robbibj
2007-07-07, 20:27
I am having a problem removing Smitfraud.
Here is the log for Combofix.
"Owner" - 2007-07-07 13:00:59 - ComboFix 07-07-07.3 - Service Pack 2
C:\WINNT\system32\bgyjkylr.dll
C:\WINNT\system32\cgcxssld.dll
C:\WINNT\system32\pplhnkio.dll
C:\WINNT\system32\sachwtvq.dll
C:\WINNT\system32\syfesdym.dll
C:\WINNT\system32\vcguqunm.dll
C:\WINNT\system32\hjkkj.bak1
C:\WINNT\system32\hjkkj.bak2
C:\WINNT\system32\hjkkj.ini
C:\WINNT\system32\hjkkj.ini2
C:\WINNT\system32\hjkkj.tmp
C:\WINNT\system32\rlykjygb.ini
C:\WINNT\system32\dlssxcgc.ini
C:\WINNT\system32\mnuqugcv.ini
C:\WINNT\system32\hjkkj.bak1
C:\WINNT\system32\hjkkj.bak2
C:\WINNT\system32\hjkkj.ini
C:\WINNT\system32\hjkkj.ini2
C:\WINNT\system32\hjkkj.tmp
C:\WINNT\system32\hjkkj.bak1
C:\WINNT\system32\hjkkj.bak2
C:\WINNT\system32\hjkkj.ini
C:\WINNT\system32\hjkkj.ini2
C:\WINNT\system32\hjkkj.tmp
C:\WINNT\system32\jkkjh.dll
C:\WINNT\system32\byxwwur.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\Owner.\err.log
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\TTC.dll
C:\temp\0b9
C:\temp\0b9\tmpTF.log
C:\temp\iee
C:\temp\iee\tmpZTF.log
C:\temp\tn3
C:\WINNT\system32\drivers\core.cache.dsk
C:\WINNT\system32\drivers\core.sys
C:\WINNT\system32\drivers\fopn.sys
C:\WINNT\system32\o02PrEz
C:\WINNT\system32\o02PrEz\o02PrEz1065.exe
C:\WINNT\system32\win
C:\WINNT\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\LEGACY_DOMAINSERVICE
-------\core
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-06-07 to 2007-07-07 )))))))))))))))))))))))))))))))
2007-07-07 13:00 51,200 --a------ C:\WINNT\nircmd.exe
2007-07-07 11:33 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-07 11:33 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-07-06 19:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-01 22:47 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\DivX
2007-07-01 22:44 129,784 --a------ C:\WINNT\system32\pxafs.dll
2007-07-01 22:44 <DIR> d-------- C:\Program Files\DivX
2007-07-01 19:15 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Smith Micro
2007-06-24 19:02 <DIR> d-------- C:\Program Files\Windows Defender
2007-06-24 10:48 2,624 --a------ C:\WINNT\system32\jrldaich.exe
2007-06-24 10:45 4,672 --a------ C:\WINNT\system32\osrccfge.exe
2007-06-23 19:10 <DIR> d-------- C:\WINNT\system32\G4
2007-06-23 19:10 <DIR> d-------- C:\WINNT\system32\G3
2007-06-23 19:10 <DIR> d-------- C:\WINNT\system32\G2
2007-06-23 19:10 <DIR> d-------- C:\WINNT\system32\G1
2007-06-21 13:28 5,020 --a------ C:\WINNT\system32\ealregsnapshot1.reg
2007-06-21 13:28 <DIR> d-------- C:\ProgramData
2007-06-20 19:04 <DIR> d-------- C:\95d0cb7812ba5284635ceb2ab354
2007-06-10 14:13 <DIR> d-------- C:\Program Files\support.com
2007-06-10 14:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Support.com
2007-06-07 16:41 93,872 --a------ C:\WINNT\system32\drivers\sscdmdm.sys
2007-06-07 16:41 8,272 --a------ C:\WINNT\system32\drivers\sscdmdfl.sys
2007-06-07 16:41 73,696 --a------ C:\WINNT\system32\drivers\sscdserd.sys
2007-06-07 16:41 6,176 --a------ C:\WINNT\system32\drivers\sscdcmnt.sys
2007-06-07 16:41 6,176 --a------ C:\WINNT\system32\drivers\sscdcm.sys
2007-06-07 16:41 58,352 --a------ C:\WINNT\system32\drivers\sscdbus.sys
2007-06-07 16:41 5,840 --a------ C:\WINNT\system32\drivers\sscdwhnt.sys
2007-06-07 16:41 5,840 --a------ C:\WINNT\system32\drivers\sscdwh.sys
2007-06-07 16:41 <DIR> d-------- C:\Program Files\Samsung
2007-06-07 16:39 <DIR> d-------- C:\Program Files\Sprint music manager
2007-06-07 16:37 <DIR> d-------- C:\WINNT\system32\LogFiles
