Kaspersky anti virus is only a trial i usually use avg which one is best to use.
ComboFix 08-01-20.1 - Simon 2008-01-22 19:20:27.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.159 [GMT 0:00]
Running from: C:\Documents and Settings\Simon\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Simon\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\drivers\hldrrr.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\hldrrr.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-22 to 2008-01-22 )))))))))))))))))))))))))))))))
.
2008-01-22 17:38 . 2008-01-22 17:38 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-01-22 17:38 . 2008-01-22 17:38 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-01-22 17:36 . 2008-01-22 17:36 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-22 17:36 . 2008-01-22 19:20 337,952 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-22 17:36 . 2008-01-22 19:24 12,064 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-22 17:36 . 2008-01-22 18:27 3,380 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-22 17:36 . 2008-01-22 18:27 1,844 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-22 17:14 . 2008-01-22 17:14 <DIR> d-------- C:\kav
2008-01-21 18:00 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-21 16:36 . 2008-01-22 18:08 250 --a------ C:\WINDOWS\gmer.ini
2008-01-19 09:09 . 2008-01-19 09:09 5,630 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-19 09:07 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-01-19 09:07 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-01-19 09:07 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-01-19 09:07 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-01-19 09:07 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-01-19 09:07 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-18 22:56 . 2008-01-18 15:51 602 --a------ C:\WINDOWS\system\hpsysdrv.dat.oth
2008-01-18 22:52 . 2008-01-18 22:52 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-18 22:39 . 2008-01-22 17:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-18 22:39 . 2008-01-18 22:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-18 22:23 . 2008-01-18 22:23 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-18 20:44 . 2008-01-18 20:44 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-18 20:44 . 2008-01-18 20:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 20:43 . 2008-01-18 20:43 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-18 16:21 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-18 16:02 . 2008-01-18 16:02 <DIR> d--hs---- C:\Documents and Settings\All Users\DRM
2008-01-18 16:00 . 2008-01-22 18:28 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-01-18 15:42 . 2008-01-18 15:42 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-01-13 12:44 . 2008-01-13 14:47 <DIR> d-------- C:\PSP Movies
2008-01-09 07:41 . 2008-01-09 07:41 <DIR> d-------- C:\Program Files\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-22 18:29 --------- d-----w C:\Documents and Settings\Simon\Application Data\Skype
2008-01-22 18:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-20 13:56 32,768 ----a-w C:\WINDOWS\system32\instlsp.exe
2008-01-18 22:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-18 19:47 --------- d-----w C:\Program Files\Google
2008-01-18 18:50 47,360 ----a-w C:\Documents and Settings\Simon\Application Data\pcouffin.sys
2008-01-18 18:50 --------- d-----w C:\Program Files\VSO
2008-01-18 18:50 --------- d-----w C:\Documents and Settings\Simon\Application Data\Vso
2008-01-17 18:33 --------- d-----w C:\Program Files\Lx_cats
2008-01-02 17:49 125,824 ----a-w C:\Documents and Settings\Simon\Application Data\GDIPFONTCACHEV1.DAT
2007-12-18 00:44 219,664 ----a-w C:\WINDOWS\system32\klogon.dll
2007-12-18 00:43 23,396 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
2007-12-14 21:20 --------- d-----w C:\Program Files\iTunes
2007-12-14 21:19 --------- d-----w C:\Program Files\iPod
2007-12-14 21:18 --------- d-----w C:\Program Files\QuickTime
2007-12-14 11:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-13 13:28 24,592 ----a-w C:\WINDOWS\system32\drivers\klim5.sys
2007-12-11 07:29 --------- d-----w C:\Program Files\Common Files\xing shared
2007-12-11 07:29 --------- d-----w C:\Program Files\Common Files\Real
2007-12-03 12:16 --------- d-----w C:\Program Files\PQDVD
2007-11-28 22:11 --------- d---a-w C:\Program Files\Java
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-04-09 15:00 99,488 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2005-08-28 16:04 38,060,544 ----a-w C:\Program Files\cjB2300EN.exe
2003-06-20 02:05 49,776 ----a-w C:\WINDOWS\inf\usbhub20.sys
2003-06-20 02:05 24,752 ----a-w C:\WINDOWS\inf\hidclass.sys
2003-06-20 02:05 20,688 ----a-w C:\WINDOWS\inf\usbd.sys
2003-06-20 02:05 19,728 ----a-w C:\WINDOWS\inf\usbehci.sys
2003-06-20 02:05 138,288 ----a-w C:\WINDOWS\inf\usbport.sys
.
((((((((((((((((((((((((((((( snapshot@2008-01-21_18.18.23.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 18:01:22 737,280 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-22 19:20:19 1,429,504 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-21 18:01:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-22 19:20:19 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-21 18:01:22 729,088 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-22 19:20:19 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-21 18:01:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-22 19:20:19 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-21 18:01:22 4,370,432 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-22 19:20:19 5,435,392 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-21 18:01:22 303,104 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-22 19:20:20 303,104 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2008-01-21 17:52:51 53,552 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-22 19:16:59 53,552 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-21 17:52:51 382,000 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-22 19:16:59 382,000 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll" [2003-05-03 06:19 835654 C:\WINDOWS\system32\nview.dll]
"BackupNotify"="c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2006-06-12 10:03 668735]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-08-31 16:40 22879528]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 07:33 8720384]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-22 18:25 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:31 208952]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-01-21 06:59 59392]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-01-21 07:18 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-01-21 07:18 455168]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 14:07 114688]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 14:23 90112]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-14 06:53 49152]
"HPHUPD05"="c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 10:03 49152]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 09:55 483328]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 15:01 155648]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 04:42 212992]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-05-03 06:19 4640768]
"nwiz"="nwiz.exe" [2003-05-03 06:19 323584 C:\WINDOWS\system32\nwiz.exe]
"VTTimer"="VTTimer.exe" [2003-05-08 07:32 36864 C:\WINDOWS\system32\VTTimer.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 23:57 81920]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 12:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-19 20:10 335872]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2003-08-09 11:27 139264]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2003-06-18 01:13 118784]
"LXCGCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-04-27 14:21 69632]
"lxcgmon.exe"="C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" [2005-05-05 03:24 200704]
"EzPrint"="C:\Program Files\Lexmark 2300 Series\ezprint.exe" [2005-06-08 11:19 94208]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-05-03 18:20 299008]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 07:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-25 04:20 28672]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-11 07:28 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-01-22 18:18 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 07:33 8720384]
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
AutoTBar.exe [2003-06-21 01:08:00 53248]
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 14:11:14 27136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-17 19:42:55 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
BTTray.lnk - C:\Program Files\TDK Systems\Bluetooth Software\BTTray.exe [2003-11-17 09:25:16 503869]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
NETGEAR WG111T Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe [2007-07-13 15:42:52 483412]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;C:\WINDOWS\System32\DNINDIS5.SYS [2003-07-24 12:10]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
S3 AR5523;NETGEAR WG111T USB2.0 Wireless Card Service;C:\WINDOWS\system32\DRIVERS\wg11tnd5.sys [2004-10-15 09:41]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-14 17:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\iPodSetup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-18 17:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
"2008-01-02 18:38:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-22 19:24:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-22 19:26:39
ComboFix-quarantined-files.txt 2008-01-22 19:26:26
ComboFix2.txt 2008-01-22 18:34:28
ComboFix3.txt 2008-01-21 19:10:09
ComboFix4.txt 2008-01-21 18:18:59
.
2008-01-22 19:00:49 --- E O F ---