[center]Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.551 [GMT 3:00]
Running from: C:\Documents and Settings\FOFO\My Documents\Downloads\Programs\AutoPlay\Docs\ComboFix.exe
* Created a new restore point
* Resident AV is active
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\artools.dll
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\vb6lib.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-20 to 2008-07-20 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-20 01:44 --------- d-----w C:\Documents and Settings\FOFO\Application Data\DMCache
2008-07-20 01:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-20 01:42 753,696 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-20 01:42 6,361,632 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-20 01:42 54,972 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-20 01:42 5,752 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-10 23:08 --------- d-----w C:\Program Files\BitComet
2008-07-10 21:26 2,560 ----a-w C:\WINDOWS\system32\bitcometres.dll
2008-07-10 05:01 --------- d-----w C:\Program Files\AutoPlay Media Studio 7.0
2008-07-10 05:01 --------- d-----w C:\Documents and Settings\FOFO\Application Data\IndigoRose
2008-07-10 05:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\IndigoRose
2008-07-10 04:59 --------- d-----w C:\Documents and Settings\FOFO\Application Data\Downloaded Installations
2008-07-10 04:48 --------- d-----w C:\Program Files\UltraISO
2008-07-10 04:48 --------- d-----w C:\Program Files\Common Files\EZB Systems
2008-07-10 04:46 --------- d-----w C:\Program Files\nLite
2008-07-10 04:38 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-07-08 11:55 --------- d-----w C:\Program Files\Unlocker
2008-07-08 06:47 --------- d-----w C:\Documents and Settings\FOFO\Application Data\Desktopicon
2008-07-08 04:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-08 04:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-07 23:10 286,720 ------w C:\WINDOWS\Setup1.exe
2008-07-07 00:48 --------- d-----w C:\Program Files\Video Convert Master
2008-07-05 22:17 --------- d-----w C:\Program Files\Counter-Strike Source
2008-07-05 22:00 --------- d-----w C:\Program Files\Disney Interactive
2008-07-04 15:52 --------- d-----w C:\Program Files\Valve
2008-07-03 10:11 326,144 ----a-w C:\WINDOWS\system32\EAREMOVE.EXE
2008-07-02 23:57 --------- d-----w C:\Program Files\QuickTime
2008-07-02 10:11 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-06-30 22:06 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-06-27 19:42 --------- d-----w C:\Documents and Settings\FOFO\Application Data\U3
2008-06-26 11:39 --------- d-----w C:\Documents and Settings\FOFO\Application Data\Datalayer
2008-06-26 11:34 --------- d-----w C:\Documents and Settings\FOFO\Application Data\Nokia
2008-06-26 11:33 --------- d-----w C:\Program Files\Nokia
2008-06-26 11:33 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-06-26 11:33 --------- d-----w C:\Program Files\Common Files\Nokia
2008-06-26 11:33 --------- d-----w C:\Documents and Settings\FOFO\Application Data\PC Suite
2008-06-26 11:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-25 11:23 --------- d-----w C:\Program Files\LeapFTP
2008-06-24 13:34 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-24 08:50 --------- d-----w C:\Program Files\DIFX
2008-06-23 17:06 --------- d-----w C:\Program Files\Internet Download Manager
2008-06-22 08:19 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-06-22 08:19 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-06-21 11:06 64,949 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-06-21 11:06 5,997 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-06-21 10:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-06-21 09:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\{BA5D4C17-BBA0-42C9-A526-23FE5567F32B}
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:00 --------- d-----w C:\Program Files\IObit
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:33 --------- d-----w C:\Program Files\AutoIt3
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 10:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\zyz Kaspersky Lab setup files
2008-06-18 10:58 --------- d-----w C:\Program Files\Hotspot Shield
2008-06-17 20:14 --------- d-----w C:\Documents and Settings\FOFO\Application Data\Nero
2008-06-17 18:36 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-06-15 14:56 --------- d-----w C:\Documents and Settings\FOFO\Application Data\HP
2008-06-15 10:08 --------- d-----w C:\Program Files\Foxit Software
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 19:46 73,216 ------w C:\WINDOWS\ST6UNST.EXE
2008-06-10 16:08 --------- d-----w C:\Program Files\Common Files\xing shared
2008-06-10 16:08 --------- d-----w C:\Program Files\Common Files\Real
2008-06-10 16:07 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-10 16:07 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-10 11:21 --------- d-----w C:\Program Files\Real_SC
