mask_kishore
2008-06-03, 10:03
I have Yahoo CA Antispy and Kaspersky Internet Security.A few days ago, when I scanned I found a downloader named Darksma installed into
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\MS JUAN
I tried deleting it and it did,only to reappear after scanning again.I also tried to delete the registry key it had created but to no avail. Please help as I'm facing great difficulty.My internet connection has become so slow that even a search on google takes hours.I am totally unable to open sites like Yahoo.com.
And also, internet explorer and Mozilla firefox windows open by themselves every now and then.
Here are Hijackthis and Combofix logs:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:31:34 PM, on 6/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
D:\Program Files-2\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files-2\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files-2\Microsoft Office\Office12\ONENOTEM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files-2\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files-2\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files-2\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/oas/ActiveX/MSDcode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1212138580500
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205499308780
O17 - HKLM\System\CCS\Services\Tcpip\..\{C86B090E-38B9-4FF0-995A-5F90C9413511}: NameServer = 202.56.215.6,202.56.215.54
O20 - AppInit_DLLs: D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: geBrQKeD - geBrQKeD.dll (file missing)
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - D:\Program Files-2\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 4408 bytes
And the Combofix Log:
ComboFix 08-06-01.6 - Animesh 2008-06-02 18:15:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.263 [GMT 5.5:30]
Running from: C:\Documents and Settings\Animesh.FERRARI\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM2b5a6e5a.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\AJTEOqss.ini
C:\WINDOWS\system32\AJTEOqss.ini2
C:\WINDOWS\system32\bbowdnte.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\khfDvwXP.dll
C:\WINDOWS\system32\krbxqoai.dll
C:\WINDOWS\system32\ksbyxwei.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\qtoomlhf.ini
C:\WINDOWS\system32\rhqugqaa.dll
C:\WINDOWS\system32\ssqOETJA.dll
C:\WINDOWS\system32\vxphfphu.dll
C:\WINDOWS\system32\ylobtwjm.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-02 to 2008-06-02 )))))))))))))))))))))))))))))))
.
2008-06-02 17:40 . <DIR> C:\WINDOWS\LastGood.Tmp
2008-06-01 18:09 . 2004-08-04 00:56 220,672 --a------ C:\WINDOWS\system32\logon.scr
2008-06-01 18:09 . 2004-08-04 00:56 220,672 --a--c--- C:\WINDOWS\system32\dllcache\logon.scr
2008-06-01 08:55 . 2008-06-01 08:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-31 21:24 . 2008-05-31 21:24 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-31 21:23 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-05-31 20:13 . 2001-08-17 12:20 334,208 --a--c--- C:\WINDOWS\system32\dllcache\ds1wdm.sys
2008-05-31 20:13 . 2008-04-14 00:09 206,976 --a--c--- C:\WINDOWS\system32\dllcache\dot4.sys
2008-05-31 20:13 . 2001-08-17 12:12 28,062 --a--c--- C:\WINDOWS\system32\dllcache\dp83820.sys
2008-05-31 20:13 . 2001-08-17 13:47 23,808 --a--c--- C:\WINDOWS\system32\dllcache\dot4usb.sys
2008-05-31 20:13 . 2008-04-14 05:42 20,992 --a--c--- C:\WINDOWS\system32\dllcache\dshowext.ax
2008-05-31 20:13 . 2001-08-17 14:07 20,192 --a--c--- C:\WINDOWS\system32\dllcache\dpti2o.sys
2008-05-31 20:13 . 2001-08-17 13:47 12,928 --a--c--- C:\WINDOWS\system32\dllcache\dot4prt.sys
2008-05-31 20:13 . 2001-08-17 13:47 8,704 --a--c--- C:\WINDOWS\system32\dllcache\dot4scan.sys
2008-05-31 20:11 . 2008-04-14 05:41 249,856 --a--c--- C:\WINDOWS\system32\dllcache\ctmasetp.dll
2008-05-31 20:10 . 2001-08-17 12:13 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2008-05-31 20:09 . 2001-08-17 14:05 314,752 --a--c--- C:\WINDOWS\system32\dllcache\camdro21.sys
2008-05-31 20:08 . 2001-08-17 22:36 102,400 --a--c--- C:\WINDOWS\system32\dllcache\binlsvc.dll
