ComboFix 08-03-24.1 - kp 2008-03-24 17:34:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.997 [GMT -4:00]
Running from: C:\Documents and Settings\kp\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.exe
C:\WINDOWS\dwnrpofk.dll
C:\WINDOWS\mslagent
C:\WINDOWS\mslagent\2_mslagent.dll
C:\WINDOWS\mslagent\mslagent.exe
C:\WINDOWS\mslagent\uninstall.exe
.
((((((((((((((((((((((((( Files Created from 2008-02-24 to 2008-03-24 )))))))))))))))))))))))))))))))
.
2008-03-24 16:13 . 2008-03-24 16:13 <DIR> d-------- C:\Program Files\Windows Defender
2008-03-24 14:51 . 2008-03-24 14:51 <DIR> d-------- C:\Program Files\PC-Cleaner
2008-03-24 14:10 . 2008-03-24 14:10 <DIR> d-------- C:\Documents and Settings\kp\Desktopvirii
2008-03-24 14:10 . 2008-03-24 14:10 4,096 --a------ C:\Documents and Settings\kp\DesktopTrojan.Win32.BlackBird.exe
2008-03-24 14:10 . 2008-03-24 14:10 4,096 --a------ C:\Documents and Settings\kp\DesktopFWebdEditor.exe
2008-03-24 14:10 . 2008-03-24 14:10 4,096 --a------ C:\Documents and Settings\kp\Desktopfwebd.exe
2008-03-24 14:10 . 2008-03-24 14:10 4,096 --a------ C:\Documents and Settings\kp\Desktopfkwp2.0.exe
2008-03-24 14:10 . 2008-03-24 14:10 4,096 --a------ C:\Documents and Settings\kp\Desktopfkwp1.5.exe
2008-03-24 14:10 . 2008-03-24 14:10 4,096 --a------ C:\Documents and Settings\kp\Desktopfilemanagerclient.exe
2008-03-24 14:10 . 2008-03-24 14:10 4,096 --a------ C:\Documents and Settings\kp\DesktopEditorFKWP2.0.exe
2008-03-24 14:10 . 2008-03-24 14:10 4,096 --a------ C:\Documents and Settings\kp\DesktopEditorFKWP1.5.exe
2008-03-24 14:09 . 2008-03-24 14:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\tmxudghg
2008-03-24 14:09 . 2008-03-24 12:41 270,336 --a------ C:\WINDOWS\vbgtorfd.dll
2008-03-24 14:09 . 2008-03-24 12:41 249,856 --a------ C:\WINDOWS\kdftlboeopx.dll
2008-03-24 14:09 . 2008-03-24 14:09 114,688 --a------ C:\WINDOWS\system32\dyfqvibg.exe
2008-03-24 14:06 . 2008-03-24 14:07 45 --a------ C:\xmp.bat
2008-03-11 11:45 . 2008-03-16 18:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-11 11:45 . 2008-03-11 11:45 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-04 15:15 . 2008-03-04 15:15 <DIR> d-------- C:\Program Files\MSECache
2008-03-03 21:14 . 2008-03-03 21:15 <DIR> d-------- C:\Program Files\MFInstall
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-24 20:25 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-03-23 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-03-18 01:38 --------- d-----w C:\Program Files\mIRC
2008-03-11 14:42 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-03-03 03:51 --------- d-----w C:\Program Files\Trillian
2008-02-22 19:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-18 15:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Philips Intelligent Agent
2008-01-12 17:50 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2F97A8CB-0E8F-4AF0-B737-12C03F355794}]
2008-03-24 12:41 249856 --a------ C:\WINDOWS\kdftlboeopx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"Philips Intelligent Agent"="C:\Program Files\Philips Intelligent Agent\Philips Intelligent Agent.exe" [2007-03-06 11:58 579760]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 18:43 4670704]
"gagehbjp"="C:\WINDOWS\system32\dyfqvibg.exe" [2008-03-24 14:09 114688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 13:08 143360]
"nwiz"="nwiz.exe" [2006-08-11 21:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
"PDF Complete"="C:\Program Files\PDF Complete\pdfsty.exe" [2005-03-07 00:52 276480]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 09:21 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 19:27 85696]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 17:48 479232]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 21:43 86016]
"DLink Control Panel Silent"="dlnetcp.cpl" [2003-09-29 04:14 471040 C:\WINDOWS\system32\dlNetCp.cpl]
"DLink System Tray"="C:\Program Files\D-Link\DGE-530T\dlnetst.exe" [2003-09-29 04:14 24576]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2005-02-04 09:14 1695744]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088]
"NWEReboot"="" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2006-05-30 15:22 542208]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2008-02-17 22:23 2476408]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 15:07 188416]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 15:07 348160]
"HPHUPD04"="C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-12 14:25 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 11:56 286720]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
C:\Documents and Settings\kp\Start Menu\Programs\Startup\
Trillian.lnk - C:\Program Files\Trillian\trillian.exe [2007-12-11 01:00:00 1873280]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-03-23 12:01:40 106560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"k0qetSkS9C"= C:\Documents and Settings\All Users\Application Data\tmxudghg\hstgvazg.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PrxWin"= {3947aea9-6ef5-44be-a61f-5601a663649e} - C:\WINDOWS\Installer\{3947aea9-6ef5-44be-a61f-5601a663649e}\PrxWin.dll [2008-03-24 14:08 14378]
"vbgtorfd"= {0CFDAE17-0694-4B7F-8DAD-05452DC297FE} - C:\WINDOWS\vbgtorfd.dll [2008-03-24 12:41 270336]
"dwnrpofk"= {44633588-96DA-4372-B682-A1BA04330009} - C:\WINDOWS\dwnrpofk.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"587:TCP"= 587:TCP:outlook
R2 pdfcDispatcher;PDF Document Manager;C:\Program Files\PDF Complete\pdfsvc.exe [2005-03-07 00:52]
S3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link PCI Express Ethernet Controller;C:\WINDOWS\system32\DRIVERS\m4cxw2k3.sys [2006-06-22 00:39]
S3 m4cxwxp;NDIS5.1 Miniport Driver for D-Link DGE-530T Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\m4cxwxp.sys [2003-08-27 06:23]
S3 SkLaggProtocol;Link Aggregation Protocol (LAGG) Support;C:\WINDOWS\system32\DRIVERS\sklagg.sys []
.
Contents of the 'Scheduled Tasks' folder
"2007-12-20 21:33:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-24 21:09:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-03-24 20:57:47 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
"2008-03-24 20:57:48 C:\WINDOWS\Tasks\HP Usg Login.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
"2008-03-24 20:28:06 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-24 17:36:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="C:\Program Files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
Completion time: 2008-03-24 17:37:27
ComboFix-quarantined-files.txt 2008-03-24 21:37:24
.
2008-03-23 03:09:35 --- E O F ---