"Korene" - 07-05-02 18:11:13 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\Korene\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\cbawx.dll
C:\WINDOWS\system32\xxyvw.dll
C:\WINDOWS\system32\etbpjgku.dll
C:\WINDOWS\system32\jjoakeak.dll
C:\WINDOWS\system32\qcfcxmon.dll
C:\WINDOWS\system32\vgqaqbqv.dll
C:\WINDOWS\system32\mljiihf.dll
C:\WINDOWS\system32\mljjihi.dll
C:\WINDOWS\system32\urqnmmk.dll
C:\WINDOWS\system32\vturonm.dll
C:\WINDOWS\system32\xxyvtus.dll
C:\WINDOWS\system32\xxyxyaw.dll
C:\WINDOWS\system32\xwabc.ini2
C:\WINDOWS\system32\xwabc.tmp
C:\WINDOWS\system32\wvyxx.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\ipwindows\ipwins.exe
C:\Program Files\ipwindows\UnInstall.exe
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\hosts
C:\Program Files\inetget2
C:\Program Files\ipwindows
((((((((((((((((((((((((((((((( Files Created from 2007-04-02 to 2007-05-02 ))))))))))))))))))))))))))))))))))
2007-05-02 18:05 <DIR> d-------- C:\DOCUME~1\Korene\APPLIC~1\Comodo
2007-05-02 18:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
2007-05-02 17:58 <DIR> d-------- C:\Program Files\Comodo
2007-05-01 20:49 869,950 ---hs---- C:\WINDOWS\SYSTEM32\ddcfe.bak1
2007-05-01 20:25 26,678 --a------ C:\WINDOWS\SYSTEM32\nnnlkjh.dll
2007-05-01 20:21 26,678 --a------ C:\WINDOWS\SYSTEM32\nnnkkhh.dll
2007-04-30 20:49 865,376 ---hs---- C:\WINDOWS\SYSTEM32\ddcfe.bak2
2007-04-30 20:49 132,660 --a------ C:\WINDOWS\SYSTEM32\bqnfbrcm.dll
2007-04-30 20:06 26,678 --a------ C:\WINDOWS\SYSTEM32\khfdede.dll
2007-04-30 20:05 270,336 --a------ C:\DOCUME~1\Korene\olo.exe
2007-04-30 20:05 26,678 --a------ C:\WINDOWS\SYSTEM32\pmnkkhe.dll
2007-04-30 20:05 12,374 --a------ C:\DOCUME~1\Korene\sis.exe
2007-04-30 20:01 26,678 --a------ C:\WINDOWS\SYSTEM32\mljklkh.dll
2007-04-30 18:14 284,244 ---hs---- C:\WINDOWS\SYSTEM32\efcdd.dll
2007-04-30 18:14 284,244 ---hs---- C:\WINDOWS\SYSTEM32\cbxyx.dll
2007-04-30 17:40 45,056 --a------ C:\WINDOWS\retadpu1000904.exe
2007-04-30 17:40 26,678 --a------ C:\WINDOWS\SYSTEM32\yayvuvs.dll
2007-04-26 23:31 77,312 --a------ C:\WINDOWS\ua2.dll
2007-04-26 22:01 272,384 --a--c--- C:\kk.exe
2007-04-26 21:59 956,525 ---hs---- C:\WINDOWS\SYSTEM32\gffii.bak2
2007-04-26 21:28 961,837 ---hs---- C:\WINDOWS\SYSTEM32\gffii.ini2
2007-04-26 17:31 956,193 ---hs---- C:\WINDOWS\SYSTEM32\gffii.bak1
2007-04-26 17:24 272,384 --a------ C:\WINDOWS\kk.exe
2007-04-24 10:11 <DIR> d-------- C:\Program Files\Showoff Home Design
2007-04-22 16:53 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
2007-04-22 14:01 <DIR> d-------- C:\Program Files\Bonjour
2007-04-22 13:45 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-04-15 09:59 81 --a--c--- C:\CTX.DAT
2007-04-15 09:59 <DIR> d-------- C:\DOCUME~1\Korene\Citrix
2007-04-10 18:05 <DIR> d-------- C:\Program Files\Verbatim
2007-04-09 13:33 <DIR> d-------- C:\Program Files\Benjamin Moore
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-27 18:38 62266 --a------ C:\WINDOWS\SYSTEM32\nvmodes.dat
2007-04-26 17:25 -------- d-------- C:\Program Files\msn messenger
2007-04-22 19:08 -------- d-------- C:\Program Files\google
2007-04-22 18:58 -------- d--h----- C:\Program Files\installshield installation information
2007-03-21 20:54 77312 --a------ C:\WINDOWS\SYSTEM32\twain_32.dll
2007-03-21 20:54 69632 --a------ C:\WINDOWS\SYSTEM32\twunk_32.exe
2007-03-21 20:54 48560 --a------ C:\WINDOWS\SYSTEM32\twunk_16.exe
2007-03-19 17:32 -------- d-------- C:\Program Files\logitech
2007-03-18 10:32 44288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\cdr4_xp.sys
2007-03-17 06:43 292864 --a------ C:\WINDOWS\SYSTEM32\winsrv.dll
2007-03-15 07:08 101438 --a------ C:\WINDOWS\b122.exe
2007-03-08 08:36 577536 --a------ C:\WINDOWS\SYSTEM32\user32.dll
2007-03-08 08:36 40960 --a------ C:\WINDOWS\SYSTEM32\mf3216.dll
2007-03-08 08:36 281600 --a------ C:\WINDOWS\SYSTEM32\gdi32.dll
2007-03-08 06:47 1843584 --a------ C:\WINDOWS\SYSTEM32\win32k.sys
2007-02-08 00:24 323624 --a------ C:\WINDOWS\SYSTEM32\wiaaut.dll
2007-02-05 13:17 185344 --a------ C:\WINDOWS\SYSTEM32\upnphost.dll
2007-02-03 10:32 527136 --a------ C:\WINDOWS\SYSTEM32\lvui2rc.dll
2007-02-03 10:32 215840 --a------ C:\WINDOWS\SYSTEM32\lvui2.dll
2007-02-03 10:29 264992 --a------ C:\WINDOWS\SYSTEM32\lvcodec2.dll
2007-02-03 10:29 129824 --a------ C:\WINDOWS\SYSTEM32\lvci1051.dll
2007-02-03 09:01 13398 --a------ C:\WINDOWS\SYSTEM32\repository.reg
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{469A7591-94FA-43BF-B8F7-91B00715363B} C:\WINDOWS\system32\yayvuvs.dll
{4A368E80-174F-4872-96B5-0B27DDD11DB2} C:\Program Files\Spy Ware Apps\SpywareGuard\dlprotect.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{8D0C8CC2-40CB-4B1E-B6C2-0C572E10BDB3} C:\WINDOWS\system32\efcdd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"PCTVOICE"="pctspk.exe"
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"VF0070 STISvc"="RunDLL32.exe V0070Pin.dll,RunDLL32EP 513"
