ComboFix 07-07-30.2 - "Dodo" 2008-07-09 9:15:02.6 [GMT 2:00] - NTFS
Syst‚m Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.Pravda
((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
2008-07-08 14:32 <DIR> d-------- C:\Program Files\Secure PC Solutions
2008-07-08 12:30 7,340,032 --a------ C:\DOCUME~1\Dodo\ntuser.dat
2008-07-08 12:30 314,656 --a------ C:\WINDOWS\system32\efcASmMg.dll
2008-07-08 12:30 201,659 --ahs---- C:\WINDOWS\system32\gMmSAcfe.ini2
2008-07-08 12:25 24,832 --a------ C:\WINDOWS\system32\nnnnKaab.dll
2008-07-04 14:52 <DIR> d-------- C:\Program Files\Spamihilator
2008-07-02 17:43 <DIR> d-------- C:\DOCUME~1\Dodo\Phone Browser
2008-06-15 14:23 61,603 --a------ C:\DOCUME~1\Dodo\APPLIC~1\mdbu.bin
2008-06-15 14:21 <DIR> d-------- C:\Program Files\HappyFoto
2008-06-15 13:49 <DIR> d-------- C:\DOCUME~1\Dodo\APPLIC~1\Nokia Multimedia Player
2008-06-15 12:02 <DIR> d-------- C:\CD
2008-06-15 11:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
2008-06-15 11:41 <DIR> d-------- C:\DOCUME~1\Dodo\APPLIC~1\Nokia
2008-06-15 11:40 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-06-15 11:40 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-06-15 11:39 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2008-06-15 11:39 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-06-15 11:39 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2008-06-15 11:39 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-06-15 11:39 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2008-06-15 11:39 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-06-15 11:39 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-06-15 11:39 <DIR> d-------- C:\Program Files\DIFX
2008-06-15 11:39 <DIR> d-------- C:\DOCUME~1\Dodo\APPLIC~1\PC Suite
2008-06-15 11:38 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-06-15 11:38 <DIR> d-------- C:\Program Files\Nokia
2008-06-15 11:34 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
2008-06-11 16:37 <DIR> d-------- C:\DVD oprava
2008-06-11 16:30 <DIR> d-------- C:\Program Files\Smart Projects
2008-06-09 17:29 <DIR> d-------- C:\DOCUME~1\Dodo\APPLIC~1\Smart PC Solutions
2008-06-09 15:46 <DIR> d-------- C:\Dodo
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-07-09 09:22 --------- d-------- C:\DOCUME~1\Dodo\APPLIC~1\Spamihilator
2008-07-08 15:11 --------- d-------- C:\Program Files\EsetOnlineScanner
2008-07-08 14:59 --------- d-------- C:\Program Files\eMule
2008-07-07 13:17 --------- d-------- C:\Program Files\SpywareBlaster
2008-07-04 16:17 --------- d-------- C:\DOCUME~1\Dodo\APPLIC~1\Skype
2008-07-02 18:00 --------- d-------- C:\Program Files\Norton Security Scan
2008-07-02 17:16 --------- d-------- C:\Program Files\Stellarium
2008-07-02 17:13 --------- d-------- C:\Program Files\LocalCooling
2008-06-29 09:59 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-15 19:16 --------- d-------- C:\DOCUME~1\Dodo\APPLIC~1\Happy Foto
2008-06-14 17:12 --------- d-------- C:\Program Files\Ice Princess
2008-06-13 15:10 272128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 15:48 --------- d-------- C:\Program Files\Lexmark X1100 Series
2008-06-09 17:12 --------- d-------- C:\Program Files\IKEA HomePlanner
2008-06-09 17:12 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-09 17:08 --------- d-------- C:\Program Files\ICQLite
2008-06-09 16:05 --------- d-------- C:\Program Files\Mozilla Thunderbird
2008-06-09 15:58 286720 --------- C:\WINDOWS\Setup1.exe
2008-05-17 07:26 --------- d-------- C:\Program Files\Nero
2008-05-17 07:26 --------- d-------- C:\Program Files\Common Files\Ahead
