amateur,
I dont know how to get the kaspersky log, but i got the combofix and dds
ComboFix 08-11-26.03 - Thomas Cao 2008-11-26 17:26:09.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.688 [GMT -5:00]
Running from: c:\documents and settings\Thomas Cao\My Documents\Combo-Fix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\iiffEttq.dll
c:\windows\Tasks\cvrvyokn.job
.
((((((((((((((((((((((((( Files Created from 2008-10-26 to 2008-11-26 )))))))))))))))))))))))))))))))
.
2008-11-26 17:23 . 2008-11-26 17:24 <DIR> d--hs---- c:\documents and settings\Thomas Cao\CCAFBF4419BECE80
2008-11-26 17:23 . 2008-11-26 17:23 34,816 --a------ c:\windows\system32\awtsTMdb.dll
2008-11-25 22:46 . 2008-11-25 22:46 <DIR> d-------- c:\windows\Sun
2008-11-25 22:43 . 2008-11-25 22:42 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-24 23:32 . 2008-11-25 22:29 <DIR> d-------- c:\documents and settings\Thomas Cao\.SunDownloadManager
2008-11-20 22:53 . 2008-11-20 22:53 249,592 --a------ c:\windows\system32\cssdll32.dll
2008-11-20 22:52 . 2008-11-26 17:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\comodo
2008-11-20 22:51 . 2008-11-26 17:22 <DIR> d-------- c:\program files\COMODO
2008-11-20 18:35 . 2008-11-20 21:41 3,058 --a------ c:\windows\system32\tmp.reg
2008-11-20 17:39 . 2008-11-20 17:39 <DIR> d-------- C:\rsit
2008-11-20 17:39 . 2008-11-20 17:39 <DIR> d-------- c:\program files\trend micro
2008-11-20 00:19 . 2008-11-20 00:19 <DIR> d-------- c:\program files\Windows Live Safety Center
2008-11-19 23:27 . 2008-11-19 23:36 <DIR> d-------- c:\program files\XoftSpySE
2008-11-19 22:35 . 2008-11-24 23:59 250 --a------ c:\windows\gmer.ini
2008-11-19 21:52 . 2008-11-19 21:56 <DIR> d-------- c:\program files\WinAce
2008-11-19 20:55 . 2008-11-25 17:47 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-19 20:54 . 2008-11-25 17:47 <DIR> d-------- c:\program files\SpywareBlaster
2008-11-11 21:28 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-11 21:28 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-26 22:29 41,608,480 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-26 22:29 1,153,824 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-26 22:23 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-26 22:22 557,612 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-26 22:22 108,932 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-26 03:42 --------- d-----w c:\program files\Java
2008-11-20 03:20 --------- d-----w c:\documents and settings\Thomas Cao\Application Data\LimeWire
2008-11-19 02:08 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-10 17:36 --------- d-----w c:\program files\Common Files\Adobe
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 01:10 --------- d-----w c:\program files\iTunes
2008-10-16 01:10 --------- d-----w c:\program files\iPod
2008-10-16 01:06 --------- d-----w c:\program files\QuickTime
2008-10-16 01:05 --------- d-----w c:\program files\Common Files\Apple
2008-10-16 00:45 --------- d-----w c:\program files\Bonjour
2008-10-04 15:19 --------- d-----w c:\documents and settings\Thomas Cao\Application Data\CyberLink
2008-10-04 15:18 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-04 15:18 --------- d-----w c:\program files\CyberLink
2008-10-01 17:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-29 14:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-08-29 13:53 61,440 ----a-w c:\windows\system32\dnssd.dll
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((
[email protected]_14.44.08.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-14 05:57:22 135,168 ----a-w c:\windows\system32\java.exe
+ 2008-11-26 03:42:44 144,792 ----a-w c:\windows\system32\java.exe
- 2007-12-14 05:57:24 135,168 ----a-w c:\windows\system32\javaw.exe
+ 2008-11-26 03:42:44 144,792 ----a-w c:\windows\system32\javaw.exe
- 2007-12-14 06:59:16 139,264 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-26 03:42:44 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-26 22:23:05 16,384 ----atw c:\windows\temp\Perflib_Perfdata_260.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-25 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-26 185896]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2008-11-20 278264]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= "c:\windows\system32\awtsTMdb.dll" [2008-11-26 34816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-02-25 10:59 10792 c:\program files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsTMdb]
2008-11-26 17:23 34816 c:\windows\system32\awtsTMdb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\kav\\kav7\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 CCAFBF4419BECE80;CCAFBF4419BECE80;\??\c:\documents and settings\Thomas Cao\CCAFBF4419BECE80\CCAFBF4419BECE80 []
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 GoToAssist;GoToAssist;"c:\program files\Citrix\GoToAssist\480\g2aservice.exe" Start=service [2008-02-25 16936]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - CCAFBF4419BECE80
.
Contents of the 'Scheduled Tasks' folder
2008-11-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-25 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2008-04-13 19:12]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Explorer_Run-QuickTime Task - c:\program files\WebMediaViewer\qttask.exe
.
------- File Associations -------
.
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-26 17:29:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\CCAFBF4419BECE80]
"ImagePath"="\??\c:\documents and settings\Thomas Cao\CCAFBF4419BECE80\CCAFBF4419BECE80"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1328)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\Citrix\GoToAssist\480\G2AWinLogon.dll
c:\windows\system32\klogon.dll
c:\windows\system32\awtsTMdb.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
- - - - - - - > 'lsass.exe'(1384)
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\fssync.dll
.
Completion time: 2008-11-26 17:31:06
ComboFix-quarantined-files.txt 2008-11-26 22:31:02
ComboFix2.txt 2008-11-25 19:45:42
Pre-Run: 61,689,884,672 bytes free
Post-Run: 61,781,876,736 bytes free
171 --- E O F --- 2008-11-12 04:19:10