ComboFix 09-05-18.04 - OneAndOnlyBG 05/19/2009 14:29.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.2046.1551 [GMT 3:00]
Running from: c:\documents and settings\OneAndOnlyBG\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\OneAndOnlyBG\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\documents and settings\OneAndOnlyBG\Temp\esihdrv.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\kbdbds.Dll
c:\windows\system32\KBDBPH.dLL
c:\windows\system32\kbdbphz.dLL
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ESIHDRV
-------\Service_esihdrv
((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.
2009-05-19 11:23 . 2009-05-19 11:24 -------- d-----w c:\program files\Garena
2009-05-19 11:23 . 2009-05-19 11:23 -------- d-----w c:\documents and settings\OneAndOnlyBG\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-19 11:23 . 2009-05-19 07:55 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-19 11:15 . 2009-05-19 07:41 -------- d-----w c:\program files\Datecs
2009-05-19 10:47 . 2009-05-19 08:24 -------- d-----w c:\program files\DAEMON Tools Lite
2009-05-19 09:34 . 2009-05-19 09:32 -------- d-----w c:\program files\The KMPlayer
2009-05-19 09:26 . 2009-05-19 07:40 -------- d-----w c:\program files\FlashGet
2009-05-19 09:22 . 2009-05-19 09:22 -------- d-----w c:\program files\uTorrent
2009-05-19 09:07 . 2009-05-19 09:07 -------- d-----w c:\program files\Opera
2009-05-19 08:54 . 2009-05-19 08:54 -------- d-----w c:\program files\ESET
2009-05-19 08:25 . 2009-05-19 08:25 -------- d-----w c:\program files\DAEMON Tools Toolbar
2009-05-19 08:23 . 2009-05-19 08:23 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-05-19 08:00 . 2009-05-19 08:00 -------- d-----w c:\program files\AMD
2009-05-19 07:55 . 2009-05-19 07:55 -------- d-----w c:\program files\Realtek
2009-05-19 07:54 . 2009-05-19 07:54 -------- d-----w c:\program files\VIA
2009-05-19 07:54 . 2009-05-19 07:39 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-19 07:40 . 2009-05-19 07:40 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2009-05-19 07:38 . 2009-05-19 07:38 -------- d-----w c:\program files\Skype
2009-05-19 07:38 . 2009-05-19 07:38 -------- d-----w c:\program files\Common Files\Skype
2009-05-19 07:33 . 2009-05-19 07:33 12328 ----a-w c:\documents and settings\OneAndOnlyBG\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 07:29 . 2009-05-19 07:29 -------- d-----w c:\program files\microsoft frontpage
2009-05-19 07:26 . 2009-05-19 07:26 21640 ----a-w c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[7] 2004-08-04 12:00 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\system32\dllcache\tcpip.sys
[-] 2004-08-04 12:00 359040 6A603809F598332DBEDD535BDBCE313E c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-05-19_10.18.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-19 11:31 . 2009-05-19 11:31 16384 c:\windows\temp\Perflib_Perfdata_580.dat
+ 2004-08-04 12:00 . 2006-07-14 15:31 332288 c:\windows\system32\netapi32.dll
- 2004-08-04 12:00 . 2004-08-04 12:00 332288 c:\windows\system32\netapi32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-02-01 21898024]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-12 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-12 81920]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-04-12 1626112]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2006-01-11 577536]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2009-5-19 95232]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2/6/2009 2:23 PM 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2/6/2009 2:24 PM 93336]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2/6/2009 2:23 PM 727720]
.
.
------- Supplementary Scan -------
.
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
TCP: {82E458FA-8A71-49F5-85F5-21FBCBF5736A} = 192.168.1.1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-19 14:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3512)
c:\windows\system32\newdll.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2009-05-19 14:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-19 11:32
ComboFix2.txt 2009-05-19 10:48
ComboFix3.txt 2009-05-19 10:19
Pre-Run: 50,228,690,944 bytes free
Post-Run: 50,194,644,992 bytes free
121