ComboFix 08-02.05.3 - Slobodan 2008-02-05 18:29:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.257 [GMT 1:00]
Running from: \\10d1\Install\Bobito\ComboFix.exe
* Created a new restore point
[color=red]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\semo2x.exe
C:\u.bat
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
C:\WINDOWS\system32\winsys.exe
D:\Autorun.inf
D:\semo2x.exe
D:\u.bat
E:\Autorun.inf
E:\semo2x.exe
E:\u.bat
F:\Autorun.inf
F:\semo2x.exe
F:\u.bat
.
((((((((((((((((((((((((( Files Created from 2008-01-05 to 2008-02-05 )))))))))))))))))))))))))))))))
.
2008-02-05 18:27 . 2004-08-03 23:56 388,608 --a------ C:\kmd.exe
2008-02-05 12:42 . 2008-02-05 12:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-02-04 21:54 . 2008-02-04 09:16 104,044 -r-hs---- C:\h.cmd
2008-02-04 21:46 . 2008-02-04 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-01-30 16:35 . 2008-01-30 16:35 72,838 --a------ C:\WINDOWS\FontData.fdb
2008-01-29 03:17 . 2008-01-29 03:17 104,734 -r-hs---- C:\ylr.exe
2008-01-28 00:49 . 2008-01-28 00:49 <DIR> d---s---- C:\Documents and Settings\Slobodan\UserData
2008-01-26 22:19 . 2008-01-26 22:19 <DIR> d-------- C:\Documents and Settings\Slobodan\Application Data\Corel
2008-01-26 22:16 . 2008-01-26 22:16 <DIR> d-------- C:\Program Files\Common Files\Corel
2008-01-26 22:15 . 2008-01-26 22:15 <DIR> d-------- C:\Program Files\Corel
2008-01-25 15:50 . 2008-01-27 21:01 103,781 -r-hs---- C:\xo8wr9.exe
2008-01-25 00:30 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-01-25 00:02 . 2008-01-25 00:09 <DIR> d-------- C:\Program Files\3dmax
2008-01-24 23:12 . 2008-01-25 00:02 <DIR> d-------- C:\Program Files\backburner 2
2008-01-18 13:26 . 2008-01-23 14:47 105,199 -r-hs---- C:\xn1i9x.com
2008-01-18 01:48 . 2008-01-18 02:11 105,525 -r-hs---- C:\m1t8ta.com
2008-01-12 12:18 . 2008-01-15 13:33 104,451 -r-hs---- C:\d.com
2008-01-10 12:08 . 2001-07-06 13:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll
2008-01-10 12:08 . 2001-07-06 11:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll
2008-01-10 12:08 . 2001-07-06 17:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-01-10 12:08 . 2001-07-09 10:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-01-10 12:08 . 2004-03-03 20:30 125,184 --a------ C:\WINDOWS\system32\drivers\imagesrv.sys
2008-01-10 12:08 . 2000-06-26 10:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-01-10 12:08 . 2001-06-26 07:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
2008-01-10 12:08 . 2004-03-03 20:30 5,504 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2008-01-10 10:53 . 2008-01-10 10:53 <DIR> d-------- C:\Documents and Settings\Slobodan\Application Data\Ahead
2008-01-10 10:52 . 2008-01-10 12:08 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-01-10 04:54 . 2008-01-22 05:18 191,783 --a------ C:\acadminidump.dmp
2008-01-09 23:52 . 2008-01-26 22:18 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-01-08 00:18 . 2008-01-08 00:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 11:42 5,767,168 ---ha-w C:\Documents and Settings\Slobodan\NTUSER.DAT
2008-02-04 20:36 --------- d-----w C:\Program Files\Yahoo!
