ComboFix 09-01-31.01 - usuario 2009-02-01 11:23:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1982.1536 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point
.
ADS - WINDOWS: deleted 48 bytes in 1 streams.
((((((((((((((((((((((((( Files Created from 2009-01-01 to 2009-02-01 )))))))))))))))))))))))))))))))
.
2009-01-31 14:09 . 2009-01-31 14:09 d——– c:\program files\MSXML 4.0
2009-01-31 14:08 . 2008-04-14 14:00 221,184 –a—— c:\windows\system32\wmpns.dll
2009-01-31 14:02 . 2008-10-16 21:38 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2009-01-31 14:02 . 2007-04-17 10:32 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2009-01-31 14:02 . 2007-03-08 06:10 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2009-01-31 14:02 . 2008-10-16 21:38 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2009-01-31 14:02 . 2008-10-16 21:38 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2009-01-31 14:02 . 2008-06-13 12:05 272,128 ——— c:\windows\system32\drivers\bthport.sys
2009-01-31 14:02 . 2008-06-13 12:05 272,128 —–c— c:\windows\system32\dllcache\bthport.sys
2009-01-31 14:02 . 2008-10-16 21:38 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2009-01-31 14:02 . 2008-10-16 21:38 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2009-01-31 14:02 . 2008-10-16 21:38 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2009-01-31 14:02 . 2008-10-16 14:11 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2009-01-31 13:59 . 2008-08-14 11:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2009-01-31 13:59 . 2008-08-14 11:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-01-31 13:59 . 2008-08-14 10:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-01-31 13:59 . 2008-08-14 10:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2009-01-31 13:53 . 2009-01-31 18:58 d–h—– c:\windows\$hf_mig$
2009-01-31 13:22 . 2008-10-24 12:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2009-01-28 10:35 . 2009-01-28 10:35 d——– c:\documents and settings\usuario\Application Data\Malwarebytes
2009-01-28 10:35 . 2009-01-28 10:35 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-27 16:39 . 2009-01-27 16:39 d——– c:\program files\Trend Micro
2009-01-26 18:44 . 2009-01-26 18:44 d——– c:\documents and settings\usuario\Application Data\Sony Corporation
2009-01-26 18:13 . 2009-01-26 18:13 d——– c:\program files\Sony
2009-01-26 18:13 . 2006-11-02 16:57 118,520 –a—— c:\windows\system32\PxInsI64.exe
2009-01-26 18:13 . 2006-10-18 19:43 115,960 –a—— c:\windows\system32\PxCpyI64.exe
2009-01-26 18:12 . 2009-01-26 18:12 d——– c:\documents and settings\All Users\Application Data\Sony Corporation
2009-01-26 18:10 . 2009-01-26 18:10 d——– c:\documents and settings\usuario\Application Data\InstallShield
2009-01-22 09:05 . 2009-01-22 09:05 d——– c:\windows\system32\LogFiles
2009-01-19 18:35 . 2004-05-14 16:53 462,848 –a—— c:\windows\system32\ltkrn13n.dll
2009-01-19 18:35 . 2004-05-14 16:53 450,560 –a—— c:\windows\system32\ltimg13n.dll
2009-01-19 18:35 . 2004-05-14 16:53 401,408 –a—— c:\windows\system32\lfcmp13n.dll
2009-01-19 18:35 . 2004-05-14 16:53 299,008 –a—— c:\windows\system32\ltdis13n.dll
2009-01-19 18:35 . 2004-01-12 02:09 206,336 –a—— c:\windows\system32\ltefx13n.dll
2009-01-19 18:35 . 2004-05-14 16:53 163,840 –a—— c:\windows\system32\ltfil13n.dll
