combo2
((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.
2008-01-04 12:42 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-04 12:34 . 2008-01-04 12:34 29 --a------ C:\WINDOWS\system32\fyqgihat.tmp
2008-01-03 10:58 . 2008-01-03 10:58 <DIR> d-------- C:\Program Files\Avira
2008-01-03 10:58 . 2008-01-03 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-01-03 10:37 . 2008-01-03 10:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-03 10:08 . 2008-01-03 10:08 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-02 17:13 . 2008-01-02 17:13 <DIR> d-------- C:\kav
2008-01-02 15:59 . 2008-01-02 15:59 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2008-01-02 10:41 . 2008-01-02 10:41 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-02 10:41 . 2008-01-02 10:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-01 20:00 . 2008-01-03 11:30 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-01 18:55 . 2008-01-01 20:02 1,031,199 --ahs---- C:\WINDOWS\system32\mbdgwehj.ini
2008-01-01 16:22 . 2008-01-01 16:45 1,031,148 --ahs---- C:\WINDOWS\system32\cdbeyvdy.ini
2007-12-31 22:10 . 2008-01-03 13:23 <DIR> d-------- C:\Program Files\kernel
2007-12-31 22:01 . 2007-12-31 22:01 <DIR> d-------- C:\WINDOWS\system32\ardCo01
2007-12-31 22:01 . 2007-12-31 22:01 <DIR> d-------- C:\Temp\cEeer12
2007-12-31 12:15 . 2007-12-31 12:16 1,031,139 --ahs---- C:\WINDOWS\system32\mvhplesj.ini
2007-12-30 18:28 . 2007-12-30 21:30 1,031,139 --ahs---- C:\WINDOWS\system32\cvhfaosa.ini
2007-12-30 10:42 . 2007-12-30 10:42 1,031,319 --ahs---- C:\WINDOWS\system32\dkpuxvdr.tmp
2007-12-29 20:02 . 2007-12-29 20:03 1,031,199 --ahs---- C:\WINDOWS\system32\dkpuxvdr.ini2
2007-12-29 18:48 . 2008-01-02 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-28 09:56 . 2007-12-28 10:33 1,031,199 --ahs---- C:\WINDOWS\system32\cxdxixcl.ini
2007-12-25 18:30 . 2007-12-26 11:06 1,027,582 --ahs---- C:\WINDOWS\system32\okjqjxci.ini
2007-12-24 18:31 . 2007-12-24 18:31 294 --ahs---- C:\WINDOWS\system32\qhhggccv.ini
2007-12-21 14:53 . 2007-12-21 14:53 137,216 --a------ C:\WINDOWS\system32\drivers\Pjmr55.sys
2007-12-15 14:00 . 2007-12-15 14:03 <DIR> d-------- C:\Program Files\iTunes
2007-12-15 13:40 . 2007-12-15 13:45 <DIR> d-------- C:\Program Files\QuickTime
2007-12-14 19:50 . 2007-12-18 07:44 4,565 --a------ C:\WINDOWS\system32\sft.res
2007-12-14 12:19 . 2007-12-14 12:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Citrix
2007-12-13 09:34 . 2008-01-03 14:14 <DIR> d-------- C:\WINDOWS\sdir
2007-12-12 15:32 . 2007-12-12 15:32 294 --ahs---- C:\WINDOWS\system32\mxpcwkwh.ini
2007-12-11 10:57 . 2007-12-11 10:57 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
2007-12-11 09:18 . 2007-12-11 09:18 <DIR> d--h----- C:\C_DILLA
2007-12-11 09:18 . 2007-12-11 09:17 112,128 -r-h----- C:\WINDOWS\CdaC14BA.DLL
2007-12-11 09:18 . 2007-12-11 09:18 39,936 --a------ C:\WINDOWS\system32\drivers\CDAC11BA.EXE
