ComboFix 08-04-03.5 - Dero 2008-04-04 18:26:48.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1279 [GMT 1:00]
Running from: C:\Users\Dero\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Dero\Desktopblackbird.jpg
C:\Users\Dero\DesktopEditorFKWP1.5.exe
C:\Users\Dero\DesktopEditorFKWP2.0.exe
C:\Users\Dero\Desktopfilemanagerclient.exe
C:\Users\Dero\Desktopfkwp1.5.exe
C:\Users\Dero\Desktopfkwp2.0.exe
C:\Users\Dero\Desktopfwebd.exe
C:\Users\Dero\DesktopFWebdEditor.exe
C:\Users\Dero\DesktopTrojan.Win32.BlackBird.exe
C:\Users\Dero\Desktopvirii
C:\Windows\a.bat
C:\Windows\base64.tmp
C:\Windows\bdn.com
C:\Windows\fkdnrwsv.dll
C:\Windows\FVProtect.exe
C:\Windows\iTunesMusic.exe
C:\Windows\mssecu.exe
C:\Windows\sxfnewqb.dll
C:\Windows\system32akttzn.exe
C:\Windows\system32anticipator.dll
C:\Windows\system32awtoolb.dll
C:\Windows\system32bdn.com
C:\Windows\system32bsva-egihsg52.exe
C:\Windows\system32dpcproxy.exe
C:\Windows\system32emesx.dll
C:\Windows\system32h@tkeysh@@k.dll
C:\Windows\system32hoproxy.dll
C:\Windows\system32hxiwlgpm.dat
C:\Windows\system32hxiwlgpm.exe
C:\Windows\system32medup012.dll
C:\Windows\system32medup020.dll
C:\Windows\system32msgp.exe
C:\Windows\system32msnbho.dll
C:\Windows\system32mssecu.exe
C:\Windows\system32msvchost.exe
C:\Windows\system32mtr2.exe
C:\Windows\system32mwin32.exe
C:\Windows\system32netode.exe
C:\Windows\system32newsd32.exe
C:\Windows\system32ps1.exe
C:\Windows\system32psof1.exe
C:\Windows\system32psoft1.exe
C:\Windows\system32regc64.dll
C:\Windows\system32regm64.dll
C:\Windows\system32Rundl1.exe
C:\Windows\system32smp
C:\Windows\system32smp\msrc.exe
C:\Windows\system32sncntr.exe
C:\Windows\system32ssurf022.dll
C:\Windows\system32ssvchost.com
C:\Windows\system32ssvchost.exe
C:\Windows\system32sysreq.exe
C:\Windows\system32taack.dat
C:\Windows\system32taack.exe
C:\Windows\system32temp#01.exe
C:\Windows\system32thun.dll
C:\Windows\system32thun32.dll
C:\Windows\system32VBIEWER.OCX
C:\Windows\system32vbsys2.dll
C:\Windows\system32vcatchpi.dll
C:\Windows\system32winlogonpc.exe
C:\Windows\system32winsystem.exe
C:\Windows\system32WINWGPX.EXE
C:\Windows\userconfig9x.dll
C:\Windows\Web\def.htm
C:\Windows\winsystem.exe
C:\Windows\zip1.tmp
C:\Windows\zip2.tmp
C:\Windows\zip3.tmp
C:\Windows\zipped.tmp
.
((((((((((((((((((((((((( Files Created from 2008-03-04 to 2008-04-04 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-04 17:20 --------- d-----w C:\Program Files\PC-Cleaner
2008-04-04 16:16 --------- d-----w C:\Program Files\Trend Micro
2008-04-01 19:20 90,112 ----a-w C:\Windows\System32\xgzivcve.exe
2008-03-31 21:54 --------- d-----w C:\ProgramData\Kaspersky Lab
2008-03-31 19:57 102,400 ----a-w C:\Windows\System32\xydmvshg.exe
2008-03-30 19:30 110,592 ----a-w C:\Windows\System32\kxcrkrah.exe
2008-03-30 00:07 94,208 ----a-w C:\Windows\System32\yzepcdiv.exe
2008-03-30 00:07 --------- d-----w C:\ProgramData\efkxoryj
2008-03-28 21:20 --------- d-----w C:\Users\Dero\AppData\Roaming\Azureus
2008-03-27 00:25 --------- d-----w C:\ProgramData\Microsoft Help
2008-03-24 23:34 --------- d-----w C:\ProgramData\Symantec
2008-03-23 23:24 --------- d-----w C:\ProgramData\Azureus
2008-03-23 23:23 --------- d-----w C:\Program Files\Azureus
2008-03-23 23:20 --------- d-----w C:\Program Files\Java
2008-03-23 23:18 --------- d-----w C:\Program Files\Common Files\Java
2008-03-12 03:24 --------- d-----w C:\Program Files\Windows Mail
2008-03-06 21:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-03-06 21:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-03-06 21:32 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat
2008-02-22 14:10 --------- d-----w C:\Program Files\Media
2008-02-22 14:10 --------- d-----w C:\Program Files\iPod
2008-02-22 14:09 --------- d-----w C:\Program Files\QuickTime
2008-02-17 11:59 --------- d-----w C:\Users\Guest\AppData\Roaming\Apple Computer
2008-02-14 00:52 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 00:52 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-14 00:48 806,400 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-14 00:48 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-14 00:48 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 00:48 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 00:48 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 00:48 217,144 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-14 00:48 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-14 00:48 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 00:48 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-14 00:48 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-14 00:47 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 00:47 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 00:47 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 00:47 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 00:47 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 00:47 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-14 00:45 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 00:45 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-14 00:45 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 00:45 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-11 23:16 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-07 00:27 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-02-07 00:25 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-07 00:20 691,545 ----a-w C:\Windows\unins000.exe
