ComboFix 07-12-07.3 - Satan 2007-12-07 22:43:47.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1515 [GMT 0:00]
Running from: C:\Documents and Settings\Satan\My Documents\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\tmp33.tmp
.
((((((((((((((((((((((((( Files Created from 2007-11-07 to 2007-12-07 )))))))))))))))))))))))))))))))
.
2007-12-07 20:10 . 2007-12-07 20:10 <DIR> d-------- C:\Program Files\Avira
2007-12-07 20:10 . 2007-12-07 20:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-07 17:04 . 2007-12-07 17:04 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 16:02 . 2007-12-04 16:02 <DIR> d-------- C:\Program Files\DAEMON Tools
2007-12-04 15:48 . 2007-12-04 15:52 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2007-12-02 19:29 . 2007-12-02 19:29 <DIR> d-------- C:\WINDOWS\San Andreas Mod Installer
2007-12-02 19:29 . 2007-12-02 19:30 <DIR> d-------- C:\Program Files\San Andreas Mod Installer
2007-12-02 18:48 . 2007-12-02 18:48 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01001_C oinstaller_Critical.Wdf
2007-12-02 18:48 . 2007-12-02 18:48 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_xusb21_010 01.Wdf
2007-12-02 17:59 . 2007-12-02 17:59 <DIR> d-------- C:\Program Files\Rockstar Games
2007-12-01 16:17 . 2007-12-01 16:18 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2007-12-01 15:50 . 2007-12-01 15:50 <DIR> d-------- C:\Program Files\Microsoft Xbox 360 Accessories
2007-12-01 15:50 . 2007-02-26 18:15 1,421,216 --a------ C:\WINDOWS\system32\WdfCoInstaller01001.dll
2007-12-01 15:50 . 2007-02-26 18:15 61,984 --a------ C:\WINDOWS\system32\drivers\xusb21.sys
2007-12-01 14:09 . 2007-12-01 14:12 <DIR> d-------- C:\Program Files\mIRC
2007-12-01 14:09 . 2007-12-01 14:13 <DIR> d-------- C:\Documents and Settings\Satan\Application Data\mIRC
2007-12-01 12:33 . 2007-12-01 14:40 <DIR> d-------- C:\Program Files\MagicISO
2007-12-01 12:18 . 2007-12-01 12:18 <DIR> d-------- C:\Program Files\Alcohol Soft
2007-11-30 19:09 . 2007-11-30 19:09 <DIR> d-------- C:\Documents and Settings\Satan\Application Data\DataCast
2007-11-30 19:09 . 2007-08-23 21:06 110,592 --a------ C:\WINDOWS\system32\TG_DUMP0708.DLL
2007-11-30 19:09 . 2007-11-20 15:36 44,544 --------- C:\WINDOWS\system32\msxml4a.dll
2007-11-29 14:15 . 2007-11-29 14:15 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-11-21 18:23 . 2007-11-21 18:23 81,920 --a------ C:\WINDOWS\system32\frapsvid.dll
2007-11-16 20:24 . 2007-11-16 20:24 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Xfire
2007-11-16 20:21 . 2007-11-30 22:31 <DIR> d-------- C:\Program Files\Xfire
2007-11-16 20:21 . 2007-12-07 21:48 <DIR> d-------- C:\Documents and Settings\Satan\Application Data\Xfire
2007-11-16 16:34 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-11-16 16:34 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-11-16 16:34 . 2007-11-16 16:34 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe
2007-11-16 16:34 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-11-16 16:09 . 2007-11-16 16:09 <DIR> d-------- C:\WINDOWS\NV4443792.TMP
2007-11-16 16:09 . 2007-10-04 17:14 136,260 --a------ C:\WINDOWS\system32\nvapps.nvb
2007-11-16 01:10 . 2007-11-16 14:13 <DIR> d-------- C:\Program Files\Trillian
2007-11-15 19:56 . 2007-11-15 19:58 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-15 19:55 . 2007-11-15 20:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-13 17:15 . 2007-12-05 17:27 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-13 11:04 . 2007-11-13 11:04 <DIR> d-------- C:\Documents and Settings\Satan\Application Data\Lavasoft
2007-11-09 19:11 . 2007-11-09 19:11 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-09 19:10 . 2007-12-07 19:44 <DIR> d-------- C:\Documents and Settings\Satan\Application Data\AVG7
2007-11-09 19:10 . 2007-11-09 19:10 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-09 19:10 . 2007-11-09 19:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-09 19:10 . 2007-11-09 19:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-11-09 19:08 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-09 18:52 . 2007-11-09 18:52 <DIR> d-------- C:\Program Files\ZyDAS Technology Corporation
2007-11-09 18:52 . 2006-08-24 13:44 477,696 --a------ C:\WINDOWS\system32\drivers\ZD1211BU.sys
2007-11-09 18:52 . 2004-01-14 11:25 81,920 --a------ C:\WINDOWS\system32\ZDPN50.DLL
2007-11-09 18:52 . 2005-03-18 15:35 31,744 --a------ C:\WINDOWS\system32\drivers\ZDPSp50a64.sys
2007-11-09 18:52 . 2005-06-08 18:44 29,184 --a------ C:\WINDOWS\system32\drivers\BRGSp50a64.sys
2007-11-09 18:52 . 2004-03-23 16:38 28,672 --a------ C:\WINDOWS\system32\InsDrvZD.dll
2007-11-09 18:52 . 2003-03-14 12:24 24,576 --a------ C:\WINDOWS\system32\ZyDelReg.exe
2007-11-09 18:52 . 2005-06-08 18:44 20,608 --a------ C:\WINDOWS\system32\drivers\BRGSp50.sys
2007-11-09 18:52 . 2004-10-25 13:40 17,664 --a------ C:\WINDOWS\system32\drivers\ZDPSp50.sys
2007-11-09 18:52 . 2004-01-14 11:30 17,151 --a------ C:\WINDOWS\system32\ZDPNDIS5.SYS
2007-11-09 18:52 . 2005-07-12 14:44 15,872 --a------ C:\WINDOWS\system32\InsDrvZD64.DLL
2007-11-09 18:28 . 2005-05-03 10:43 69,632 -r------- C:\WINDOWS\Alcmtr.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-12-07 17:14 --------- d-----w C:\Documents and Settings\Satan\Application Data\uTorrent