2007-12-11 09:18 . 2007-12-11 09:17 30,720 -r-h----- C:\WINDOWS\CdaC13BA.EXE
2007-12-07 13:58 . 2007-12-13 09:48 <DIR> d-------- C:\Documents and Settings\rachp\Application Data\ArcSoft
2007-12-07 13:50 . 2007-12-12 19:13 8,864 --a------ C:\WINDOWS\system32\drivers\CDAC15BA.SYS
2007-12-05 16:09 . 2007-12-29 14:20 <DIR> d-------- C:\Documents and Settings\Danielle\Application Data\BLSTOOLBAR
2007-12-05 10:27 . 2007-12-05 10:27 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-04 21:03 . 2007-12-04 21:03 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-12-04 18:35 . 2007-12-06 16:19 4 --a------ C:\WINDOWS\system32\jpewocmz.ini
2007-12-04 09:29 . 2007-12-04 10:11 7,043 --ahs---- C:\WINDOWS\system32\jmllm.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 14:53 --------- d-----w C:\Program Files\Common Files\okwf
2008-01-03 14:53 --------- d-----w C:\Documents and Settings\LocalService\Application Data\BLSTOOLBAR
2008-01-01 07:43 --------- d-----w C:\Program Files\Microsoft Image Composer
2007-12-30 02:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Rabio
2007-12-29 19:20 --------- d-----w C:\Documents and Settings\rachp\Application Data\blstoolbar
2007-12-29 19:19 --------- d-----w C:\Documents and Settings\rachp\Application Data\LimeWire
2007-12-15 19:02 --------- d-----w C:\Program Files\iPod
2007-12-13 17:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-13 17:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-05 19:34 --------- d-----w C:\Program Files\Zpsekzdo
2007-12-05 19:33 --------- d-----w C:\Program Files\Twpejcvz
2007-12-03 16:17 --------- d-----w C:\Program Files\wdcbcxyx
2007-11-29 21:45 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-11-29 13:38 --------- d-----w C:\Documents and Settings\Administrator.TOSHIBA-USER.000\Application Data\Viewpoint
2007-11-29 03:40 --------- d-----w C:\Documents and Settings\Administrator.TOSHIBA-USER.000\Application Data\PC Tools
2007-11-26 18:16 --------- d-----w C:\Program Files\MySpace
2007-11-26 15:22 --------- d-----w C:\Program Files\Cool
2007-11-24 18:00 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-24 16:19 --------- d-----w C:\Program Files\blstoolbar
2007-11-24 14:56 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-23 22:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-23 20:54 --------- d-----w C:\Documents and Settings\rachp\Application Data\Viewpoint
2007-11-23 20:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-23 19:41 --------- d-----w C:\Program Files\Symantec
2007-11-20 00:30 --------- d-----w C:\Documents and Settings\rachp\Application Data\Media Player Classic
2007-11-15 03:05 --------- d-----w C:\Documents and Settings\Danielle\Application Data\Yahoo!
2007-11-15 03:02 --------- d-----w C:\Documents and Settings\Danielle\Application Data\TuneUp Software
2007-11-15 03:01 --------- d-----w C:\Documents and Settings\Danielle\Application Data\MySpace
2007-11-13 16:06 --------- d-----w C:\Program Files\Microsoft Plus!
