ComboFix 11-03-10.04 - Martin Kubat 11.03.2011 18:08:43.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.420.1033.18.1022.542 [GMT 1:00]
Running from: c:\documents and settings\Martin Kubat\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Tiger Install
c:\documents and settings\Martin Kubat\Application Data\rhcpnvj0e78s
c:\documents and settings\Martin Kubat\Local Settings\Application Data\ieytpjd.dat
c:\documents and settings\Martin Kubat\Local Settings\Application Data\ieytpjd_nav.dat
c:\documents and settings\Martin Kubat\Local Settings\Application Data\ieytpjd_navps.dat
c:\documents and settings\Martin Kubat\Local Settings\Application Data\yguouoi.dat
c:\documents and settings\Martin Kubat\Local Settings\Application Data\yguouoi_nav.dat
c:\documents and settings\Martin Kubat\Local Settings\Application Data\yguouoi_navps.dat
c:\program files\akl
c:\program files\akl\akl.dll
c:\program files\akl\akl.exe
c:\program files\akl\uninstall.exe
c:\program files\akl\unsetup.exe
c:\program files\Antivirus 2009
c:\program files\PC-Cleaner
c:\program files\rhcpnvj0e78s
c:\windows\a.bat
c:\windows\bdn.com
c:\windows\cookies.ini
c:\windows\FVProtect.exe
c:\windows\iTunesMusic.exe
c:\windows\mslagent
c:\windows\mslagent\2_mslagent.dll
c:\windows\mslagent\mslagent.exe
c:\windows\mslagent\uninstall.exe
c:\windows\mssecu.exe
c:\windows\system32\akttzn.exe
c:\windows\system32\anticipator.dll
c:\windows\system32\awtoolb.dll
c:\windows\system32\bdn.com
c:\windows\system32\bsva-egihsg52.exe
c:\windows\system32\dpcproxy.exe
c:\windows\system32\emesx.dll
c:\windows\system32\hoproxy.dll
c:\windows\system32\hxiwlgpm.dat
c:\windows\system32\hxiwlgpm.exe
c:\windows\system32\medup012.dll
c:\windows\system32\medup020.dll
c:\windows\system32\msgp.exe
c:\windows\system32\msnbho.dll
c:\windows\system32\mssecu.exe
c:\windows\system32\msvchost.exe
c:\windows\system32\mtr2.exe
c:\windows\system32\mwin32.exe
c:\windows\system32\netode.exe
c:\windows\system32\newsd32.exe
c:\windows\system32\nvs2.inf
c:\windows\system32\ps1.exe
c:\windows\system32\psof1.exe
c:\windows\system32\psoft1.exe
c:\windows\system32\regc64.dll
c:\windows\system32\regm64.dll
c:\windows\system32\Rundl1.exe
c:\windows\system32\smp
c:\windows\system32\smp\msrc.exe
c:\windows\system32\sncntr.exe
c:\windows\system32\ssurf022.dll
c:\windows\system32\ssvchost.com
c:\windows\system32\ssvchost.exe
c:\windows\system32\sysreq.exe
c:\windows\system32\taack.dat
c:\windows\system32\taack.exe
c:\windows\system32\temp#01.exe
c:\windows\system32\thun.dll
c:\windows\system32\thun32.dll
c:\windows\system32\VBIEWER.OCX
c:\windows\system32\vbsys2.dll
c:\windows\system32\vcatchpi.dll
c:\windows\system32\winlogonpc.exe
c:\windows\system32\winsystem.exe
c:\windows\system32\WINWGPX.EXE
c:\windows\userconfig9x.dll
c:\windows\winsystem.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_TDSSSERV.SYS
.
.
((((((((((((((((((((((((( Files Created from 2011-02-11 to 2011-03-11 )))))))))))))))))))))))))))))))
.
.