2008-01-30 16:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-27 20:01 103,781 ----a-w C:\WINDOWS\system32\help.exe.tmp
2008-01-26 21:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-26 21:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-24 23:27 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-01-24 23:25 --------- d-----w C:\Program Files\Autodesk
2008-01-24 23:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-01-20 16:27 --------- d-----w C:\Program Files\Yu recnik
2008-01-10 11:08 --------- d-----w C:\Program Files\Ahead
2008-01-08 20:48 --------- d-----w C:\Documents and Settings\Slobodan\Application Data\Autodesk
2008-01-02 22:12 --------- d-----w C:\Program Files\Valve
2007-12-28 11:19 104,507 --sh--r C:\xfoolavp.com
2007-12-23 19:05 --------- d-----w C:\Program Files\FastStone Image Viewer
2007-12-22 16:02 10,368 ----a-w C:\WINDOWS\system32\drivers\pfc.sys
2007-12-22 16:02 --------- d-----w C:\Program Files\Common Files\ACD Systems
2007-12-22 16:02 --------- d-----w C:\Program Files\ACD Systems
2007-12-22 16:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2007-12-18 19:38 --------- d-----w C:\Program Files\Don't Get Angry 2
2007-12-18 19:22 --------- d-----w C:\Program Files\Common Files\SWF Studio
2007-12-18 11:03 --------- d-----w C:\Program Files\Google
2007-12-16 20:37 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-16 19:47 --------- d-----w C:\Program Files\acdsee 9.0
2007-12-16 19:47 --------- d-----w C:\Documents and Settings\Slobodan\Application Data\ACD Systems
2007-12-15 19:58 --------- d-----w C:\Program Files\GetData
2007-12-15 19:36 --------- d-----w C:\Program Files\Alcohol Soft
2007-12-15 19:30 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2007-12-15 19:30 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-15 19:30 --------- d-----w C:\Documents and Settings\Slobodan\Application Data\TuneUp Software
2007-12-15 19:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-12-15 19:21 --------- d-----w C:\Program Files\MSBuild
2007-12-15 19:21 --------- d-----w C:\Program Files\Microsoft Works
2007-12-15 19:20 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-15 19:18 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2007-12-15 19:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-15 19:12 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-15 19:12 --------- d-----w C:\Program Files\Bonjour
2007-12-15 19:05 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-12-15 19:03 --------- d-----w C:\Program Files\LAN Search Pro
2007-12-15 18:58 --------- d-----w C:\Program Files\AutoCAD 2008
2007-12-15 18:46 --------- d-----w C:\Program Files\Vypress Chat
2007-12-15 18:45 --------- d-----w C:\Documents and Settings\Slobodan\Application Data\VyPRESS
2007-12-15 18:33 --------- d-----w C:\Program Files\Winamp
2007-12-15 18:32 --------- d-----w C:\Documents and Settings\Slobodan\Application Data\BSplayer Pro
2007-12-15 18:31 --------- d-----w C:\Program Files\Webteh
2007-12-15 18:31 --------- d-----w C:\Documents and Settings\Slobodan\Application Data\Media Player Classic
2007-12-15 18:30 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-12-15 18:22 --------- d-----w C:\Program Files\Realtek
2007-12-15 18:12 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 10:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 10:22 7618560]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"CorelDRAW Graphics Suite 11b"="C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe" [2003-11-25 13:39 729088]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Vypress Chat StartUp.lnk - C:\WINDOWS\Installer\{A1E1619F-036F-4176-8563-AA9E570113F0}\iconVCAdvertised.exe [2007-12-15 19:45:52 12390]
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-03 23:56]
S3 SetupNTGLM7X;SetupNTGLM7X;G:\NTGLM7X.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70c5882f-b39d-11dc-b77b-001617bcc494}]
\Shell\AutoRun\command - J:\xn1i9x.com
\Shell\explore\Command - J:\xn1i9x.com
\Shell\open\Command - J:\xn1i9x.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79a7558d-b52d-11dc-b77d-001617bcc494}]
\Shell\AutoRun\command - I:\xo8wr9.exe
\Shell\explore\Command - I:\xo8wr9.exe
\Shell\open\Command - I:\xo8wr9.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8edb37f1-ab47-11dc-b76d-001617bcc494}]
\Shell\AutoRun\command - h.cmd
\Shell\explore\Command - h.cmd
\Shell\open\Command - h.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef42ac40-cb4f-11dc-b794-001617bcc494}]
\Shell\AutoRun\command - I:\ntde1ect.com
\Shell\explore\Command - I:\ntde1ect.com
\Shell\open\Command - I:\ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fff7d752-b5fa-11dc-b77e-001617bcc494}]
\Shell\AutoRun\command - I:\xfoolavp.com
\Shell\explore\Command - I:\xfoolavp.com
\Shell\open\Command - I:\xfoolavp.com
.
Contents of the 'Scheduled Tasks' folder
"2008-02-01 16:32:44 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-05 18:31:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-05 18:31:30
ComboFix-quarantined-files.txt 2008-02-05 17:31:23