2008-05-14 20:17 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-14 19:13 --------- d-------- C:\DOCUME~1\Dodo\APPLIC~1\InterVideo
2008-05-14 19:11 --------- d--h----- C:\Program Files\InstallShield Installation Information
2008-05-14 19:11 --------- d-------- C:\Program Files\InterVideo
2008-05-13 07:34 --------- d-------- C:\DOCUME~1\Dodo\APPLIC~1\Pexeso
2008-05-07 07:18 1287680 --a------ C:\WINDOWS\system32\quartz.dll
2008-04-21 19:57 665088 --a------ C:\WINDOWS\system32\spsplib1.dll
2008-03-31 15:08 24344 --a------ C:\DOCUME~1\Dodo\APPLIC~1\GDIPFONTCACHEV1.DAT
2006-10-20 15:43 81920 --a------ C:\DOCUME~1\Dodo\APPLIC~1\ezpinst.exe
2006-10-20 15:43 47360 --a------ C:\DOCUME~1\Dodo\APPLIC~1\pcouffin.sys
2008-03-25 15:20:18 15,872 --sha-w C:\WINDOWS\AnyTrial.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4FBB10CB-F720-4280-8006-BC7DAAD5961A}]
2008-07-08 12:25 24832 --a------ C:\WINDOWS\system32\nnnnKaab.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{535AD24B-46AF-4AEA-9102-DE480CC30AAD}]
2008-07-08 12:30 314656 --a------ C:\WINDOWS\system32\efcASmMg.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spamihilator"="C:\Program Files\Spamihilator\spamihilator.exe" [2008-04-21 20:00]
"SecurePCSolutionsBootCheck"="C:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\BootCheck.exe" [2005-11-15 16:23]
"1ClickFixerPlus"="C:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\1ClickFixerPlus.exe" [2006-08-01 17:36]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rainlendar"="C:\Program Files\Rainlendar\Rainlendar.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"NOD32 Control Center GUI"="C:\Program Files\Eset\nod32kui.exe" [2007-07-22 22:14]
"MuralPix Agent"="C:\Program Files\MuralPix\MpAgent.exe" [2006-12-30 16:47]
"IncrediMail Application"="C:\PROGRA~1\INCRED~1\bin\IncMail.exe" [2005-09-15 15:33]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-05-14 19:12:12]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 12:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoInstrumentation"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4FBB10CB-F720-4280-8006-BC7DAAD5961A}"= C:\WINDOWS\system32\nnnnKaab.dll [2008-07-08 12:25 24832]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnKaab]
nnnnKaab.dll 2008-07-08 12:25 24832 C:\WINDOWS\system32\nnnnKaab.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\efcASmMg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"OM_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
"Outlook Express"=C:\Program Files\Outlook Express\msimn.exe
"MuralPix Manager"=C:\Program Files\MuralPix\MpManag.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
R0 a347bus;a347bus;C:\WINDOWS\system32\DRIVERS\a347bus.sys
R0 a347scsi;a347scsi;C:\WINDOWS\system32\Drivers\a347scsi.sys
R0 FVXSCSI;FVXSCSI;C:\WINDOWS\system32\DRIVERS\fvxscsi.sys
R0 prohlp02;StarForce Protection Helper Driver v2;C:\WINDOWS\system32\drivers\prohlp02.sys
R0 prosync1;StarForce Protection Synchronization Driver v1;C:\WINDOWS\system32\drivers\prosync1.sys
R0 sfhlp01;StarForce Protection Helper Driver;C:\WINDOWS\system32\drivers\sfhlp01.sys
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x);C:\WINDOWS\system32\drivers\sfsync02.sys
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys
R1 cdrbsdrv;cdrbsdrv;C:\WINDOWS\system32\drivers\cdrbsdrv.sys
R1 prodrv06;StarForce Protection Environment Driver v6;C:\WINDOWS\system32\drivers\prodrv06.sys
R2 AnyTrial;BugSoft AnyTrial;C:\WINDOWS\AnyTrial.exe
R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys
R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe
R3 AnyDVD;AnyDVD;C:\WINDOWS\system32\Drivers\AnyDVD.sys
R3 dvd43llh;dvd43llh;C:\WINDOWS\system32\DRIVERS\dvd43llh.sys
