ComboFix 07-12-21.4 - Albert 2007-12-29 23:11:21.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1095 [GMT 0:00] Running from: C:\Documents and Settings\Albert\Desktop\ComboFix.exe * Created a new restore point . The following files were disabled during the run: C:\WINDOWS\system32\guard32.dll ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\Cfx32.lic C:\WINDOWS\system32\cfx32.ocx . ((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 ))))))))))))))))))))))))))))))) . 2007-12-29 16:04 . 2007-12-29 16:04 2007-12-29 16:04 . 2007-12-29 16:04 34,064 --a------ C:\WINDOWS\system32\lhacm.acm 2007-12-29 15:49 . 2004-08-04 00:56 16,384 --a------ C:\WINDOWS\system32\ipsink.ax 2007-12-29 15:49 . 2004-08-04 00:56 16,384 --a–c— C:\WINDOWS\system32\dllcache\ipsink.ax 2007-12-29 15:49 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys 2007-12-29 15:49 . 2004-08-03 23:10 15,360 --a–c— C:\WINDOWS\system32\dllcache\streamip.sys 2007-12-29 15:49 . 2004-08-03 23:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys 2007-12-29 15:49 . 2004-08-03 23:10 10,880 --a–c— C:\WINDOWS\system32\dllcache\ndisip.sys 2007-12-29 15:49 . 2004-08-03 22:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys 2007-12-29 15:49 . 2004-08-03 22:58 5,504 --a–c— C:\WINDOWS\system32\dllcache\mstee.sys 2007-12-29 15:48 . 2004-08-03 23:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys 2007-12-29 15:48 . 2004-08-03 23:10 85,376 --a–c— C:\WINDOWS\system32\dllcache\nabtsfec.sys 2007-12-29 15:48 . 2004-08-03 23:10 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS 2007-12-29 15:48 . 2004-08-03 23:10 19,328 --a–c— C:\WINDOWS\system32\dllcache\wstcodec.sys 2007-12-29 15:48 . 2004-08-03 23:10 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys 2007-12-29 15:48 . 2004-08-03 23:10 11,136 --a–c— C:\WINDOWS\system32\dllcache\slip.sys 2007-12-29 15:47 . 2004-08-03 23:10 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys 2007-12-29 15:47 . 2004-08-03 23:10 17,024 --a–c— C:\WINDOWS\system32\dllcache\ccdecode.sys 2007-12-29 15:46 . 2004-08-04 00:56 90,624 --a------ C:\WINDOWS\system32\kswdmcap.ax 2007-12-29 15:46 . 2004-08-04 00:56 90,624 --a–c— C:\WINDOWS\system32\dllcache\kswdmcap.ax 2007-12-29 15:46 . 2004-08-04 00:56 28,672 --a------ C:\WINDOWS\system32\vidcap.ax 2007-12-29 15:46 . 2004-08-04 00:56 28,672 --a–c— C:\WINDOWS\system32\dllcache\vidcap.ax 2007-12-29 15:45 . 2004-08-04 00:56 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax 2007-12-29 15:45 . 2004-08-04 00:56 61,952 --a–c— C:\WINDOWS\system32\dllcache\kstvtune.ax 2007-12-29 15:45 . 2004-08-04 00:56 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll 2007-12-29 15:45 . 2004-08-04 00:56 53,760 --a–c— C:\WINDOWS\system32\dllcache\vfwwdm32.dll 2007-12-29 15:45 . 2004-08-04 00:56 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax 2007-12-29 15:45 . 2004-08-04 00:56 43,008 --a–c— C:\WINDOWS\system32\dllcache\ksxbar.ax 2007-12-29 15:44 . 2006-07-03 10:31 94,208 --a------ C:\WINDOWS\amcap.exe 2007-12-29 15:44 . 2007-04-19 13:56 20,480 --a------ C:\WINDOWS\FixCamera.exe 2007-12-29 15:43 . 2007-12-29 15:43 2007-12-29 15:43 . 2007-03-27 18:19 10,252,544 --a------ C:\WINDOWS\system32\drivers\snpstd3.sys 2007-12-29 15:43 . 2006-09-19 09:07 827,392 --a------ C:\WINDOWS\vsnpstd3.exe 2007-12-29 15:43 . 2007-04-23 09:48 262,144 --a------ C:\WINDOWS\tsnpstd3.exe 2007-12-29 15:43 . 2007-02-09 14:13 172,032 --a------ C:\WINDOWS\system32\rsnpstd3.dll 2007-12-29 15:43 . 