ComboFix 08-01-04.1 - Admin 2008-01-05 15:53:14.12 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.570 [GMT -6:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\imsins.BAK
C:\WINDOWS\system32\nscdapyd.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
C:\WINDOWS\imsins.BAK
C:\WINDOWS\system32\nscdapyd.ini
.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.
2008-01-05 15:53 . 2007-12-30 10:08 15,360 --a--c--- C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-05 15:53 . 2007-12-30 10:08 15,360 --a------ C:\WINDOWS\system32\ctfmon.exe
2008-01-05 11:23 . 2008-01-05 12:45 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-04 21:22 . 2007-12-05 14:17 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-01-04 21:21 . 2008-01-04 21:21 <DIR> d-------- C:\Program Files\ATI Technologies
2008-01-04 20:57 . 2008-01-04 20:57 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-04 13:39 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-30 15:13 . 2007-12-30 15:13 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-29 00:07 . 2007-12-29 00:07 <DIR> d-------- C:\Deckard
2007-12-28 20:01 . 2007-12-28 20:01 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-26 19:27 . 2004-08-03 23:08 59,136 --a------ C:\WINDOWS\system32\drivers\GcKernel.sys
2007-12-26 19:27 . 2004-08-03 23:08 59,136 --a--c--- C:\WINDOWS\system32\dllcache\gckernel.sys
2007-12-26 19:27 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-12-26 19:27 . 2004-08-03 22:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2007-12-26 19:27 . 2001-08-17 14:02 2,688 --a------ C:\WINDOWS\system32\drivers\HIDSwvd.sys
2007-12-26 19:27 . 2001-08-17 14:02 2,688 --a--c--- C:\WINDOWS\system32\dllcache\hidswvd.sys
2007-12-26 09:52 . 2007-12-26 10:01 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-26 09:52 . 2007-12-26 10:01 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-26 09:50 . 2007-12-26 09:50 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-12-26 09:50 . 2008-01-05 11:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-26 09:49 . 2008-01-05 15:58 16,056,352 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-26 09:49 . 2008-01-05 15:58 103,456 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-26 09:49 . 2008-01-05 11:08 78,884 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-26 09:49 . 2008-01-05 11:08 11,504 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-26 09:38 . 2007-12-26 09:38 <DIR> d-------- C:\KAV
2007-12-23 18:46 . 2007-12-23 18:46 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2007-12-23 18:46 . 2007-12-23 18:46 <DIR> d-------- C:\Program Files\MSECACHE
2007-12-23 18:25 . 2007-12-23 18:25 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-23 18:25 . 2007-12-23 18:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-23 18:15 . 2007-12-23 18:20 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-12-23 18:05 . 2007-12-23 18:05 <DIR> d-------- C:\Program Files\Comodo
2007-12-23 18:05 . 2007-11-26 10:38 238,848 --a------ C:\WINDOWS\UNBOC.EXE
2007-12-23 18:05 . 2007-05-08 17:01 208,896 --a------ C:\WINDOWS\CMDLIC.DLL
2007-12-23 18:05 . 2004-08-03 23:56 22,528 --a------ C:\WINDOWS\system32\wsock32.dlb
2007-12-22 11:21 . 2008-01-04 21:12 381 --a------ C:\WINDOWS\wininit.ini
2007-12-20 11:26 . 2007-12-31 08:35 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-20 11:26 . 2007-12-20 11:26 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-18 09:34 . 2007-12-19 17:32 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\DAEMON Tools
2007-12-18 09:29 . 2007-12-18 09:34 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2007-12-18 09:25 . 2007-12-18 09:25 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-18 08:50 . 2007-12-27 08:51 <DIR> d-------- C:\Program Files\LucasArts
2007-12-11 13:46 . 2007-12-11 13:46 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-12-11 13:46 . 2007-12-11 13:46 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-12-11 13:46 . 2007-12-11 13:46 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2007-12-11 13:45 . 2007-12-11 13:45 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-12-11 13:45 . 2007-12-11 13:45 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-12-11 13:43 . 2007-12-11 13:43 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-10 20:06 . 2007-12-10 20:06 <DIR> d-------- C:\WINDOWS\system32\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 16:06 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-05 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-05 03:15 --------- d-----w C:\Program Files\Google
2008-01-05 03:12 --------- d-----w C:\Program Files\Apple Software Update
2008-01-04 02:04 --------- d-----w C:\Program Files\Last.fm
2008-01-03 21:48 --------- d-----w C:\Documents and Settings\Admin\Application Data\uTorrent
2008-01-02 15:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-31 15:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-31 15:47 --------- d-----w C:\Program Files\Java
2007-12-26 15:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-25 23:25 --------- d-----w C:\Program Files\DivX
2007-12-24 01:49 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-24 00:24 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-20 17:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\iolo
2007-12-16 18:08 --------- d-----w C:\Program Files\ShurikSoft
2007-12-11 19:44 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-11 19:44 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-11 19:44 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-12-11 19:44 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-11 19:44 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2007-12-11 19:44 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-12-11 19:44 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-12-11 19:44 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-12-11 19:44 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-12-11 19:44 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-12-11 19:44 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-12-11 19:44 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-12-11 19:44 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-12-05 05:26 2,782,208 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-12-05 03:05 368,640 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-05 03:04 269,312 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-05 02:56 147,456 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-05 02:55 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-05 02:55 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-05 02:55 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-05 02:55 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-05 02:54 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-12-05 02:53 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-05 02:53 495,616 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-05 02:48 9,535,488 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-05 02:44 3,175,584 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-05 02:33 1,640,192 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-05 02:19 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-05 02:19 385,024 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-05 02:17 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-05 02:16 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-12-05 02:14 180,224 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-05 02:11 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-12-02 16:56 321 ----a-w C:\license.dat
2007-12-02 16:37 --------- d-----w C:\Documents and Settings\Admin\Application Data\SSH
2007-12-01 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-01 23:28 --------- d-----w C:\Documents and Settings\Admin\Application Data\NewsBin
2007-11-20 03:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\SimCity Societies
2007-11-20 03:09 --------- d-----w C:\Program Files\Electronic Arts
2007-11-18 21:35 --------- d-----w C:\Program Files\PeerGuardian2
2007-11-18 17:27 --------- d-----w C:\Documents and Settings\Admin\Application Data\EndNote
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-05 01:39 429 ----a-w C:\
0030BD1CDE94__0-741837788253016.dat
2007-11-03 17:38 363,368 ----a-w C:\WINDOWS\system32\Incinerator.dll
2007-10-30 23:43 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 15:04 74,703 ----a-w C:\WINDOWS\system32\mfc45.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51 218376]
C:\Documents and Settings\Admin\Start Menu\Programs\Startup\
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2007-09-16 20:05:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" -atboottime
R2 BT848;BtCap, WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2000-03-29 08:26]
R2 BTTUNER;BtTuner, WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2000-03-29 08:26]
R2 BTXBAR;BtXBar, WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [2000-03-29 08:26]
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2005-06-10 08:01]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 BOCDRIVE;BOClean Kernel Monitor.;C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys []
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2005-08-02 15:10]
S3 PEEK5;PEEK5 Protocol Driver;C:\DOCUME~1\Admin\Desktop\WINDOW~1\AIRSNO~1.6_W\PEEK5.SYS []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-05 15:59:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-05 16:00:35
ComboFix-quarantined-files.txt 2008-01-05 22:00:28
ComboFix2.txt 2008-01-05 17:17:39