2008-05-31 20:06 . 2001-08-17 13:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-05-31 20:05 . 2001-08-17 13:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-05-31 20:04 . 2001-08-17 14:56 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-05-31 20:03 . 2008-04-14 00:54 2,145,280 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-05-31 19:38 . 2008-05-31 20:11 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-05-31 19:38 . 2008-05-31 20:11 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-05-31 19:36 . 2008-06-02 17:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-31 19:36 . 2008-06-02 18:27 1,895,968 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-31 19:36 . 2008-06-02 18:24 35,360 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-31 19:36 . 2008-06-02 18:23 28,532 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-31 19:36 . 2008-06-02 18:23 5,312 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-31 19:25 . 2008-05-31 19:25 <DIR> d-------- C:\WINDOWS\system32\VIRepair
2008-05-31 19:22 . 2008-05-31 19:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-05-30 14:16 . 2008-06-02 18:22 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-05-29 20:14 . 2008-05-29 20:14 214 --a------ C:\WINDOWS\HP_48BitScanUpdatePatch.ini
2008-05-29 20:11 . 2008-05-29 20:11 <DIR> d-------- C:\Program Files\Microsoft Calculator Plus
2008-05-29 18:02 . 2008-05-29 20:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-29 17:56 . 2008-05-29 20:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-05-27 18:51 . 2008-05-27 18:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-25 15:42 . 2008-05-25 15:49 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg(2)
2008-05-25 15:41 . 2008-05-27 12:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8(2)
2008-05-24 15:26 . 2008-05-29 20:38 <DIR> d-------- C:\Documents and Settings\Animesh.FERRARI\Application Data\AVGTOOLBAR
2008-05-24 11:57 . 2008-05-24 11:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-05-24 11:55 . 2008-05-24 11:55 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-05-24 11:55 . 2008-05-24 11:57 <DIR> d-------- C:\Program Files\Escape The Museum
2008-05-23 16:50 . 2001-08-17 22:36 65,536 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_mailmsg.dll
2008-05-23 16:50 . 2001-08-17 22:36 57,856 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
2008-05-23 16:50 . 2001-08-17 22:36 43,520 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_fcachdll.dll
2008-05-23 16:50 . 2001-08-17 22:36 38,912 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll
2008-05-23 16:50 . 2001-08-17 22:36 23,040 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_regtrace.exe
2008-05-23 16:50 . 2001-08-17 22:36 12,288 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpctrs.dll
2008-05-23 16:50 . 2001-08-17 22:36 7,168 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_snprfdll.dll
2008-05-23 16:50 . 2001-08-17 22:36 5,632 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_adsiisex.dll
2008-05-23 14:58 . 2008-05-23 16:59 26,845 --a------ C:\WINDOWS\imsins.BAK
2008-05-22 21:49 . 2008-05-22 21:49 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-22 15:22 . 2005-02-27 21:48 356,352 --a------ C:\WINDOWS\system32\RealMediaSplitter.ax
2008-05-22 14:35 . 2008-05-22 14:35 <DIR> d-------- C:\Documents and Settings\Shin Chan\Application Data\Styler
2008-05-22 14:25 . 2008-05-22 14:25 <DIR> d-------- C:\Documents and Settings\AKP\Application Data\Styler
2008-05-22 14:16 . 2008-05-22 14:17 <DIR> d-------- C:\Documents and Settings\Animesh.FERRARI\Application Data\ViStart
2008-05-22 12:49 . 2008-05-22 12:49 <DIR> d-------- C:\Documents and Settings\Animesh.FERRARI\Application Data\Styler
2008-05-22 12:40 . 2008-05-22 12:40 <DIR> d-------- C:\Program Files\WinFlip
2008-05-22 12:40 . 2008-05-22 12:40 <DIR> d-------- C:\Program Files\TrueTransparency
2008-05-22 12:40 . 2008-05-31 19:25 <DIR> d-------- C:\Program Files\Styler
2008-05-22 12:40 . 2008-05-22 12:40 <DIR> d-------- C:\Documents and Settings\Administrator.FERRARI\Application Data\Styler
2008-05-22 12:36 . 2008-05-31 19:26 <DIR> d-------- C:\WINDOWS\system32\VITrans
2008-05-22 12:36 . 2006-12-03 17:15 111,104 --a------ C:\WINDOWS\system32\Uharc.exe
2008-05-22 12:36 . 2008-05-22 12:36 78,942 --a------ C:\WINDOWS\Icon_1.ico
2008-05-22 12:36 . 2006-12-03 17:15 19,968 --a------ C:\WINDOWS\system32\reico.exe
2008-05-22 12:36 . 2006-12-03 17:14 8,636 --a------ C:\WINDOWS\system32\modifype.exe
2008-05-22 12:29 . 2008-05-31 19:15 <DIR> d-------- C:\Documents and Settings\Administrator.FERRARI
2008-05-20 15:10 . 2008-05-20 15:10 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-20 15:10 . 2008-05-20 15:10 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-05-20 15:10 . 2008-05-20 15:10 <DIR> d-------- C:\Program Files\MSBuild
