ComboFix 07-12-18.1 - Admin 2007-12-18 17:02:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.655 [GMT 0:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\gcpcmhtf.ini
C:\WINDOWS\system32\jkmpqpsk.ini
C:\WINDOWS\system32\jmvbyovx.ini
C:\WINDOWS\system32\tevttqjt.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\rqstv.bak1.bad
C:\VundoFix Backups\rqstv.bak2.bad
C:\VundoFix Backups\rqstv.ini.bad
C:\VundoFix Backups\rqstv.ini2.bad
C:\VundoFix Backups\rqstv.tmp.bad
C:\VundoFix Backups\vtsqr.dll.bad
C:\WINDOWS\system32\gcpcmhtf.ini
C:\WINDOWS\system32\jkmpqpsk.ini
C:\WINDOWS\system32\jmvbyovx.ini
C:\WINDOWS\system32\tevttqjt.ini
C:\WINDOWS\system32\winsecurityxp
C:\WINDOWS\system32\winsecurityxp\mswinup.exe
C:\WINDOWS\system32\winsecurityxp\rk.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-18 to 2007-12-18 )))))))))))))))))))))))))))))))
.
2007-12-18 17:00 . 2007-12-18 17:00 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2007-12-17 23:02 . 2007-10-10 23:55 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-17 23:02 . 2007-07-01 03:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-17 23:02 . 2007-07-01 03:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-17 23:02 . 2007-10-10 23:55 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-17 23:02 . 2007-10-10 23:55 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-17 23:02 . 2007-10-10 23:55 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-17 23:02 . 2007-10-10 23:55 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-17 23:02 . 2007-10-10 23:55 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-17 23:02 . 2007-10-10 10:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-15 12:07 . 2007-12-15 12:07 <DIR> d-------- C:\temp_dvd
2007-12-15 11:52 . 2007-12-15 12:07 <DIR> d-------- C:\Program Files\Dvd-cloner
2007-12-15 00:39 . 2007-12-15 00:40 <DIR> d-------- C:\Program Files\Winamp
2007-12-15 00:39 . 2007-12-15 16:17 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Winamp
2007-12-14 20:15 . 2007-12-14 20:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-14 20:15 . 2007-12-14 20:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-14 19:58 . 2007-12-14 19:58 <DIR> d-------- C:\Program Files\Safer Networking
2007-12-13 21:59 . 2007-12-13 21:59 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-13 17:04 . 2007-12-13 17:04 <DIR> d-------- C:\Program Files\AC3Filter
2007-12-13 17:04 . 2007-08-18 07:54 380,928 --a------ C:\WINDOWS\system32\ac3filter.acm
2007-12-13 16:36 . 2007-12-13 16:36 203,776 --a------ C:\WINDOWS\system32\clrviddc.dll
2007-12-12 22:56 . 2007-12-12 22:56 <DIR> d-------- C:\Program Files\Executive Software
2007-12-12 22:56 . 2007-12-12 22:56 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Leadertech
2007-12-12 22:53 . 2007-12-15 00:45 <DIR> d-------- C:\Randomness
2007-12-12 22:36 . 2007-12-13 21:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-12 22:26 . 2007-12-12 22:26 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2007-12-12 21:25 . 2007-12-12 21:25 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Symantec
2007-12-12 21:01 . 2007-12-12 21:01 16 --a------ C:\WINDOWS\system32\coh.cache
2007-12-12 20:47 . 2007-12-12 22:47 <DIR> d-------- C:\Program Files\Symantec
2007-12-12 20:47 . 2007-12-12 22:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-12 20:46 . 2007-12-12 22:49 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-12 20:32 . 2007-12-12 20:32 1,024 --a------ C:\WINDOWS\system32\drivers\C3864004-0F5E-48B4-AB0B-5C2AEFF131FC.cxv
2007-12-12 14:02 . 2007-12-12 17:21 3,072 --a------ C:\WINDOWS\system32\drivers\BE6802F2-45FE-4A2F-A97D-96BB82CBEB58.cxv
2007-12-12 13:59 . 2007-12-12 14:00 6,144 --a------ C:\WINDOWS\system32\drivers\292A1AA5-4A39-43B4-A942-99C82DF4BC43.cxv
2007-12-12 13:51 . 2007-12-12 20:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2007-12-11 23:40 . 2007-12-11 23:40 <DIR> d-------- C:\Program Files\PowerISO
2007-12-09 00:56 . 2007-12-09 00:56 268 --ah----- C:\sqmdata00.sqm
2007-12-09 00:56 . 2007-12-09 00:56 244 --ah----- C:\sqmnoopt00.sqm
2007-12-08 23:21 . 2007-12-08 23:21 <DIR> d-------- C:\Program Files\LucasArts
2007-12-08 17:30 . 2007-12-08 17:30 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-12-07 08:32 . 2007-12-07 08:32 67,072 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
2007-12-02 15:33 . 2007-12-02 15:33 22,328 --a------ C:\Documents and Settings\Admin\Application Data\PnkBstrK.sys
