
ComboFix 09-01-16.03 - Martin 2009-01-17 10:46:06.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1250.1.1033.18.2047.1220 [GMT 1:00]
Running from: c:\users\Martin\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\acovcnt.exe
.
((((((((((((((((((((((((( Files Created from 2008-12-17 to 2009-01-17 )))))))))))))))))))))))))))))))
.
2009-01-17 02:49 . 2009-01-17 02:52 <DIR> d-------- c:\program files\Anti Trojan Elite
2009-01-17 02:28 . 2009-01-16 17:35 <DIR> d-------- c:\windows\Panther
2009-01-17 02:28 . 2009-01-16 18:42 <DIR> d--hs---- C:\Boot
2009-01-17 02:28 . 2009-01-16 18:09 443,912 -rahs---- C:\bootmgr
2009-01-17 02:28 . 2009-01-17 02:28 8,192 -ra-s---- C:\BOOTSECT.BAK
2009-01-17 02:27 . 2009-01-17 02:27 <DIR> d-------- c:\windows\System32\OEM
2009-01-17 02:27 . 2007-03-16 17:40 59 -ra------ c:\windows\DELL_VERSION
2009-01-17 01:48 . 2009-01-17 01:48 <DIR> d-------- c:\users\Martin\AppData\Roaming\Kerio
2009-01-17 01:46 . 2009-01-17 01:46 <DIR> d-------- c:\program files\Kerio
2009-01-16 22:39 . 2009-01-16 22:39 <DIR> d-------- c:\users\Martin\AppData\Roaming\ACD Systems
2009-01-16 22:35 . 2009-01-16 22:35 <DIR> d-------- c:\users\All Users\ACD Systems
2009-01-16 22:35 . 2009-01-16 22:35 <DIR> d-------- c:\programdata\ACD Systems
2009-01-16 22:35 . 2009-01-16 22:35 <DIR> d-------- c:\program files\Common Files\ACD Systems
2009-01-16 22:35 . 2009-01-16 22:35 <DIR> d-------- c:\program files\ACD Systems
2009-01-16 22:35 . 2009-01-16 22:35 10,368 --a------ c:\windows\System32\drivers\pfc.sys
2009-01-16 22:34 . 2009-01-16 22:34 <DIR> d-------- c:\windows\Downloaded Installations
2009-01-16 21:59 . 2009-01-16 21:59 <DIR> d-------- c:\users\Martin\AppData\Roaming\InstallShield
2009-01-16 21:59 . 2009-01-16 21:59 <DIR> d-------- c:\program files\ASUS
2009-01-16 21:59 . 2005-07-06 15:43 155,648 --a------ c:\windows\System32\ACEngSvr.exe
2009-01-16 21:52 . 2009-01-16 21:52 <DIR> d-------- c:\windows\System32\RTCOM
2009-01-16 21:52 . 2007-02-06 18:29 1,840,640 --a------ c:\windows\System32\RtkAPO.dll
2009-01-16 21:52 . 2007-02-14 14:11 1,740,904 --a------ c:\windows\System32\drivers\RTKVHDA.sys
2009-01-16 21:52 . 2007-01-16 10:39 1,191,936 --a------ c:\windows\RtlUpd.exe
2009-01-16 21:52 . 2007-01-29 15:34 532,480 --a------ c:\windows\System32\RTSndMgr.cpl
2009-01-16 21:52 . 2007-02-06 14:55 494,080 --a------ c:\windows\System32\RtkPgExt.dll
2009-01-16 21:52 . 2006-12-13 10:30 339,968 --a------ c:\windows\System32\SRSTSXT.dll
2009-01-16 21:52 . 2009-01-16 21:52 319,456 --a------ c:\windows\DIFxAPI.dll
2009-01-16 21:52 . 2006-11-29 18:47 135,168 --a------ c:\windows\System32\SRSWOW.dll
2009-01-16 21:52 . 2007-01-25 18:22 17,920 --a------ c:\windows\System32\RtkCoInst.dll
2009-01-16 21:51 . 2009-01-16 21:51 <DIR> d-------- c:\program files\Realtek
2009-01-16 21:51 . 2009-01-16 21:51 <DIR> d-------- c:\program files\Common Files\InstallShield
2009-01-16 21:51 . 2007-02-15 17:07 4,390,912 --a------ c:\windows\RtHDVCpl.exe
2009-01-16 21:51 . 2007-01-12 16:54 520,192 --a------ c:\windows\RtlExUpd.dll