2008-05-20 15:08 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-05-20 14:03 . 2008-05-20 14:03 <DIR> d-------- C:\WINDOWS\Sun
2008-05-20 14:01 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-15 21:32 . 2008-05-15 21:32 <DIR> d-------- C:\DVDVideoSoft
2008-05-15 16:54 . 2008-05-15 16:54 <DIR> d-------- C:\WINDOWS\Performance
2008-05-15 16:53 . 2008-05-19 15:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-05-15 15:49 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-05-13 21:58 . 2008-05-13 21:58 <DIR> d-------- C:\WINDOWS\system32\en
2008-05-13 21:58 . 2008-05-13 21:58 <DIR> d-------- C:\WINDOWS\l2schemas
2008-05-13 21:58 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0411.dll
2008-05-13 21:58 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0404.dll
2008-05-13 21:57 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0804.dll
2008-05-13 21:57 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0412.dll
2008-05-13 21:57 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0401.dll
2008-05-13 21:56 . 2008-04-14 05:41 218,112 --a--c--- C:\WINDOWS\system32\dllcache\c_g18030.dll
2008-05-13 21:56 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt040d.dll
2008-05-13 21:52 . 2008-04-13 22:06 144,384 --a------ C:\WINDOWS\system32\drivers\hdaudbus.sys
2008-05-13 21:52 . 2008-04-14 00:10 10,240 --a------ C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-05-09 16:27 . 2008-05-09 16:27 0 --a------ C:\WINDOWS\pws.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-31 14:43 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-31 13:35 --------- d-----w C:\Documents and Settings\Animesh.FERRARI\Application Data\uTorrent
2008-05-27 13:45 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-26 12:03 --------- d-----w C:\Program Files\Yahoo!
2008-05-23 08:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-05-16 12:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-12 10:45 --------- d-----w C:\Documents and Settings\Animesh.FERRARI\Application Data\GetRight Pro
2008-04-29 15:26 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-21 12:50 --------- d-----w C:\Documents and Settings\Animesh.FERRARI\Application Data\Talkback
2008-04-21 12:18 --------- d-----w C:\Program Files\Google
2008-04-18 08:40 --------- d-----w C:\Documents and Settings\Shin Chan\Application Data\Microsoft Games
2008-04-17 10:36 --------- d-----w C:\Documents and Settings\Animesh.FERRARI\Application Data\Microsoft Games
2008-04-17 10:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Games
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:13 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:11 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 21:00 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:27 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 19:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 19:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 19:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 18:54 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 18:53 36,608 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 18:53 264,832 ----a-w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 18:51 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 18:51 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 18:51 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 18:51 55,808 ----a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 18:51 101,120 ----a-w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 18:45 60,160 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
2008-04-13 18:44 81,664 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 18:44 799,744 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 18:44 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys
2008-04-13 18:44 153,344 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 18:43 14,208 ----a-w C:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 18:43 12,672 ----a-w C:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 18:41 52,352 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 18:41 42,112 ----a-w C:\WINDOWS\system32\drivers\imapi.sys
2008-04-13 18:39 7,552 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 18:39 5,504 ----a-w C:\WINDOWS\system32\drivers\mstee.sys
2008-04-13 18:39 5,376 ----a-w C:\WINDOWS\system32\drivers\mspclock.sys
2008-04-13 18:39 42,368 ----a-w C:\WINDOWS\system32\drivers\mountmgr.sys
2008-04-13 18:39 4,992 ----a-w C:\WINDOWS\system32\drivers\mspqm.sys