2007-06-07 16:37 <DIR> d-------- C:\WINNT\system32\drivers\UMDF
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-07 15:50:51 -------- d-----w C:\Program Files\Viewpoint
2007-07-07 15:49:39 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-07 15:40:59 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Viewpoint
2007-06-30 00:15:25 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-25 10:19:17 -------- d-----w C:\Program Files\GatInst
2007-06-24 20:19:58 1,086 ----a-w C:\WINNT\checkip.dat
2007-06-24 20:17:24 1,235 ----a-w C:\WINNT\ipconfig.dat
2007-06-24 01:31:19 -------- d-----w C:\Program Files\WildTangent
2007-06-24 01:29:45 -------- d-----w C:\Program Files\Yahoo! Games
2007-06-24 01:29:33 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-06-24 01:29:09 -------- d-----w C:\Program Files\Playboy - The Mansion
2007-06-24 01:21:10 -------- d-----w C:\Program Files\IrfanView
2007-06-24 01:20:16 -------- d-----w C:\Program Files\Gateway
2007-06-24 01:13:29 -------- d-----w C:\Program Files\Electronic Arts
2007-06-24 01:11:55 -------- d-----w C:\Program Files\Critical Seeker
2007-06-20 00:09:44 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\AdobeUM
2007-06-14 18:37:15 4,500 ----a-w C:\WINNT\mozver.dat
2007-06-10 19:14:21 -------- d-----w C:\Program Files\BroadJump
2007-06-09 02:56:27 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Yahoo!
2007-06-07 21:43:18 -------- d-----w C:\Program Files\AIM6
2007-05-31 06:45:07 524,288 ----a-w C:\WINNT\system32\DivXsm.exe
2007-05-31 06:44:55 823,296 ----a-w C:\WINNT\system32\divx_xx07.dll
2007-05-31 06:44:54 823,296 ----a-w C:\WINNT\system32\divx_xx0c.dll
2007-05-31 06:44:54 802,816 ----a-w C:\WINNT\system32\divx_xx11.dll
2007-05-31 06:44:54 740,442 ----a-w C:\WINNT\system32\DivX.dll
2007-05-27 23:45:50 32,520 ----a-w C:\DOCUME~1\Owner\APPLIC~1\wklnhst.dat
2007-05-16 15:12:02 683,520 ----a-w C:\WINNT\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINNT\system32\schannel.dll
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINNT\system32\qt-dx331.dll
2007-04-23 00:15:24 118,520 ----a-w C:\WINNT\system32\pxinsi64.exe
2007-04-23 00:15:24 116,472 ----a-w C:\WINNT\system32\pxcpyi64.exe
2007-04-23 00:15:18 200,704 ----a-w C:\WINNT\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINNT\system32\libdivx.dll
2007-04-23 00:02:34 73,728 ----a-w C:\WINNT\system32\dpl100.dll
2007-04-23 00:02:34 196,608 ----a-w C:\WINNT\system32\dtu100.dll
2007-04-23 00:02:33 53,248 ----a-w C:\WINNT\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 ----a-w C:\WINNT\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 ----a-w C:\WINNT\system32\dpv11.dll
2007-04-23 00:02:31 344,064 ----a-w C:\WINNT\system32\dpus11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINNT\system32\dpu11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINNT\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINNT\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINNT\system32\DivXCodecUpdateChecker.exe
2007-04-20 16:32:05 4 ----a-w C:\WINNT\uccspecb.sys
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINNT\system32\msi.dll
2007-04-17 03:47:36 33,624 ----a-w C:\WINNT\system32\wups.dll
2007-04-17 03:45:54 1,710,936 ----a-w C:\WINNT\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 ----a-w C:\WINNT\system32\wuapi.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINNT\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINNT\system32\wuweb.dll
2007-04-17 03:45:28 92,504 ----a-w C:\WINNT\system32\cdm.dll
