"KyoSuke" - 07-04-25 16:01:14 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Program Files\FlashGet\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\inst.exe.exe
C:\WINDOWS\system32\zup.exe.exe
C:\WINDOWS\system32\pdp.exe.exe
C:\Program Files\Common Files\{37301~1\Bar888.dll
C:\Program Files\Common Files\{37301~1\UnInstall.exe
C:\Program Files\Common Files\{27301~1\Update.exe
C:\Program Files\Common Files\{37301~2\UnInstall.exe
C:\DOCUME~1\KyoSuke\Desktop.\internet explorer.lnk
C:\WINDOWS\system32\wincom32.ini
C:\WINDOWS\system32\winsub.xml
C:\Program Files\inetget2
C:\Program Files\Common Files\{37301~1
C:\Program Files\Common Files\{27301~1
C:\Program Files\Common Files\{37301~2
C:\Program Files\Common Files\{27301~2
C:\WINDOWS\system32\lzx32.sys
C:\cp1041.nls
Infected copy of C:\WINDOWS\system32\drivers\ndis.sys was found & disinfected
Restored copy from - "C:\WINDOWS\system32\dllcache\ndis.sys"
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\ntldr
-------\LEGACY_CLIENT_IP-IPX
-------\LEGACY_NTLDR
((((((((((((((((((((((((((((((( Files Created from 2007-03-25 to 2007-04-25 ))))))))))))))))))))))))))))))))))
2007-04-24 14:57 <DIR> d--hs---- C:\FOUND.005
2007-04-23 23:06 <DIR> d--h----- C:\WINDOWS\HUL
2007-04-23 22:56 <DIR> d-------- C:\DOCUME~1\KyoSuke\APPLIC~1\InstallShield
2007-04-23 22:01 <DIR> d-------- C:\ijji
2007-04-22 12:26 <DIR> d-------- C:\Program Files\CCleaner
2007-04-21 15:30 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-04-21 15:19 <DIR> d--hs---- C:\FOUND.004
2007-04-21 15:14 <DIR> d-------- C:\WINDOWS\pss
2007-04-20 16:20 <DIR> d-------- C:\Program Files\Hamachi
2007-04-20 16:14 <DIR> d--hs---- C:\FOUND.003
2007-04-16 20:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2007-04-16 19:27 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2007-04-15 17:16 <DIR> d-------- C:\Program Files\MSN Messenger
2007-04-15 12:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-04-15 00:00 <DIR> d--hs---- C:\FOUND.002
2007-04-14 22:23 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-04-14 19:43 <DIR> d--hs---- C:\FOUND.001
2007-04-13 19:30 91,849 --a------ C:\WINDOWS\system32\3ti.exe
2007-04-12 19:59 91,849 --a------ C:\WINDOWS\system32\inst.exe
2007-04-12 19:57 21,504 --a------ C:\WINDOWS\system32\gct.dll
2007-04-12 19:40 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-04-12 19:38 561,152 --a------ C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-04-12 19:06 21,504 --a------ C:\WINDOWS\system32\eintztm.dll
2007-04-12 18:54 <DIR> d--hs---- C:\FOUND.000
2007-04-12 18:50 21,504 --a------ C:\WINDOWS\system32\wjvvn.dll
2007-04-12 18:49 8,704 --a------ C:\WINDOWS\system32\sporder.dll
2007-04-08 10:16 <DIR> d-------- C:\DOCUME~1\KyoSuke\APPLIC~1\Google
2007-04-08 10:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-04-08 10:15 <DIR> d-------- C:\Program Files\Google
2007-04-03 22:00 <DIR> d-------- C:\Program Files\Real Alternative
2007-04-03 22:00 <DIR> d-------- C:\Program Files\Media Player Classic
2007-04-03 22:00 <DIR> d-------- C:\DOCUME~1\KyoSuke\APPLIC~1\Real
2007-04-03 22:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
2007-03-31 12:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\GRETECH
2007-03-31 12:55 <DIR> d-------- C:\DOCUME~1\KyoSuke\APPLIC~1\GRETECH
2007-03-26 21:25 <DIR> d-------- C:\Program Files\QuickTime
2007-03-25 00:48 36,624 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-03-25 00:48 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-03-25 00:48 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-03-25 00:48 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-03-25 00:48 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-03-25 00:48 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-03-25 00:48 <DIR> d-------- C:\Program Files\DivX
2007-03-25 00:46 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-03-25 00:46 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-03-25 00:46 <DIR> d-------- C:\Program Files\Xvid
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )))
Rootkit driver pe386 is present. ... attempting disinfection pe386 ...... driver unloaded successfully.
2007-04-20 16:20 26056 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2007-03-17 18:36 62508 --ah----- C:\WINDOWS\system32\mlfcache.dat
2007-03-15 23:14 -------- d-------- C:\Program Files\skype
2007-03-15 18:46 -------- d-------- C:\DOCUME~1\KyoSuke\APPLIC~1\screenshot sender
2007-03-11 22:42 -------- d-------- C:\Program Files\gamepot
2007-03-10 21:38 -------- d-------- C:\Program Files\utorrent
2007-03-10 21:38 -------- d-------- C:\DOCUME~1\KyoSuke\APPLIC~1\utorrent
2007-03-10 11:28 -------- d-------- C:\Program Files\bittorrent
2007-03-07 18:58 -------- d-------- C:\Program Files\auditionsea
2007-02-25 02:22 -------- d-------- C:\Program Files\mirc
2007-02-22 20:30 524288 --a------ C:\WINDOWS\system32\divxsm.exe
2007-02-22 20:29 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-02-22 20:29 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-02-22 20:29 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-02-22 20:25 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-02-22 20:25 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-02-22 20:25 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-02-22 20:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-02-22 20:25 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-02-22 20:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2007-02-22 20:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-02-22 20:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2007-02-22 20:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-02-22 20:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-02-22 20:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-02-22 20:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-02-15 17:40 124472 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-01-26 23:43 86114 --a------ C:\WINDOWS\war3unin.dat
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects]
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
{A5366673-E8CA-11D3-9CD9-0090271D075B} C:\PROGRA~1\FLASHGET\jccatch.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run]
"SoundMan"="SOUNDMAN.EXE"
"GrooveMonitor"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"nwiz"="nwiz.exe /install"
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.ex e"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="Groove GFS Stub Execution Hook"
HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnph ost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
************************************************** ******************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-04-25 16:05:06
Windows 5.1.2600 Service Pack 2 FAT
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
************************************************** ******************
Completion time: 07-04-25 16:06:15 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-04-25 16:06