ComboFix 07-10-29.1** - dm 2007-10-30 22:38:16.3 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.55 [GMT 1:00] Running from: C:\Program Files\ComboFix.exe Command switches used :: C:\Program Files\CFScript.txt * Created a new restore point FILE:: C:\WINNT\S8A67796B.tmp . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINNT\S8A67796B.tmp . ((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-30 ))))))))))))))))))))))))))))))) . 2007-10-30 22:35 1,396,245 --a------ C:\Program Files\ComboFix.exe 2007-10-30 20:31 2007-10-30 19:03 2007-10-30 18:50 2007-10-29 23:15 51,200 --a------ C:\WINNT\NirCmd.exe 2007-10-29 22:52 1,130 --a------ C:\WINNT\system32\tmp.reg 2007-10-29 22:22 289,144 --a------ C:\WINNT\system32\VCCLSID.exe 2007-10-29 22:22 288,417 --a------ C:\WINNT\system32\SrchSTS.exe 2007-10-29 22:22 53,248 --a------ C:\WINNT\system32\Process.exe 2007-10-29 22:22 51,200 --a------ C:\WINNT\system32\dumphive.exe 2007-10-29 22:22 25,600 --a------ C:\WINNT\system32\WS2Fix.exe 2007-10-29 22:21 2007-10-29 22:09 966,744 --a------ C:\Program Files\SmitfraudFix.zip 2007-10-29 22:00 2007-10-29 19:29 2007-10-29 13:18 2007-10-29 13:18 2007-10-29 13:18 2007-10-24 20:20 2007-10-24 20:06 2007-10-24 20:06 2,293,712 --a------ C:\Program Files\FLV PlayerFCSetup.exe 2007-10-24 20:04 2007-10-24 20:01 2007-10-24 20:01 3,655,488 --a------ C:\Program Files\FLV PlayerRCATSetup.exe 2007-10-24 20:00 2007-10-24 20:00 411,248 --a------ C:\Program Files\FLV PlayerRCSetup.exe 2007-10-20 23:02 2007-10-19 13:23 2007-10-19 13:05 2007-10-19 13:05 592 --a------ C:\WINNT\chgkey.vbs 2007-10-18 20:13 2007-10-18 20:13 2007-10-18 20:13 2007-10-18 20:13 2007-10-18 20:13 2007-10-18 20:12 2007-10-18 20:12 2007-10-18 20:12 2007-10-18 20:12 2007-10-18 20:12 2007-10-18 20:12 2007-10-18 20:12 2007-10-18 20:07 221,184 --a------ C:\WINNT\system32\wmpns.dll 2007-10-18 20:04 2007-10-18 19:59 6,400 --a------ C:\WINNT\system32\drivers\splitter.sys 2007-10-18 19:57 19,017 --a------ C:\WINNT\system32\drivers\RTL8029.sys 2007-10-18 19:14 2007-10-18 19:14 24,661 --a------ C:\WINNT\system32\spxcoins.dll 2007-10-18 19:14 24,661 --a------ C:\WINNT\system32\dllcache\spxcoins.dll 2007-10-18 19:14 13,312 --a------ C:\WINNT\system32\irclass.dll 2007-10-18 19:14 13,312 --a------ C:\WINNT\system32\dllcache\irclass.dll 2007-10-18 19:14 11,264 --a------ C:\WINNT\system32\drivers\irenum.sys 2007-10-18 19:14 11,264 --a------ C:\WINNT\system32\dllcache\irenum.sys 2007-10-18 17:30 2007-10-18 11:52 2007-10-17 10:01 2007-10-16 13:34 2007-10-16 13:33 2007-10-16 13:28 2007-10-16 13:24 2007-10-16 13:19 171,792 --a------ C:\WINNT\system32\wjview.exe 2007-10-16 13:19 144,896 --a------ C:\WINNT\system32\dllcache\wmiprov.dll 2007-10-16 13:19 13,824 --a------ C:\WINNT\system32\dllcache\winmgmt.exe 2007-10-16 13:16 90,112 --a------ C:\WINNT\system32\mtxoci.dll 2007-10-16 13:16 90,112 --a------ C:\WINNT\system32\dllcache\mtxoci.dll 2007-10-16 13:16 20,480 --a------ C:\WINNT\system32\mtxdm.dll 2007-10-16 13:16 20,480 --a------ C:\WINNT\system32\dllcache\mtxdm.dll 2007-10-16 13:16 6,928 --------- C:\WINNT\system32\schmupd.exe 2007-10-16 13:13 678,400 --a------ C:\WINNT\system32\inetcomm.dll 2007-10-16 13:13 678,400 --a------ C:\WINNT\system32\dllcache\inetcomm.dll 2007-10-16 13:13 618,605 --a------ C:\WINNT\system32\dllcache\fp4autl.dll 2007-10-16 13:13 472,064 --a------ C:\WINNT\system32\dllcache\fastprox.dll 2007-10-16 13:13 349,696 --a------ C:\WINNT\system32\hypertrm.dll 2007-10-16 13:13 49,664 --a------ C:\WINNT\system32\inetres.dll 2007-10-16 13:13 49,664 --a------ C:\WINNT\system32\dllcache\inetres.dll 2007-10-16 13:11 67,584 --a------ C:\WINNT\system32\dllcache\acctres.dll 2007-10-16 13:11 67,584 --a------ C:\WINNT\system32\acctres.dll 2007-10-16 13:04 2007-10-16 12:18 2007-10-16 12:17 2007-10-16 12:17 2007-10-16 12:17 2007-10-16 10:51 2007-10-16 10:49 2007-10-16 10:44 2007-10-16 10:44 757,760 --------- C:\WINNT\Unnero.exe 2007-10-16 10:44 532,480 --------- C:\WINNT\system32\imagx5.dll 2007-10-16 10:44 507,904 --------- C:\WINNT\system32\imagr5.dll 2007-10-16 10:44 275,312 --------- C:\WINNT\system32\ImagXpr5.dll 2007-10-16 10:44 155,648 --------- C:\WINNT\system32\NeroCheck.exe 2007-10-16 10:44 106,496 --------- C:\WINNT\system32\TwnLib20.dll 2007-10-16 10:44 49,152 --------- C:\WINNT\system32\MultiSZ.dll 2007-10-16 10:44 35,328 --------- C:\WINNT\system32\picn20.dll 2007-10-16 10:37 2007-10-15 18:54 226,816 --a------ C:\WINNT\system32\dllcache\npdrmv2.dll 2007-10-15 18:54 10,240 --a------ C:\WINNT\system32\dllcache\npwmsdrm.dll 2007-10-15 18:48 2007-10-15 18:48 2007-10-15 18:29 2007-10-15 18:29 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-30 21:36 31 ----a-w