2007-04-17 03:45:20 53,080 ----a-w C:\WINNT\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 ----a-w C:\WINNT\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2004-12-14 01:56 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6ADBE2BD-80F9-45F8-9556-41FC23DB8E53}]
C:\WINNT\System32\ikmcib.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
2005-08-02 13:41 524288 --a------ C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}]
2003-09-06 11:31 126976 --a------ C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
2003-12-04 18:22 103368 --a------ C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-06-26 18:04]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-02-28 17:46]
"URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2003-12-11 19:35]
"HiJackThis3"="WINDOWSUPDATER.EXE" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-06-25 14:08]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" []
"lxczbmgr.exe"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2007-02-08 17:52]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2007-02-08 17:56]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 02:56]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 16:17]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"=C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
"Symantec NetDriver Warning"=C:\PROGRA~1\SYMNET~1\SNDWarn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\saie]
c:\winnt\system32\saie.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebRebates0]
"C:\Program Files\Web_Rebates\WebRebates0.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xhrmy]
C:\WINNT\Xhrmy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe"
Contents of the 'Scheduled Tasks' folder
2007-07-06 03:13:01 C:\WINNT\tasks\AppleSoftwareUpdate.job
2004-03-04 04:45:00 C:\WINNT\tasks\ISP signup reminder 1.job
2004-03-12 04:15:00 C:\WINNT\tasks\ISP signup reminder 2.job
2004-03-17 04:45:00 C:\WINNT\tasks\ISP signup reminder 3.job
2007-07-07 17:11:11 C:\WINNT\tasks\MP Scheduled Scan.job
2007-07-07 01:34:30 C:\WINNT\tasks\Norton AntiVirus - Scan my computer.job
2007-07-07 16:18:57 C:\WINNT\tasks\Symantec NetDetect.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-07 13:12:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-07 13:15:17 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-07 13:15
--- E O F ---
Here is the log for Combofix.
"Owner" - 2007-07-07 13:00:59 - ComboFix 07-07-07.3 - Service Pack 2
C:\WINNT\system32\bgyjkylr.dll
C:\WINNT\system32\cgcxssld.dll
C:\WINNT\system32\pplhnkio.dll
C:\WINNT\system32\sachwtvq.dll
C:\WINNT\system32\syfesdym.dll
C:\WINNT\system32\vcguqunm.dll
C:\WINNT\system32\hjkkj.bak1
C:\WINNT\system32\hjkkj.bak2
C:\WINNT\system32\hjkkj.ini
C:\WINNT\system32\hjkkj.ini2
C:\WINNT\system32\hjkkj.tmp
C:\WINNT\system32\rlykjygb.ini
C:\WINNT\system32\dlssxcgc.ini
C:\WINNT\system32\mnuqugcv.ini
C:\WINNT\system32\hjkkj.bak1
C:\WINNT\system32\hjkkj.bak2
C:\WINNT\system32\hjkkj.ini
C:\WINNT\system32\hjkkj.ini2
C:\WINNT\system32\hjkkj.tmp
C:\WINNT\system32\hjkkj.bak1
C:\WINNT\system32\hjkkj.bak2
C:\WINNT\system32\hjkkj.ini
C:\WINNT\system32\hjkkj.ini2
C:\WINNT\system32\hjkkj.tmp
C:\WINNT\system32\jkkjh.dll
C:\WINNT\system32\byxwwur.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\Owner.\err.log
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\TTC.dll
C:\temp\0b9
C:\temp\0b9\tmpTF.log
C:\temp\iee
C:\temp\iee\tmpZTF.log
C:\temp\tn3
C:\WINNT\system32\drivers\core.cache.dsk
C:\WINNT\system32\drivers\core.sys
C:\WINNT\system32\drivers\fopn.sys
C:\WINNT\system32\o02PrEz
C:\WINNT\system32\o02PrEz\o02PrEz1065.exe
C:\WINNT\system32\win
