ComboFix 07-08-17.2 - "P Gnodde" 2007-08-20 14:04:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.490 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))
2007-08-20 14:02 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-19 16:10 <DIR> d-------- C:\VundoFix Backups
2007-08-17 23:00 17,346 --a------ C:\WINDOWS\system32\gibloceg.dll
2007-08-16 19:45 23,186 --a------ C:\WINDOWS\system32\cnlyvjje.dll
2007-08-16 06:19 65,526 --a------ C:\WINDOWS\system32\dwuftfwk.dll
2007-08-16 06:13 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-08-14 16:04 61,146 --a------ C:\WINDOWS\system32\ggvvbsto.dll
2007-08-12 08:52 59,686 --a------ C:\WINDOWS\system32\xnloqgon.dll
2007-08-10 13:27 82,248 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-10 13:27 57,672 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-10 13:27 38,728 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-10 13:27 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-08-10 13:27 <DIR> d-------- C:\DOCUME~1\PGNODD~1\APPLIC~1\PC Tools
2007-08-10 13:08 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-08-10 13:06 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-01 14:37 <DIR> d-------- C:\WINDOWS\Replay Media Catcher
2007-07-31 10:11 <DIR> d-------- C:\Program Files\AWS
2007-07-31 10:03 <DIR> d-------- C:\Program Files\Common Files\3DO Shared
2007-07-31 10:03 <DIR> d-------- C:\Program Files\3DO
2007-07-29 08:47 <DIR> d--h----- C:\WINDOWS\PIF
2007-07-27 19:06 7,296 --a------ C:\WINDOWS\system32\drivers\grmnusb.sys
2007-07-27 19:06 17,536 --a------ C:\WINDOWS\system32\drivers\grmn0200.sys
2007-07-27 19:06 17,024 --a------ C:\WINDOWS\system32\drivers\grmngen.sys
2007-07-27 19:06 16,512 --a------ C:\WINDOWS\system32\drivers\grmn0400.sys
2007-07-27 19:06 11,776 --a------ C:\WINDOWS\system32\drivers\grmn1200.sys
2007-07-27 19:06 <DIR> d-------- C:\Garmin
2007-07-22 11:17 <DIR> d-------- C:\Program Files\THQ
2007-07-22 11:11 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-22 11:11 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Sjablonen
2007-07-21 21:04 <DIR> d-------- C:\DOCUME~1\PGNODD~1\APPLIC~1\BullGuard
2007-07-21 21:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BullGuard
2007-07-21 14:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic(2)
2007-07-20 23:21 9,699,328 --a------ C:\DOCUME~1\PGNODD~1\ntuser.dat
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-19 2OCUME~1\PGNODD~1\APPLIC~1\dvdcss
2007-08-19 1rogram Files\nbpro
2007-08-13 1rogram Files\PKR
2007-08-11 0rogram Files\Everest Poker
2007-08-03 0rogram Files\World of Warcraft
2007-07-31 10:13 28400 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-07-22 1rogram Files\PartyGaming
2007-07-22 1rogram Files\Google
2007-07-05 1rogram Files\iPod
2007-07-05 1rogram Files\QuickTime
2007-07-05 1rogram Files\Apple Software Update
2007-07-05 1rogram Files\Common Files\Apple
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-23 1rogram Files\RegistryFix
2007-06-21 18:11 512096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-06-21 18:11 298104 --a------ C:\WINDOWS\system32\imon.dll
2007-06-21 18:11 15424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-06-19 15:33 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 15:24 1036800 --a------ C:\WINDOWS\explorer.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-26 08:16 C:\WINDOWS\RTHDCPL.EXE]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 14:00 C:\WINDOWS\system32\bthprops.cpl]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 14:27]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-30 00:48]
"nod32kui"="g:\Program Files\Eset\nod32kui.exe" [2007-06-21 18:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="G:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"gStart"="C:\Garmin\gStart.exe" [2006-09-06 10:05]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\P Gnodde\Menu Start\Programma's\Opstarten\
TimeLeft.lnk - C:\Program Files\TimeLeft3\TimeLeft.exe [2007-06-02 19:27:09]
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-11-27 10:19:28]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R0 SI3132;SiI-3132 SATALink Controller;C:\WINDOWS\system32\DRIVERS\SI3132.sys
S3 BTNetFilter;Bluetooth Network Filter;\??\C:\WINDOWS\system32\drivers\BTNetFilter.sys
S3 grmnusb;grmnusb;C:\WINDOWS\system32\drivers\grmnusb.sys
Contents of the 'Scheduled Tasks' folder
2007-07-05 11:15:46 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-20 11:32:08 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-20 14:07:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-20 14:07:53
--- E O F ---