2008-04-13 18:39 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys
2008-04-13 18:39 384,768 ----a-w C:\WINDOWS\system32\drivers\update.sys
2008-04-13 18:39 24,576 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 07:41 114688]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2001-11-08 23:10 147456]
"AVP"="D:\Program Files-2\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2008-02-08 18:36 227856]
C:\Documents and Settings\Shin Chan\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - D:\Program Files-2\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
C:\Documents and Settings\Animesh.FERRARI\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - D:\Program Files-2\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geBrQKeD]
geBrQKeD.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"ViOrb"=C:\Program Files\ViOrb\ViOrb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="D:\Program Files-2\Java\jre1.6.0_06\bin\jusched.exe"
"BM2b5a6e5a"=Rundll32.exe "C:\WINDOWS\system32\bbowdnte.dll",s
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files-2\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Program Files-2\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"D:\\Program Files-2\\uTorrent\\utorrent.exe"=
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-10-15 14:43]
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 13:41]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-14 05:42]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-31 21:24]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-22 10:19:03 C:\WINDOWS\Tasks\Backup.job"
- C:\WINDOWS\system32\ntbackup.exe–backup
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-02 18:24:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Netropa\Multimedia Keyboard\Traymon.exe
C:\Program Files\Netropa\Onscreen Display\osd.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-02 18:29:42 - machine was rebooted [Animesh]
ComboFix-quarantined-files.txt 2008-06-02 12:59:33
Pre-Run: 13,413,732,352 bytes free
Post-Run: 13,444,157,440 bytes free
301 --- E O F --- 2008-05-19 09:48:29
Please Help!!!
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\MS JUAN
I tried deleting it and it did,only to reappear after scanning again.I also tried to delete the registry key it had created but to no avail. Please help as I'm facing great difficulty.My internet connection has become so slow that even a search on google takes hours.I am totally unable to open sites like Yahoo.com.
And also, internet explorer and Mozilla firefox windows open by themselves every now and then.
Here are Hijackthis and Combofix logs:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:31:34 PM, on 6/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
D:\Program Files-2\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files-2\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files-2\Microsoft Office\Office12\ONENOTEM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files-2\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files-2\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files-2\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/oas/ActiveX/MSDcode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1212138580500
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205499308780
O17 - HKLM\System\CCS\Services\Tcpip\..\{C86B090E-38B9-4FF0-995A-5F90C9413511}: NameServer = 202.56.215.6,202.56.215.54
O20 - AppInit_DLLs: D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: geBrQKeD - geBrQKeD.dll (file missing)
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - D:\Program Files-2\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 4408 bytes
And the Combofix Log:
ComboFix 08-06-01.6 - Animesh 2008-06-02 18:15:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.263 [GMT 5.5:30]
Running from: C:\Documents and Settings\Animesh.FERRARI\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM2b5a6e5a.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\AJTEOqss.ini
C:\WINDOWS\system32\AJTEOqss.ini2
C:\WINDOWS\system32\bbowdnte.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\khfDvwXP.dll
C:\WINDOWS\system32\krbxqoai.dll
C:\WINDOWS\system32\ksbyxwei.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\qtoomlhf.ini
C:\WINDOWS\system32\rhqugqaa.dll
C:\WINDOWS\system32\ssqOETJA.dll
C:\WINDOWS\system32\vxphfphu.dll
C:\WINDOWS\system32\ylobtwjm.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-02 to 2008-06-02 )))))))))))))))))))))))))))))))
.
