinUpdater.exe" [2004-08-04 10:56 C:\WINDOWS\system32\WinUpdater.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Pinnacle Scheduler.lnk - D:\Softwares\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe [2006-10-26 21:43:17]
[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-23 10:48:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-23 10:49:11
.
--- E O F ---