ComboFix 08-05-07.2 - Juuso Turpeinen 2008-05-08 20:14:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1107 [GMT 3:00]
Running from: E:\Imut\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\AbJRBJlm.ini
C:\WINDOWS\system32\AbJRBJlm.ini2
C:\WINDOWS\system32\byXqNhiJ.dll
C:\WINDOWS\system32\ccilfcwm.ini
C:\WINDOWS\system32\ctfmona.exe
C:\WINDOWS\system32\das.bat
C:\WINDOWS\system32\mlJBRJbA.dll
C:\WINDOWS\system32\mwcflicc.dll
C:\WINDOWS\system32\yayyXQGy.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-08 to 2008-05-08 )))))))))))))))))))))))))))))))
.
2008-05-08 19:56 . 2008-05-08 19:56 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-08 14:23 . 2008-05-08 14:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adsl Software Limited
2008-05-08 14:23 . 2008-05-08 19:53 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
2008-05-08 14:23 . 2008-05-08 19:53 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-05-08 14:23 . 2008-05-08 14:23 1 --a------ C:\WINDOWS\system32\kr_done1de
2008-05-05 22:21 . 2001-04-11 03:47 80,384 --a------ C:\WINDOWS\gamedelete.exe
2008-05-04 00:58 . 2008-05-04 00:58 <DIR> d-------- C:\Program Files\WinPcap
2008-05-02 23:49 . 1994-09-21 01:00 92,208 --a------ C:\WINDOWS\system32\WING.DLL
2008-04-28 01:07 . 2005-01-22 22:12 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2008-04-26 19:56 . 2006-02-04 04:50 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd
2008-04-26 19:56 . 2006-02-04 04:50 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2008-04-26 19:49 . 2008-04-26 19:49 <DIR> d-------- C:\Documents and Settings\Juuso Turpeinen\Application Data\InstallShield
2008-04-26 17:15 . 2008-04-26 17:15 68,096 --a------ C:\WINDOWS\ScUnin.exe
2008-04-26 17:15 . 2008-04-26 17:15 10,800 --a------ C:\WINDOWS\scunin.dat
2008-04-26 17:15 . 2008-04-26 17:15 967 --a------ C:\WINDOWS\ScUnin.pif
2008-04-24 16:42 . 1999-08-13 06:00 317,952 --a------ C:\WINDOWS\system32\Roboex32.dll
2008-04-24 16:42 . 1999-06-23 11:46 54,272 --a------ C:\WINDOWS\system32\Serial.ocx
2008-04-24 16:42 . 1999-06-23 11:46 53,760 --a------ C:\WINDOWS\system32\Infrared.ocx
2008-04-24 16:42 . 1999-06-23 11:46 51,712 --a------ C:\WINDOWS\system32\USB.ocx
2008-04-24 16:42 . 1999-08-13 06:00 47,104 --a------ C:\WINDOWS\system32\Wh2Robo.dll
2008-04-23 21:34 . 2008-04-23 21:34 4,532 --a------ C:\WINDOWS\Juuso Turpeinen.acl
2008-04-23 15:34 . 2008-04-23 15:34 <DIR> d-------- C:\WINDOWS\SendTo
2008-04-23 15:34 . 2008-04-23 15:34 5,560 --a------ C:\WINDOWS\system32\mapisvc.inf
2008-04-23 15:34 . 2008-04-23 15:34 611 --a------ C:\WINDOWS\ODBC.INI
2008-04-23 15:34 . 2008-04-23 15:34 22 --a------ C:\WINDOWS\exchng.ini
2008-04-23 15:33 . 2008-04-23 15:34 <DIR> d-------- C:\WINDOWS\forms
2008-04-23 15:33 . 2008-04-23 15:33 <DIR> d-------- C:\Program Files\Windows Messaging
2008-04-23 11:49 . 2008-04-23 11:49 5,760,054 --a------ C:\WINDOWS\AW_1600x1200.bmp
2008-04-23 01:43 . 2008-05-08 14:29 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-20 04:10 . 2008-04-20 04:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{5AB1F146-BB6B-4FEC-A1A0-A5F0F3E9B91D}
2008-04-17 07:59 . 2008-04-17 07:59 <DIR> d-------- C:\Program Files\GameSpy Arcade
2008-04-16 19:14 . 2008-04-16 19:14 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-04-16 19:14 . 2008-03-19 18:26 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-04-16 19:14 . 2008-03-19 18:29 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-04-16 17:33 . 2008-04-16 17:33 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-04-16 15:20 . 2008-04-19 22:49 <DIR> d-------- C:\Documents and Settings\Juuso Turpeinen\Application Data\Xfire
2008-04-15 18:18 . 2008-04-15 18:18 230,424 --a------ C:\img2-
001.raw
2008-04-15 18:01 . 2008-04-15 18:02 <DIR> d-------- C:\Documents and Settings\Juuso Turpeinen\Application Data\Ventrilo
2008-04-15 17:37 . 2008-04-15 17:38 <DIR> d-------- C:\Program Files\Microsoft LifeCam
2008-04-15 17:35 . 2007-04-11 00:46 1,966,696 -
ra------ C:\WINDOWS\system32\drivers\VX3000.sys
2008-04-15 17:34 . 2008-04-15 17:34 <DIR> d-------- C:\WINDOWS\system32\drivers\umdf
2008-04-15 17:31 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-04-15 17:31 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-04-15 17:31 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-15 17:31 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-10 18:00 . 2008-04-10 18:02 319 --a------ C:\WINDOWS\DESKADV.INI
2008-04-08 22:53 . 1994-08-24 01:00 188,960 --a------ C:\WINDOWS\system\WINGDE.DLL
2008-04-08 22:53 . 1994-09-21 01:00 92,208 --a------ C:\WINDOWS\system\WING.DLL
2008-04-08 22:53 . 1994-02-18 17:47 26,112 --a------ C:\WINDOWS\system\WAVEMIX.DLL
2008-04-08 22:53 . 1994-09-21 01:00 6,736 --a------ C:\WINDOWS\system\WINGDIB.DRV
2008-04-08 22:53 . 1994-09-21 01:00 5,024 --a------ C:\WINDOWS\system\WINGPAL.WND
2008-04-08 22:53 . 1996-02-27 18:54 2,552 --a------ C:\WINDOWS\WAVEMIX.INI
2008-04-08 22:53 . 1994-06-20 01:00 1,966 --a------ C:\WINDOWS\system\DVA.386
2008-04-08 22:53 . 2008-04-14 15:23 259 --a------ C:\WINDOWS\YODESK.INI
