ComboFix 08-05-29.1 - Jere 2008-05-30 18:25:00.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.358.1033.18.477 [GMT 3:00]
Running from: C:\Documents and Settings\Jere\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jere\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\winudspm.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\service.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\winudspm.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-30 )))))))))))))))))))))))))))))))
.
2008-05-30 17:54 . 2008-05-30 17:54 60,132 --a------ C:\dci.exe
2008-05-27 19:11 . 2008-05-27 19:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TrackMania
2008-05-27 19:04 . 2008-05-27 19:04 <DIR> d-------- C:\Program Files\TmNationsForever
2008-05-15 17:47 . 2008-05-15 17:47 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-05-15 06:57 . 2008-05-15 06:57 <DIR> d--hs---- C:\FOUND.012
2008-05-14 04:29 . 2008-05-14 04:29 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-05-10 17:23 . 2008-05-10 17:23 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-10 17:23 . 2008-05-10 17:23 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-04-27 18:46 . 2008-05-11 16:17 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-04-27 18:30 . 2008-04-27 18:30 94,208 --a------ C:\WINDOWS\DIIUnin.exe
2008-04-27 18:30 . 2008-04-27 18:46 34,883 --a------ C:\WINDOWS\DIIUnin.dat
2008-04-27 18:30 . 2008-04-27 18:30 2,829 --a------ C:\WINDOWS\DIIUnin.pif
2008-04-27 18:06 . 2008-04-27 18:06 <DIR> d-------- C:\Program Files\Diablo II
2008-04-21 20:16 . 2008-04-21 20:16 <DIR> d--hs---- C:\FOUND.011
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-30 14:58 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-30 14:58 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-29 18:02 12,441,647 ------w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-05-29 12:30 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-29 12:30 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-04-27 15:45 21,840 ----a-w C:\WINDOWS\system32\SIntfNT.dll
2008-04-27 15:45 17,212 ----a-w C:\WINDOWS\system32\SIntf32.dll
2008-04-27 15:45 12,067 ----a-w C:\WINDOWS\system32\SIntf16.dll
2008-04-27 14:08 1,933,312 ------w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-04-05 19:13 2,440,192 ------w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 15:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-26 11:59 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
2008-02-26 11:59 294,912 ----a-w C:\WINDOWS\system32\dllcache\msctf.dll
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-18 16:34 2,654,208 ------w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-02-18 16:34 2,195,456 ------w C:\WINDOWS\Internet Logs\xDB8.tmp
2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-02-09 12:00 2,654,208 ------w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-02-02 12:13 2,654,208 ------w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-01-07 12:18 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-12-24 09:30 22,328 ----a-w C:\Documents and Settings\Jere\Application Data\PnkBstrK.sys
2007-10-06 06:29 10,240 --sha-w C:\Program Files\Thumbs.db
2007-09-04 16:01 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-09-04 16:00 88 --sh--r C:\WINDOWS\system32\2E7D753320.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2007-12-16 14:52 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-16 15:47 68856]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 20:00 15360]
"Steam"="D:\Steam.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512]
"LaunchApp"="" []
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [ ]
"ntiMUI"="C:\Program Files\NewTech Infosystems\NTI
CD &
DVD-Maker 7\ntiMUI.exe" [ ]
"Acer ePresentation HPD"="C:\Acer\Empowering Technology\ePresentation\ePresentation.exe" [2006-03-31 16:39 204800]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 20:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 20:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 20:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 20:00 455168]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-30 12:11 421888]
"Boot"="C:\Acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 22:12 579584]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 13:07 761946]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-06-23 06:59 602112]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 14:40 413696]
"anysee_TR"="" []
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 20:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"PKR Pal"="C:\Program Files\PKR\pkrpal.exe" [ ]
"Microsoft Keyboard Support"="C:\WINDOWS\system32\type32.exe" [ ]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-15 20:05 249896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36 229376]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"avast!"="D:\Avast!\ashDisp.exe" [2008-05-16 02:19 79224]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Windows UDP Control"="winudspm.exe" []
"Windows svchost"="service.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360]
D:\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2008-05-14 04:29:28 3007824]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2006-03-27 11:37:58 45056]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 10:45:32 618557]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"vidc.ffds"=
ffdshow.ax
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%/system32/type32.exe"= C:\\WINDOWS\\system32\\type32.exe
"C:\\WINDOWS\\System32\\PnkBstrA.exe"=
"C:\\WINDOWS\\System32\\PnkBstrB.exe"=
"D:\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 AMTBDA_P861F;anysee
Capture Service;C:\WINDOWS\system32\DRIVERS\anyseeTU.SYS [2007-05-23 07:33]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys []
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys []
S3 n558;N558
Bluetooth USB Filter Driver;C:\WINDOWS\system32\Drivers\n558.sys [2007-07-20 06:20]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2008-05-30 18:28:54
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-30 18:29:53
ComboFix-quarantined-files.txt 2008-05-30 15:29:46
Pre-Run: 5,294,456,832 bytes free
Post-Run: 7,018,151,936 bytes free
166 --- E O F --- 2008-05-28 19:25:52