ComboFix 07-12-19.2 - Tabion 2007-12-18 16:45:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.456 [GMT -5:00]
Running from: C:\Documents and Settings\Tabion\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\windows\system32\kdfol.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NPF
((((((((((((((((((((((((( Files Created from 2007-11-19 to 2007-12-19 )))))))))))))))))))))))))))))))
.
2007-12-18 16:44 . 2007-12-18 16:44 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-14 16:36 . 2007-12-14 16:51 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-12-14 15:59 . 2007-12-14 15:59 <DIR> d-------- C:\Program Files\MSConfig CleanUp
2007-12-14 05:23 . 2007-12-14 05:23 <DIR> d-------- C:\Program Files\DAEMON Tools
2007-12-13 00:05 . 2007-12-13 00:05 <DIR> d-------- C:\Program Files\WiFiConnector
2007-12-13 00:00 . 2007-12-13 00:00 <DIR> d-------- C:\Nintendo
2007-12-13 00:00 . 2004-05-12 13:49 1 --a------ C:\WINDOWS\system32\drivers\RT25USBAP.CAT
2007-12-12 23:59 . 2007-12-12 23:59 1,784,670 --a------ C:\Nintendo_WFC_USB.zip
2007-12-12 05:31 . 2007-12-12 05:31 <DIR> d-------- C:\Documents and Settings\Tabion\Application Data\Grisoft
2007-12-12 05:30 . 2007-12-12 05:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-12 05:30 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-12 05:29 . 2007-12-12 05:29 12,413,440 --a------ C:\avgas-setup-7.5.1.43.exe
2007-12-12 04:50 . 2007-12-12 04:50 251,392 --a------ C:\hijackthis_sfx.exe
2007-12-12 04:17 . 2007-12-12 05:22 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-12-12 04:16 . 2007-12-12 04:16 121 --a------ C:\WINDOWS\bdagent.INI
2007-12-12 03:14 . 2007-12-12 03:14 77,824 --a------ C:\WINDOWS\system32\xcomm.dll
2007-12-11 06:43 . 2007-12-17 08:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-11 06:43 . 2007-12-11 06:43 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-10 16:10 . 2004-03-29 16:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-12-07 21:02 . 2007-12-18 00:16 <DIR> d-------- C:\Program Files\Metin2.us
2007-12-07 19:17 . 2007-12-07 19:55 <DIR> d-------- C:\metin2_20071126
2007-12-01 19:02 . 2007-12-01 19:02 <DIR> d-------- C:\Program Files\Netropa
2007-12-01 19:02 . 2002-07-11 07:47 98,304 --a------ C:\WINDOWS\system32\msikbd.dll
2007-12-01 19:02 . 2000-06-08 02:09 28,672 --------- C:\WINDOWS\system32\msiosd32.dll
2007-12-01 19:02 . 2001-12-20 09:02 6,656 --------- C:\WINDOWS\system32\drivers\Msikbd2k.sys
2007-12-01 19:02 . 2007-12-19 16:50 253 --a------ C:\WINDOWS\Msiosd.ini
2007-12-01 19:01 . 2007-12-01 19:01 <DIR> d-------- C:\smartoffice
2007-12-01 19:01 . 2007-12-01 19:01 <DIR> d-------- C:\kb740x
2007-12-01 19:01 . 2007-12-01 19:01 3,909,432 --a------ C:\kb740x.zip
2007-11-30 16:29 . 2007-11-30 16:38 <DIR> d-------- C:\books
2007-11-30 12:44 . 2007-11-30 12:44 <DIR> d-------- C:\Program Files\Realtek AC97
2007-11-30 12:44 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2007-11-30 12:31 . 2007-11-30 12:40 18,476,841 --a------ C:\WDM_A403.exe
2007-11-29 22:05 . 2007-11-29 23:05 289,278,764 --a------ C:\[DB]_Naruto_Shippuuden_036-037_[B06574F4].avi
2007-11-28 23:43 . 2007-11-28 23:43 <DIR> d-------- C:\WINDOWS\Sun
2007-11-28 23:43 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-11-28 23:42 . 2007-11-28 23:43 <DIR> d-------- C:\Program Files\Java
2007-11-28 23:42 . 2007-11-28 23:42 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-28 21:05 . 2007-11-28 22:38 <DIR> d-------- C:\ijji
2007-11-19 11:02 . 2007-11-19 11:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IJJIGame
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-17 13:36 --------- d-----w C:\Documents and Settings\Tabion\Application Data\uTorrent
2007-12-17 10:40 --------- d-----w C:\Program Files\Lexmark 1300 Series
2007-12-17 10:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-17 06:06 --------- d-----w C:\Program Files\Lx_cats
2007-12-16 23:45 --------- d-----w C:\Program Files\DazzlingEvents
2007-12-14 21:00 --------- d-----w C:\Documents and Settings\Tabion\Application Data\IGN_DLM
2007-12-14 10:17 685,816 ----a-w C:\windows\system32\drivers\sptd.sys
2007-12-12 09:18 --------- d-----w C:\Documents and Settings\Tabion\Application Data\Juniper Networks
2007-12-12 09:17 --------- d-----w C:\Program Files\Axialis
2007-12-07 05:12 --------- d-----w C:\Program Files\Winamp Remote
2007-11-29 03:18 --------- d-----w C:\Program Files\Winamp
2007-11-29 01:41 --------- d--h--w C:\Documents and Settings\Tabion\Application Data\ijjigame
2007-11-28 17:31 --------- d-----w C:\Program Files\Razor
2007-11-15 12:34 --------- d--h--r C:\Documents and Settings\All Users\Application Data\yahoo!