2008-06-02 17:40 . <DIR> C:\WINDOWS\LastGood.Tmp
2008-06-01 18:09 . 2004-08-04 00:56 220,672 --a------ C:\WINDOWS\system32\logon.scr
2008-06-01 18:09 . 2004-08-04 00:56 220,672 --a--c--- C:\WINDOWS\system32\dllcache\logon.scr
2008-06-01 08:55 . 2008-06-01 08:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-31 21:24 . 2008-05-31 21:24 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-31 21:23 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-05-31 20:13 . 2001-08-17 12:20 334,208 --a--c--- C:\WINDOWS\system32\dllcache\ds1wdm.sys
2008-05-31 20:13 . 2008-04-14 00:09 206,976 --a--c--- C:\WINDOWS\system32\dllcache\dot4.sys
2008-05-31 20:13 . 2001-08-17 12:12 28,062 --a--c--- C:\WINDOWS\system32\dllcache\dp83820.sys
2008-05-31 20:13 . 2001-08-17 13:47 23,808 --a--c--- C:\WINDOWS\system32\dllcache\dot4usb.sys
2008-05-31 20:13 . 2008-04-14 05:42 20,992 --a--c--- C:\WINDOWS\system32\dllcache\dshowext.ax
2008-05-31 20:13 . 2001-08-17 14:07 20,192 --a--c--- C:\WINDOWS\system32\dllcache\dpti2o.sys
2008-05-31 20:13 . 2001-08-17 13:47 12,928 --a--c--- C:\WINDOWS\system32\dllcache\dot4prt.sys
2008-05-31 20:13 . 2001-08-17 13:47 8,704 --a--c--- C:\WINDOWS\system32\dllcache\dot4scan.sys
2008-05-31 20:11 . 2008-04-14 05:41 249,856 --a--c--- C:\WINDOWS\system32\dllcache\ctmasetp.dll
2008-05-31 20:10 . 2001-08-17 12:13 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2008-05-31 20:09 . 2001-08-17 14:05 314,752 --a--c--- C:\WINDOWS\system32\dllcache\camdro21.sys
2008-05-31 20:08 . 2001-08-17 22:36 102,400 --a--c--- C:\WINDOWS\system32\dllcache\binlsvc.dll
2008-05-31 20:06 . 2001-08-17 13:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-05-31 20:05 . 2001-08-17 13:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-05-31 20:04 . 2001-08-17 14:56 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-05-31 20:03 . 2008-04-14 00:54 2,145,280 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-05-31 19:38 . 2008-05-31 20:11 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-05-31 19:38 . 2008-05-31 20:11 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-05-31 19:36 . 2008-06-02 17:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-31 19:36 . 2008-06-02 18:27 1,895,968 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-31 19:36 . 2008-06-02 18:24 35,360 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-31 19:36 . 2008-06-02 18:23 28,532 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-31 19:36 . 2008-06-02 18:23 5,312 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-31 19:25 . 2008-05-31 19:25 <DIR> d-------- C:\WINDOWS\system32\VIRepair
2008-05-31 19:22 . 2008-05-31 19:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-05-30 14:16 . 2008-06-02 18:22 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-05-29 20:14 . 2008-05-29 20:14 214 --a------ C:\WINDOWS\HP_48BitScanUpdatePatch.ini
2008-05-29 20:11 . 2008-05-29 20:11 <DIR> d-------- C:\Program Files\Microsoft Calculator Plus
2008-05-29 18:02 . 2008-05-29 20:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-29 17:56 . 2008-05-29 20:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-05-27 18:51 . 2008-05-27 18:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-25 15:42 . 2008-05-25 15:49 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg(2)
2008-05-25 15:41 . 2008-05-27 12:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8(2)
2008-05-24 15:26 . 2008-05-29 20:38 <DIR> d-------- C:\Documents and Settings\Animesh.FERRARI\Application Data\AVGTOOLBAR
2008-05-24 11:57 . 2008-05-24 11:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-05-24 11:55 . 2008-05-24 11:55 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-05-24 11:55 . 2008-05-24 11:57 <DIR> d-------- C:\Program Files\Escape The Museum
2008-05-23 16:50 . 2001-08-17 22:36 65,536 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_mailmsg.dll
2008-05-23 16:50 . 2001-08-17 22:36 57,856 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
2008-05-23 16:50 . 2001-08-17 22:36 43,520 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_fcachdll.dll