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_07\\bin\\jusched.exe"
"Motive SmartBridge"="C:\\PROGRA~1\\TELUSE~1\\SMARTB~1\\MotiveSB.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"LogitechCommunicationsManager"="\"C:\\Program Files\\Common Files\\LogiShrd\\LComMgr\\Communications_Helper.exe\""
"LogitechQuickCamRibbon"="\"C:\\Program Files\\Logitech\\QuickCam10\\QuickCam10.exe\" /hide"
"ButtonMonitor"="C:\\Program Files\\Verbatim\\ButtonMonitor\\/ButtonMonitor.exe"
"runner1"="C:\\WINDOWS\\retadpu1000904.exe 61A847B5BBF72813329B385F72FD01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310"
"InfoData"="rundll32.exe \"C:\\WINDOWS\\system32\\bqnfbrcm.dll\",realset"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"COMODO Firewall Pro"="\"C:\\Program Files\\Comodo\\Firewall\\CPF.exe\" /background"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"PopUpStopperFreeEdition"="\"C:\\Program Files\\Panicware\\Pop-Up Stopper Free Edition\\PSFree.exe\""
"Registry Cleaner Scheduler"="\"C:\\Program Files\\CleanMyPC\\Registry Cleaner\\RCScheduler.exe\" /startup"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"IpWins"="C:\\Program Files\\Ipwindows\\ipwins.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EC496241-89E3-4449-A6EF-9FBC6C8CCA93}"=""
"{0EB1F5A0-D3DD-4F3F-AFFC-9DBE20DB79B0}"=""
"{469A7591-94FA-43BF-B8F7-91B00715363B}"=""
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcdd
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyxxx
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ied026
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiffg
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqronom
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayvuvs
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe\" "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
"backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -h"
"item"="Kodak EasyShare software"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
"backup"="C:\\WINDOWS\\pss\\Kodak software updater.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE "
"item"="Kodak software updater"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DirectCD"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MimBoot"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MMTray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mm_tray.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="New.net Startup"
"hkey"="HKLM"
"command"="rundll32 C:\\PROGRA~1\\NEWDOT~1\\NEWDOT~1.DLL,NewDotNetStartup -s"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Reminder"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TkBellExe"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
HTTPFilter REG_MULTI_SZ HTTPFilter\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_CMDAGENT
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_CMDMON
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_INSPECT
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20050815-090930-458
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
backup-20050503-032545-940
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
backup-20050503-032534-675
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
backup-20050502-164216-896
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
backup-20050502-164216-439
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
backup-20050502-164216-196
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
backup-20050502-164216-807
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
backup-20050502-164216-629
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
backup-20050502-164216-332
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
backup-20050502-164216-523
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
backup-20050502-164216-552
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
backup-20050418-184015-711
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
http://download.abac...abasetup132.cab
backup-20050418-184015-555
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} -
http://www.azebar.co...l/azesearch.cab
backup-20050418-184015-733
O3 - Toolbar: Search Toolbar - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - C:\WINDOWS\system32\azesearch3.dll
backup-20050418-184015-450
O2 - BHO: AddressBar Class - {f65b197f-8260-4d52-909a-f70118e646eb} - C:\WINDOWS\system32\iasadm.dll
backup-20050418-184015-947
O2 - BHO: ZToolbar Activator Class - {da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} - C:\WINDOWS\system32\azesearch3.dll
backup-20050418-184014-628
O2 - BHO: AddressBar Class - {1474CE44-8057-4AE3-8F3E-ED37C7C63D8A} - C:\WINDOWS\system32\iasad.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Symantec NetDetect.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-02 18:26:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-05-02 18:27:26
C:\ComboFix-quarantined-files.txt ... 07-05-02 18:27