ComboFix 07-10-12.1 - x 2007-10-12 23:43:13.2 - NTFSx86
Syst‚m Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.581 [GMT 2:00]
Running from: C:\Documents and Settings\x\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\x\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-09-12 to 2007-10-12 )))))))))))))))))))))))))))))))
.
2007-10-12 23:47 126,976 --a------ C:\zip.exe
2007-10-12 23:47 1,080 --a------ C:\uchbrhyx.bat
2007-10-11 22:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-11 21:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-11 21:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-11 20:13 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2007-10-11 18:28 <DIR> d-------- C:\VundoFix Backups
2007-10-11 16:16 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-10 23:07 <DIR> d-------- C:\bc90ffd65340b7a4983fd63b91
2007-10-10 22:31 <DIR> d-------- C:\0fc55752b7181cf1ffc3faccd4686901
2007-10-10 21:48 <DIR> d-------- C:\WINDOWS\nview
2007-10-10 21:48 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-10-10 21:25 <DIR> d-------- C:\Program Files\MultiRes
2007-10-10 21:25 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-10-10 21:15 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-10-10 19:52 <DIR> d-------- C:\8bf6130e3143052c4776a56a
2007-10-10 14:06 <DIR> d-------- C:\WINDOWS\OPTIONS
2007-10-10 14:06 <DIR> d-------- C:\Program Files\Realtek
2007-10-10 14:06 96,384 --a------ C:\WINDOWS\system32\drivers\Rtnicxp.sys
2007-10-04 08:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-09-30 19:17 <DIR> d-------- C:\Program Files\Sun
2007-09-29 23:52 <DIR> d--h----- C:\WINDOWS\PIF
2007-09-29 23:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-29 22:43 <DIR> d-------- C:\Program Files\Sunbelt Software
2007-09-27 19:34 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-09-27 19:34 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-09-22 18:15 <DIR> d-------- C:\Program Files\Philips
2007-09-22 18:15 <DIR> d-------- C:\Documents and Settings\x\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-12 21:47 60,416 ----a-w C:\WINDOWS\system32\drivers\mjjtaytb.sys
2007-10-12 21:01 --------- d-----w C:\Documents and Settings\x\Application Data\AVG7
2007-10-11 17:08 167 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-10-11 12:29 --------- d-----w C:\Program Files\Save
2007-10-10 12:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-04 06:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-09-30 17:17 --------- d-----w C:\Program Files\Java
2007-09-29 20:51 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-09-16 23:24 356,352 ----a-w C:\WINDOWS\system32\nvusmb.exe
2007-09-16 23:24 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-09-16 23:24 356,352 ----a-w C:\WINDOWS\system32\nvuide.exe
2007-09-16 23:24 356,352 ----a-w C:\WINDOWS\system32\nvugart.exe
2007-09-16 23:07 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-09-16 23:07 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-09-16 23:07 8,491,008 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-09-16 23:07 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-09-16 23:07 6,853,088 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-09-16 23:07 6,746,112 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-09-16 23:07 6,344,704 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-09-16 23:07 5,783,040 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-09-16 23:07 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-09-16 23:07 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-09-16 23:07 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-09-16 23:07 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-09-16 23:07 364,544 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-09-16 23:07 36,864 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-09-16 23:07 36,864 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-09-16 23:07 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-09-16 23:07 3,551,232 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-09-16 23:07 3,334,144 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-09-16 23:07 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-09-16 23:07 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-09-16 23:07 2,371,584 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-09-16 23:07 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-09-16 23:07 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-09-16 23:07 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-09-16 23:07 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-09-16 23:07 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe
2007-09-16 23:07 1,478,656 ----a-w C:\WINDOWS\system32\nview.dll
2007-09-16 23:07 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-09-16 23:07 1,150,976 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-09-16 23:07 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll
2007-09-08 17:26 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-06 12:02 --------- d-----w C:\Program Files\ICQ6
2007-09-03 18:27 --------- d-----w C:\Documents and Settings\x\Application Data\Hamachi
2007-09-02 17:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ubisoft
2007-09-02 17:33 --------- d--h--r C:\Documents and Settings\x\Application Data\SecuROM
2007-08-28 21:12 --------- d-----w C:\Program Files\Macromedia
2007-08-28 21:12 --------- d-----w C:\Program Files\Common Files\Macromedia
2007-08-28 21:11 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-08-28 18:41 --------- d-----w C:\Program Files\Common Files\EasyInfo
2007-08-27 19:59 --------- d-----w C:\Documents and Settings\x\Application Data\fltk.org
2007-08-27 17:36 --------- d-----w C:\Documents and Settings\x\Application Data\Publish Providers
2007-08-27 17:35 --------- d-----w C:\Documents and Settings\x\Application Data\Sony
2007-08-27 17:32 --------- d-----w C:\Program Files\Microsoft SQL Server
2007-08-27 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony
2007-08-27 17:31 --------- d-----w C:\Program Files\Vstplugins
2007-08-27 17:30 --------- d-----w C:\Program Files\Sony
2007-08-27 17:29 --------- d-----w C:\Program Files\Sony Setup
2007-08-26 20:41 --------- d-----w C:\Program Files\Sonic Foundry
2007-08-26 20:41 --------- d-----w C:\Program Files\Pure Motion
2007-08-26 20:41 --------- d-----w C:\Program Files\DebugMode
2007-08-25 22:15 73,124 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2007-08-25 22:15 5,047 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-08-25 22:15 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-20 12:18 --------- d-----w C:\Program Files\Common Files\Adobe
2007-08-18 22:09 --------- d-----w C:\Program Files\Common Files\Real
2007-08-18 22:06 --------- d-----w C:\Program Files\Real
2007-08-15 23:27 --------- d-----w C:\Program Files\PSPad editor
2007-08-15 20:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\{B14D9CDC-90D5-4BB2-B6CA-DCF6842AEFD0}
2007-08-08 14:30 19,456 ----a-w C:\WINDOWS\system32\OnlineScannerLang.dll
2007-08-02 16:11 253,952 ----a-w C:\WINDOWS\system32\OnlineScannerDLLA.dll
2007-08-02 16:11 241,664 ----a-w C:\WINDOWS\system32\OnlineScannerDLLW.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-27 13:49 225,355 ----a-w C:\WINDOWS\system32\lnod32apiW.dll
2007-07-27 13:49 196,683 ----a-w C:\WINDOWS\system32\lnod32apiA.dll
2007-07-15 12:33 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-07-15 12:33 249,856 ------w C:\WINDOWS\Setup1.exe
2004-03-11 11:27 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 09:54 C:\WINDOWS\SOUNDMAN.EXE]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-09-07 15:25]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-12 10:34]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-04 08:23]
"nwiz"="nwiz.exe" [2007-09-17 01:07 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07]
"pwfkhknb"="C:\uchbrhyx.bat" [2007-10-12 23:47]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
C:\Documents and Settings\x\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 00:05:02]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 11:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" -lang 1033
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe"
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\system32\DRIVERS\psched.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e7ccf07-1931-11dc-ae10-806d6172696f}]
AutoRun\command - F:\Setup.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-12 23:47:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ????????????l?@?l?@?D?????A~??????????????A~l?@?l?@????? ???????????W?D~??A~??????A~K?A~x???????[?A~???????? ??????????????|x???0???????????? st??A~????????????????G?B?&???R???????l?@?l?@?????Q?B~????t?@?????l?@?8?@?l?@?3??s????????????????????8?@?_??s8?@?8?@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-12 23:48:53
C:\ComboFix2.txt ... 2007-10-12 23:03
.
--- E O F ---