ComboFix 08-06-20.4 - sfarr 06/28/2008 2:13:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.654 [GMT 3:00]
Running from: C:\Documents and Settings\sfarr\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kakle.dll
C:\WINDOWS\system32\winitn.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 23:18 15,004,448 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-27 23:18 1,308,704 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-27 23:11 --------- d-----w C:\Documents and Settings\sfarr\Application Data\DMCache
2008-06-27 20:43 --------- d-----w C:\Documents and Settings\sfarr\Application Data\Orbit
2008-06-27 20:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-27 13:58 206,600 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-27 13:58 128,552 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-26 23:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-23 16:05 --------- d-----w C:\Documents and Settings\sfarr\Application Data\U3
2008-06-21 21:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-06-21 19:16 --------- d-----w C:\Documents and Settings\OoO\Application Data\Orbit
2008-06-19 10:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-19 10:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-18 18:34 --------- d-----w C:\Program Files\Common Files\delet
2008-06-17 17:50 --------- d-----w C:\Documents and Settings\sfarr\Application Data\Skype
2008-06-17 07:57 --------- d-----w C:\Program Files\Orbitdownloader
2008-06-17 07:56 --------- d-----w C:\Documents and Settings\sfarr\Application Data\GrabPro
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-08 08:34 --------- d-----w C:\Program Files\Sun
2008-06-08 08:33 --------- d-----w C:\Program Files\Java
2008-06-03 07:01 --------- d-----w C:\Program Files\Common Files\stardock
2008-06-03 06:59 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-06-03 06:43 --------- d-----w C:\Program Files\Stardock
2008-06-02 22:36 --------- d-----w C:\Documents and Settings\OoO\Application Data\U3
2008-05-31 20:23 --------- d-----w C:\Documents and Settings\OoO\Application Data\PC Suite
2008-05-31 11:06 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-31 11:06 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-31 11:06 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-24 21:27 --------- d-----w C:\Documents and Settings\sfarr\Application Data\mIRC
2008-05-24 21:26 --------- d-----w C:\Program Files\mIRC
2008-05-23 11:09 --------- d-----w C:\Documents and Settings\sfarr\Application Data\PC Suite
2008-05-23 11:08 --------- d-----w C:\Documents and Settings\sfarr\Application Data\Datalayer
2008-05-22 18:44 --------- d-----w C:\Program Files\Microsoft Works
2008-05-17 18:41 --------- d-----w C:\Program Files\Common Files\Vbox
2008-05-16 22:35 --------- d-----w C:\Program Files\Magic Swf2Avi 2008
2008-05-16 01:39 155,995 ----a-w C:\WINDOWS\java\Packages\ZPJ5VP37.ZIP
2008-05-16 00:53 --------- d-----w C:\Program Files\SWiSHmax
2008-05-15 09:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-05-15 09:50 --------- d-----w C:\Program Files\ma-config.com
2008-05-14 16:44 --------- d-----w C:\Program Files\Acoustica Shared Effects
2008-05-14 16:44 --------- d-----w C:\Program Files\Acoustica Mixcraft
2008-05-13 17:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-05-13 17:04 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-05-11 17:41 --------- d-----w C:\Documents and Settings\sfarr\Application Data\IDM
2008-05-11 10:46 --------- d-----w C:\Program Files\Google
2008-05-09 11:25 --------- d-----w C:\Program Files\Internet Download Manager
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 13:53 --------- d-----w C:\Program Files\TopThemesXP
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-06 13:37 --------- d-----w C:\Program Files\BitComet
2008-05-06 13:15 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2008-05-06 12:47 --------- d-----w C:\Documents and Settings\sfarr\Application Data\Media Player Classic
2008-05-06 12:05 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-06 12:03 --------- d-----w C:\Program Files\Real
2008-05-06 12:03 --------- d-----w C:\Program Files\Common Files\Real
2008-05-05 20:11 --------- d-----w C:\Program Files\GRETECH
2008-05-05 20:11 --------- d-----w C:\Documents and Settings\sfarr\Application Data\GRETECH
2008-05-05 20:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-05-05 20:10 --------- d-----w C:\Documents and Settings\sfarr\Application Data\vlc
2008-05-05 20:09 --------- d-----w C:\Program Files\VideoLAN
2008-05-04 10:50 --------- d-----w C:\Documents and Settings\sfarr\Application Data\CyberLink
2008-05-04 10:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-05-04 10:22 --------- d-----w C:\Program Files\CyberLink
2008-04-30 17:33 --------- d-----w C:\Program Files\Toolbar
2008-04-30 17:31 --------- d-----w C:\Program Files\Languages
2008-04-26 20:37 724,992 ----a-w C:\WINDOWS\iun6002.exe
2008-04-23 16:04 344,064 ----a-w C:\WINDOWS\system32\dkll.dll
