ComboFix 08-01-03.3 - ELI 2008-01-03 19:53:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.387 [GMT 1:00]
Running from: F:\Letőltések\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\avviiypd.dll
C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\system32\dhyvwvht.dll
C:\WINDOWS\system32\dpyiivva.ini
C:\WINDOWS\system32\epoompcn.dll
C:\WINDOWS\system32\felrmuio.dll
C:\WINDOWS\system32\ghilhfkt.dll
C:\WINDOWS\system32\gtfplyun.dll
C:\WINDOWS\system32\hpnugren.ini
C:\WINDOWS\system32\ieevnbat.dll
C:\WINDOWS\system32\isuucjrp.dll
C:\WINDOWS\system32\jlnmp.ini
C:\WINDOWS\system32\jlnmp.ini2
C:\WINDOWS\system32\lutwnuhs.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mrdlopxa.dll
C:\WINDOWS\system32\ncpmoope.ini
C:\WINDOWS\system32\nucaxnbl.ini
C:\WINDOWS\system32\nuylpftg.ini
C:\WINDOWS\system32\oqboiyqx.dll
C:\WINDOWS\system32\oqhjkaeo.ini
C:\WINDOWS\system32\pfdbmgun.dll
C:\WINDOWS\system32\pmnlj.dll
C:\WINDOWS\system32\svyckmbd.dll
C:\WINDOWS\system32\teqcyeji.dll
C:\WINDOWS\system32\tibaoyij.dll
C:\WINDOWS\system32\tkhwdesm.dll
C:\WINDOWS\system32\tsvekemo.dll
C:\WINDOWS\system32\vofdwcwh.dll
C:\WINDOWS\system32\wdyfjwkt.dll
C:\WINDOWS\system32\wmaisxay.dll
C:\WINDOWS\system32\wnmfsgdh.dll
C:\WINDOWS\system32\yrvoautw.dll
C:\WINDOWS\system32\yytikvjh.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.
2008-01-03 19:47 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 22:08 . 2008-01-01 22:08 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\DivX
2008-01-01 22:07 . 2008-01-01 22:07 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\Yahoo!
2008-01-01 22:07 . 2008-01-01 22:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-01 22:06 . 2008-01-01 22:06 <DIR> d-------- C:\Program Files\Yahoo!
2008-01-01 22:06 . 2008-01-01 22:07 <DIR> d-------- C:\Program Files\DivX
2008-01-01 22:06 . 2007-11-29 23:30 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-01 22:06 . 2007-11-29 23:30 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-01-01 22:06 . 2007-11-29 23:30 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-12-31 12:18 . 2008-01-01 16:40 1,032,219 ---hs---- C:\WINDOWS\system32\iggxwlrm.ini
2007-12-30 11:14 . 2007-12-31 12:12 1,032,039 ---hs---- C:\WINDOWS\system32\lrxjwqsm.ini
2007-12-28 19:54 . 2007-12-30 11:14 1,031,799 ---hs---- C:\WINDOWS\system32\usjfkbre.ini
2007-12-28 18:38 . 2007-12-28 18:38 1,409 --a------ C:\WINDOWS\system32\tmp47704.FOT
2007-12-27 19:49 . 2007-12-28 19:50 1,031,499 ---hs---- C:\WINDOWS\system32\qivbqcnn.ini
2007-12-26 19:54 . 2007-12-27 12:20 1,027,983 ---hs---- C:\WINDOWS\system32\ssjyfoqv.ini
2007-12-19 17:01 . 2008-01-01 23:07 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-12-19 17:01 . 2008-01-01 23:07 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-19 17:00 . 2008-01-01 23:07 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-12-19 16:46 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-12-19 16:46 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-12-19 16:46 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-12-19 16:46 . 2007-03-12 16:42 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-12-19 16:46 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-12-19 16:46 . 2007-03-15 16:57 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-12-19 16:46 . 2007-06-20 20:46 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-12-19 16:46 . 2007-04-04 18:55 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-12-19 16:46 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-12-19 16:46 . 2007-06-20 20:45 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-12-19 16:28 . 2007-12-19 16:29 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\DAEMON Tools Pro
2007-12-19 16:28 . 2007-12-19 16:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2007-12-19 16:23 . 2007-12-19 16:30 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2007-12-19 16:16 . 2007-12-19 16:16 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-19 15:37 . 2007-12-19 15:37 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\PCToolsSpamMonitorPlus