2008-02-05 18:56 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-01-08 19:03 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2007-09-26 18:33 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 20:03 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"googletalk"="C:\Users\Dero\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 22:22 3739648]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
"fyejuyvf"="C:\Windows\system32\kxcrkrah.exe" [2008-03-30 20:30 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-18 20:44 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 14:51 4435968 C:\Windows\RtHDVCpl.exe]
"P17Helper"="SPIRun.dll" [2006-07-03 05:43 10752 C:\Windows\System32\SPIRun.dll]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 06:59 115816]
"PWRISOVM.EXE"="C:\Program Files\Media\PowerISO\PWRISOVM.EXE" [2006-11-06 09:27 200704]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-11 22:28 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-11 22:28 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-11 22:28 81920]
"Windows Mobile-based device management"="%windir%\WindowsMobile\wmdSync.exe" [ ]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 20:51 583048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\Media\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"DefaultP17"="resdef.exe" [2006-07-03 05:55 53248 C:\Windows\resdef.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"qghTzFC2Xz"= C:\ProgramData\efkxoryj\ojadalcl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
"vidc.wmv3"= wmv9vcm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A084994D-CCE2-4B98-A5F1-CBA3ADAE6C04}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{F1A494DF-9178-48FC-BD20-0BD0C947A18F}"= UDP:C:\Program Files\Media\iTunes\iTunes.exe:iTunes
"{845C4D28-07EE-4DF6-8685-DE6910478BDF}"= TCP:C:\Program Files\Media\iTunes\iTunes.exe:iTunes
"{4E5C3D4D-DA72-49B6-84CB-015940B131BB}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{68EC26A9-AE65-4B03-97BE-233FF8DAA413}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{D598E264-0E88-4E03-8B0B-896442FD8B80}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{CC3EB4CD-C3F0-409F-A0DA-AC7D8F793772}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EC0E8E67-4A16-457E-99CA-6479FE8A30C7}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B9FB235-597B-46F2-BAB6-4981FDCF7F5F}"= UDP:C:\Program Files\Games\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{A429C823-2D7C-4A68-A0CC-06303EFAE958}"= TCP:C:\Program Files\Games\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{2196BC13-5DEB-4877-9901-55FC75B86F6B}"= UDP:990:LocalSubnet:LocalSubnet|IF={F4AC0AB4-948D-40FD-BB1D-8FFE31FEEA98}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr

%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{C64E7888-6EDF-48E1-9013-F8B99D8B7008}"= UDP:C:\Program Files\Media\iTunes\iTunes.exe:iTunes
"{FF6C83D9-67DF-483A-BF12-440C25543043}"= TCP:C:\Program Files\Media\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 videX32;videX32;C:\Windows\system32\drivers\videx32.sys [2006-10-17 20:22]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\Windows\system32\drivers\xfilt.sys [2006-10-18 17:39]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\IDS-DI~1\20080331.001\IDSvix86.sys [2008-02-13 17:18]
R2 RapiMgr;Windows Mobile-based device connectivity;C:\Windows\system32\svchost.exe [2006-11-02 10:45]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 12:43]
R2 WcesComm;Windows Mobile 2003-based device connectivity;C:\Windows\system32\svchost.exe [2006-11-02 10:45]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-10-30 20:55]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);C:\Windows\system32\DRIVERS\s125bus.sys [2007-04-24 10:33]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;C:\Windows\system32\DRIVERS\s125mdfl.sys [2007-04-24 10:33]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;C:\Windows\system32\DRIVERS\s125mdm.sys [2007-04-24 10:33]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);C:\Windows\system32\DRIVERS\s125mgmt.sys [2007-04-24 10:33]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;C:\Windows\system32\DRIVERS\s125obex.sys [2007-04-24 10:33]
S4 nvrd32;NVIDIA nForce RAID Driver ;C:\Windows\system32\drivers\nvrd32.sys [2007-07-02 16:37]
S4 nvsmu;nvsmu;C:\Windows\system32\drivers\nvsmu.sys [2007-02-16 07:50]
S4 Si3132r5;SiI-3132 SoftRaid 5 Controller;C:\Windows\system32\drivers\si3132r5.sys [2006-01-12 04:41]
S4 Si3531;SiI-3531 SATA Controller;C:\Windows\system32\drivers\si3531.sys [2006-11-17 09:57]
S4 UGURU;UGURU;C:\Windows\system32\drivers\uguru.sys [2006-10-02 04:10]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
"2007-09-27 22:32:06 C:\Windows\Tasks\Norton AntiVirus - Run Full System Scan - Dero.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeB/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-04 18:28:47
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-04 18:29:21
ComboFix-quarantined-files.txt 2008-04-04 17:29:18
The system cannot find message text for message number 0x2379 in the message file for Application.
The system cannot find message text for message number 0x2379 in the message file for Application.
.
2008-03-12 03:01:50 --- E O F ---