2008-05-23 16:50 . 2001-08-17 22:36 38,912 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll
2008-05-23 16:50 . 2001-08-17 22:36 23,040 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_regtrace.exe
2008-05-23 16:50 . 2001-08-17 22:36 12,288 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpctrs.dll
2008-05-23 16:50 . 2001-08-17 22:36 7,168 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_snprfdll.dll
2008-05-23 16:50 . 2001-08-17 22:36 5,632 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_adsiisex.dll
2008-05-23 14:58 . 2008-05-23 16:59 26,845 --a------ C:\WINDOWS\imsins.BAK
2008-05-22 21:49 . 2008-05-22 21:49 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-22 15:22 . 2005-02-27 21:48 356,352 --a------ C:\WINDOWS\system32\RealMediaSplitter.ax
2008-05-22 14:35 . 2008-05-22 14:35 <DIR> d-------- C:\Documents and Settings\Shin Chan\Application Data\Styler
2008-05-22 14:25 . 2008-05-22 14:25 <DIR> d-------- C:\Documents and Settings\AKP\Application Data\Styler
2008-05-22 14:16 . 2008-05-22 14:17 <DIR> d-------- C:\Documents and Settings\Animesh.FERRARI\Application Data\ViStart
2008-05-22 12:49 . 2008-05-22 12:49 <DIR> d-------- C:\Documents and Settings\Animesh.FERRARI\Application Data\Styler
2008-05-22 12:40 . 2008-05-22 12:40 <DIR> d-------- C:\Program Files\WinFlip
2008-05-22 12:40 . 2008-05-22 12:40 <DIR> d-------- C:\Program Files\TrueTransparency
2008-05-22 12:40 . 2008-05-31 19:25 <DIR> d-------- C:\Program Files\Styler
2008-05-22 12:40 . 2008-05-22 12:40 <DIR> d-------- C:\Documents and Settings\Administrator.FERRARI\Application Data\Styler
2008-05-22 12:36 . 2008-05-31 19:26 <DIR> d-------- C:\WINDOWS\system32\VITrans
2008-05-22 12:36 . 2006-12-03 17:15 111,104 --a------ C:\WINDOWS\system32\Uharc.exe
2008-05-22 12:36 . 2008-05-22 12:36 78,942 --a------ C:\WINDOWS\Icon_1.ico
2008-05-22 12:36 . 2006-12-03 17:15 19,968 --a------ C:\WINDOWS\system32\reico.exe
2008-05-22 12:36 . 2006-12-03 17:14 8,636 --a------ C:\WINDOWS\system32\modifype.exe
2008-05-22 12:29 . 2008-05-31 19:15 <DIR> d-------- C:\Documents and Settings\Administrator.FERRARI
2008-05-20 15:10 . 2008-05-20 15:10 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-20 15:10 . 2008-05-20 15:10 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-05-20 15:10 . 2008-05-20 15:10 <DIR> d-------- C:\Program Files\MSBuild
2008-05-20 15:08 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-05-20 14:03 . 2008-05-20 14:03 <DIR> d-------- C:\WINDOWS\Sun
2008-05-20 14:01 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-15 21:32 . 2008-05-15 21:32 <DIR> d-------- C:\DVDVideoSoft
2008-05-15 16:54 . 2008-05-15 16:54 <DIR> d-------- C:\WINDOWS\Performance
2008-05-15 16:53 . 2008-05-19 15:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-05-15 15:49 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-05-13 21:58 . 2008-05-13 21:58 <DIR> d-------- C:\WINDOWS\system32\en
2008-05-13 21:58 . 2008-05-13 21:58 <DIR> d-------- C:\WINDOWS\l2schemas
2008-05-13 21:58 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0411.dll
2008-05-13 21:58 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0404.dll
2008-05-13 21:57 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0804.dll
2008-05-13 21:57 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0412.dll
2008-05-13 21:57 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0401.dll
2008-05-13 21:56 . 2008-04-14 05:41 218,112 --a--c--- C:\WINDOWS\system32\dllcache\c_g18030.dll
2008-05-13 21:56 . 2007-04-02 23:56 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt040d.dll
2008-05-13 21:52 . 2008-04-13 22:06 144,384 --a------ C:\WINDOWS\system32\drivers\hdaudbus.sys
2008-05-13 21:52 . 2008-04-14 00:10 10,240 --a------ C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-05-09 16:27 . 2008-05-09 16:27 0 --a------ C:\WINDOWS\pws.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-31 14:43 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-31 13:35 --------- d-----w C:\Documents and Settings\Animesh.FERRARI\Application Data\uTorrent
2008-05-27 13:45 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-26 12:03 --------- d-----w C:\Program Files\Yahoo!