2007-12-19 15:37 . 2007-12-19 15:37 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\PCToolsFirewallPlus
2007-12-19 15:35 . 2007-12-19 15:51 <DIR> d-------- C:\Program Files\PC Tools Internet Security
2007-12-19 15:20 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-12-19 15:20 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2007-12-19 15:20 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-12-19 15:20 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-19 15:20 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-19 15:20 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-19 15:20 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-19 15:20 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-19 15:12 . 2007-12-19 15:12 0 --a------ C:\WINDOWS\system32\mapisvc.inf
2007-12-19 15:11 . 2007-12-19 15:11 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-12-19 15:11 . 2007-12-19 15:11 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-12-19 15:11 . 2007-12-19 15:11 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-12-19 15:03 . 2007-12-19 15:03 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\URSoft
2007-12-19 15:02 . 2007-12-19 15:07 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2007-12-17 20:45 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-17 20:45 . 2007-07-01 04:36 1,028,096 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-17 20:44 . 2007-12-17 20:45 <DIR> d-------- C:\WINDOWS\system32\hu-hu
2007-12-17 20:39 . 2007-10-11 00:53 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-17 20:39 . 2007-10-11 00:53 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-17 20:39 . 2007-10-11 00:53 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-17 20:39 . 2007-10-11 00:53 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-17 20:39 . 2007-10-11 00:53 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-17 20:39 . 2007-10-11 00:53 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-17 20:39 . 2007-10-10 11:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-17 20:38 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2007-12-12 18:58 . 2007-12-12 18:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\sentinel
2007-12-12 18:53 . 2007-12-26 22:51 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2007-12-09 19:20 . 2007-12-09 19:20 <DIR> d-------- C:\Program Files\Ashampoo
2007-12-09 18:56 . 2007-12-09 18:56 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\Thinstall
2007-12-09 18:55 . 2007-12-09 18:55 <DIR> d-------- C:\Program Files\Ashampoo AntiSpyWare 2.01 [ Portable by seven ]
2007-12-09 18:34 . 2007-12-09 18:34 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-09 18:26 . 2007-12-09 18:26 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\Spyware Terminator
2007-12-09 18:26 . 2007-12-09 18:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2007-12-04 18:17 . 2007-12-27 12:31 963 --a------ C:\WINDOWS\disney.ini
2007-12-04 18:17 . 2007-12-27 12:28 206 --a------ C:\WINDOWS\disneysy.ini
2007-12-04 02:33 . 2007-12-04 02:33 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 02:33 . 2007-12-04 02:33 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 02:33 . 2007-12-04 02:33 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 02:33 . 2007-12-04 02:33 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 18:44 --------- d-----w C:\Documents and Settings\ELI\Application Data\Skype
2008-01-02 15:01 --------- d-----w C:\Documents and Settings\ELI\Application Data\LimeWire
2007-12-31 18:45 --------- d-----w C:\Documents and Settings\ELI\Application Data\uTorrent
2007-12-31 16:16 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-29 14:01 --------- d-----w C:\Documents and Settings\ELI\Application Data\Image Zone Express