2007-03-12 11:41 61,440 --a------ C:\WINDOWS\system32\vsnpstd3.dll 2007-12-29 15:43 . 2005-11-23 12:55 53,248 --a------ C:\WINDOWS\system32\csnpstd3.dll 2007-12-29 15:43 . 2005-11-23 13:55 53,248 --a------ C:\WINDOWS\csnpstd3.dll 2007-12-29 15:43 . 2004-02-27 16:36 15,498 --a------ C:\WINDOWS\snpstd3.ini 2007-12-29 15:43 . 2004-02-27 16:36 13,023 --a------ C:\WINDOWS\snpstd3.src 2007-12-29 15:42 . 2007-12-29 15:42 2007-12-29 15:42 . 2007-12-29 15:42 2007-12-27 14:26 . 2007-12-27 14:26 139,008 --a------ C:\WINDOWS\system32\guard32.dll.vir 2007-12-27 14:26 . 2007-12-27 14:26 81,272 --a------ C:\WINDOWS\system32\drivers\cmdGuard.sys 2007-12-27 14:26 . 2007-12-27 14:26 23,672 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys 2007-12-26 13:27 . 2007-12-26 15:39 2007-12-26 13:25 . 2007-12-26 13:25 2007-12-26 13:12 . 2005-05-18 11:43 81,920 --a------ C:\WINDOWS\system32\CloseApp.exe 2007-12-26 11:12 . 2007-12-29 12:07 2007-12-26 11:12 . 2007-05-17 11:55 61,440 --a------ C:\WINDOWS\system32\Vista.Emulation.dll 2007-12-25 20:40 . 2007-12-27 17:37 2,450 --a------ C:\WINDOWS\VPlayer.INI 2007-12-25 20:40 . 2007-12-27 17:37 87 --a------ C:\WINDOWS\VplayerINI.vpl 2007-12-25 20:39 . 2007-12-25 20:39 2007-12-25 04:41 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2007-12-25 04:41 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2007-12-25 04:41 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui 2007-12-24 22:03 . 2007-12-25 20:35 2007-12-24 15:13 . 2007-12-24 15:13 2007-12-24 15:11 . 2007-12-24 15:11 2007-12-24 15:07 . 2007-12-24 15:07 2007-12-24 14:49 . 2007-12-24 14:49 1,637,888 --a------ C:\Program Files\WPG1_1Beta2.exe 2007-12-24 11:14 . 2007-11-05 07:54 3,564,584 --a------ C:\Program Files\procexp.exe 2007-12-23 20:38 . 2007-12-24 01:48 2007-12-22 20:17 . 2007-12-22 20:17 2007-12-22 09:11 . 2004-04-30 09:37 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys 2007-12-22 09:11 . 2004-04-30 09:33 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys 2007-12-22 09:00 . 2007-12-22 09:00 2007-12-21 23:40 . 2007-12-21 23:40 2007-12-21 23:40 . 2004-08-04 20:46 520,192 --a------ C:\WINDOWS\system32\wscma2u.exe 2007-12-21 23:40 . 2005-10-21 20:20 278,528 --a------ C:\WINDOWS\system32\ammpp.dll 2007-12-21 23:40 . 2003-07-17 23:49 193,536 --a------ C:\WINDOWS\system32\atomid.exe 2007-12-21 23:40 . 2005-07-13 15:13 65,536 --a------ C:\WINDOWS\system32\a1.dll 2007-12-21 23:40 . 2005-09-18 13:17 61,440 --a------ C:\WINDOWS\system32\anming.ocx 2007-12-21 23:40 . 2007-12-22 02:55 334 --a------ C:\WINDOWS\MP3trt.ini 2007-12-21 19:37 . 2007-12-21 19:37 2007-12-21 19:37 . 2007-12-21 19:39 2007-12-20 23:30 . 2007-12-20 23:37 2007-12-20 23:30 . 2007-12-20 23:58 2007-12-20 22:54 . 2003-04-10 15:31 177,152 --------- C:\WINDOWS\system32\ibinstall.dll 2007-12-20 11:45 . 2007-12-20 11:47 2007-12-20 09:57 . 2007-12-20 10:17 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb 2007-12-20 09:57 . 2007-12-20 10:17 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb 2007-12-20 09:56 . 2004-08-04 01:07 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-12-20 09:18 . 2005-09-28 10:31 49,152 --a------ C:\WINDOWS\rebuild.exe 2007-12-20 09:17 . 2006-10-18 22:47 8,231,936 --a------ C:\WINDOWS\system32\wmploc.backup 2007-12-20 09:16 . 2007-10-31 05:12 3,590,656 --a------ C:\WINDOWS\system32\mshtml.backup 2007-12-20 09:16 . 