2008-05-23 08:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-05-16 12:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-12 10:45 --------- d-----w C:\Documents and Settings\Animesh.FERRARI\Application Data\GetRight Pro
2008-04-29 15:26 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-21 12:50 --------- d-----w C:\Documents and Settings\Animesh.FERRARI\Application Data\Talkback
2008-04-21 12:18 --------- d-----w C:\Program Files\Google
2008-04-18 08:40 --------- d-----w C:\Documents and Settings\Shin Chan\Application Data\Microsoft Games
2008-04-17 10:36 --------- d-----w C:\Documents and Settings\Animesh.FERRARI\Application Data\Microsoft Games
2008-04-17 10:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Games
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:13 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:11 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 21:00 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:27 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 19:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 19:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 19:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 18:54 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 18:53 36,608 ----a-w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 18:53 264,832 ----a-w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 18:51 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 18:51 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 18:51 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 18:51 55,808 ----a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 18:51 101,120 ----a-w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 18:45 60,160 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
2008-04-13 18:44 81,664 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 18:44 799,744 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 18:44 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys
2008-04-13 18:44 153,344 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 18:43 14,208 ----a-w C:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 18:43 12,672 ----a-w C:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 18:41 52,352 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 18:41 42,112 ----a-w C:\WINDOWS\system32\drivers\imapi.sys
2008-04-13 18:39 7,552 ----a-w C:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 18:39 5,504 ----a-w C:\WINDOWS\system32\drivers\mstee.sys
2008-04-13 18:39 5,376 ----a-w C:\WINDOWS\system32\drivers\mspclock.sys
2008-04-13 18:39 42,368 ----a-w C:\WINDOWS\system32\drivers\mountmgr.sys
2008-04-13 18:39 4,992 ----a-w C:\WINDOWS\system32\drivers\mspqm.sys
2008-04-13 18:39 4,352 ----a-w C:\WINDOWS\system32\drivers\swenum.sys
2008-04-13 18:39 384,768 ----a-w C:\WINDOWS\system32\drivers\update.sys
2008-04-13 18:39 24,576 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 07:41 114688]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2001-11-08 23:10 147456]
"AVP"="D:\Program Files-2\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2008-02-08 18:36 227856]
C:\Documents and Settings\Shin Chan\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - D:\Program Files-2\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
C:\Documents and Settings\Animesh.FERRARI\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - D:\Program Files-2\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geBrQKeD]
geBrQKeD.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=D:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"ViOrb"=C:\Program Files\ViOrb\ViOrb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="D:\Program Files-2\Java\jre1.6.0_06\bin\jusched.exe"
"BM2b5a6e5a"=Rundll32.exe "C:\WINDOWS\system32\bbowdnte.dll",s
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files-2\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Program Files-2\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"D:\\Program Files-2\\uTorrent\\utorrent.exe"=
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-10-15 14:43]
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 13:41]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-14 05:42]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-31 21:24]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-22 10:19:03 C:\WINDOWS\Tasks\Backup.job"
- C:\WINDOWS\system32\ntbackup.exe–backup
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-02 18:24:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Netropa\Multimedia Keyboard\Traymon.exe
C:\Program Files\Netropa\Onscreen Display\osd.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-02 18:29:42 - machine was rebooted [Animesh]
ComboFix-quarantined-files.txt 2008-06-02 12:59:33
Pre-Run: 13,413,732,352 bytes free
Post-Run: 13,444,157,440 bytes free
301 --- E O F --- 2008-05-19 09:48:29
Please Help!!!