hi viktors,
ok good. i have pasted your combo log below for easier viewing:
ComboFix 08-03-30.1 - Viktor Salonski 2008-03-30 13:55:30.3 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1251.381.1033.18.377 [GMT 2:00]
Running from: C:\Documents and Settings\Viktor Salonski\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM7b9babbf.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ddcBUlKA.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\fdohxpwu.dll
C:\WINDOWS\system32\fsuxkibq.dll
C:\WINDOWS\system32\goqeware.dll
C:\WINDOWS\system32\macgjaxo.ini
C:\WINDOWS\system32\mlJYoppo.dll
C:\WINDOWS\system32\opnoLcbX.dll
C:\WINDOWS\system32\oppoYJlm.ini
C:\WINDOWS\system32\oppoYJlm.ini2
C:\WINDOWS\system32\oxajgcam.dll
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\swvoeexp.dll
C:\WINDOWS\system32\vtUlMedD.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\win32.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\wvUnKEuT.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\NPF
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-30 )))))))))))))))))))))))))))))))
.
2008-03-29 16:49 . 2008-03-29 16:49 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-29 16:49 . 2008-03-29 16:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-29 16:48 . 2008-03-29 16:48 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\Malwarebytes
2008-03-29 14:13 . 2008-01-07 14:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-03-29 14:10 . 2008-03-29 14:10 <DIR> d-------- C:\Program Files\ESET
2008-03-29 13:36 . 2008-03-29 13:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-03-28 13:13 . 2008-03-30 01:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-28 13:13 . 2008-03-28 13:13 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-25 16:32 . 2008-03-25 16:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-03-25 15:29 . 2008-03-25 15:29 <DIR> d--hs---- C:\FOUND.040
2008-03-25 00:11 . 2008-03-25 00:11 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\FLV Extract
2008-03-23 14:52 . 2008-03-23 14:52 <DIR> d-------- C:\Program Files\Total Video Converter
2008-03-23 14:42 . 2008-03-23 14:42 <DIR> d-------- C:\VideoOutput
2008-03-23 14:41 . 2008-03-23 14:41 <DIR> d-------- C:\Program Files\AVD Video Processor 7.7 TRIAL
2008-03-22 14:43 . 2008-03-22 14:48 6,993 --a------ C:\WINDOWS\system32\fsmgmt.dll
2008-03-21 16:35 . 2008-03-21 16:35 <DIR> d-------- C:\WINDOWS\system32\VIRepair
2008-03-16 23:54 . 2008-03-16 23:54 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\Submersible
2008-03-16 23:53 . 2006-03-31 02:39 368,640 --a------ C:\WINDOWS\system32\ReWire.dll
2008-03-16 23:53 . 2006-03-30 01:11 233,472 --a------ C:\WINDOWS\system32\REX Shared Library.dll
2008-03-16 23:30 . 2008-03-16 23:30 <DIR> d-------- C:\Program Files\Paint.NET
2008-03-16 23:27 . 2008-03-16 23:27 <DIR> d-------- C:\Program Files\Vista Drive Icon
2008-03-11 17:51 . 2008-03-11 17:51 <DIR> d-------- C:\vcs5BGEffects
2008-03-10 23:54 . 2008-03-10 23:54 <DIR> d-------- C:\My Music
2008-03-10 08:00 . 2008-03-10 08:00 <DIR> d--hs---- C:\FOUND.039
2008-03-08 16:23 . 2008-03-08 16:23 <DIR> d--hs---- C:\FOUND.038
2008-03-08 15:46 . 2008-03-08 15:46 <DIR> drahs---- C:\dcht
2008-03-08 15:39 . 2008-03-08 15:39 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\WNR
2008-03-07 03:08 . 2008-03-07 03:08 3,072 --ahs---- C:\Thumbs.db
2008-03-07 03:07 . 2008-03-07 03:07 1,127,243 --a------ C:\Misolovka.wmv
2008-03-06 18:05 . 2008-03-06 18:05 <DIR> d-------- C:\Program Files\Sony
2008-03-06 18:05 . 2008-03-06 18:05 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\Sony
2008-03-06 18:04 . 2008-03-06 18:04 <DIR> d-------- C:\Program Files\Sony Setup
2008-03-02 15:27 . 2008-03-02 15:27 <DIR> d-------- C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-28 21:14 . 2008-02-28 21:14 176 --a------ C:\WINDOWS\wininit.ini
2008-02-28 21:10 . 2008-02-28 21:10 <DIR> d-------- C:\Program Files\Mozilla Firefox 3 Beta 1
2008-02-28 20:39 . 2008-02-28 20:39 <DIR> d-------- C:\Program Files\Pricaonica
2008-02-27 13:01 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-02-27 13:01 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-02-27 13:01 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-02-26 18:59 . 2008-02-26 18:59 <DIR> d-------- C:\Program Files\Windows Live