2007-12-02 15:32 . 2007-12-02 15:32 319 --a------ C:\WINDOWS\game.ini
2007-12-02 15:22 . 2007-12-02 15:22 <DIR> d-------- C:\Program Files\Activision
2007-12-01 09:32 . 2007-12-01 21:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-01 09:23 . 2007-12-01 09:23 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-12-01 09:22 . 2007-12-01 09:22 <DIR> d-------- C:\Program Files\Bonjour
2007-12-01 09:16 . 2007-12-01 09:16 <DIR> d-------- C:\Program Files\MagicISO
2007-11-27 20:38 . 2007-11-27 20:38 <DIR> d-------- C:\Program Files\Common Files\xing shared
2007-11-23 23:22 . 2007-11-24 00:15 <DIR> d-------- C:\Program Files\Defcon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-17 23:17 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-17 23:17 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-17 21:54 --------- d-----w C:\Program Files\Steam
2007-12-16 15:53 --------- d-----w C:\Documents and Settings\Admin\Application Data\uTorrent
2007-12-14 19:59 --------- d-----w C:\Documents and Settings\Admin\Application Data\Xfire
2007-12-14 04:38 --------- d-s---w C:\Program Files\Xfire
2007-12-13 21:59 --------- d-----w C:\Program Files\BulletProofSoft.com
2007-12-13 21:59 --------- d-----w C:\Program Files\BearShare
2007-12-12 22:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-12 22:25 --------- d-----w C:\Program Files\SoftSpot Software
2007-12-08 23:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-04 22:33 --------- d-----w C:\Program Files\Wolfenstein - Enemy Territory
2007-12-02 23:46 66,872 ----a-w C:\WINDOWS\system32\pnkbstra.exe
2007-12-01 09:31 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-27 20:37 --------- d-----w C:\Program Files\Common Files\Real
2007-11-27 20:20 --------- d-----w C:\Documents and Settings\Admin\Application Data\SopCast
2007-11-24 23:40 --------- d-----w C:\Documents and Settings\Admin\Application Data\Hamachi
2007-11-15 21:50 --------- d-----w C:\Program Files\Ventrilo
2007-11-15 21:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 12:28 --------- d-----w C:\Program Files\SopCast
2007-11-06 00:12 --------- d-----w C:\Program Files\uTorrent
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 17:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 09:53 --------- d-----w C:\Program Files\Java
2007-02-16 09:59 0 ----a-w C:\Documents and Settings\Admin\.EXE
.
((((((((((((((((((((((((((((( snapshot@2007-12-18_14.23.28.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-27 15:49:02 196,683 ----a-w C:\WINDOWS\system32\lnod32apiA.dll
+ 2007-07-27 15:49:02 225,355 ----a-w C:\WINDOWS\system32\lnod32apiW.dll
+ 2005-12-05 20:25:22 139,264 ----a-w C:\WINDOWS\system32\lnod32umc.dll
+ 2005-12-05 13:37:10 106,496 ----a-w C:\WINDOWS\system32\lnod32upd.dll
+ 2007-08-02 18:11:28 253,952 ----a-w C:\WINDOWS\system32\OnlineScannerDLLA.dll
+ 2007-08-02 18:11:14 241,664 ----a-w C:\WINDOWS\system32\OnlineScannerDLLW.dll
+ 2007-08-08 16:30:12 19,456 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll
+ 2007-06-13 11:10:34 77,824 ----a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
+ 2004-12-07 11:11:34 258,352 ----a-w C:\WINDOWS\system32\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USBIR2"="C:\Program Files\USBIR\Display.exe" []
"USBIR1"="C:\Program Files\USBIR\FrontPanelIo.exe" [2004-12-06 10:41]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 08:12]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-27 20:37]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 05:28]
C:\Documents and Settings\Admin\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2007-12-05 02:25:52]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk.disabled [2007-02-14 22:17:46]
SystemControl.lnk - C:\Program Files\SystemControl\SystemControl\FanConditioner.exe [2007-02-14 23:24:02]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" /pause
R1 ATITool;ATITool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\ATITool.sys [2006-11-10 13:08]
R1 BIOS;BIOS;C:\WINDOWS\system32\drivers\BIOS.sys [2005-03-16 06:23]
R1 BS_I2cIo;BS_I2cIo;C:\WINDOWS\system32\drivers\BS_I2cIo.sys [2005-04-22 13:23]
S3 Razerlow;Razerlow USB Filter Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-04-24 21:43]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-18 17:04:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-18 17:05:27
C:\ComboFix2.txt ... 2007-12-18 14:24
.
2007-12-16 08:39:02 --- E O F ---