C:\Program Files\CFScript_used_2007-10-30@22.38.txt 2007-10-16 12:25 9,488 ----a-w C:\WINNT\AppPatch_STARTKY.DLL 2007-10-16 12:25 9,488 ----a-w C:\WINNT\AppPatch_PROFRQV.DLL 2007-10-16 12:25 9,488 ----a-w C:\WINNT\AppPatch_HNULLPR.DLL 2007-10-16 12:25 9,488 ----a-w C:\WINNT\AppPatch_FGDISPY.DLL 2007-10-16 12:25 9,488 ----a-w C:\WINNT\AppPatch_CDRSTOP.DLL 2007-10-16 12:25 8,976 ----a-w C:\WINNT\AppPatch_FDXSETP.DLL 2007-10-16 12:25 8,976 ----a-w C:\WINNT\AppPatch_DELFILE.DLL 2007-10-16 12:25 8,976 ----a-w C:\WINNT\AppPatch_DELAYSG.DLL 2007-10-16 12:25 8,464 ----a-w C:\WINNT\AppPatch_SYNCS32.DLL 2007-10-16 12:25 8,464 ----a-w C:\WINNT\AppPatch_SPAIAPA.DLL 2007-10-16 12:25 8,464 ----a-w C:\WINNT\AppPatch_SPAFTSL.DLL 2007-10-16 12:25 8,464 ----a-w C:\WINNT\AppPatch_DPEORDR.DLL 2007-10-16 12:25 8,464 ----a-w C:\WINNT\AppPatch_DINOACT.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_SACPROC.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_ROCDDIR.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_ILDLB.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_FWDTEXP.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_FOEBACK.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_DRANEXE.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_DNWODBS.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_DDWAIT.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_CDScrSv.DLL 2007-10-16 12:25 7,952 ----a-w C:\WINNT\AppPatch_BZONE01.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_USOCMAN.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_USNF97.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_ULTIMA9.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_LimFF.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_IALTTAB.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_FULLCMD.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_FSLRNUI.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_FREDRAW.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_FOCUSON.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_DXMUTEX.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_CMMANDO.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_CHKHEAP.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_CCV5.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_CCP16Bt.DLL 2007-10-16 12:25 7,440 ----a-w C:\WINNT\AppPatch_3DJNGTR.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_WRPRMDV.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_TEXTCOL.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_SWMSGBX.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_RIVEN00.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_RESTART.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_RCPYEXE.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_PROFENV.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_MAPID.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_IFRLIB.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_HIDERES.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_HBORD2K.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_FOROFIL.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_EXPNDSZ.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_DEWMMCB.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_CASINO4.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_APFOCUS.DLL 2007-10-16 12:25 6,928 ----a-w C:\WINNT\AppPatch_AMOVIEP.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_WMPAINT.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_WIR2Reg.dll 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_WIN95VL.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_WIN2KVL.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_WFAXP9.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_USR2COM.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_STATRSC.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_RMIMESS.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_PANZERC.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_IE5DOMS.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_HWVSPRX.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_GFAEXCP.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_FTMPMOD.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_FREHEAP.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_F18CARR.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_EXCRACE.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_DSYSPAL.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_DIRTTRA.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_DELFREE.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_CREVNAM.