ComboFix 08-11-17.04 - Viral 2008-11-18 10:43:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1271 [GMT -5:00]
Running from: c:\documents and settings\Viral\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LocalService\Application Data\NetMon
c:\documents and settings\LocalService\Application Data\NetMon\domains.txt
c:\documents and settings\LocalService\Application Data\NetMon\log.txt
c:\documents and settings\Viral\Application Data\gadcom
c:\documents and settings\Viral\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\network monitor
c:\program files\network monitor\netmon.exe
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\windows\system32\atmtd.dll
c:\windows\system32\atmtd.dll._
c:\windows\system32\atuwddsq.dll
c:\windows\system32\laqxtuxp.ini
c:\windows\system32\mlJAsrrR.dll
c:\windows\system32\mlJCRhhh.dll
c:\windows\system32\MSINET.oca
c:\windows\system32\msnav32.ax
c:\windows\system32\nqxlbb.dll
c:\windows\system32\pac.txt
c:\windows\system32\qeiauz.dll
c:\windows\system32\rgdeqjpf.ini
c:\windows\system32\RrrsAJlm.ini
c:\windows\system32\RrrsAJlm.ini2
c:\windows\system32\winpfz33.sys
c:\windows\system32\zxdnt3d.cfg
c:\windows\uninstall_nmon.vbs
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
((((((((((((((((((((((((( Files Created from 2008-10-18 to 2008-11-18 )))))))))))))))))))))))))))))))
.
2008-11-18 10:22 . 2008-11-18 10:22 <DIR> d-------- c:\program files\Trend Micro
2008-11-17 16:53 . 2008-11-17 16:53 <DIR> d-------- c:\documents and settings\Administrator
2008-11-17 16:46 . 2008-11-17 16:46 0 --a------ c:\windows\system32\lo2.txtt
2008-11-17 00:13 . 2008-11-17 00:13 64,859 --a------ c:\windows\system32\rjfmcgezzgmkckxz.exe
2008-11-17 00:09 . 2008-11-17 00:09 <DIR> d-------- c:\program files\Kaspersky Lab
2008-11-17 00:09 . 2008-11-18 10:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-17 00:09 . 2008-11-18 10:45 3,082,272 --ahs---- c:\windows\system32\drivers\fidbox.dat
2008-11-17 00:09 . 2008-11-18 10:47 376,864 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2008-11-17 00:09 . 2008-11-17 00:17 96,976 --a------ c:\windows\system32\drivers\klin.dat
2008-11-17 00:09 . 2008-11-17 00:09 87,855 --a------ c:\windows\system32\drivers\klick.dat
2008-11-17 00:09 . 2008-11-18 10:45 26,208 --ahs---- c:\windows\system32\drivers\fidbox.idx
2008-11-17 00:09 . 2008-11-18 10:45 3,388 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2008-11-16 23:15 . 2008-11-16 23:15 <DIR> d-------- c:\documents and settings\Viral\Application Data\IUpd721
2008-11-16 23:10 . 2008-11-17 00:23 <DIR> d-------- c:\documents and settings\Viral\Application Data\NI.GSCNS
2008-11-16 23:02 . 2008-11-17 01:39 <DIR> d-------- c:\windows\system32\wpd
2008-11-16 23:02 . 2008-11-17 01:39 <DIR> d-------- c:\windows\system32\spc
2008-11-16 23:02 . 2008-11-16 23:02 <DIR> d-------- c:\windows\system32\ocx
2008-11-16 23:02 . 2008-11-17 01:39 <DIR> d-------- c:\windows\system32\dom
2008-11-16 23:02 . 2008-11-17 00:23 <DIR> d--hs---- c:\windows\dmlydQ
2008-11-16 23:01 . 2008-11-17 01:39 <DIR> d-------- c:\windows\system32\sX3i19
2008-11-16 23:01 . 2008-11-16 23:02 <DIR> d-------- c:\temp\PRE45
2008-11-16 23:01 . 2008-11-16 23:01 35,840 --a------ c:\windows\system32\prun.exe
2008-11-16 02:24 . 2008-11-16 02:36 <DIR> d-------- c:\documents and settings\Viral\Application Data\Nero
2008-11-16 02:01 . 2008-11-16 02:01 4,767 --a------ c:\windows\Irremote.ini
2008-11-16 02:00 . 2008-11-16 02:00 <DIR> d-------- c:\program files\Windows Sidebar
2008-11-16 01:51 . 2008-11-16 02:01 <DIR> d-------- c:\program files\Nero
2008-11-16 01:51 . 2008-11-16 02:11 <DIR> d-------- c:\program files\Common Files\Nero
2008-11-16 01:51 . 2008-11-16 01:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2008-11-15 18:04 . 2008-11-15 18:04 799,329 --a------ C:\IMG_0431.jpg
2008-11-09 23:29 . 2008-11-09 23:29 6,537 --a------ C:\index.html
2008-10-30 23:01 . 2008-10-30 23:02 <DIR> d-------- c:\documents and settings\Viral\Application Data\Multi-Note
2008-10-23 13:01 . 2008-10-23 13:01 <DIR> d-------- c:\documents and settings\Viral\Application Data\Motive
2008-10-23 12:56 . 2008-10-23 12:56 <DIR> d-------- c:\documents and settings\Viral\Application Data\Research In Motion
2008-10-23 12:56 . 2008-10-23 12:56 256 --a------ c:\windows\system32\pool.bin
2008-10-23 12:55 . 2008-10-23 12:55 <DIR> d-------- c:\program files\Research In Motion
2008-10-23 12:55 . 2008-10-23 12:55 <DIR> d-------- c:\program files\Common Files\Research In Motion
2008-10-23 12:55 . 2007-01-18 09:24 26,496 -ra------ c:\windows\system32\drivers\RimSerial.sys
2008-10-23 12:42 . 2008-10-23 12:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\MSN6
2008-10-23 12:39 . 2008-10-23 12:39 <DIR> d-------- c:\windows\bin
2008-10-23 12:39 . 2008-10-23 12:39 <DIR> d-------- c:\program files\Common Files\Motive