2008-02-26 18:59 . 2008-02-26 18:59 <DIR> d--hs---- C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-26 18:59 . 2008-02-26 18:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-25 17:55 . 2008-02-25 17:55 <DIR> d-------- C:\WINDOWS\ERUNT
2008-02-25 16:59 . 2008-02-25 15:14 <DIR> d-------- C:\SDFix
2008-02-24 22:54 . 2008-02-24 22:54 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-24 22:20 . 2008-02-24 22:20 <DIR> d-------- C:\Program Files\Alwil Software
2008-02-24 19:42 . 2008-02-24 19:42 <DIR> d--hs---- C:\FOUND.037
2008-02-22 14:12 . 2008-02-22 14:12 28,672 --a------ C:\WINDOWS\system32\klfv.exe
2008-02-22 14:07 . 2008-02-22 14:07 <DIR> d-------- C:\Program Files\FolderVault
2008-02-22 14:07 . 2008-02-22 14:07 921,654 --a------ C:\WINDOWS\stones6865E094.bmp
2008-02-22 14:07 . 2008-02-22 14:07 135,168 --a------ C:\WINDOWS\system32\Lock.dll
2008-02-22 14:07 . 2008-02-22 14:11 1,940 --a------ C:\WINDOWS\system32\fv2.lic
2008-02-22 14:07 . 2008-02-22 14:07 19 --a------ C:\WINDOWS\CTDChannels_Version.6865E094.cdf
2008-02-22 13:50 . 2008-02-22 13:50 <DIR> d-------- C:\Program Files\Folder Lock
2008-02-22 13:50 . 2007-12-02 19:54 79,920 --a------ C:\WINDOWS\system32\FLKill.exe
2008-02-22 13:50 . 2008-02-22 14:20 20 --a------ C:\sccfg.sys
2008-02-21 19:54 . 2008-02-21 19:54 <DIR> d--hs---- C:\FOUND.036
2008-02-20 21:38 . 2008-02-20 21:38 <DIR> d-------- C:\Program Files\RipCast 1.9
2008-02-19 17:40 . 2008-02-19 17:40 <DIR> d--hs---- C:\FOUND.035
2008-02-18 20:00 . 2008-02-18 20:00 <DIR> d-------- C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-02-18 20:00 . 2008-02-18 20:00 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\Audacity
2008-02-18 19:56 . 2008-02-18 19:56 220 --a------ C:\WINDOWS\system32\test.aok
2008-02-18 19:55 . 2008-02-18 19:55 <DIR> d-------- C:\Program Files\Ultra Video Converter
2008-02-18 19:55 . 2007-04-12 14:19 129,024 --a------ C:\WINDOWS\system32\AVERM.dll
2008-02-18 19:55 . 2006-09-26 13:57 28,672 --a------ C:\WINDOWS\system32\AVEQT.dll
2008-02-18 14:18 . 2008-02-18 14:18 <DIR> d--hs---- C:\FOUND.034
2008-02-16 14:04 . 2008-02-16 14:04 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\ViStart
2008-02-16 13:58 . 2008-02-16 13:58 78,942 --a------ C:\WINDOWS\Icon_2.ico
2008-02-16 13:50 . 2008-02-16 13:50 <DIR> d-------- C:\Program Files\WinFlip
2008-02-16 13:50 . 2008-02-16 13:50 <DIR> d-------- C:\Program Files\TrueTransparency
2008-02-16 13:50 . 2008-02-16 13:50 <DIR> d-------- C:\Program Files\Styler
2008-02-16 13:47 . 2008-02-16 13:47 78,942 --a------ C:\WINDOWS\Icon_1.ico
2008-02-16 13:46 . 2008-02-16 13:46 <DIR> d-------- C:\WINDOWS\system32\VITrans
2008-02-16 13:19 . 2008-02-16 13:19 <DIR> d-------- C:\Program Files\Safarp
2008-02-15 22:21 . 2007-12-09 08:51 889 --a------ C:\ma477.bin
2008-02-15 19:19 . 2008-02-15 19:19 <DIR> d-------- C:\Program Files\Apple Software Update
2008-02-15 19:19 . 2008-02-15 19:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-02-15 15:24 . 2008-02-15 15:24 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-02-15 14:24 . 2008-02-15 14:24 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\Styler
2008-02-15 14:23 . 2006-12-03 17:15 111,104 --a------ C:\WINDOWS\system32\Uharc.exe
2008-02-15 14:23 . 2006-12-03 17:15 19,968 --a------ C:\WINDOWS\system32\reico.exe
2008-02-15 14:23 . 2006-12-03 17:14 8,636 --a------ C:\WINDOWS\system32\modifype.exe
2008-02-14 21:26 . 2008-02-14 21:26 <DIR> d-------- C:\Program Files\Bad CD DVD Reader
2008-02-14 21:18 . 2003-06-25 16:05 266,360 --a------ C:\WINDOWS\system32\TweakUI.exe
2008-02-14 21:18 . 2002-06-21 15:09 160,217 --a------ C:\WINDOWS\system32\PowerToysLicense.rtf
2008-02-14 14:16 . 2008-02-14 14:16 <DIR> d-------- C:\Program Files\Nexus_Radio
2008-02-14 13:59 . 2008-02-14 13:59 <DIR> d-------- C:\Program Files\Nexus Radio
2008-02-14 13:55 . 2008-02-14 13:55 <DIR> d-------- C:\Program Files\JLC's Software
2008-02-14 13:55 . 2008-02-14 13:55 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\JLC's Software
2008-02-13 20:03 . 2008-02-13 20:03 <DIR> d-------- C:\Program Files\Ocean Technology
2008-02-13 20:03 . 2008-02-13 20:03 <DIR> d-------- C:\Documents and Settings\Viktor Salonski\Application Data\InstallShield
2008-02-13 20:03 . 2006-03-14 02:26 53,248 --a------ C:\WINDOWS\system32\ImageOle.dll
2008-02-11 20:24 . 2008-02-11 20:24 <DIR> d-------- C:\Program Files\GameHouse
2008-02-11 13:00 . 2008-02-11 13:00 <DIR> d--hs---- C:\FOUND.033
2008-02-10 20:50 . 2008-02-10 21:00 26 --a------ C:\WINDOWS\Zone.Identifier