2008-06-09 15:50 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-06-09 03:05 --------- d-----w C:\Program Files\Naevius YouTube Converter
2008-06-08 23:52 47,360 ----a-w C:\WINDOWS\system32\drivers\Pcouffin.sys
2008-06-08 22:19 --------- d-----w C:\Program Files\MSXML 4.0
2008-06-08 20:05 --------- d-----w C:\Documents and Settings\FOFO\Application Data\IDM
2008-06-08 14:00 --------- d-----w C:\Documents and Settings\FOFO\Application Data\Media Player Classic
2008-06-08 13:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\HP
2008-06-08 13:53 --------- d-----w C:\Program Files\HP
2008-06-08 13:53 --------- d-----w C:\Program Files\Common Files\HP
2008-06-08 13:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-06-08 13:52 --------- d-----w C:\Program Files\Hewlett-Packard
2008-06-08 13:51 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-06-08 07:40 --------- d-----w C:\Program Files\Real
2008-06-08 07:35 --------- d-----w C:\Program Files\Windows Live
2008-06-08 07:33 --------- d-----w C:\Program Files\Nero
2008-06-08 07:33 --------- d-----w C:\Program Files\Common Files\Nero
2008-06-08 07:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-06-08 07:29 --------- d-----w C:\Program Files\Java
2008-06-08 07:29 --------- d-----w C:\Program Files\Common Files\Java
2008-06-08 07:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-08 07:26 --------- d-----w C:\Program Files\MSBuild
2008-06-08 07:26 --------- d-----w C:\Program Files\Microsoft Works
2008-06-07 21:17 --------- d-----w C:\Program Files\Realtek
2008-06-07 21:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-07 21:16 --------- d-----w C:\Documents and Settings\FOFO\Application Data\InstallShield
2008-06-07 21:15 4,716 ----a-w C:\WINDOWS\gdrv.sys
2008-06-07 21:13 --------- d-----w C:\Program Files\Intel
2008-06-07 20:59 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-28 06:52 2,121,235 ----a-w C:\WINDOWS\system32\x264vfw.dll
2008-04-25 15:22 206,088 ----a-w C:\WINDOWS\system32\klogon.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
------- Sigcheck -------
06/13/2007 01:23 PM 975360 9784e0719124e4a23989aef9e7ca02d6 C:\WINDOWS\explorer.exe
06/13/2007 02:26 PM 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
08/04/2004 01:56 AM 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
06/13/2007 01:23 PM 975360 9784e0719124e4a23989aef9e7ca02d6 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 11:34 AM 5724184]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [06/23/2008 08:06 PM 932864]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/27/2006 04:21 PM 1449984]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [06/03/2008 06:42 AM 2596152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [04/19/2007 08:26 AM 7700480]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [04/19/2007 08:26 AM 86016]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM 31016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 AM 144784]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/19/2006 02:41 AM 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/10/2008 07:07 PM 185896]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [05/02/2008 07:15 AM 15872]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [06/15/2006 12:36 PM 229376]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [04/25/2008 06:21 PM 201992]
"RTHDCPL"="RTHDCPL.EXE" [11/14/2006 12:21 PM 16270848 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [05/16/2006 01:04 PM 2879488 C:\WINDOWS\SkyTel.exe]
"Resume copy"="copyfstq.exe" [03/24/2002 02:54 PM 46080 C:\WINDOWS\COPYFSTQ.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]
C:\Documents and Settings\FOFO\Start Menu\Programs\Startup\
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 22:41:18 65536]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-08 07:41:12 113664]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
07/22/2006 11:49 PM 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\kav\\kis8.0\\english\\setup.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\LeapFTP\\LeapFTP.exe"=
"C:\\Program Files\\Counter-Strike Source\\hl2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9525:TCP"= 9525:TCP:BitComet 9525 TCP
"9525:UDP"= 9525:UDP:BitComet 9525 UDP
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [03/25/2008 08:07 PM]
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [07/23/2006 12:44 PM]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-nwiz - nwiz.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-20 04:44:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\ComboFix\KAV.exe
C:\ComboFix\reg_reset.exe
C:\DOCUME~1\FOFO\LOCALS~1\Temp\RarSFX1\run.exe
C:\DOCUME~1\FOFO\LOCALS~1\Temp\RarSFX0\zyzoom1.com
C:\DOCUME~1\FOFO\LOCALS~1\Temp\RarSFX0\zyzoom1.exe
C:\WINDOWS\system32\wscript.exe
.
**************************************************************************
.
Completion time: 07/20/2008 4:48:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-20 01:48:40
Pre-Run: 10,535,424,000 bytes free
Post-Run: 11,004,977,152 bytes free
239 --- E O F --- 2008-07-13 02:41:48
[/center]