R3 ElbyCDIO;ElbyCDIO Driver;C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
R3 ElbyDelay;ElbyDelay;C:\WINDOWS\system32\Drivers\ElbyDelay.sys
R3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator;C:\WINDOWS\system32\drivers\nvax.sys
R3 NVENET;NVIDIA nForce MCP Networking Controller Driver;C:\WINDOWS\system32\DRIVERS\NVENET.sys
R3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio;C:\WINDOWS\system32\drivers\nvapu.sys
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\system32\DRIVERS\psched.sys
R3 Tetris;Tetris driver;C:\WINDOWS\system32\Drivers\Tetris.sys
S0 fcdabus;fcdabus;C:\WINDOWS\system32\DRIVERS\fcdabus.sys
S2 CWMonitor;Symantec Crimeware Protection Driver;\??\C:\Program Files\Common Files\Symantec Shared\coShared\CW\1.0\Monitor.sys
S3 Ad-Watch Real-Time Scanner;AW Real-Time Scanner;\??\C:\WINDOWS\system32\drivers\AWRTPD.sys
S3 Ad-Watch Registry Filter;Ad-Watch Registry Kernel Filter;\??\C:\WINDOWS\system32\drivers\AWRTRD.sys
S3 ASFW_HideEXE;ASFW_HideEXE;\??\C:\DOCUME~1\Dodo\LOCALS~1\Temp\ASFW_HideEXE
S3 ASFWHide;ASFWHide;\??\C:\DOCUME~1\Dodo\LOCALS~1\Temp\ASFWHide
S3 dtscsi;dtscsi;C:\WINDOWS\system32\Drivers\dtscsi.sys
S3 fsRamDsk;RamDisk Drive Service;C:\WINDOWS\system32\Drivers\fsRamDsk.sys
S3 GMSIPCI;GMSIPCI;\??\D:\INSTALL\GMSIPCI.SYS
S3 Maplom;Maplom;C:\WINDOWS\system32\drivers\Maplom.sys
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\WINDOWS\system32\SophosMEMSWEEP.SYS
S3 nmwcd;Nokia USB Phone Parent;C:\WINDOWS\system32\drivers\nmwcd.sys
S3 nmwcdc;Nokia USB Generic;C:\WINDOWS\system32\drivers\nmwcdc.sys
S3 nmwcdcj;Nokia USB Port;C:\WINDOWS\system32\drivers\nmwcdcj.sys
S3 nmwcdcm;Nokia USB Modem;C:\WINDOWS\system32\drivers\nmwcdcm.sys
S3 Pcouffin;VSO Software pcouffin;C:\WINDOWS\system32\Drivers\Pcouffin.sys
S3 TUWinStylerThemeSvc;TuneUp WinStyler Theme Service;"C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe"
S3 VGAUTI;VGAUTI;\??\C:\WINDOWS\system32\DRIVERS\VGAUTI.sys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule
Contents of the 'Scheduled Tasks' folder
2008-06-27 16:02:21 C:\WINDOWS\Tasks\1-Click Maintenance.job - C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
2008-07-02 16:01:08 C:\WINDOWS\Tasks\Norton Security Scan.job - C:\Program Files\Norton Security Scan\Nss.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-09 09:23:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\\f\1i]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,00,04,00,00,00,00,00,1a,38,5d,19,db,..
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}]
"DisplayName"="Alcohol 120"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\f\1i]
"Inno Setup: Setup Version"="2.0.19"
"Inno Setup: App Path"="C:\Program Files\\x10cisti\x10d"
"Inno Setup: Icon Group"="\x10cisti\x10d"
"Inno Setup: User"="Dodo"
"Inno Setup: Selected Tasks"="desktopicon"
"Inno Setup: Deselected Tasks"=""
"DisplayName"="\x10cisti\x10d 1.5"
"UninstallString"=""C:\Program Files\\x10cisti\x10d\unins000.exe""
"Publisher"="Mart"
"URLInfoAbout"="http://mart.webz.cz"
"HelpLink"="http://mart.webz.cz"
"URLUpdateInfo"="http://mart.webz.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000498
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\\f\1i]
"Order"=hex:08,00,00,00,02,00,00,00,ee,01,00,00,01,00,00,00,04,00,00,00,74,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65AA164C-FC8C-BC7A-8375-4F31E8464F83}]
"nalalojcejaipenbjenfmdonccce"=hex:69,61,6c,70,66,6b,70,6d,6d,65,6f,6a,6a,61,64,61,69,62,00,00
"mafbbbdfcojoaeimhhklokmgpm"=hex:69,61,6c,70,66,6b,70,6d,6d,65,6f,6a,6a,61,64,61,69,62,00,00
scanning hidden files ...
scan completed successfully
hidden files: 0