2009-01-19 18:35 . 2003-11-04 15:11 159,744 –a—— c:\windows\system32\lfpng13n.dll
2009-01-19 18:35 . 2003-11-04 15:10 69,632 –a—— c:\windows\system32\lfgif13n.dll
2009-01-19 18:35 . 2004-05-14 16:53 57,344 –a—— c:\windows\system32\lfbmp13n.dll
2009-01-17 15:07 . 2009-01-28 12:50 69 –a—— c:\windows\NeroDigital.ini
2009-01-17 10:43 . 2009-01-17 10:43 d——– c:\windows\Sun
2009-01-17 03:56 . 2009-01-17 03:56 d——– c:\program files\Common Files\snp2std
2009-01-17 03:56 . 2006-01-19 20:34 10,221,440 –a—— c:\windows\system32\drivers\snp2sxp.sys
2009-01-17 03:56 . 2005-01-27 00:45 349,472 –a—— c:\windows\WindowsXP-KB822603-x86.exe
2009-01-17 03:56 . 2006-01-06 22:57 344,064 –a—— c:\windows\vsnp2std.exe
2009-01-17 03:56 . 2005-12-21 23:06 147,456 –a—— c:\windows\rsnp2std.dll
2009-01-17 03:56 . 2006-01-16 23:06 114,688 –a—— c:\windows\tsnp2std.exe
2009-01-17 03:56 . 2004-08-10 02:43 94,208 –a—— c:\windows\amcap.exe
2009-01-17 03:56 . 2006-01-04 04:04 61,440 –a—— c:\windows\vsnp2std.dll
2009-01-17 03:56 . 2005-11-23 22:55 53,248 –a—— c:\windows\system32\csnp2std.dll
2009-01-17 03:56 . 2005-11-12 01:46 24,960 –a—— c:\windows\system32\drivers\sncamd.sys
2009-01-17 03:56 . 2005-12-06 22:08 20,480 –a—— c:\windows\FixCamera.exe
2009-01-17 03:56 . 2004-12-10 02:23 15,497 –a—— c:\windows\snp2std.ini
2009-01-17 03:56 . 2004-12-10 02:23 13,022 –a—— c:\windows\snp2std.src
2009-01-17 03:51 . 2009-01-17 03:51 d——– c:\program files\Hewlett-Packard
2009-01-17 03:51 . 2006-01-30 17:00 442,368 -ra—— c:\windows\system32\ZSHP1018.EXE
2009-01-17 03:51 . 2006-01-30 17:00 143,360 -ra—— c:\windows\apptune1018.exe
2009-01-17 03:51 . 2006-01-30 17:00 129,092 -ra—— c:\windows\system32\hp1018.img
2009-01-17 03:51 . 2006-01-30 17:00 106,496 -ra—— c:\windows\system32\VSHP1018.DLL
2009-01-17 03:51 . 2006-01-30 17:00 102,400 –a—— c:\windows\system32\zlhp1018.dll
2009-01-17 03:51 . 2006-01-30 17:00 86,016 –a—— c:\windows\system32\ZSPOOL.DLL
2009-01-17 03:51 . 2006-01-30 17:00 28,672 –a—— c:\windows\system32\zlm.dll
2009-01-17 03:51 . 2006-01-30 17:00 28,672 –a—— c:\windows\system32\IMF32.DLL
2009-01-17 03:51 . 2006-01-30 17:00 24,576 –a—— c:\windows\system32\ZTAG32.DLL
2009-01-17 03:51 . 2006-01-30 17:00 7,280 -ra—— c:\windows\system32\ZSHP1018.HLP
2009-01-17 03:48 . 2008-04-14 09:17 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2009-01-17 03:48 . 2008-04-14 09:17 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2009-01-16 19:49 . 2009-01-16 19:49 d——– c:\program files\Common Files\Real
2009-01-16 19:49 . 2009-01-16 19:49 d——– C:\My Music
2009-01-16 19:49 . 2009-01-16 19:49 26,112 –a—— c:\windows\system32\prefscpl.cpl
2009-01-16 19:48 . 2009-01-16 19:49 d——– c:\program files\Real
2009-01-16 19:48 . 2009-01-16 19:50 d——– c:\program files\Logitech
2009-01-16 19:48 . 2009-01-16 19:48 d——– c:\program files\Common Files\xing shared
2009-01-16 19:48 . 2009-01-16 19:48 d——– c:\program files\Common Files\Logitech
2009-01-16 19:48 . 2001-02-14 12:13 322,832 –a—— c:\windows\system32\MFC30.DLL
2009-01-16 19:48 . 2001-02-14 02:59 9,952 ——— c:\windows\system32\drivers\LKBDHLPR.SYS
2009-01-16 02:02 . 2009-01-16 02:02 d——– c:\windows\vnDrvBas
2009-01-16 02:02 . 2005-10-18 15:48 42,496 –a—— c:\windows\system32\drivers\fetnd5bv.sys
2009-01-16 01:56 . 2009-01-16 02:05 d——– c:\windows\SxsCaPendDel
2009-01-16 01:18 . 2009-01-16 01:18 d——– c:\documents and settings\LocalService\Application Data\DivX
