ComboFix 08-11-16.05 - A 11/17/2008 20:30:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.168 [GMT 3:00]
Running from: c:\documents and settings\A\Desktop\ComboFix.exe
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\Autoexec.bat
c:\windows\system\_sv_CMD_
c:\windows\system32\AutoRun.inf
c:\windows\system32\setting.ini
.
((((((((((((((((((((((((( Files Created from 2008-10-17 to 2008-11-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 17:35 114,208 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-17 17:35 1,983,776 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-17 17:06 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-17 16:52 27,872 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-17 16:52 12,464 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-17 12:24 0 ----a-w C:\osy3.sys
2008-11-17 12:06 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-11-17 12:06 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-11-17 12:06 112,144 ----a-w c:\windows\system32\drivers\kl1.sys
2008-11-17 10:54 --------- d-----w c:\program files\Kaspersky Lab
2008-11-17 10:53 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-17 07:18 552,960 ----a-w C:\data88.dat
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-19 06:47 3,198,976 ----a-w C:\data999.dat
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
2008-02-20 21:31 426 ----a-w c:\documents and settings\A\Autoexec.bat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [04/14/2008 03:12 AM 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [04/14/2008 03:12 AM 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [08/03/2004 11:32 PM 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/03/2004 11:32 PM 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [08/03/2004 11:32 PM 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [03/10/2005 04:20 AM 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [03/10/2005 04:16 AM 126976]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [03/11/2007 09:34 PM 49152]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [01/07/2005 05:07 PM 61952 c:\windows\system32\HdAShCut.exe]
"SMSERIAL"="sm56hlpr.exe" [12/29/2004 01:01 AM 544768 c:\windows\sm56hlpr.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/14/2008 03:12 AM 110592 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [04/14/2008 03:12 AM 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-12-11 1179648]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
Ralink Wireless Utility.lnk - c:\program files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe [2006-12-11 561152]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-Tok-Cirrhatus - (no file)
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [URL]http://www.gmer.net[/URL]
Rootkit scan 2008-11-17 20:35:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 11/17/2008 20:36:42
ComboFix-quarantined-files.txt 2008-11-17 17:36:38
Pre-Run: 9,920,376,832 bytes free
Post-Run: 9,972,281,344 bytes free
96 --- E O F --- 2008-11-17 14:52:38