2007-12-28 12:34 --------- d-----w C:\Documents and Settings\ELI\Application Data\Wildfire
2007-12-27 11:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-23 11:32 --------- d-----w C:\Program Files\Opera
2007-12-22 21:49 --------- d-----w C:\Documents and Settings\ELI\Application Data\Azureus
2007-12-21 09:06 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2007-12-19 15:24 --------- d-----w C:\Program Files\D-Tools
2007-11-29 22:30 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-11-24 08:32 --------- d-----w C:\Program Files\Java
2007-11-20 17:22 --------- d-----w C:\Program Files\Picasa2
2007-11-19 12:17 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-21 19:23 21,472 ----a-w C:\Documents and Settings\ELI\Application Data\GDIPFONTCACHEV1.DAT
2007-08-29 18:47 4,727,821 ----a-w C:\Program Files\Setup_0699dx.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-23 09:17 68856]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-05-18 12:14 23423528]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
"msnmsgr"="~C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:47 15360]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 14:08 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Remote Addressing"="wnpcgs.exe" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-03-10 18:45 35328]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 06:49 106544 C:\WINDOWS\system32\tweakui.cpl]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2006-12-27 16:53 73840]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [ ]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11 1388544]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" [2004-08-06 07:27 860160]
"SlowDownCPU"="C:\WINDOWS\INF\MSI\SlowDownCPU\SlowDownCPU.exe" [2005-02-25 03:22 208896]
"SaiSmart"="C:\Program Files\Saitek\Software\SaiSmart.exe" [2004-01-28 09:19 98304]
"QuickTime Task"="C:\WINDOWS\system32\qttask.exe" [2006-12-05 17:07 77824]
"Profiler"="C:\Program Files\Saitek\Software\Profiler.exe" [2004-01-28 09:19 159744]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"MMTrayLSI"="MMTrayLSI.exe" [2003-03-25 06:49 53248 C:\WINDOWS\system32\MMTrayLSI.exe]
"MMTray2K"="MMTray2k.exe" [2003-03-25 06:49 57344 C:\WINDOWS\system32\MMTray2k.exe]
"MMTray"="MMTray.exe" [2003-03-25 06:49 53248 C:\WINDOWS\system32\MMTray.exe]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 16:58 213936]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 20:52 49152]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 15:48 110592 C:\WINDOWS\system32\bthprops.cpl]
"BigDog303"="C:\WINDOWS\VM303_STI.exe" [2005-10-25 11:56 61440]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 18:41 45056]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-12-19 15:11 949376]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:47 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcbxvv]
ddcbxvv.dll
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-12-06 16:11]
R3 RushTopDevice;RushTopDevice;C:\WINDOWS\INF\MSI\SlowDownCPU\RushTop.sys [2005-02-22 07:47]
R3 SlowDownCPU;SlowDownCPU;C:\WINDOWS\INF\MSI\SlowDownCPU\NTGLM7X.sys [2004-11-01 10:12]
R3 ZSMC303;A4 TECH PC Camera H;C:\WINDOWS\system32\Drivers\usbVM303.sys [2005-10-27 07:34]
S3 SaiH0109;SaiH0109;C:\WINDOWS\system32\DRIVERS\SaiH0109.sys [2004-01-30 14:19]
S3 SaiU0109;SaiU0109;C:\WINDOWS\system32\DRIVERS\SaiU0109.sys [2004-01-30 14:19]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8716cc8a-1cf9-11dc-be2a-0013d33c4480}]
\Shell\AutoRun\command - K:\RavMon.exe
\Shell\explore\Command - K:\RavMon.exe -e
\Shell\open\Command - K:\RavMon.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-02 19:11:00 C:\WINDOWS\Tasks\WebReg Deskjet F2100 series.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-03 20:00:22
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\Program Files\Eset\pr_imon.dll
.
Completion time: 2008-01-03 20:02:47 - machine was rebooted [ELI]
ComboFix-quarantined-files.txt 2008-01-03 19:02:44
.