2009-01-16 01:18 . 2008-04-14 14:42 91,136 –a—— c:\windows\system32\kswdmcap.ax
2009-01-16 01:14 . 2009-01-16 01:56 d——– c:\documents and settings\usuario\Application Data\Uniblue
2009-01-16 01:14 . 2009-01-16 01:56 d——– c:\documents and settings\All Users\Application Data\DriverScanner
2009-01-16 00:30 . 2009-01-16 00:30 d——– c:\program files\MSBuild
2009-01-16 00:30 . 2009-01-16 00:30 d——– c:\program files\Microsoft Works
2009-01-16 00:29 . 2009-01-16 00:29 d——– c:\program files\Microsoft.NET
2009-01-16 00:24 . 2009-01-16 00:29 d——– c:\windows\SHELLNEW
2009-01-16 00:22 . 2009-01-16 00:22 dr-h—– C:\MSOCache
2009-01-15 23:47 . 2009-01-15 23:47 d——– c:\documents and settings\usuario\Application Data\Ahead
2009-01-15 23:46 . 2009-01-15 23:46 d——– c:\documents and settings\All Users\Application Data\Ahead
2009-01-15 23:45 . 2009-01-15 23:45 d——– c:\program files\Nero
2009-01-15 23:45 . 2009-01-15 23:45 d——– c:\program files\Common Files\Ahead
2009-01-15 23:45 . 2009-01-15 23:45 d——– c:\documents and settings\All Users\Application Data\Nero
2009-01-15 23:39 . 2009-01-15 23:39 d——– c:\program files\Java
2009-01-15 23:39 . 2009-02-01 11:28 d——– c:\documents and settings\usuario\Tracing
2009-01-15 23:39 . 2009-01-15 23:39 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-15 23:39 . 2009-01-15 23:39 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-15 23:37 . 2009-01-15 23:37 d——– c:\program files\Windows Live SkyDrive
2009-01-15 23:37 . 2009-01-15 23:37 d——– c:\program files\Windows Live
2009-01-15 23:37 . 2009-01-15 23:37 d——– c:\program files\Microsoft
2009-01-15 23:34 . 2009-01-15 23:34 d——– c:\program files\Common Files\Windows Live
2009-01-15 23:33 . 2009-01-15 23:33 d——– c:\program files\Common Files\Adobe AIR
2009-01-15 23:32 . 2009-01-15 23:32 d——– c:\program files\Common Files\Adobe
2009-01-15 23:31 . 2009-01-15 23:31 d——– c:\program files\QuickTime
2009-01-15 23:31 . 2009-01-15 23:31 d——– c:\program files\Common Files\Apple
2009-01-15 23:31 . 2009-01-15 23:31 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-15 23:30 . 2009-01-15 23:30 d——– c:\program files\Apple Software Update
2009-01-15 23:30 . 2009-01-15 23:30 d——– c:\documents and settings\All Users\Application Data\Apple
2009-01-15 23:28 . 2009-01-20 16:01 d——– c:\documents and settings\All Users\Application Data\Google Updater
2009-01-15 23:26 . 2006-10-27 04:56 32,592 –a—— c:\windows\system32\msonpmon.dll
2009-01-15 23:26 . 2006-10-27 04:58 30,512 –a—— c:\windows\system32\mdimon.dll
2009-01-15 23:12 . 2009-01-15 23:13 d——– c:\program files\SpywareBlaster
2009-01-15 23:12 . 2009-01-15 23:12 d——– c:\documents and settings\All Users\Application Data\TEMP
2009-01-15 23:11 . 2009-01-15 23:11 d——– c:\documents and settings\All Users\Application Data\SlySoft
2009-01-15 23:11 . 2009-01-15 23:11 d——– c:\documents and settings\All Users\Application Data\Elaborate Bytes
2009-01-15 23:10 . 2009-01-15 23:10 d——– c:\program files\SlySoft
2009-01-15 23:10 . 2009-01-15 23:10 d——– c:\program files\K-Lite Codec Pack
2009-01-15 23:07 . 2009-01-15 23:07 d——– c:\program files\Ares
2009-01-15 23:06 . 2008-07-31 23:17 9,200 ——— c:\windows\system32\drivers\cdralw2k.sys
2009-01-15 23:06 . 2008-07-31 23:17 9,072 ——— c:\windows\system32\drivers\cdr4_xp.sys
2009-01-15 23:02 . 2009-01-15 23:02 d——– c:\windows\system32\IOSUBSYS