2008-02-10 02:44 . 2008-02-10 02:44 45,056 --a------ C:\WINDOWS\system32\fsmgmt.dll.tmp
2008-02-09 15:29 . 2008-02-09 15:29 271,360 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2008-02-09 15:29 . 2008-02-09 15:29 18,048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2008-02-09 15:28 . 2008-02-09 15:28 <DIR> d-------- C:\Program Files\Eclypse
2008-02-02 17:22 . 2008-02-02 17:22 <DIR> d-------- C:\Program Files\Zuma Deluxe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 20:23 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-01-11 04:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-12-19 22:01 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 08:51 179,584 ----a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-08 04:21 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 10:01 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 10:00 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 03:59 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-04 17:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 17:38 550,912 ----a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-06-29 17:45 17 ----a-w C:\Program Files\Sims2Pack Clean Installer.ini
2007-08-08 12:32 801 --sha-w C:\WINDOWS\system32\mmf.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 22:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-04 18:06 68856]
"speedfan"="C:\Program Files\SpeedFan\speedfan.exe" [2007-09-17 18:04 2902528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-15 17:20 6803456]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"DrvIcon"="C:\Program Files\Vista Drive Icon\DrvIcon.exe" [2007-07-04 20:59 45056]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-15 15:23 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 08:21 1443072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsmgmt]
fsmgmt.dll 2008-03-22 14:48 6993 C:\WINDOWS\system32\fsmgmt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-04-13 11:09 49152 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2005-12-07 22:57 30208 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\Icq\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\DC++\\DCPlusPlus.exe"=
"C:\\WINDOWS\\System32\\autmgr32.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Real\\RealOne Player\\REALPLAY.EXE"=
"C:\\TOTALCMD\\totalcmd.exe"=
"C:\\Program Files\\ApexDC++\\ApexDC.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\WINDOWS\\System32\\rtcshare.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\GGclient.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-12-21 08:21]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-03 22:56]
S2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe []
S3 ES-620;Edisonsoft ES-620 USB Infrared Adapter;C:\WINDOWS\system32\DRIVERS\ES-620.sys [2003-04-17 11:42]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2006-12-24 15:49]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2006-12-24 15:49]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys [2006-12-24 15:49]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2006-12-24 15:49]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys [2006-12-24 15:49]
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys []
S3 z530bus;Sony Ericsson Z530 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\z530bus.sys [2006-12-24 15:49]
S3 z530mdfl;Sony Ericsson Z530 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\z530mdfl.sys [2006-12-24 15:49]
S3 z530mdm;Sony Ericsson Z530 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\z530mdm.sys [2006-12-24 15:49]
S3 z530mgmt;Sony Ericsson Z530 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\z530mgmt.sys [2006-12-24 15:49]
S3 z530obex;Sony Ericsson Z530 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\z530obex.sys [2006-12-24 15:49]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-03-29 20:47:04 C:\WINDOWS\Tasks\{1C82364A-8B8D-40B7-A7BC-F7E694BE0141}_PRIVATE-B55B9C7_Viktor Salonski.job"
- C:\WINDOWS\system32\mobsync.exeT /Schedule=
"2008-03-28 15:16:06 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-30 14:05:23
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2008-03-30 14:07:46 - machine was rebooted
ComboFix2.txt 2008-02-26 00:11:14
ComboFix-quarantined-files.txt 2008-03-30 12:07:42
Pre-Run: 7,609,204,736 bytes free
Post-Run: 7,736,770,560 bytes free
.
2008-03-24 00:11:17 --- E O F ---