2007-10-10 23:55 1,831,424 --a------ C:\WINDOWS\system32\inetcpl.backup 2007-12-20 09:16 . 2007-10-11 06:13 1,494,528 --a------ C:\WINDOWS\system32\shdocvw.backup 2007-12-20 09:16 . 2007-10-10 23:56 1,159,680 --a------ C:\WINDOWS\system32\urlmon.backup 2007-12-20 09:16 . 2007-10-11 06:13 1,023,488 --a------ C:\WINDOWS\system32\browseui.backup 2007-12-20 09:16 . 2007-10-10 23:55 105,984 --a------ C:\WINDOWS\system32\url.backup 2007-12-20 09:13 . 2004-08-04 01:07 388,608 --a------ C:\WINDOWS\system32\cmd.backup 2007-12-20 09:12 . 2007-10-26 03:34 8,460,288 --a------ C:\WINDOWS\system32\shell32.backup 2007-12-20 09:12 . 2004-08-04 01:07 2,897,920 --a------ C:\WINDOWS\system32\xpsp2res.backup 2007-12-20 09:12 . 2004-08-04 01:07 589,312 --a------ C:\WINDOWS\system32\wiashext.backup 2007-12-20 09:12 . 2004-08-04 01:07 438,272 --a------ C:\WINDOWS\system32\shimgvw.backup 2007-12-20 09:12 . 2007-10-10 23:56 232,960 --a------ C:\WINDOWS\system32\webcheck.backup 2007-12-20 09:12 . 2004-08-04 01:07 191,488 --a------ C:\WINDOWS\system32\syncui.backup 2007-12-20 09:10 . 2007-06-13 10:23 1,033,216 --a------ C:\WINDOWS\explorer.backup 2007-12-20 09:10 . 2004-08-04 01:07 549,888 --a------ C:\WINDOWS\system32\appwiz.backup . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-27 14:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Comodo 2007-12-27 14:26 --------- d-----w C:\Documents and Settings\Albert\Application Data\Comodo 2007-12-13 06:42 --------- d-----w C:\Program Files\C-Media 2007-12-13 06:36 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-12-13 06:25 --------- d-----w C:\Program Files\microsoft frontpage 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll 2007-10-24 01:47 96,760 ----a-w C:\WINDOWS\system32\dfshim.dll 2007-10-24 01:47 84,480 ----a-w C:\WINDOWS\system32\mscories.dll 2007-10-24 01:47 282,112 ----a-w C:\WINDOWS\system32\mscoree.dll 2007-10-24 01:47 158,720 ----a-w C:\WINDOWS\system32\mscorier.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “RocketDock”=“C:\Program Files\RocketDock\RocketDock.exe” [2007-09-02 13:58] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NvCplDaemon”=“RUNDLL32.exe” [2004-08-04 01:07 C:\WINDOWS\system32\rundll32.exe] “NvMediaCenter”=“RUNDLL32.exe” [2004-08-04 01:07 C:\WINDOWS\system32\rundll32.exe] “AVP”=“C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe” [2007-06-28 12:51] “COMODO Firewall Pro”=“D:\Comodo\cfp.exe” [2007-12-27 14:26] “FixCamera”=“C:\WINDOWS\FixCamera.exe” [2007-04-19 13:56] “tsnpstd3”=“C:\WINDOWS\tsnpstd3.exe” [2007-04-23 09:48] “snpstd3”=“C:\WINDOWS\vsnpstd3.exe” [2006-09-19 09:07] C:\Documents and Settings\Albert\Start Menu\Programs\Startup\ Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2007-12-15 09:19:01] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv] C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2005-12-06 21:16 176128 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “AppInit_DLLs”=wbsys.dll C:\WINDOWS\system32\guard32.dll R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2007-12-27 14:26] R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2007-12-27 14:26] R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58] *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-29 23:14:31 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\guard32.dll PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180] -> C:\WINDOWS\system32\guard32.dll . Completion time: 2007-12-29 23:15:47 . 2007-12-13 14:50:19 — E O F —