2011-03-11 16:29 . 2011-03-11 16:29 1377112 ----a-w- c:\program files\tdsskiller.exe
2011-03-11 15:02 . 2011-02-11 06:54 5943120 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{DC429204-1133-46CE-9153-C0414D3056A0}\mpengine.dll
2011-03-10 21:41 . 2011-03-10 21:41 -------- d-----w- c:\documents and settings\Martin Kubat\Local Settings\Application Data\ESET
2011-03-10 20:43 . 2011-03-10 20:43 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2011-03-10 20:34 . 2011-03-10 20:34 -------- d-----w- c:\program files\ESET
2011-03-10 20:34 . 2011-03-10 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2011-03-10 20:26 . 2011-03-10 20:27 44018688 ----a-w- c:\program files\eav_nt32_csy.msi
2011-03-09 15:16 . 2011-03-09 15:16 -------- d-----w- c:\program files\7-Zip
2011-03-08 20:02 . 2011-03-08 20:02 -------- d-----w- c:\program files\Axis Communications
2011-03-05 15:57 . 2011-03-05 15:57 -------- d-----w- c:\program files\Common Files\Skype
2011-03-02 20:03 . 2011-03-02 20:03 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-11 06:54 . 2008-05-01 16:40 5943120 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-02-04 16:48 . 2005-08-06 05:01 456192 ----a-w- c:\windows\system32\encdec.dll
2011-02-04 16:48 . 2005-08-06 05:01 291840 ----a-w- c:\windows\system32\sbe.dll
2011-02-02 16:11 . 2009-10-05 15:37 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-02-02 07:58 . 2004-08-10 15:00 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2004-08-10 15:00 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-08-10 15:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-10 15:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2004-08-10 15:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2010-12-22 12:34 301568 ----a-w- c:\windows\system32\SET6E.tmp
2010-12-22 12:34 . 2004-08-10 15:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-21 14:04 . 2010-12-21 14:04 141264 ----a-w- c:\windows\system32\drivers\eamon.sys
2010-12-21 14:04 . 2010-12-21 14:04 115008 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-12-21 12:47 . 2010-12-21 12:47 94872 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2010-12-20 23:59 . 2004-08-10 15:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2004-08-10 15:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2004-08-10 15:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2004-08-10 15:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-08-10 15:00 385024 ----a-w- c:\windows\system32\html.iec
2009-02-14 18:31 . 2009-02-14 18:31 16483464 ----a-w- c:\program files\ashampoo_winoptimizer6_se.exe
2009-02-13 01:50 . 2009-02-13 01:50 3199752 ----a-w- c:\program files\sp35384.exe
2009-02-13 01:41 . 2009-02-13 01:41 17701816 ----a-w- c:\program files\LightScribeSimpleLabeler_1.17.90.1.exe
2008-11-10 01:55 . 2008-11-10 01:55 128408 ----a-w- c:\program files\Download_UltimateSuiteReg.exe
2008-11-09 18:36 . 2008-11-09 18:35 21189685 ----a-w- c:\program files\video-download-studio.exe
2008-11-07 18:16 . 2008-11-07 18:16 10428116 ----a-w- c:\program files\PlatoDVDRipper_SE.exe
2008-11-07 18:00 . 2008-11-07 18:00 4628236 ----a-w- c:\program files\avi-vcd.exe
2008-10-31 02:36 . 2008-10-31 02:35 3415298 -c--a-w- c:\program files\mg4.exe
2008-10-25 00:53 . 2008-10-25 00:49 67167528 -c--a-w- c:\program files\iTunes801Setup.exe
2008-10-04 16:13 . 2008-10-04 16:10 1131888 -c--a-w- c:\program files\ActiveSetupN.exe
2008-09-27 02:15 . 2008-09-27 02:14 3777324 -c--a-w- c:\program files\ZiepodPlusSetup.exe
2008-09-27 02:01 . 2008-09-27 02:01 2909031 -c--a-w- c:\program files\ZiepodSetup.exe
2008-09-23 02:19 . 2007-11-13 23:23 30214576 -c--a-w- c:\program files\zunesetuppkg-x86.exe
2008-07-07 00:05 . 2008-07-07 00:04 9884748 -c--a-w- c:\program files\panoramamaker4_retail_trial_e.exe
2008-07-06 23:39 . 2008-04-11 20:47 3456567 -c--a-w- c:\program files\PanoStudioSetupEn.exe
2008-04-30 21:40 . 2008-04-30 21:40 5186048 ----a-w- c:\program files\WindowsDefender.msi
2008-04-11 02:17 . 2008-04-11 02:17 4938208 -c--a-w- c:\program files\AutopanoPro_130_121106.exe