2007-12-21 21:54:24 --- E O F ---
ComboFix 08-01-03.3 - ELI 2008-01-03 19:53:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1038.18.387 [GMT 1:00]
Running from: F:\Letőltések\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\avviiypd.dll
C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\system32\dhyvwvht.dll
C:\WINDOWS\system32\dpyiivva.ini
C:\WINDOWS\system32\epoompcn.dll
C:\WINDOWS\system32\felrmuio.dll
C:\WINDOWS\system32\ghilhfkt.dll
C:\WINDOWS\system32\gtfplyun.dll
C:\WINDOWS\system32\hpnugren.ini
C:\WINDOWS\system32\ieevnbat.dll
C:\WINDOWS\system32\isuucjrp.dll
C:\WINDOWS\system32\jlnmp.ini
C:\WINDOWS\system32\jlnmp.ini2
C:\WINDOWS\system32\lutwnuhs.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mrdlopxa.dll
C:\WINDOWS\system32\ncpmoope.ini
C:\WINDOWS\system32\nucaxnbl.ini
C:\WINDOWS\system32\nuylpftg.ini
C:\WINDOWS\system32\oqboiyqx.dll
C:\WINDOWS\system32\oqhjkaeo.ini
C:\WINDOWS\system32\pfdbmgun.dll
C:\WINDOWS\system32\pmnlj.dll
C:\WINDOWS\system32\svyckmbd.dll
C:\WINDOWS\system32\teqcyeji.dll
C:\WINDOWS\system32\tibaoyij.dll
C:\WINDOWS\system32\tkhwdesm.dll
C:\WINDOWS\system32\tsvekemo.dll
C:\WINDOWS\system32\vofdwcwh.dll
C:\WINDOWS\system32\wdyfjwkt.dll
C:\WINDOWS\system32\wmaisxay.dll
C:\WINDOWS\system32\wnmfsgdh.dll
C:\WINDOWS\system32\yrvoautw.dll
C:\WINDOWS\system32\yytikvjh.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.
2008-01-03 19:47 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 22:08 . 2008-01-01 22:08 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\DivX
2008-01-01 22:07 . 2008-01-01 22:07 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\Yahoo!
2008-01-01 22:07 . 2008-01-01 22:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-01 22:06 . 2008-01-01 22:06 <DIR> d-------- C:\Program Files\Yahoo!
2008-01-01 22:06 . 2008-01-01 22:07 <DIR> d-------- C:\Program Files\DivX
2008-01-01 22:06 . 2007-11-29 23:30 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-01 22:06 . 2007-11-29 23:30 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-01-01 22:06 . 2007-11-29 23:30 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-12-31 12:18 . 2008-01-01 16:40 1,032,219 ---hs---- C:\WINDOWS\system32\iggxwlrm.ini
2007-12-30 11:14 . 2007-12-31 12:12 1,032,039 ---hs---- C:\WINDOWS\system32\lrxjwqsm.ini
2007-12-28 19:54 . 2007-12-30 11:14 1,031,799 ---hs---- C:\WINDOWS\system32\usjfkbre.ini
2007-12-28 18:38 . 2007-12-28 18:38 1,409 --a------ C:\WINDOWS\system32\tmp47704.FOT
2007-12-27 19:49 . 2007-12-28 19:50 1,031,499 ---hs---- C:\WINDOWS\system32\qivbqcnn.ini
2007-12-26 19:54 . 2007-12-27 12:20 1,027,983 ---hs---- C:\WINDOWS\system32\ssjyfoqv.ini
2007-12-19 17:01 . 2008-01-01 23:07 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-12-19 17:01 . 2008-01-01 23:07 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-19 17:00 . 2008-01-01 23:07 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-12-19 16:46 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-12-19 16:46 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-12-19 16:46 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-12-19 16:46 . 2007-03-12 16:42 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-12-19 16:46 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-12-19 16:46 . 2007-03-15 16:57 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-12-19 16:46 . 2007-06-20 20:46 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-12-19 16:46 . 2007-04-04 18:55 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-12-19 16:46 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-12-19 16:46 . 2007-06-20 20:45 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-12-19 16:28 . 2007-12-19 16:29 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\DAEMON Tools Pro
2007-12-19 16:28 . 2007-12-19 16:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2007-12-19 16:23 . 2007-12-19 16:30 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2007-12-19 16:16 . 2007-12-19 16:16 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-19 15:37 . 2007-12-19 15:37 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\PCToolsSpamMonitorPlus