2009-01-16 21:51 . 2009-01-16 21:51 315,392 --a------ c:\windows\HideWin.exe
2009-01-16 21:15 . 2009-01-16 21:15 0 --a------ c:\windows\nsreg.dat
2009-01-16 20:34 . 2009-01-16 20:34 <DIR> d-------- c:\program files\Codec Pack - All In 1
2009-01-16 20:34 . 2009-01-16 20:34 737,280 --a------ c:\windows\iun6002.exe
2009-01-16 20:28 . 2009-01-16 20:28 <DIR> d-------- c:\program files\CoreCodec
2009-01-16 20:22 . 2009-01-16 20:24 <DIR> d-------- c:\program files\The KMPlayer
2009-01-16 19:31 . 2009-01-16 19:32 <DIR> d-------- c:\users\Martin\AppData\Roaming\ICQ
2009-01-16 19:31 . 2009-01-16 19:31 <DIR> d-------- c:\users\All Users\ICQ
2009-01-16 19:31 . 2009-01-16 19:31 <DIR> d-------- c:\programdata\ICQ
2009-01-16 19:31 . 2009-01-17 02:33 <DIR> d--h----- c:\program files\InstallShield Installation Information
2009-01-16 19:31 . 2009-01-16 19:31 <DIR> d-------- c:\program files\ICQ6Toolbar
2009-01-16 19:31 . 2009-01-16 19:33 <DIR> d-------- c:\program files\ICQ6.5
2009-01-16 19:01 . 2009-01-16 19:01 <DIR> d-------- c:\users\Martin\AppData\Roaming\Malwarebytes
2009-01-16 19:01 . 2009-01-16 19:01 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-01-16 19:01 . 2009-01-16 19:01 <DIR> d-------- c:\programdata\Malwarebytes
2009-01-16 19:01 . 2009-01-16 19:01 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-16 19:01 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-01-16 19:01 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-01-16 18:53 . 2009-01-16 18:53 <DIR> d-------- c:\users\All Users\ESET
2009-01-16 18:53 . 2009-01-16 18:53 <DIR> d-------- c:\programdata\ESET
2009-01-16 18:53 . 2009-01-16 18:53 <DIR> d-------- c:\program files\ESET
2009-01-16 18:51 . 2009-01-16 18:51 <DIR> d-------- c:\users\Martin\AppData\Roaming\ATI
2009-01-16 18:51 . 2009-01-16 18:51 <DIR> d-------- c:\users\All Users\ATI
2009-01-16 18:51 . 2009-01-16 18:51 <DIR> d-------- c:\programdata\ATI
2009-01-16 18:50 . 2009-01-16 18:50 0 --a------ c:\windows\ativpsrm.bin
2009-01-16 18:47 . 2009-01-17 02:21 <DIR> d--hs---- c:\windows\Installer
2009-01-16 18:47 . 2009-01-16 18:49 <DIR> d-------- c:\program files\ATI Technologies
2009-01-16 18:47 . 2009-01-16 21:56 <DIR> d-------- c:\program files\ATI
2009-01-16 18:45 . 2009-01-16 18:45 <DIR> d-------- c:\program files\MobilityDotNET
2009-01-16 18:33 . 2009-01-16 18:33 361,984 --a------ c:\windows\System32\IPSECSVC.DLL
2009-01-16 18:33 . 2009-01-16 18:33 272,896 --a------ c:\windows\System32\polstore.dll
2009-01-16 18:33 . 2009-01-16 18:33 205,824 --a------ c:\windows\System32\msoeacct.dll
2009-01-16 18:33 . 2009-01-16 18:33 87,040 --a------ c:\windows\System32\msoert2.dll
2009-01-16 18:33 . 2009-01-16 18:33 61,440 --a------ c:\windows\System32\winipsec.dll
2009-01-16 18:33 . 2009-01-16 18:33 39,424 --a------ c:\windows\System32\ACCTRES.dll
2009-01-16 18:33 . 2009-01-16 18:33 28,672 --a------ c:\windows\System32\FwRemoteSvr.dll
2009-01-16 18:32 . 2009-01-16 18:32 194,560 --a------ c:\windows\System32\WebClnt.dll