C:\WINNT\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\LEGACY_DOMAINSERVICE
-------\core
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-06-07 to 2007-07-07 )))))))))))))))))))))))))))))))
2007-07-07 13:00 51,200 --a------ C:\WINNT\nircmd.exe
2007-07-07 11:33 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-07 11:33 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-07-06 19:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-01 22:47 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\DivX
2007-07-01 22:44 129,784 --a------ C:\WINNT\system32\pxafs.dll
2007-07-01 22:44 <DIR> d-------- C:\Program Files\DivX
2007-07-01 19:15 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Smith Micro
2007-06-24 19:02 <DIR> d-------- C:\Program Files\Windows Defender
2007-06-24 10:48 2,624 --a------ C:\WINNT\system32\jrldaich.exe
2007-06-24 10:45 4,672 --a------ C:\WINNT\system32\osrccfge.exe
2007-06-23 19:10 <DIR> d-------- C:\WINNT\system32\G4
2007-06-23 19:10 <DIR> d-------- C:\WINNT\system32\G3
2007-06-23 19:10 <DIR> d-------- C:\WINNT\system32\G2
2007-06-23 19:10 <DIR> d-------- C:\WINNT\system32\G1
2007-06-21 13:28 5,020 --a------ C:\WINNT\system32\ealregsnapshot1.reg
2007-06-21 13:28 <DIR> d-------- C:\ProgramData
2007-06-20 19:04 <DIR> d-------- C:\95d0cb7812ba5284635ceb2ab354
2007-06-10 14:13 <DIR> d-------- C:\Program Files\support.com
2007-06-10 14:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Support.com
2007-06-07 16:41 93,872 --a------ C:\WINNT\system32\drivers\sscdmdm.sys
2007-06-07 16:41 8,272 --a------ C:\WINNT\system32\drivers\sscdmdfl.sys
2007-06-07 16:41 73,696 --a------ C:\WINNT\system32\drivers\sscdserd.sys
2007-06-07 16:41 6,176 --a------ C:\WINNT\system32\drivers\sscdcmnt.sys
2007-06-07 16:41 6,176 --a------ C:\WINNT\system32\drivers\sscdcm.sys
2007-06-07 16:41 58,352 --a------ C:\WINNT\system32\drivers\sscdbus.sys
2007-06-07 16:41 5,840 --a------ C:\WINNT\system32\drivers\sscdwhnt.sys
2007-06-07 16:41 5,840 --a------ C:\WINNT\system32\drivers\sscdwh.sys
2007-06-07 16:41 <DIR> d-------- C:\Program Files\Samsung
2007-06-07 16:39 <DIR> d-------- C:\Program Files\Sprint music manager
2007-06-07 16:37 <DIR> d-------- C:\WINNT\system32\LogFiles
2007-06-07 16:37 <DIR> d-------- C:\WINNT\system32\drivers\UMDF
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-07 15:50:51 -------- d-----w C:\Program Files\Viewpoint
2007-07-07 15:49:39 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-07 15:40:59 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Viewpoint
2007-06-30 00:15:25 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-25 10:19:17 -------- d-----w C:\Program Files\GatInst
2007-06-24 20:19:58 1,086 ----a-w C:\WINNT\checkip.dat
2007-06-24 20:17:24 1,235 ----a-w C:\WINNT\ipconfig.dat
2007-06-24 01:31:19 -------- d-----w C:\Program Files\WildTangent
2007-06-24 01:29:45 -------- d-----w C:\Program Files\Yahoo! Games
2007-06-24 01:29:33 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-06-24 01:29:09 -------- d-----w C:\Program Files\Playboy - The Mansion
2007-06-24 01:21:10 -------- d-----w C:\Program Files\IrfanView
2007-06-24 01:20:16 -------- d-----w C:\Program Files\Gateway
2007-06-24 01:13:29 -------- d-----w C:\Program Files\Electronic Arts
2007-06-24 01:11:55 -------- d-----w C:\Program Files\Critical Seeker
2007-06-20 00:09:44 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\AdobeUM
2007-06-14 18:37:15 4,500 ----a-w C:\WINNT\mozver.dat
2007-06-10 19:14:21 -------- d-----w C:\Program Files\BroadJump
2007-06-09 02:56:27 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Yahoo!