2007-12-19 15:37 . 2007-12-19 15:37 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\PCToolsFirewallPlus
2007-12-19 15:35 . 2007-12-19 15:51 <DIR> d-------- C:\Program Files\PC Tools Internet Security
2007-12-19 15:20 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-12-19 15:20 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2007-12-19 15:20 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-12-19 15:20 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-19 15:20 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-19 15:20 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-19 15:20 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-19 15:20 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-19 15:12 . 2007-12-19 15:12 0 --a------ C:\WINDOWS\system32\mapisvc.inf
2007-12-19 15:11 . 2007-12-19 15:11 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-12-19 15:11 . 2007-12-19 15:11 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-12-19 15:11 . 2007-12-19 15:11 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-12-19 15:03 . 2007-12-19 15:03 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\URSoft
2007-12-19 15:02 . 2007-12-19 15:07 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2007-12-17 20:45 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-17 20:45 . 2007-07-01 04:36 1,028,096 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-17 20:44 . 2007-12-17 20:45 <DIR> d-------- C:\WINDOWS\system32\hu-hu
2007-12-17 20:39 . 2007-10-11 00:53 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-17 20:39 . 2007-10-11 00:53 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-17 20:39 . 2007-10-11 00:53 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-17 20:39 . 2007-10-11 00:53 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-17 20:39 . 2007-10-11 00:53 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-17 20:39 . 2007-10-11 00:53 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-17 20:39 . 2007-10-10 11:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-17 20:38 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2007-12-12 18:58 . 2007-12-12 18:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\sentinel
2007-12-12 18:53 . 2007-12-26 22:51 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2007-12-09 19:20 . 2007-12-09 19:20 <DIR> d-------- C:\Program Files\Ashampoo
2007-12-09 18:56 . 2007-12-09 18:56 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\Thinstall
2007-12-09 18:55 . 2007-12-09 18:55 <DIR> d-------- C:\Program Files\Ashampoo AntiSpyWare 2.01 [ Portable by seven ]
2007-12-09 18:34 . 2007-12-09 18:34 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-09 18:26 . 2007-12-09 18:26 <DIR> d-------- C:\Documents and Settings\ELI\Application Data\Spyware Terminator
2007-12-09 18:26 . 2007-12-09 18:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2007-12-04 18:17 . 2007-12-27 12:31 963 --a------ C:\WINDOWS\disney.ini
2007-12-04 18:17 . 2007-12-27 12:28 206 --a------ C:\WINDOWS\disneysy.ini
2007-12-04 02:33 . 2007-12-04 02:33 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 02:33 . 2007-12-04 02:33 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 02:33 . 2007-12-04 02:33 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 02:33 . 2007-12-04 02:33 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 18:44 --------- d-----w C:\Documents and Settings\ELI\Application Data\Skype
2008-01-02 15:01 --------- d-----w C:\Documents and Settings\ELI\Application Data\LimeWire
2007-12-31 18:45 --------- d-----w C:\Documents and Settings\ELI\Application Data\uTorrent
2007-12-31 16:16 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-29 14:01 --------- d-----w C:\Documents and Settings\ELI\Application Data\Image Zone Express