2007-11-13 02:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-11-13 00:44 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-11-13 00:43 --------- d-----w C:\Program Files\InterVideo
2007-11-09 04:24 --------- d-----w C:\Program Files\Plus! for Windows XP
2007-11-09 04:19 --------- d-----w C:\Program Files\TuneUp Utilities 2004
2007-11-09 04:18 --------- d-----w C:\Documents and Settings\rachp\Application Data\TuneUp Software
2007-10-27 17:27 66,269 ----a-w C:\Program Files\INSTALL.LOG
2003-08-27 21:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
2005-09-26 22:49 422,726 --sha-w C:\WINDOWS\system32\kjllm.bak1
2005-10-07 19:20 338,578 --sha-w C:\WINDOWS\system32\kjllm.bak2
2005-10-07 21:32 338,982 --sha-w C:\WINDOWS\system32\kjllm.ini2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00E37622-B2CE-405E-9EFE-DF7B95493FF3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{314962DC-22C5-4288-8498-528E9F7FB691}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4A54500A-65FE-4F4A-B860-20EAE2F577F9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5DF6AFEE-2291-4041-9A74-354624861746}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5F811539-C263-4BD2-9DF6-1EF9C2A6DAE7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8EFBA3A0-6708-4F9C-B577-FDCBFF6ADE7D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91C56471-C1DE-491C-86C9-505B62717093}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A74F3FC3-CC9A-4D4C-AFB5-B56F0CAA445D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA9B6101-A336-49A2-878B-A06D6693A8A7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7DCFF4D-15FB-3B2B-D85A-4DE605F3599D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D760BC35-3F8C-46E4-8102-12025521060E}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA74AF32-80B1-45B4-8E75-4282C4711546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1B987CD-8C91-4CD5-A7CA-E4C0515530C7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E60261F1-7525-48D8-9F56-F2EF8FEA3A92}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E78B911A-6F68-4B84-8C19-EC417C9590E2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EAE158E8-E25B-46D4-838E-C89A4A26B8A3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EF15D661-C2B8-4790-ADB0-E7AC20D6A31C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F87298B5-BF2B-47E0-ACCA-0EC11610279D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBBADC36-691D-4DB3-87D8-473814B9BF0A}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-01-22 19:09 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-01-22 19:08 495616]
"TPSMain"="TPSMain.exe" [2004-03-03 14:57 278528 C:\WINDOWS\system32\TPSMain.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-02-03 16:47 1089589]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2003-10-20 10:39 159744]
"BellSouthAlertManager.exe"="C:\Program Files\BellSouth\AM\BellSouthAlertManager.exe" [2007-01-28 11:14 2061816]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"14b20e69"="C:\WINDOWS\system32\jhewgdbm.dll" [ ]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-03 11:37 249896]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Wireless-G Notebook Adapter.lnk - C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe [2006-12-15 14:05:35]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyywx]
ddcyywx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhfda]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlljk]
C:\WINDOWS\System32\mlljk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvvsqp]
tuvvsqp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winuqw32]
winuqw32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\ddcya.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Reserved]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-10 19:51 39792 --a------ C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bilkxezq]
rundll32.exe C:\Program Files\wdcbcxyx\cjyxcnct.dll,Init
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nudgxazm]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\nudgxazm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTAVApp]
C:\Program Files\PC Tools AntiVirus\PCTAV.exe /MONITORSCAN
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winshow]
C:\WINDOWS\winshow.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yjyvstov]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\yjyvstov.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Viewpoint Manager Service"=2 (0x2)
"TUWinStylerThemeSvc"=2 (0x2)
"SymWSC"=2 (0x2)
"Swupdtmr"=2 (0x2)
"PCTAVSvc"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NNServ"=2 (0x2)
"NICSer_WPC54G"=2 (0x2)
"MDM"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"DVD-RAM_Service"=2 (0x2)
"CFSvcs"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"aawservice"=2 (0x2)
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys [2004-04-14 16:52]
R3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys [2004-09-25 02:36]
S2 Windows Hosts Plugin;Windows Hosts Plugin;"C:\WINDOWS\system32\spoolcv.exe" []
S3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 12:48]
S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\System32\CBTNDIS5.SYS [2003-07-17 01:28]
S4 NICSer_WPC54G;NICSer_WPC54G;C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe [2003-11-13 16:29]
.
Contents of the 'Scheduled Tasks' folder
"2007-11-08 23:22:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-26 21:10:04 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-04 13:10:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\QTFont.for 1409 bytes
C:\WINDOWS\QTFont.qfn 54156 bytes
scan completed successfully
hidden files: 2
**************************************************************************
.
Completion time: 2008-01-04 13:15:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-04 18:15:20
.
2008-01-02 21:01:22 --- E O F ---