ComboFix 08-01-04.1 - erin 2008-01-06 16:39:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.61 [GMT 1:00]Running from: D:\Documents and Settings\erin\My Documents\Download\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\_000004_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000013_.tmp.dll
C:\WINDOWS\system32\_000016_.tmp.dll
C:\WINDOWS\system32\_000017_.tmp.dll
C:\WINDOWS\system32\_000018_.tmp.dll
C:\WINDOWS\system32\_000024_.tmp.dll
C:\WINDOWS\system32\_000111_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.
2008-01-06 16:39 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-06 16:32 . 2008-01-06 16:32 <DIR> d-------- C:\Program Files\Kerio
2008-01-05 16:31 . 2008-01-05 16:31 <DIR> d-------- C:\Program Files\Opera 9
2008-01-05 16:10 . 2008-01-05 16:10 250 --a------ C:\WINDOWS\gmer.ini
2008-01-02 23:08 . 2008-01-04 15:46 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-02 23:08 . 2008-01-02 23:08 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-02 15:05 . 2008-01-02 15:05 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-01-02 15:04 . 2008-01-02 15:05 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-01-01 16:16 . 2008-01-01 16:16 <DIR> d-------- C:\Documents and Settings\erin\Application Data\ESET
2008-01-01 16:14 . 2008-01-01 16:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2007-12-31 15:10 . 2002-04-15 12:28 102,912 --------- C:\WINDOWS\system32\drivers\FWDRV.SYS
2007-12-31 14:19 . 2007-12-31 14:21 <DIR> d-------- C:\Program Files\MSECache
2007-12-31 13:58 . 2008-01-02 13:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-31 13:23 . 2007-12-31 13:23 <DIR> d-------- C:\Program Files\uTorrent
2007-12-31 13:23 . 2008-01-01 18:56 <DIR> d-------- C:\Documents and Settings\erin\Application Data\uTorrent
2007-12-11 20:23 . 2004-08-04 00:56 17,408 --a------ C:\WINDOWS\system32\msyuv.dll
2007-12-11 20:23 . 2004-08-04 00:56 17,408 --a--c--- C:\WINDOWS\system32\dllcache\msyuv.dll
2007-12-11 20:23 . 2001-08-17 22:36 8,192 --a------ C:\WINDOWS\system32\tsbyuv.dll
2007-12-11 20:23 . 2001-08-17 22:36 8,192 --a--c--- C:\WINDOWS\system32\dllcache\tsbyuv.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 14:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-05 20:46 --------- d-----w C:\Documents and Settings\erin\Application Data\Skype
2007-12-04 18:44 --------- d-----w C:\Program Files\MSN Messenger
2007-11-18 22:37 45,056 ----a-w C:\WINDOWS\NCUNINST.EXE
2007-11-18 18:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Advanced Chemistry Development
2007-11-17 13:20 --------- d-----w C:\Program Files\Aardvark Digital
2007-11-14 14:06 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-11-14 14:04 27,656 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-11-14 14:03 33,800 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:35 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 16:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-11-14 15:05 1410304]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-11-14 15:06]
R1 fwdrv;Kerio Personal Firewall Driver;C:\WINDOWS\system32\Drivers\fwdrv.sys [2002-04-15 12:28]
R3 SNPHV71;PC Camera (602a VGA);C:\WINDOWS\system32\DRIVERS\snphv71.sys [2002-11-08 16:24]
S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 12:36]
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 16:41:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-06 16:42:47
ComboFix-quarantined-files.txt 2008-01-06 15:42:21
.
2007-12-13 00:02:06 --- E O F ---
|