ComboFix 08-02.01.1 - Main 2008-01-31 16:02:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.581 [GMT -5:00]
Running from: C:\Documents and Settings\Main\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\autodis.dll
C:\WINDOWS\system32\drivers\hgymoimw.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_UQHSSEJI
-------\uqhsseji
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.
2008-01-30 21:25 . 2008-01-30 21:25 <DIR> d-------- C:\Program Files\IObit
2008-01-30 21:10 . 2008-01-30 23:16 <DIR> d-------- C:\Program Files\AdwareAlert
2008-01-30 21:10 . 2008-01-30 21:10 <DIR> d-------- C:\Documents and Settings\Main\Application Data\AdwareAlert
2008-01-29 02:10 . 2008-01-31 14:49 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-01-29 02:10 . 2008-01-29 02:10 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-01-29 02:09 . 2008-01-29 02:09 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-29 02:09 . 2008-02-01 16:15 3,851,040 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-29 02:09 . 2008-02-01 16:06 52,580 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-29 02:09 . 2008-02-01 16:15 43,296 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-29 02:09 . 2008-02-01 16:06 5,060 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-29 02:08 . 2008-01-29 02:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-01-27 21:36 . 2008-01-27 21:36 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-27 21:36 . 2008-02-01 16:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-27 19:09 . 2008-01-27 21:27 <DIR> d-------- C:\Documents and Settings\Main\.housecall6.6
2008-01-26 23:33 . 2008-01-26 23:33 <DIR> d-------- C:\Program Files\AC3Filter
2008-01-26 23:33 . 2007-08-18 02:54 380,928 --a------ C:\WINDOWS\system32\ac3filter.acm
2008-01-22 00:25 . 2008-01-22 00:25 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-22 00:24 . 2008-01-22 00:24 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-01-22 00:11 . 2008-01-22 00:11 <DIR> d-------- C:\Deckard
2008-01-17 22:38 . 2008-01-20 14:13 <DIR> d-------- C:\Program Files\iPod
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-09 11:02 . 2008-01-27 08:00 <DIR> d-------- C:\Documents and Settings\Main\Application Data\AVG7
2008-01-09 11:02 . 2008-01-09 11:02 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-09 11:01 . 2008-01-27 23:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-30 04:44 --------- d-----w C:\Documents and Settings\Main\Application Data\Azureus
2008-01-30 03:12 --------- d-----w C:\Program Files\Full Tilt Poker
2008-01-20 19:13 --------- d-----w C:\Program Files\QuickTime
2008-01-20 19:13 --------- d-----w C:\Program Files\iTunes
2008-01-09 15:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-01-09 15:47 --------- d-----w C:\Program Files\Symantec
2008-01-09 15:47 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-09 15:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-09 15:44 --------- d-----w C:\Program Files\ElastoManiaRegistered
2008-01-05 19:51 --------- d-----w C:\Program Files\MSN Messenger
2008-01-05 19:51 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-29 05:25 --------- d-----w C:\Program Files\Azureus
2007-12-18 05:43 23,396 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
2007-12-13 18:28 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys
2007-12-10 23:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-10 23:53 --------- d-----w C:\Program Files\Codemasters
2007-09-27 20:32 785 ----a-w C:\Program Files\INSTALL.LOG
2006-12-04 21:26 774,144 ----a-w C:\Program Files\RngInterstitial.dll
1998-12-09 02:53 99,840 ----a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 ----a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 ----a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 ----a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 ----a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 ----a-w C:\Program Files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:00 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 13:44 196608]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 17:49 68856]
"WeatherEye"="C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2007-09-26 13:14 4484816]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="launchapp" []
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2005-12-28 18:21 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"NDSTray.exe"="NDSTray.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 03:02 761948]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-02 19:25 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-02 19:22 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-02 19:26 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 11:37 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 10:41 602182]
"Toshiba Hotkey Utility"="C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" [2006-03-14 21:12 1769472]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 05:03 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 05:03 81920]
"Samsung Common SM"="C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 02:20 372736]
"CFSServ.exe"="CFSServ.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-12-18 00:43 227856]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
IEHOME.LNK - C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat [2006-08-16 18:57:45 298]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2006-02-28 03:21:01 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
R3 BoiHwsetup;Access 32bits INT15 routine;C:\WINDOWS\system32\drivers\BoiHwSetup.sys [2005-06-10 01:42]
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2005-06-20 11:26]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
R3 qkbfiltr;Quanta HotKey Keyboard Filter Driver;C:\WINDOWS\system32\drivers\qkbfiltr.sys [2006-01-12 19:21]
R3 qmofiltr;Quanta HotKey Mouse Filter Driver;C:\WINDOWS\system32\drivers\qmofiltr.sys [2005-05-05 17:27]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4e44b7b-3a25-11db-8350-001302acc24c}]
\Shell\AutoRun\command - E:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b22d0d59-5a45-11dc-840f-001302acc24c}]
\Shell\AutoRun\command - F:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 21:00:00 C:\WINDOWS\Tasks\9AFAE2D585B1BFBD.job"
- c:\docume~1\main\applic~1\timewm~1\window anti way.exe
"2008-01-31 08:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2008-01-25 03:27:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-31 20:32:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-01 16:14:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2008-02-01 16:17:58 - machine was rebooted [Main]
ComboFix-quarantined-files.txt 2008-02-01 21:17:54
.
2008-01-09 09:53:54 --- E O F ---