2009-01-16 18:32 . 2009-01-16 18:32 110,080 --a------ c:\windows\System32\drivers\mrxdav.sys
2009-01-16 18:31 . 2009-01-16 18:31 376,320 --a------ c:\windows\System32\winsrv.dll
2009-01-16 18:31 . 2009-01-16 18:31 49,664 --a------ c:\windows\System32\csrsrv.dll
2009-01-16 18:30 . 2009-01-16 18:30 297,472 --a------ c:\windows\System32\gdi32.dll
2009-01-16 18:29 . 2009-01-16 18:29 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-01-16 18:28 . 2009-01-16 18:28 211,456 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2009-01-16 18:27 . 2009-01-16 18:27 4,247,552 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2009-01-16 18:27 . 2009-01-16 18:27 1,687,040 --a------ c:\windows\System32\gameux.dll
2009-01-16 18:27 . 2009-01-16 18:27 374,456 --a------ c:\windows\System32\mcupdate_GenuineIntel.dll
2009-01-16 18:27 . 2009-01-16 18:27 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2009-01-16 18:26 . 2009-01-16 18:26 303,616 --a------ c:\windows\System32\wmpeffects.dll
2009-01-16 18:25 . 2009-01-16 18:25 2,027,520 --a------ c:\windows\System32\win32k.sys
2009-01-16 18:25 . 2009-01-16 18:25 1,194,496 --a------ c:\windows\System32\msxml3.dll
2009-01-16 18:25 . 2009-01-16 18:25 2,048 --a------ c:\windows\System32\msxml3r.dll
2009-01-16 18:24 . 2009-01-16 18:24 414,208 --a------ c:\windows\System32\msscp.dll
2009-01-16 18:24 . 2009-01-16 18:24 396,800 --a------ c:\windows\System32\MPSSVC.dll
2009-01-16 18:24 . 2009-01-16 18:24 392,192 --a------ c:\windows\System32\FirewallAPI.dll
2009-01-16 18:24 . 2009-01-16 18:24 178,688 --a------ c:\windows\System32\iphlpsvc.dll
2009-01-16 18:24 . 2009-01-16 18:24 86,016 --a------ c:\windows\System32\icfupgd.dll
2009-01-16 18:24 . 2009-01-16 18:24 63,488 --a------ c:\windows\System32\drivers\mpsdrv.sys
2009-01-16 18:24 . 2009-01-16 18:24 61,952 --a------ c:\windows\System32\cmifw.dll
2009-01-16 18:24 . 2009-01-16 18:24 23,040 --a------ c:\windows\System32\drivers\tunnel.sys
2009-01-16 18:24 . 2009-01-16 18:24 16,896 --a------ c:\windows\System32\wfapigp.dll
2009-01-16 18:24 . 2009-01-16 18:24 15,360 --a------ c:\windows\System32\drivers\TUNMP.SYS
2009-01-16 18:22 . 2009-01-16 18:22 2,048 --a------ c:\windows\System32\tzres.dll
2009-01-16 18:20 . 2009-01-16 18:20 8,147,968 --a------ c:\windows\System32\wmploc.DLL
2009-01-16 18:20 . 2009-01-16 18:20 104,448 --a------ c:\windows\System32\DWWIN.EXE
2009-01-16 18:20 . 2009-01-16 18:20 7,680 --a------ c:\windows\System32\spwmp.dll
2009-01-16 18:20 . 2009-01-16 18:20 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-01-16 18:20 . 2009-01-16 18:20 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-01-16 18:19 . 2009-01-16 18:19 2,923,520 --a------ c:\windows\explorer.exe
2009-01-16 18:16 . 2009-01-16 18:16 12,240,896 --a------ c:\windows\System32\NlsLexicons0007.dll
2009-01-16 18:15 . 2009-01-16 18:15 6,917,120 --a------ c:\windows\System32\NlsLexicons0c1a.dll
2009-01-16 18:15 . 2009-01-16 18:15 4,493,312 --a------ c:\windows\System32\NlsData0816.dll
2009-01-16 18:15 . 2009-01-16 18:16 4,493,312 --a------ c:\windows\System32\NlsData0416.dll