2007-06-07 21:43:18 -------- d-----w C:\Program Files\AIM6
2007-05-31 06:45:07 524,288 ----a-w C:\WINNT\system32\DivXsm.exe
2007-05-31 06:44:55 823,296 ----a-w C:\WINNT\system32\divx_xx07.dll
2007-05-31 06:44:54 823,296 ----a-w C:\WINNT\system32\divx_xx0c.dll
2007-05-31 06:44:54 802,816 ----a-w C:\WINNT\system32\divx_xx11.dll
2007-05-31 06:44:54 740,442 ----a-w C:\WINNT\system32\DivX.dll
2007-05-27 23:45:50 32,520 ----a-w C:\DOCUME~1\Owner\APPLIC~1\wklnhst.dat
2007-05-16 15:12:02 683,520 ----a-w C:\WINNT\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINNT\system32\schannel.dll
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINNT\system32\qt-dx331.dll
2007-04-23 00:15:24 118,520 ----a-w C:\WINNT\system32\pxinsi64.exe
2007-04-23 00:15:24 116,472 ----a-w C:\WINNT\system32\pxcpyi64.exe
2007-04-23 00:15:18 200,704 ----a-w C:\WINNT\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINNT\system32\libdivx.dll
2007-04-23 00:02:34 73,728 ----a-w C:\WINNT\system32\dpl100.dll
2007-04-23 00:02:34 196,608 ----a-w C:\WINNT\system32\dtu100.dll
2007-04-23 00:02:33 53,248 ----a-w C:\WINNT\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 ----a-w C:\WINNT\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 ----a-w C:\WINNT\system32\dpv11.dll
2007-04-23 00:02:31 344,064 ----a-w C:\WINNT\system32\dpus11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINNT\system32\dpu11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINNT\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINNT\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINNT\system32\DivXCodecUpdateChecker.exe
2007-04-20 16:32:05 4 ----a-w C:\WINNT\uccspecb.sys
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINNT\system32\msi.dll
2007-04-17 03:47:36 33,624 ----a-w C:\WINNT\system32\wups.dll
2007-04-17 03:45:54 1,710,936 ----a-w C:\WINNT\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 ----a-w C:\WINNT\system32\wuapi.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINNT\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINNT\system32\wuweb.dll
2007-04-17 03:45:28 92,504 ----a-w C:\WINNT\system32\cdm.dll
2007-04-17 03:45:20 53,080 ----a-w C:\WINNT\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 ----a-w C:\WINNT\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2004-12-14 01:56 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6ADBE2BD-80F9-45F8-9556-41FC23DB8E53}]
C:\WINNT\System32\ikmcib.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
2005-08-02 13:41 524288 --a------ C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}]
2003-09-06 11:31 126976 --a------ C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
2003-12-04 18:22 103368 --a------ C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-06-26 18:04]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-02-28 17:46]
"URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2003-12-11 19:35]
"HiJackThis3"="WINDOWSUPDATER.EXE" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-06-25 14:08]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" []
"lxczbmgr.exe"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2007-02-08 17:52]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2007-02-08 17:56]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 02:56]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 16:17]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"=C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
"Symantec NetDriver Warning"=C:\PROGRA~1\SYMNET~1\SNDWarn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\saie]
c:\winnt\system32\saie.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebRebates0]
"C:\Program Files\Web_Rebates\WebRebates0.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xhrmy]
C:\WINNT\Xhrmy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe"
Contents of the 'Scheduled Tasks' folder
2007-07-06 03:13:01 C:\WINNT\tasks\AppleSoftwareUpdate.job
2004-03-04 04:45:00 C:\WINNT\tasks\ISP signup reminder 1.job
2004-03-12 04:15:00 C:\WINNT\tasks\ISP signup reminder 2.job
2004-03-17 04:45:00 C:\WINNT\tasks\ISP signup reminder 3.job
2007-07-07 17:11:11 C:\WINNT\tasks\MP Scheduled Scan.job
2007-07-07 01:34:30 C:\WINNT\tasks\Norton AntiVirus - Scan my computer.job
2007-07-07 16:18:57 C:\WINNT\tasks\Symantec NetDetect.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-07 13:12:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-07 13:15:17 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-07 13:15
--- E O F ---