2007-12-07 05:43 --------- d-----w C:\Program Files\SwiftSwitch
2007-12-06 16:22 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-06 16:15 --------- d-----w C:\Program Files\HyCam2
2007-12-05 17:27 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-05 17:24 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-12-02 17:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-01 15:32 --------- d-----w C:\Program Files\Electronic Arts
2007-11-30 19:34 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2007-11-26 22:11 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-20 15:36 118,784 ----a-w C:\WINDOWS\system32\MaDRM.dll
2007-11-20 15:35 40,960 ----a-w C:\WINDOWS\system32\MAMACExtract.dll
2007-11-16 16:34 22,328 ----a-w C:\Documents and Settings\Satan\Application Data\PnkBstrK.sys
2007-11-12 20:08 --------- d-----w C:\Program Files\Common Files\AOL
2007-11-09 18:35 --------- d-----w C:\Program Files\Activision
2007-11-09 18:28 --------- d-----w C:\Program Files\Realtek
2007-11-03 21:32 144,384 ----a-w C:\WINDOWS\system32\miccyhook.dll
2007-11-03 18:03 --------- d-----w C:\Program Files\VoyagerTest
2007-11-03 17:56 --------- d-----w C:\Program Files\Common Files\SupportSoft
2007-11-01 18:12 65,024 ----a-w C:\WINDOWS\IFinst26.exe
2007-11-01 18:12 --------- d-----w C:\Program Files\XviD
2007-11-01 18:12 --------- d-----w C:\Program Files\Lame MP3 Codec
2007-11-01 18:11 --------- d-----w C:\Program Files\Samsung
2007-11-01 18:11 --------- d-----w C:\Program Files\MarkAny
2007-10-25 19:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\SwiftSwitch
2007-10-23 16:35 --------- d-----w C:\Program Files\Java
2007-10-17 00:32 --------- d-----w C:\Documents and Settings\Satan\Application Data\dvdcss
2007-10-16 00:37 --------- d-----w C:\Program Files\MSECACHE
2007-10-10 00:58 --------- d-----w C:\Program Files\Ares
2007-10-09 14:25 --------- d-----w C:\Program Files\id Software
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 12:00]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-07-16 21:54]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-09 19:12]
"NvCplDaemon"="RUNDLL32.exe" [2006-02-28 12:00 C:\WINDOWS\system32\rundll32.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-26 23:47]
"nwiz"="nwiz.exe" [2007-06-28 23:43 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2006-02-28 12:00 C:\WINDOWS\system32\rundll32.exe]
"XboxStat"="c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 18:05]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-12-07 20:21]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-09 19:12]
C:\Documents and Settings\Satan\Start Menu\Programs\Startup\
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2007-11-15 01:00:40]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
"NoToolbarsOnTaskbar"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-20 22:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TrayMin710.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TrayMin710.exe.lnk
backup=C:\WINDOWS\pss\TrayMin710.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ZDWLan Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk
backup=C:\WINDOWS\pss\ZDWLan Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\Ares\Ares.exe -h
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2006-02-28 12:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EADM\Core.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gainward]
C:\Program Files\Vtune\TBPanel.exe /A
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-11-14 14:01 50736 --a------ C:\Program Files\Common Files\AOL\1177437489\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-09-04 22:40 67128 --a------ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
KHALMNPR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
2007-11-30 17:12 62176 --a------ C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2006-02-10 20:40 2048000 --------- C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\phc710]
2005-07-20 18:56 339968 --a------ C:\WINDOWS\vphc700.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
2007-09-20 08:23 132624 --a------ C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-09-25 00:11 132496 --a------ C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"vsmon"=2 (0x2)
"usnjsvc"=3 (0x3)
"PnkBstrA"=2 (0x2)
"ose"=3 (0x3)
"KodakCCS"=3 (0x3)
"IDriverT"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"AresChatServer"=3 (0x3)
"AOL ACS"=2 (0x2)
"Adobe LM Service"=3 (0x3)
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepK E.sys
R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu. sys
S3 Asushwio;Asushwio;\??\C:\WINDOWS\system32\drivers\ Asushwio.sys
S3 iadusb;MT882;C:\WINDOWS\system32\DRIVERS\glauiad.s ys
S3 phc700;USB PC Camera (phc710);C:\WINDOWS\system32\DRIVERS\phc700.sys
S3 PPPoEWin;PPPoEWin Miniport;C:\WINDOWS\system32\DRIVERS\PPPoEWin.SYS
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SSMDRV
.
************************************************** ************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-07 22:45:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2007-12-07 22:45:41
.
--- E O F ---