ComboFix 09-01-31.01 - Bogdanian 2009-01-31 23:44:42.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.656 [GMT 2:00]
Running from: c:\documents and settings\Bogdanian\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-31 )))))))))))))))))))))))))))))))
.
2009-01-31 23:22 . 2009-01-31 23:22 <DIR> d-------- C:\10853
2009-01-31 22:49 . 2009-01-31 22:49 <DIR> d-------- C:\4234
2009-01-31 22:45 . 2009-01-31 22:45 <DIR> d-------- C:\3440
2009-01-31 01:58 . 2009-01-31 01:58 <DIR> d-------- C:\_OTScanIt
2009-01-31 01:04 . 2009-01-31 01:04 217,088 --a------ C:\zip.exe
2009-01-31 01:04 . 2009-01-31 01:04 19,286 --a------ C:\cleanup.exe
2009-01-31 01:04 . 2009-01-31 01:04 1,297 --a------ C:\backup.reg
2009-01-31 01:04 . 2009-01-31 01:04 574 --a------ C:\cleanup.bat
2009-01-29 23:34 . 2009-01-29 23:34 4,408,452 --a------ C:\SPMT.rar
2009-01-23 20:42 . 2009-01-23 20:53 <DIR> d-------- C:\Vladu - materiale finale, corectate
2009-01-23 20:09 . 2009-01-23 20:41 156,672 --a------ C:\Revista - Vladu - corectat, TOT.doc
2009-01-23 19:49 . 2009-01-20 22:03 565,756 --a------ C:\Virgil GEORGESCU jr..jpg
2009-01-23 19:48 . 2009-01-23 19:48 1,560,614 --a------ C:\DSC_0185.JPG
2009-01-23 19:46 . 2006-03-07 19:50 421,157 --a------ C:\DSC09990.JPG
2009-01-23 01:02 . 2009-01-03 05:00 257,895 --a------ C:\screenshot.png
2009-01-23 01:00 . 2009-01-03 04:07 734,789,316 --a------ C:\HIM-Rockpalast.2000.DVBRip.x264.HIMMANIA.mkv
2009-01-23 01:00 . 2009-01-03 05:00 260,068 --a------ C:\screens-thumbs.jpg
2009-01-16 10:35 . 2009-01-16 10:37 54,530 --a------ C:\DSCF3572.jpg
2009-01-14 17:09 . 2009-01-14 17:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Winter Sports 2009
2009-01-01 02:10 . 2009-01-01 02:11 <DIR> d-------- c:\windows\NV20842420.TMP
2009-01-01 02:09 . 2009-01-01 02:09 <DIR> d-------- C:\NVIDIA
2009-01-01 02:06 . 2009-01-01 02:06 <DIR> d-------- c:\program files\SystemRequirementsLab
2009-01-01 01:36 . 2009-01-01 01:36 <DIR> d-------- c:\windows\Logs
2008-12-31 03:21 . 2008-12-31 03:21 <DIR> d-------- C:\2000
2008-12-26 17:20 . 2008-12-26 17:20 <DIR> d-------- c:\program files\Common Files\EasyInfo
2008-12-16 03:22 . 2008-12-17 18:43 <DIR> d-------- C:\CM
2008-12-14 21:10 . 2008-12-14 21:13 <DIR> d-------- c:\documents and settings\Bogdanian\Application Data\GrabIt
2008-12-02 16:19 . 2009-01-30 00:03 <DIR> d-------- c:\program files\Eset
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 12:38 --------- d-----w c:\program files\SpywareBlaster
2009-01-29 21:51 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-29 21:41 --------- d-----w c:\program files\SPMT
2009-01-29 21:33 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-29 21:32 --------- d-----w c:\program files\NoAdware5.0
2009-01-29 19:34 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-21 10:07 --------- d-----w c:\documents and settings\Bogdanian\Application Data\PlayFirst
2009-01-15 10:41 --------- d-----w c:\program files\Common Files\Adobe
2009-01-14 14:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 14:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-10 22:25 --------- d-----w c:\program files\oDC
2009-01-07 00:59 --------- d-----w c:\documents and settings\All Users\Application Data\Soulseek
2009-01-05 10:54 --------- d-----w c:\program files\Java
2009-01-02 19:54 --------- d-----w c:\documents and settings\Bogdanian\Application Data\mIRC
2009-01-02 19:01 --------- d-----w c:\program files\mIRC
2008-12-31 23:32 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-28 16:18 --------- d-----w c:\documents and settings\Bogdanian\Application Data\dvdcss
2008-12-20 19:27 --------- d-----w c:\program files\Winamp
2008-12-20 19:27 --------- d-----w c:\program files\LHM2006
2008-12-20 19:27 --------- d-----w c:\program files\LHM2003-2004
2008-12-20 19:27 --------- d-----w c:\program files\DVD Photo Slideshow Professional
2008-12-20 19:27 --------- d-----w c:\program files\Batch Watermark Creator
2008-12-20 19:27 --------- d-----w c:\program files\Astral Masters
2008-12-02 14:19 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-03-14 19:56 22,328 ----a-w c:\documents and settings\Bogdanian\Application Data\PnkBstrK.sys
2008-02-23 19:47 560 ----a-w c:\program files\Global.sw
2004-10-01 13:00 110,592 ----a-w c:\program files\Uninstall_CDS.exe