2008-04-08 20:12 . 2008-04-08 20:11 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-04-08 20:12 . 2008-04-08 20:12 40 --a------ C:\WINDOWS\RSoftInfo.dat
2008-04-08 19:25 . 2008-05-06 15:11 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-08 12:25 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\uTorrent
2008-05-08 12:25 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\LimeWire
2008-05-08 12:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 19:00 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\Creative
2008-04-21 09:37 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\Hamachi
2008-04-21 08:29 87,312 ----a-w C:\WINDOWS\system32\drivers\cmdguard.sys
2008-04-21 08:29 23,824 ----a-w C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-04-21 08:29 139,008 ----a-w C:\WINDOWS\system32\guard32.dll
2008-04-19 17:04 --------- d-----w C:\Program Files\ClamWin
2008-04-15 15:00 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-07 18:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-05 08:04 21,005 ---ha-w C:\WINDOWS\system32\facaiWow.exe
2008-04-04 21:31 41,296 ----a-w C:\WINDOWS\system32\xfcodec.dll
2008-04-02 19:21 --------- d-----w C:\Program Files\Creative
2008-04-02 19:14 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-02 19:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-03-31 18:27 --------- d-----w C:\Program Files\Common Files\DirectX
2008-03-27 16:28 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-03-27 16:13 0 ----a-r C:\logwmemory.bin
2008-03-27 16:12 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\Soldat
2008-03-27 16:04 --------- d-----w C:\Program Files\Java
2008-03-27 16:01 --------- d-----w C:\Program Files\Common Files\Java
2008-03-25 19:08 --------- d-----w C:\Program Files\MSXML 4.0
2008-03-25 19:06 --------- d-----w C:\Program Files\Microsoft Games
2008-03-25 18:57 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\Leadertech
2008-03-25 18:21 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-03-23 19:53 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2008-03-23 18:56 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2008-03-23 18:56 139,264 ----a-w C:\WINDOWS\War3Unin.exe
2008-03-23 18:12 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\mIRC
2008-03-23 18:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-23 18:09 --------- d-----w C:\Program Files\Lavasoft
2008-03-23 17:59 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\.clamwin
2008-03-23 17:36 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-23 17:36 --------- d-----w C:\Program Files\Windows Live
2008-03-23 17:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-23 17:29 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\DAEMON Tools
2008-03-23 17:28 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-03-23 17:27 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-03-23 17:26 --------- d-----w C:\Program Files\Winamp
2008-03-23 17:23 --------- d-----w C:\Program Files\7-
Zip
2008-03-23 17:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\comodo
2008-03-23 17:11 --------- d-----w C:\Program Files\COMODO
2008-03-23 17:11 --------- d-----w C:\Documents and Settings\Juuso Turpeinen\Application Data\Comodo
2008-03-23 16:47 --------- d-----w C:\Program Files\MSBuild
2008-03-23 16:44 --------- d-----w C:\Program Files\Reference Assemblies
2008-03-23 14:26 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-05 14:03 479,752 ----a-w C:\WINDOWS\system32\XAudio2_0.dll
2008-03-05 14:03 238,088 ----a-w C:\WINDOWS\system32\xactengine3_0.dll
2008-03-05 14:00 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_3.dll
2008-03-05 13:56 3,786,760 ----a-w C:\WINDOWS\system32\D3DX9_37.dll
2008-03-05 13:56 1,420,824 ----a-w C:\WINDOWS\system32\D3DCompiler_37.dll
2000-02-02 00:01 36,864 --sha-r C:\WINDOWS\system32\doni32drv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2007-12-15 13:02 482760]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 10:06 700416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-04-21 11:25 1572608]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2008-04-19 16:35 77824]
"Adobe Reader Speed Launcher"="D:\Ohjelmat\abode\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2007-04-11 00:46 709992]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2007-05-18 00:45 279912]
"ctfmona"="C:\WINDOWS\system32\ctfmona.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"D:\\Ohjelmat\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Warcraft
"6119:TCP"= 6119:TCP:Warcraft
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-04-21 11:29]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-04-21 11:29]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-18 00:45]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-01-25 20:31]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-15 14:36:18 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_setup_exe.job"
- F:\setup.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-08 20:17:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-05-08 20:20:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-08 17:20:10
Pre-Run: 13,330,354,176 bytes free
Post-Run: 13,408,804,864 bytes free
209