2009-01-15 23:02 . 2009-01-17 04:30 d——– c:\program files\Google
2009-01-15 23:02 . 2009-01-15 23:02 d——– c:\program files\Elaborate Bytes
2009-01-15 23:02 . 2008-03-20 03:26 499,712 –a—— c:\windows\system32\msvcp71.dll
2009-01-15 23:02 . 2008-03-20 03:29 348,160 –a—— c:\windows\system32\msvcr71.dll
2009-01-15 23:00 . 2009-01-15 23:02 d——– c:\windows\system32\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-15 18:54 ——— d—–w c:\program files\Windows Media Connect 2
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-28 152872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-15 39408]
"RealJukeboxSystray"="c:\program files\Real\RealJukebox\tsystray.exe" [2009-01-16 64512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"JMB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-04-25 385024]
"Ai Quicker Help"="c:\program files\ASUS\ASUS DH Remote\AsRc.exe" [2006-08-16 3171328]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-11-12 206088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-07 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-15 136600]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-02 153136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
"FixCamera"="c:\windows\FixCamera.exe" [2005-12-06 20480]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-01-16 114688]
"snp2std"="c:\windows\vsnp2std.exe" [2006-01-06 344064]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2001-02-14 168013]
"RealTray"="c:\program files\K-Lite Codec Pack\Real\mpclauncher.exe" [2008-03-13 685056]
"VTTimer"="VTTimer.exe" [2005-03-08 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-11-01 c:\windows\system32\VTTrayp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\usuario\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-01-26 385024]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ASUS WiFi-AP Solo.lnk - c:\program files\ASUS WiFi-AP Solo\RtWLan.exe [2009-01-15 987136]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-30 32784]
R1 lkbdhlpr;Logitech Keyboard Class Helper Driver;c:\windows\system32\drivers\LKBDHLPR.SYS [2009-01-16 9952]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-05-01 24592]
R3 OmniTV;Cx2388x AvStream Video Capture;c:\windows\system32\drivers\OmniTV.sys [2007-04-26 221184]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2009-01-15 332928]
R3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2009-01-15 13532]
S3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;c:\windows\system32\drivers\fetnd6v.sys [2008-09-22 43520]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://uk.mg40.mail.yahoo.com/dc/launch?.gx=1&.rand=0p7rhrvfe3k9j
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download All with FlashGet - c:\docume~1\usuario\LOCALS~1\Temp\FlashGet Portable\jc_all.htm
IE: &Download with FlashGet - c:\docume~1\usuario\LOCALS~1\Temp\FlashGet Portable\jc_link.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-01 11:28:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Logitech\iTouch\KbdTray.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-02-01 11:30:42 - machine was rebooted [usuario]
ComboFix-quarantined-files.txt 2009-02-01 10:30:38
Pre-Run: 340,386,713,600 bytes free
Post-Run: 341,040,062,464 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
248 — E O F — 2009-01-31 17:58:41