2008-04-23 16:04 196,608 ----a-w C:\WINDOWS\system32\maag.dll
2008-04-23 16:04 1,986,560 ----a-w C:\WINDOWS\system32\akll.dll
2008-04-23 16:04 1,212,416 ----a-w C:\WINDOWS\system32\ckll.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 02:42 985,088 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 02:42 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 02:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 997,376 ----a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:24 2,145,280 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:43 9,728 ------w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,023,936 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 18:14 76,800 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:39 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 17:39 2,897,920 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 187,392 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:27 79,872 ------w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 94,208 ----a-w C:\WINDOWS\system32\odbcint.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C55BBCD6-41AD-48AD-9953-3609C48EACC7}"= C:\Program Files\Orbitdownloader\GrabPro.dll [06/10/2008 10:47 AM 457848]
[HKEY_CLASSES_ROOT\clsid\{c55bbcd6-41ad-48ad-9953-3609c48eacc7}]
[HKEY_CLASSES_ROOT\GrabPro.FindBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{8091D09E-B01D-4D32-AC66-BBF8916BB1CF}]
[HKEY_CLASSES_ROOT\GrabPro.FindBar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 03:12 AM 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [11/07/2007 03:34 PM 3739672]
"IDMan"="C:\Documents and Settings\Default User\Local Settings\Temp\bsasee3y5d\IDMan.exe" [12/21/2007 07:16 PM 2573744]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [05/20/2008 12:08 AM 68856]
"DesktopX"="C:\Program Files\Stardock\ Desktop\DesktopX\DesktopX Builder.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [12/28/2005 11:55 AM 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [12/28/2005 11:56 AM 602182]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [12/13/2005 05:44 PM 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [12/13/2005 05:41 PM 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [12/13/2005 05:45 PM 118784]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [12/06/2005 10:45 AM 839680]
"ShowLOMControl"="1 (0x1)" []
"SigmatelSysTrayApp"="stsystra.exe" [11/16/2005 03:35 PM 397312 C:\WINDOWS\stsystra.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [11/29/2005 12:56 PM 761947]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM 144784]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [08/04/2004 01:00 PM 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [08/04/2004 01:00 PM 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [08/04/2004 01:00 PM 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [08/04/2004 01:00 PM 455168]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [01/23/2007 11:19 AM 223232]
"TXP"="c:\program files\topthemesxp\txp.exe" [04/18/2006 05:50 PM 475136]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/06/2005 06:03 PM 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/24/2008 02:18 PM 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [03/14/2007 09:01 PM 71216]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [02/07/2007 04:21 PM 54832]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/21/2008 10:29 PM 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [11/09/2006 05:15 PM 1634304]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 03:12 AM 15360]
C:\Documents and Settings\sfarr\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
Stardock Dock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\Dock\Dock.exe [2005-02-21 16:56:00 1826885]
Y'z ToolBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-09-29 16:41:00 90112]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 18:28:28 622653]
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2008-06-05 00:41:46 1690824]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-04-04 15:11:55 389120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16273:TCP"= 16273:TCP:BitComet 16273 TCP
"16273:UDP"= 16273:UDP:BitComet 16273 UDP
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [11/02/2006 04:51 PM]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/04/2007 02:58 PM]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [06/08/2007 09:52 AM]
S3 maconfservice;maconfservice;"C:\Program Files\ma-config.com\maconfservice.exe" [05/14/2008 04:40 PM]
S3 zlportio;ZLPORTIO - Allow user access to I/O ports;C:\WINDOWS\system32\zlportio.sys [09/22/2001 10:16 AM]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-06-28 02:18:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
Completion time: 06/28/2008 2:21:28
ComboFix-quarantined-files.txt 2008-06-27 23:20:46
Pre-Run: 57,889,394,688 bytes free
Post-Run: 58,107,580,416 bytes free
215 --- E O F --- 2008-06-20 00:03:20
===