2008-04-11 01:55 . 2008-04-11 01:55 8326024 -c--a-w- c:\program files\pfactory_setup_m32.exe
2008-04-11 01:45 . 2008-04-11 01:44 1979724 -c--a-w- c:\program files\PanoPerfectLiteSetup.exe
2008-04-10 03:00 . 2008-04-10 03:00 15452536 -c--a-w- c:\program files\IE7-WindowsXP-x86-enu.exe
2008-04-10 01:14 . 2008-04-10 01:14 22690600 -c--a-w- c:\program files\SkypeSetup.exe
2008-03-16 21:59 . 2008-03-16 21:59 779536 -c--a-w- c:\program files\MoveMediaPlayer_07076007.exe
2008-03-06 22:32 . 2008-03-06 22:32 2689536 -c--a-w- c:\program files\tnt5.msi
2008-01-29 20:56 . 2008-01-29 20:56 5410865 -c--a-w- c:\program files\abiword-setup-2.4.6.exe
2008-01-17 01:09 . 2008-01-17 01:09 13181952 -c--a-w- c:\program files\mp150xp101enz.exe
2007-11-23 01:54 . 2007-11-23 01:54 1265516 -c--a-w- c:\program files\pwpro_demo.exe
2007-11-23 01:38 . 2007-11-23 01:38 1848832 -c--a-w- c:\program files\Setup_PhotoMerge_en.msi
2007-11-23 01:32 . 2007-11-23 01:32 10122746 -c--a-w- c:\program files\pidzk2110dwn.exe
2007-10-30 03:05 . 2007-10-30 03:05 2367160 -c--a-w- c:\program files\LinksysWebConnectPC.exe
2007-09-13 03:09 . 2007-09-13 03:09 4789792 -c--a-w- c:\program files\picasa2-current.exe
2007-09-13 02:58 . 2007-09-13 02:58 3376920 -c--a-w- c:\program files\panorama_composer3.exe
2007-09-13 02:53 . 2007-09-13 02:53 6193898 -c--a-w- c:\program files\zpm_cz.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-16 68856]
"ISUSPM"="c:\documents and settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-07-12 226904]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-26 15026056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-11 344064]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"LogitechCameraAssistant"="c:\program files\Logitech\Video\CameraAssistant.exe" [2005-12-07 489472]
"LogitechVideo[inspector]"="c:\program files\Logitech\Video\InstallHelper.exe" [2005-12-07 16:33 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2009-09-04 158448]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [21.12.2010 15:04 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21.12.2010 13:47 94872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12.1.2011 16:41 810144]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [4.11.2006 1:19 13592]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [22.8.2005 10:06 231424]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [14.2.2009 19:32 410976]
.
Contents of the 'Scheduled Tasks' folder
.
2009-05-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-03-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
2011-03-10 c:\windows\Tasks\User_Feed_Synchronization-{66A1A08E-0DF4-41B6-B561-A6AA7A82E8E4}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 10:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.seznam.cz/
uSearchMigratedDefaultURL = hxxp://
www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
uSearchAssistant = hxxp://
www.google.com/ie
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://webcam.usti-nad-labem.cz/activex/AMC.cab
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{9EBF2A3D-F2E5-44CF-94DA-5BB4FAE58332} - (no file)
BHO-{CCE1DEE4-CB0F-4793-9824-0426B46DA68A} - (no file)
HKCU-Run-Antispyware - c:\program files\AntiSpywareApp\Antispyware.exe
Notify-pmnkIXRI - pmnkIXRI.dll
SafeBoot-klmdb.sys
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Ashampoo Photo Commander 5 - c:\program files\Ashampoo\Ashampoo Photo Commander 5\Uninstall\0718_Uninstall.EXE
AddRemove-Widelands_is1 - c:\program files\Widelands\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-11 18:52
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(936)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(7748)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\Ati2evxx.exe
c:\progra~1\hpq\Shared\HPQTOA~1.EXE
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2011-03-11 19:02:20 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-11 18:02
.
Pre-Run: 4 799 500 288 bytes free
Post-Run: 7 057 338 368 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - F83A8FBD476A137C0DB4E91754B1B022