2007-12-28 12:34 --------- d-----w C:\Documents and Settings\ELI\Application Data\Wildfire
2007-12-27 11:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-23 11:32 --------- d-----w C:\Program Files\Opera
2007-12-22 21:49 --------- d-----w C:\Documents and Settings\ELI\Application Data\Azureus
2007-12-21 09:06 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2007-12-19 15:24 --------- d-----w C:\Program Files\D-Tools
2007-11-29 22:30 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-11-24 08:32 --------- d-----w C:\Program Files\Java
2007-11-20 17:22 --------- d-----w C:\Program Files\Picasa2
2007-11-19 12:17 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-21 19:23 21,472 ----a-w C:\Documents and Settings\ELI\Application Data\GDIPFONTCACHEV1.DAT
2007-08-29 18:47 4,727,821 ----a-w C:\Program Files\Setup_0699dx.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-23 09:17 68856]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-05-18 12:14 23423528]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
"msnmsgr"="~C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:47 15360]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 14:08 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Remote Addressing"="wnpcgs.exe" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-03-10 18:45 35328]
"Tweak UI"="TWEAKUI.CPL" [2003-03-25 06:49 106544 C:\WINDOWS\system32\tweakui.cpl]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2006-12-27 16:53 73840]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [ ]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11 1388544]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" [2004-08-06 07:27 860160]
"SlowDownCPU"="C:\WINDOWS\INF\MSI\SlowDownCPU\SlowDownCPU.exe" [2005-02-25 03:22 208896]
"SaiSmart"="C:\Program Files\Saitek\Software\SaiSmart.exe" [2004-01-28 09:19 98304]
"QuickTime Task"="C:\WINDOWS\system32\qttask.exe" [2006-12-05 17:07 77824]
"Profiler"="C:\Program Files\Saitek\Software\Profiler.exe" [2004-01-28 09:19 159744]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"MMTrayLSI"="MMTrayLSI.exe" [2003-03-25 06:49 53248 C:\WINDOWS\system32\MMTrayLSI.exe]
"MMTray2K"="MMTray2k.exe" [2003-03-25 06:49 57344 C:\WINDOWS\system32\MMTray2k.exe]
"MMTray"="MMTray.exe" [2003-03-25 06:49 53248 C:\WINDOWS\system32\MMTray.exe]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 16:58 213936]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 20:52 49152]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-17 15:48 110592 C:\WINDOWS\system32\bthprops.cpl]
"BigDog303"="C:\WINDOWS\VM303_STI.exe" [2005-10-25 11:56 61440]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 18:41 45056]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-12-19 15:11 949376]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 15:47 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcbxvv]
ddcbxvv.dll
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-12-06 16:11]
R3 RushTopDevice;RushTopDevice;C:\WINDOWS\INF\MSI\SlowDownCPU\RushTop.sys [2005-02-22 07:47]
R3 SlowDownCPU;SlowDownCPU;C:\WINDOWS\INF\MSI\SlowDownCPU\NTGLM7X.sys [2004-11-01 10:12]
R3 ZSMC303;A4 TECH PC Camera H;C:\WINDOWS\system32\Drivers\usbVM303.sys [2005-10-27 07:34]
S3 SaiH0109;SaiH0109;C:\WINDOWS\system32\DRIVERS\SaiH0109.sys [2004-01-30 14:19]
S3 SaiU0109;SaiU0109;C:\WINDOWS\system32\DRIVERS\SaiU0109.sys [2004-01-30 14:19]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8716cc8a-1cf9-11dc-be2a-0013d33c4480}]
\Shell\AutoRun\command - K:\RavMon.exe
\Shell\explore\Command - K:\RavMon.exe -e
\Shell\open\Command - K:\RavMon.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-02 19:11:00 C:\WINDOWS\Tasks\WebReg Deskjet F2100 series.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-03 20:00:22
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\Program Files\Eset\pr_imon.dll
.
Completion time: 2008-01-03 20:02:47 - machine was rebooted [ELI]
ComboFix-quarantined-files.txt 2008-01-03 19:02:44
.
2007-12-21 21:54:24 --- E O F ---