2009-01-16 18:15 . 2009-01-16 18:15 1,963,520 --a------ c:\windows\System32\NlsData0c1a.dll
2009-01-16 18:15 . 2009-01-16 18:15 1,963,520 --a------ c:\windows\System32\NlsData081a.dll
2009-01-16 18:15 . 2009-01-16 18:15 797,696 --a------ c:\windows\System32\NaturalLanguage6.dll
2009-01-16 18:13 . 2009-01-16 18:13 441,856 --a------ c:\windows\System32\win32spl.dll
2009-01-16 18:13 . 2009-01-16 18:13 223,232 --a------ c:\windows\System32\WMASF.DLL
2009-01-16 18:13 . 2009-01-16 18:13 113,664 --a------ c:\windows\System32\drivers\rmcast.sys
2009-01-16 18:13 . 2009-01-16 18:13 37,376 --a------ c:\windows\System32\printcom.dll
2009-01-16 18:13 . 2009-01-16 18:13 14,848 --a------ c:\windows\System32\wshrm.dll
2009-01-16 18:13 . 2009-01-16 18:13 9,728 --a------ c:\windows\System32\LAPRXY.DLL
2009-01-16 18:13 . 2009-01-16 18:13 2,048 --a------ c:\windows\System32\asferror.dll
2009-01-16 18:11 . 2009-01-16 18:11 788,992 --a------ c:\windows\System32\rpcrt4.dll
2009-01-16 18:11 . 2009-01-16 18:11 737,792 --a------ c:\windows\System32\inetcomm.dll
2009-01-16 18:11 . 2009-01-16 18:11 152,576 --a------ c:\windows\System32\imagehlp.dll
2009-01-16 18:11 . 2009-01-16 18:11 130,048 --a------ c:\windows\System32\drivers\srv2.sys
2009-01-16 18:11 . 2009-01-16 18:11 101,888 --a------ c:\windows\System32\drivers\mrxsmb.sys
2009-01-16 18:11 . 2009-01-16 18:11 84,992 --a------ c:\windows\System32\drivers\srvnet.sys
2009-01-16 18:11 . 2009-01-16 18:11 84,480 --a------ c:\windows\System32\INETRES.dll
2009-01-16 18:11 . 2009-01-16 18:11 58,368 --a------ c:\windows\System32\drivers\mrxsmb20.sys
2009-01-16 18:11 . 2009-01-16 18:11 12,800 --a------ c:\windows\System32\drivers\fs_rec.sys
2009-01-16 18:11 . 2009-01-16 18:11 5,120 --a------ c:\windows\System32\wmi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-17 01:20 21,951 ----a-w c:\windows\system32\drivers\kwflower.log
2009-01-17 01:19 12,053 ----a-w c:\windows\system32\drivers\kwfupper.log
2009-01-16 17:42 174 --sha-w c:\program files\desktop.ini
2009-01-16 17:38 --------- d-----w c:\program files\Windows Sidebar
2009-01-16 17:38 --------- d-----w c:\program files\Windows Mail
2009-01-16 17:27 537,600 ----a-w c:\windows\AppPatch\AcLayers.dll
2009-01-16 17:27 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-16 17:27 449,536 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2009-01-16 17:27 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2009-01-16 17:27 2,144,256 ----a-w c:\windows\AppPatch\AcGenral.dll
2009-01-16 17:27 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2009-01-16 17:17 826,368 ----a-w c:\windows\System32\wininet.dll
2009-01-16 17:17 56,320 ----a-w c:\windows\System32\iesetup.dll
2009-01-16 17:17 26,624 ----a-w c:\windows\System32\ieUnatt.exe
2009-01-16 17:12 996,352 ----a-w c:\windows\System32\WMNetMgr.dll
2009-01-16 17:12 98,816 ----a-w c:\windows\System32\mfps.dll
2009-01-16 17:12 94,720 ----a-w c:\windows\System32\logagent.exe
2009-01-16 17:12 83,968 ----a-w c:\windows\System32\dnsrslvr.dll