2008-10-23 12:39 . 2008-10-23 12:39 <DIR> d-------- c:\documents and settings\Viral\Application Data\Verizon
2008-10-23 12:39 . 2008-10-23 12:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\Verizon
2008-10-23 12:39 . 2008-10-23 12:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\Motive
2008-10-23 12:38 . 2008-10-23 12:38 <DIR> d-------- c:\program files\verizon_broad
2008-10-23 12:38 . 2008-10-23 12:38 <DIR> d-------- c:\program files\Verizon Broadband Firefox Toolbar
2008-10-23 12:38 . 2008-10-23 14:14 <DIR> d-------- c:\documents and settings\Viral\Application Data\verizon_broad
2008-10-23 12:29 . 2008-10-23 12:42 <DIR> d-------- c:\program files\Verizon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-18 15:46 --------- d-----w c:\program files\Steam
2008-11-17 06:38 --------- d-----w c:\documents and settings\Viral\Application Data\FileZilla
2008-11-17 05:08 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-17 03:56 --------- d-----w c:\documents and settings\Viral\Application Data\uTorrent
2008-11-13 18:04 --------- d-----w c:\documents and settings\Viral\Application Data\Winamp
2008-11-10 03:41 --------- d-----w c:\documents and settings\Viral\Application Data\LimeWire
2008-10-15 07:45 --------- d-----w c:\program files\PeerGuardian2
2008-10-13 02:45 --------- d-----w c:\documents and settings\Viral\Application Data\SSH
2008-09-22 23:13 --------- d-----w c:\documents and settings\Viral\Application Data\WinAmp Control
2008-09-22 22:49 --------- d-----w c:\program files\Google
2008-09-06 02:16 1,900,544 ----a-w c:\windows\system32\usbaaplrc.dll
2005-07-29 21:24 472 --sha-r c:\windows\dmlydQ\xA5Vxk.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8398-26FADCF27386}]
2008-05-30 11:42 1991680 --a------ c:\progra~1\VERIZO~1\VERIZO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8398-26FADCF27386}"= "c:\progra~1\VERIZO~1\VERIZO~1.DLL" [2008-05-30 1991680]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-8398-26FADCF27386}"= "c:\progra~1\VERIZO~1\VERIZO~1.DLL" [2008-05-30 1991680]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8398-26fadcf27386}]
[HKEY_CLASSES_ROOT\verizon_broad.VERIZON_BROAD]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-03-06 50528]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Steam"="c:\program files\Steam\Steam.exe" [2008-10-08 1410296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-09-14 1603152]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-08 289576]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-22 30192]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-09-28 936960]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-07-29 206088]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 c:\windows\RTHDCPL.exe]
c:\documents and settings\Viral\Start Menu\Programs\Startup\
palmOne Registration.lnk - e:\program files\palmOne\register.exe [2005-09-19 2367488]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - e:\program files\palmOne\Hotsync.exe [2004-06-09 471040]
VPN Client.lnk - c:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2008-04-17 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi2"= usbkt1x1.dll
"midi3"= usbkt1x1.dll
"midi4"= usbkt1x1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.2.407\\English\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-03-23 24652]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 USBKS1X1;Midiman USB Keystation Midi Driver;c:\windows\system32\drivers\usbks1x1.sys [2008-05-30 32476]
S3 GoogleDesktopManager-090808-172447;Google Desktop Manager 5.8.809.8522;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-22 30192]
S3 UKS11LDR;Midiman USB Keystation Loader;c:\windows\system32\drivers\uks11ldr.sys [2008-05-30 15740]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8277c6f4-302c-11dd-829b-00044b038aec}]
\Shell\AutoRun\command - H:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder
2008-11-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{17b0bed7-cdc9-4bbf-ba80-ff9d43f9fe42} - c:\windows\system32\nqxlbb.dll
BHO-{1DE1AC19-0761-45CD-B39B-72EAA79AA192} - c:\windows\system32\mlJAsrrR.dll
BHO-{73259091-9574-4ED8-A40F-7F65AFC28634} - c:\windows\system32\mlJCRhhh.dll
ShellExecuteHooks-{73259091-9574-4ED8-A40F-7F65AFC28634} - c:\windows\system32\mlJCRhhh.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Viral\Application Data\Mozilla\Firefox\Profiles\3xe3bxkn.default\
FF -: plugin - c:\documents and settings\Viral\Application Data\Mozilla\Firefox\Profiles\3xe3bxkn.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-18 10:47:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-11-18 10:49:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-18 15:49:21
Pre-Run: 44,501,430,272 bytes free
Post-Run: 47,573,823,488 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
223