2006-05-03 09:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2006-10-24 4732408]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-05 253368]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-18 1003520]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 135168]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 163840]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 102400]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2006-11-02 1397760]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-01-09 135260]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 159744]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 229376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 214424]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 113520]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:\windows\system32\HdAShCut.exe]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
"P17Helper"="P17.dll" [2005-05-03 c:\windows\system32\P17.dll]
c:\documents and settings\Bogdanian\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 187392]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-08-06 51776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"VIDC.ACDV"= ACDV.dll
"MSVideo"= CSvidcap.dll
"vidc.dvsd"= pdvcodec.dll
"msacm.ac3filter"= ac3filter.acm
"VIDC.mjpg"= mcmjpg32.dll
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Marvel game\\Marvel Vs\\MarvelVs.exe"=
"e:\\motogp2\\motogp2.exe"=
"e:\\Warcraft III- Reign of Chaos & Frozen Throne\\warcraft iii\\Warcraft III.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"g:\\BitLord\\BitLord.exe"=
"c:\\Program Files\\oDC\\oDC.exe"=
"g:\\CrySis Game\\Bin32\\Crysis.exe"=
"g:\\CrySis Game\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\system32\\TV_View_Plugin_4.7.ocx"=
"e:\\Guitar Hero 3\\GH3.exe"=
"c:\\Program Files\\oDC\\StrongDC.exe"=
"d:\\ZOMBIESS\\System\\LOTD.exe"=
"g:\\Far2\\Far Cry 2\\bin\\FarCry2.exe"=
"g:\\Far2\\Far Cry 2\\bin\\FC2Launcher.exe"=
"g:\\Far2\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"d:\\Games-kitturi\\FIFA2007\\fifa07.exe"=
"c:\\WINDOWS\\system32\\HDAShCut.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"=
"c:\\WINDOWS\\notepad.exe"=
"c:\\WINDOWS\\system32\\nwiz.exe"=
"c:\\Program Files\\Creative\\Shared Files\\CTSched.exe"=
"c:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe"=
"c:\\WINDOWS\\system32\\CF14749.exe"=
R3 asc3360pr;asc3360pr;\??\c:\windows\system32\drivers\gnhhmu.sys --> c:\windows\system32\drivers\gnhhmu.sys [?]
R4 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2007-11-15 2560]
S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys --> c:\windows\system32\drivers\nod32drv.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASC3360PR
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\LaunchU3.exe -a
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uLocal Page = \blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.ro
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
FF - ProfilePath - c:\documents and settings\Bogdanian\Application Data\Mozilla\Firefox\Profiles\8r9j2g21.default\
FF - plugin: c:\documents and settings\Bogdanian\Application Data\Mozilla\plugins\npPxPlay.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-31 23:47:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \EC1A69D1C0948222]
"1"=hex:b0,cd,e0,26,42,20,9e,7c,08,f1,c1,23,e7,41,66,ec,c9,e0,20,43,a1,23,f2,
e3
"2"=hex:f1,df,16,de,80,08,0e,2a,78,a4,28,cb,d2,56,ff,58,a6,09,d8,fb,43,e9,d5,
e7,16,83,71,61,5d,be,d8,25
"3"=hex:b0,cd,e0,26,42,20,9e,7c,08,f1,c1,23,e7,41,66,ec,2b,92,4b,0d,22,14,9d,
cb,e3,f8,73,90,7d,a4,36,0d,7e,db,3a,16,4c,1a,45,81,b1,a5,77,31,f5,50,d6,e8
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \EC1A69D1C0948222\B144CCE307E78EB6EE53CA2196E4D0A2]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,36,d7,56,53,fe,9f,3d,f9
"2"=hex:8c,23,2d,03,75,bd,a0,cd
"3"=hex:ae,73,3f,fd,2b,83,eb,67,f2,93,90,8f,76,ae,d1,e9,96,73,d7,92,15,c0,66,
82,55,81,f1,8f,d8,ad,02,60,ee,7e,c3,37,11,d9,b4,42,f8,9d,1e,81,3f,79,76,02,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:6b,96,68,24,0f,2f,9e,94,e8,ce,54,f3,3b,80,63,3a,1b,c3,e7,ed,44,3a,1d,
97,9f,f9,03,77,68,81,1b,0c,34,a2,88,30,12,be,09,a0
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,73,7e,45,c6,9f,9e,10,
63,a0,2f,06,c2,a3,e9,62,70,90,4c,ec,d6,92,e1,28,ba,e5,5d,0d,25,ef,fb,b7,21,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:70,56,26,33,e3,20,f8,ab
"10"=hex:8a,86,86,9a,b4,43,5e,10
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Photodex\ProShowGold\scsiaccess.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-01-31 23:51:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-31 21:51:01
ComboFix2.txt 2009-01-30 20:27:59
Pre-Run: 2,764,701,696 bytes free
Post-Run: 2,783,842,304 bytes free
259 --- E O F --- 2008-06-27 22:52:18
PS: At the beginning, the ComboFix reveal a error [look on attachement], I chosse the CONTINUE button, and then the Combo begin to complete the stages normally.