2009-01-16 17:12 558,080 ----a-w c:\windows\System32\oleaut32.dll
2009-01-16 17:12 52,736 ----a-w c:\windows\System32\rrinstaller.exe
2009-01-16 17:12 290,304 ----a-w c:\windows\system32\drivers\srv.sys
2009-01-16 17:12 24,576 ----a-w c:\windows\System32\mfpmp.exe
2009-01-16 17:12 24,576 ----a-w c:\windows\System32\dnscacheugc.exe
2009-01-16 17:12 2,855,424 ----a-w c:\windows\System32\mf.dll
2009-01-16 17:12 2,048 ----a-w c:\windows\System32\mferror.dll
2009-01-16 17:12 11,776 ----a-w c:\windows\System32\sbunattend.exe
2008-11-24 14:19 925,696 ----a-w c:\windows\System32\ktlibeay80_0.9.8g.dll
2008-11-24 14:19 192,512 ----a-w c:\windows\System32\ktssleay80_0.9.8g.dll
2008-11-24 14:19 102,400 ----a-w c:\windows\System32\ktzlib80_1.2.3.dll
2008-11-24 14:19 1,257,472 ----a-w c:\windows\System32\kticonv80_1.11.1.dll
2008-10-29 02:21 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll
2008-10-29 02:20 331,776 ----a-w c:\windows\System32\atipdlxx.dll
2008-10-29 02:20 262,144 ----a-w c:\windows\System32\Oemdspif.dll
2008-10-29 02:20 159,744 ----a-w c:\windows\System32\atitmmxx.dll
2008-10-29 02:19 43,520 ----a-w c:\windows\System32\ati2edxx.dll
2008-10-29 02:19 274,432 ----a-w c:\windows\System32\Ati2evxx.dll
2008-10-29 02:18 712,704 ----a-w c:\windows\System32\Ati2evxx.exe
2008-10-29 02:03 3,955,712 ----a-w c:\windows\System32\atiumdag.dll
2008-10-29 01:47 10,629,120 ----a-w c:\windows\System32\atioglxx.dll
2008-10-29 01:41 4,730,880 ----a-w c:\windows\System32\atiumdva.dll
2008-10-29 01:27 54,272 ----a-w c:\windows\System32\atiadlxx.dll
2008-10-29 01:27 50,688 ----a-w c:\windows\System32\amdpcom32.dll
2008-10-21 17:51 118,784 ----a-w c:\windows\System32\atibrtmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-01-16 1232896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-01-14 399504]
"Anti Trojan Elite"="c:\program files\Anti Trojan Elite\TJEnder.exe" [2009-01-17 863232]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [2008-07-01 34312]
R1 PSched;QoS Packet Scheduler;c:\windows\System32\drivers\pacer.sys [2006-11-02 70144]
R3 ATE_PROCMON;ATE_PROCMON;c:\program files\Anti Trojan Elite\ATEPMON.sys [2009-01-17 5969]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [2009-01-16 15504]
R4 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
R4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-01-16 170640]
S3 kvpndev;Kerio VPN adapter;c:\windows\System32\drivers\kvpndrv.sys [2008-09-01 61952]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Device Detector - DevDetect.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
TCP: {0D22FDAB-EB04-40A3-BCB9-210936473BB8} = 147.175.130.10,147.175.1.11
FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\b2maoe31.default\
FF - prefs.js: browser.startup.homepage - google.sk
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-17 10:47:37
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-17 10:49:27
ComboFix-quarantined-files.txt 2009-01-17 09:49:24
Pre-Run: 30 945 247 232 bytes free
Post-Run: 30,809,059,328 bytes free
236 --- E O F --- 2009-01-16 17:34:17