ComboFix 07-10-09.3 - Kyle Zhang 2007-10-09 16:40:01.2 - NTFSx86
Script execution time was exceeded on script "C:\ComboFix\osid.vbs".
Script execution was terminated.
Running from: C:\Documents and Settings\Kyle Zhang\My Documents\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-09-09 to 2007-10-09 )))))))))))))))))))))))))))))))
.
2007-10-08 15:05 d-------- C:\Program Files\MUSHclient
2007-10-07 23:31 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-07 21:59 d-------- C:\WINDOWS\system32\ActiveScan
2007-09-26 21:29 d-------- C:\Program Files\Cheat Engine
2007-09-26 21:29 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2007-09-26 21:29 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2007-09-23 19:54 d-------- C:\Program Files\Gravity
2007-09-23 18:03 d-------- C:\Documents and Settings\Kyle Zhang\Application Data\Hamachi
2007-09-23 18:00 26,056 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2007-09-20 20:43 d-------- C:\Program Files\Autofisher
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-09 20:39 --------- d-----w C:\Program Files\Kaspersky Lab
2007-10-09 12:11 88,916 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-09 12:11 339,428 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-09 12:11 26,240,288 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-09 12:11 1,019,424 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2007-10-08 03:34 --------- d-----w C:\Program Files\FlashGet
2007-10-02 20:59 --------- d-----w C:\Program Files\DivX
2007-10-01 02:06 --------- d-----w C:\Program Files\Gaiaonline
2007-09-25 02:53 65,536 ----a-w C:\WINDOWS\IFinst27.exe
2007-09-23 23:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-22 01:36 --------- d-----w C:\Program Files\Furcadia
2007-09-14 21:06 --------- d-----w C:\Program Files\Viewpoint
2007-09-14 21:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-09-11 22:31 --------- d-----w C:\Program Files\Silkroad
2007-09-02 00:45 --------- d-----w C:\Documents and Settings\Kyle Zhang\Application Data\Sony Corporation
2007-08-15 03:36 --------- d-----w C:\Program Files\MSXML 6.0
2007-08-15 03:32 --------- d-----w C:\Program Files\MSXML 4.0
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 23:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2007-07-26 23:06 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-07-26 23:06 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
1999-07-07 00:00:00 6 -csh--r C:\WINDOWS\@@desktop.dat
1999-07-07 00:00:00 6 -csh--r C:\WINDOWS\@desktop@.dat
2006-01-12 23:41:45 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-04-08 21:29:24 1,244,799 --sha-w C:\WINDOWS\system32\ppoqr.bak1
2007-04-12 02:30:45 1,409,436 --sha-w C:\WINDOWS\system32\ppoqr.bak2
2007-04-12 10:45:35 1,408,516 --sha-w C:\WINDOWS\system32\ppoqr.ini2
2007-04-12 21:46:24 1,402,195 --sha-w C:\WINDOWS\system32\svutv.bak1
2007-04-13 00:39:50 1,403,177 --sha-w C:\WINDOWS\system32\svutv.bak2
2007-04-13 18:39:08 1,408,562 --sh--w C:\WINDOWS\system32\svutv.ini2
.
((((((((((((((((((((((((((((( snapshot@2007-10-07_23.48.39.64 )))))))))))))))))))))))))))))))))))))))))
.
----a-w 163,328 2007-03-13 14:57:10 C:\WINDOWS\erdnt\subs\ERDNT.EXE
----a-w 98,304 2004-08-10 01:27:08 C:\WINDOWS\system32\cscript.exe
----a-w 28,672 2004-08-10 01:27:00 C:\WINDOWS\system32\dispex.dll
----a-w 465,864 2006-05-17 15:43:58 C:\WINDOWS\system32\jscript.dll
----a-w 151,552 2004-08-10 01:27:04 C:\WINDOWS\system32\scrobj.dll
----a-w 151,552 2004-08-10 01:27:04 C:\WINDOWS\system32\scrrun.dll
----a-w 438,272 2004-08-10 01:27:06 C:\WINDOWS\system32\vbscript.dll
----a-w 114,688 2004-08-10 01:27:16 C:\WINDOWS\system32\wscript.exe
----a-w 28,672 2004-08-10 01:27:06 C:\WINDOWS\system32\wshcon.dll
----a-w 65,536 2004-08-10 01:27:06 C:\WINDOWS\system32\wshext.dll
----a-w 98,304 2004-08-10 01:27:08 C:\WINDOWS\system32\dllcache\cscript.exe
----a-w 28,672 2004-08-10 01:27:00 C:\WINDOWS\system32\dllcache\dispex.dll
----a-w 465,864 2006-05-17 15:43:58 C:\WINDOWS\system32\dllcache\jscript.dll
----a-w 151,552 2004-08-10 01:27:04 C:\WINDOWS\system32\dllcache\scrobj.dll
----a-w 151,552 2004-08-10 01:27:04 C:\WINDOWS\system32\dllcache\scrrun.dll
----a-w 438,272 2004-08-10 01:27:06 C:\WINDOWS\system32\dllcache\vbscript.dll
----a-w 114,688 2004-08-10 01:27:16 C:\WINDOWS\system32\dllcache\wscript.exe
----a-w 28,672 2004-08-10 01:27:06 C:\WINDOWS\system32\dllcache\wshcon.dll
----a-w 65,536 2004-08-10 01:27:06 C:\WINDOWS\system32\dllcache\wshext.dll
.