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_COMINIT.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_CJOYCAP.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_BLITZ01.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_BERP5.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_BATTLES.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_BADHOOK.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_AVIWIND.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_ACMSTRM.DLL 2007-10-16 12:25 6,416 ----a-w C:\WINNT\AppPatch_2GBFRSP.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_WOUPRDV.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_WINEDGE.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_WIN9XCD.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_WIN2SYS.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_VSASS.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_SYSCURS.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_SYSCOLO.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_SYNCMSG.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_SW99P.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_SPSOUND.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_SIMPWIN.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_SFNFIRQ.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_SANSHOW.DLL 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_RISKII.dll 2007-10-16 12:25 5,904 ----a-w C:\WINNT\AppPatch_RIFMICL.DLL . ((((((((((((((((((((((((((((( snapshot@2007-10-29_23.20.40.40 ))))))))))))))))))))))))))))))))))))))))) . + 2007-03-13 09:57:12 163,328 ----a-w C:\WINNT\erdnt\subs\F3M\ERDNT.EXE + 2007-10-25 08:52:30 163,328 ----a-w C:\WINNT\ERUNT\SDFIX\ERDNT.EXE + 2007-10-30 19:31:38 1,912,832 ----a-w C:\WINNT\ERUNT\SDFIX\Users\00000001\ntuser.dat + 2007-10-30 19:31:38 12,288 ----a-w C:\WINNT\ERUNT\SDFIX\Users\00000002\UsrClass.dat + 2007-10-25 08:52:30 163,328 ----a-w C:\WINNT\ERUNT\SDFIX_First_Run\ERDNT.EXE + 2007-10-30 19:31:28 1,912,832 ----a-w C:\WINNT\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat + 2007-10-30 19:31:28 12,288 ----a-w C:\WINNT\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat + 2007-10-30 19:35:06 16,384 ----a-w C:\WINNT\Temp\Perflib_Perfdata_40c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{d3e23b4b-f153-4687-82c2-816319dd3c5a}] 2007-10-24 18:00 1453080 --a------ C:\Program Files\free-downloads\tbfre1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] “{d3e23b4b-f153-4687-82c2-816319dd3c5a}”= C:\Program Files\free-downloads\tbfre1.dll [2007-10-24 18:00 1453080] [HKEY_CLASSES_ROOT\CLSID{d3e23b4b-f153-4687-82c2-816319dd3c5a}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] “{D3E23B4B-F153-4687-82C2-816319DD3C5A}”= C:\Program Files\free-downloads\tbfre1.dll [2007-10-24 18:00 1453080] [HKEY_CLASSES_ROOT\CLSID{D3E23B4B-F153-4687-82C2-816319DD3C5A}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Synchronization Manager”=“mobsync.exe” [2004-08-03 22:44 C:\WINNT\system32\mobsync.exe] “NvCplDaemon”=“C:\WINNT\system32\NvCpl.dll” [2006-10-22 12:22] “nwiz”=“nwiz.exe” [2006-10-22 12:22 C:\WINNT\system32\nwiz.exe] “AudioDeck”=“C:\Program Files\VIAudioi\SBADeck\ADeck.exe” [2004-07-13 14:43] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2007-10-10 07:28] “NeroCheck”=“C:\WINNT\system32\NeroCheck.exe” [2001-07-09 10:50] “NvMediaCenter”=“C:\WINNT\system32\NvMcTray.dll” [2006-10-22 12:22] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 12:06] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINNT\system32\ctfmon.exe” [2004-08-03 22:44] [HKEY_USERS.default\software\microsoft\windows\currentversion\runonce] “^SetupICWDesktop”=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop “tscuninstall”=%systemroot%\system32\tscupgrd.exe [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “internat.exe”=internat.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys] @=“Driver” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys] @=“Driver” R3 rtl8029;Sterownik NT karty Realtek RTL8029(AS)-based PCI Ethernet;C:\WINNT\system32\DRIVERS\RTL8029.SYS S2 nvcap;nVidia WDM Video Capture (universal);C:\WINNT\system32\DRIVERS\nvcap.sys S2 nvTUNEP;nVidia WDM TVTuner;C:\WINNT\system32\DRIVERS\nvtunep.sys S2 nvtvSND;nVidia WDM TVAudio Crossbar;C:\WINNT\system32\DRIVERS\nvtvsnd.sys S2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINNT\system32\DRIVERS\NVxbar.sys . ************************************************************************** catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-30 22:39:28 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-30 22:40:05 C:\ComboFix3.txt … 2007-10-29 23:21 C:\ComboFix2.txt … 2007-10-29 23:48 . — E O F —