2007-11-15 12:31 --------- d-----w C:\Program Files\Yahoo!
2007-11-14 10:25 --------- d-----w C:\Program Files\ICQ6
2007-11-08 19:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-11-08 19:26 15,081,800 ----a-w C:\winampremote.exe
2007-10-29 21:54 --------- d-----w C:\Program Files\EA GAMES
2007-10-29 19:26 --------- d-----w C:\Program Files\Diablo II
2007-10-29 18:39 --------- d-----w C:\Program Files\UOAM
2007-10-27 21:59 --------- d-----w C:\Program Files\Renaissance Software
2007-10-27 05:07 --------- d-----w C:\Documents and Settings\Tabion\Application Data\ICAClient
2007-10-27 05:04 --------- d-----w C:\Program Files\Citrix
2007-10-26 16:20 4,124,352 ----a-r C:\windows\system32\drivers\alcxwdm.sys
2007-10-23 07:46 --------- d-----w C:\Program Files\Trillian
2007-10-20 19:05 43,520 ----a-w C:\windows\system32\CmdLineExt03.dll
2007-10-19 19:20 21,840 ----a-w C:\windows\system32\SIntfNT.dll
2007-10-19 19:20 17,212 ----a-w C:\windows\system32\SIntf32.dll
2007-10-19 19:20 12,067 ----a-w C:\windows\system32\SIntf16.dll
2007-10-19 19:09 94,208 ----a-w C:\windows\DIIUnin.exe
2007-10-19 05:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-19 04:28 --------- d-----w C:\Program Files\Arovax AntiSpyware
2007-10-16 22:10 164 ----a-w C:\install.dat
2007-10-05 21:39 776,704 ----a-w C:\amem5a.exe
2007-10-05 19:37 5,290,394 ----a-w C:\win2k_xp1417.exe
2007-06-03 09:49 32 ----a-r C:\Documents and Settings\All Users\hash.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-03 18:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 08:50 C:\WINDOWS\LOGI_MWX.EXE]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 C:\WINDOWS\soundman.exe]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-19 10:50]
"lxdcamon"="C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [2007-02-05 18:32]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="regsvr32 /s /n /i:u shell32" []
"IE7-11"="advpack.dll" [2007-03-21 05:11 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Run Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2007-12-13 00:05:39]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-03 18:56 15360 --a------ C:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-20 09:32 77824 --a------ C:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 09:36 114688 --a------ C:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-09-20 09:35 94208 --a------ C:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
Logi_MwX.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdcmon.exe]
C:\Program Files\Lexmark 1300 Series\lxdcmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"wuauserv"=2 (0x2)
"IDriverT"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"AWService"=2 (0x2)
"SamSs"=2 (0x2)
"SharedAccess"=2 (0x2)
"usnjsvc"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"AVG Anti-Spyware Guard"=2 (0x2)
"lxdc_device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ipTray.exe"="C:\Program Files\Intel\IDU\iptray.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\windows\system32\DRIVERS\msikbd2k.sys [2001-12-20 09:02]
R2 EAPPkt;Realtek EAPPkt Protocol;C:\windows\system32\DRIVERS\EAPPkt.sys [2005-04-01 10:43]
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 06:41]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2006-10-27 18:18]
R2 SIODRV;SIODRV;C:\WINDOWS\system32\drivers\SIODRV.SYS [2007-05-23 09:17]
R3 smbusp;Intel® SMBus 2.0 Driver;C:\windows\system32\DRIVERS\intelsmb.sys [2006-08-30 10:09]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\windows\system32\DRIVERS\wg111v2.sys []
S4 DNADownloader;DNADownloader;C:\Program Files\GameSpot\DownloadManager_Win32.exe [2007-07-10 01:17]
S4 lxdc_device;lxdc_device;C:\windows\system32\lxdccoms.exe -service []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\autorun.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-12-19 16:50:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-19 16:51:19 - machine was rebooted
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:01:06 PM, on 12/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\windows\SOUNDMAN.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\windows\System32\svchost.exe
C:\windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [IE7-11] rundll32 advpack.dll,LaunchINFSection NR_IE7en.inf,AfterUserStart (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Global Startup: Run Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
--
End of file - 2285 bytes