----a-w 98,304 2004-08-04 10:00:00 C:\WINDOWS\system32\cscript.exe
----a-w 45,083 2004-08-04 10:00:00 C:\WINDOWS\system32\dispex.dll
----a-w 491,520 2006-10-17 18:00:00 C:\WINDOWS\system32\jscript.dll
----a-w 159,744 2004-08-04 10:00:00 C:\WINDOWS\system32\scrobj.dll
----a-w 151,552 2004-08-04 10:00:00 C:\WINDOWS\system32\scrrun.dll
----a-w 413,696 2006-10-27 20:09:58 C:\WINDOWS\system32\vbscript.dll
----a-w 114,688 2004-08-04 10:00:00 C:\WINDOWS\system32\wscript.exe
----a-w 28,672 2004-08-04 10:00:00 C:\WINDOWS\system32\wshcon.dll
----a-w 65,536 2004-08-04 10:00:00 C:\WINDOWS\system32\wshext.dll
-c--a-w 491,520 2006-10-17 18:00:00 C:\WINDOWS\system32\dllcache\jscript.dll
-c----w 413,696 2006-10-27 20:09:58 C:\WINDOWS\system32\dllcache\vbscript.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 17:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 15:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 22:05]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 12:26]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2005-01-27 13:17]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"RegistryMechanic"="" []
"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-03-24 19:09]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"gStart"="C:\Garmin\gStart.exe" [2005-07-25 11:05]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 19:38]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 05:17]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-08-20 05:45:32]
dlbcserv.lnk - C:\Program Files\Dell Photo Printer 720\dlbcserv.exe [2006-09-20 19:48:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
R3 kbdcap;kbdcap;C:\WINDOWS\system32\drivers\kbdcap.sys
S2 InCDsrvR;InCD Helper (read only);C:\Program Files\Ahead\InCD\InCDsrv.exe -r
S2 PMJ151NM;Panasonic DVC Web Camera;C:\WINDOWS\system32\DRIVERS\PMJ151NM.sys
S3 grmnusb;grmnusb;C:\WINDOWS\system32\drivers\grmnusb.sys
S3 MTDVC;Panasonic DVC USB-SERIAL Driver for NT Technology;C:\WINDOWS\system32\DRIVERS\mtdv2ku1.sys
S3 MTDVC_ENUM;Panasonic DVC COM Driver for NT Technology;C:\WINDOWS\system32\DRIVERS\mtdv2ks1.sys
S3 npkycryp;npkycryp;\??\C:\Program Files\Lineage II\system\npkycryp.sys
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys
S3 ROK;ROK;C:\DOCUME~1\KYLEZH~1\LOCALS~1\Temp\ROK.exe
S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
S4 JNGGEIFO;JNGGEIFO;C:\DOCUME~1\KYLEZH~1\LOCALS~1\Temp\JNGGEIFO.exe
S4 MIMGIC;MIMGIC;C:\DOCUME~1\KYLEZH~1\LOCALS~1\Temp\MIMGIC.exe
S4 MKBN;MKBN;C:\DOCUME~1\KYLEZH~1\LOCALS~1\Temp\MKBN.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05520de0-8177-11da-a436-0013ce2a78f8}]
AutoRun\command - Iexplores.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-10-09 20:01:33 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-09 16:46:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-10-09 16:47:46
C:\ComboFix-quarantined-files.txt ... 2007-10-09 16:47
C:\ComboFix2.txt ... 2007-10-07 23:50
.
--- E O F ---