"XiKeiyaZI" - 07-03-30 23:03:30 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Program Files\Mozilla Firefox"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\NDNuninstall6_38.exe
C:\WINDOWS\NDNuninstall7_48.exe
C:\DOCUME~1\XIKEIY~1\APPLIC~1\Dxcuknwrd.dll
C:\Program Files\ipwindows\ipwins.dll
C:\Program Files\ipwindows\ipwins.exe
C:\Program Files\ipwindows\UnInstall.exe
C:\WINDOWS\system32\bund1\ClientBundle1.exe
C:\WINDOWS\system32\bund1\temp.txt
C:\Program Files\Common Files\{3818D~1\system.dll
C:\Program Files\Common Files\{3818D~2\system.dll
C:\Program Files\ipwindows\ipwins.dll
C:\Program Files\ipwindows\ipwins.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\Program Files\ipwindows
C:\WINDOWS\system32\bund1
C:\Program Files\Common Files\{3818D~1
C:\Program Files\Common Files\{3818D~2
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\Program Files\Common Files\SMANTE~1
((((((((((((((((((((((((((((((( Files Created from 2007-02-28 to 2007-03-30 ))))))))))))))))))))))))))))))))))
2007-03-29 06:28 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-03-29 06:22 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-03-29 06:22 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-03-25 22:43 <DIR> d-------- C:\WINDOWS\system32\Tools
2007-03-25 22:13 520,192 --------- C:\WINDOWS\system32\ati2sgag.exe
2007-03-25 22:13 1,478,656 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-03-25 22:12 <DIR> d-------- C:\Program Files\ATI Technologies
2007-03-25 21:28 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-03-25 14:45 <DIR> d-------- C:\WINDOWS\pss
2007-03-25 05:21 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-03-25 04:57 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-03-25 04:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
2007-03-25 03:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-03-25 02:44 93,736 --a------ C:\WINDOWS\VTTC.exe
2007-03-25 02:10 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-25 01:48 19,296 --a------ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2007-03-25 01:27 8,464 --a------ C:\WINDOWS\system32\sporder.dll
2007-03-25 01:27 41,792 --a------ C:\WINDOWS\system32\nek.exe
2007-03-25 01:27 114 --a------ C:\WINDOWS\system32\hhjj.bat
2007-03-25 01:27 <DIR> d-------- C:\WINDOWS\system32\micro1
2007-03-25 01:26 203,149 --a------ C:\WINDOWS\system32\lo.exe
2007-03-24 21:56 <DIR> d-------- C:\Downloads
2007-03-24 21:50 <DIR> d-------- C:\Program Files\FlashGet
2007-03-24 21:43 98,304 --a------ C:\WINDOWS\system32\msir3jp.dll
2007-03-24 21:43 9,216 --a------ C:\WINDOWS\system32\kbdnecAT.dll
2007-03-24 21:43 838,144 --a------ C:\WINDOWS\system32\chtbrkr.dll
2007-03-24 21:43 70,656 --a------ C:\WINDOWS\system32\korwbrkr.dll
2007-03-24 21:43 7,680 --a------ C:\WINDOWS\system32\kbdnecNT.dll
2007-03-24 21:43 7,168 --a------ C:\WINDOWS\system32\kbdnec95.dll
2007-03-24 21:43 7,168 --a------ C:\WINDOWS\system32\kbdibm02.dll
2007-03-24 21:43 7,168 --a------ C:\WINDOWS\system32\f3ahvoas.dll
2007-03-24 21:43 6,656 --a------ C:\WINDOWS\system32\kbdlk41a.dll
2007-03-24 21:43 6,144 --a------ C:\WINDOWS\system32\kbdlk41j.dll
2007-03-24 21:43 6,144 --a------ C:\WINDOWS\system32\kbdax2.dll
2007-03-24 21:43 6,144 --a------ C:\WINDOWS\system32\kbd106n.dll
2007-03-24 21:43 6,144 --a------ C:\WINDOWS\system32\kbd101a.dll
2007-03-24 21:43 6,144 --a------ C:\WINDOWS\system32\kbd101.dll
2007-03-24 21:43 218,112 --a------ C:\WINDOWS\system32\c_g18030.dll
2007-03-24 21:43 1,677,824 --a------ C:\WINDOWS\system32\chsbrkr.dll
2007-03-24 21:42 811,064 --a------ C:\WINDOWS\system32\imjp81k.dll
2007-03-24 21:42 76,288 --a------ C:\WINDOWS\system32\uniime.dll
2007-03-24 21:42 6,656 --a------ C:\WINDOWS\system32\c_is2022.dll
2007-03-24 21:41 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll
2007-03-24 21:41 8,192 --a------ C:\WINDOWS\system32\kbdkor.dll
2007-03-24 21:41 6,144 --a------ C:\WINDOWS\system32\kbd106.dll
2007-03-24 21:41 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll
2007-03-24 21:41 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2007-03-24 21:41 5,632 --a------ C:\WINDOWS\system32\kbd103.dll
2007-03-24 21:01 <DIR> d-------- C:\Program Files\Common Files\NSV
2007-03-24 17:34 <DIR> d-------- C:\SonySupport
2007-03-24 17:34 <DIR> d-------- C:\Program Files\Sony
2007-03-24 15:52 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2007-03-24 15:52 <DIR> d-------- C:\Program Files\Viewpoint
2007-03-24 15:52 <DIR> d-------- C:\Program Files\AWS
2007-03-24 15:52 <DIR> d-------- C:\Program Files\AOD
2007-03-24 15:52 <DIR> d-------- C:\Program Files\AIM
2007-03-24 15:52 <DIR> d-------- C:\DOCUME~1\XIKEIY~1\APPLIC~1\Aim
2007-03-24 15:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
2007-03-24 15:41 <DIR> d-------- C:\DOCUME~1\XIKEIY~1\Contacts
2007-03-24 15:40 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-03-24 12:39 <DIR> d-------- C:\Program Files\XBC
2007-03-24 12:39 <DIR> d-------- C:\Program Files\WinPcap
2007-03-24 11:40 <DIR> d-------- C:\Program Files\Silkroad
2007-03-23 21:34 <DIR> d-------- C:\Program Files\Shareaza
2007-03-23 21:34 <DIR> d-------- C:\DOCUME~1\XIKEIY~1\APPLIC~1\Shareaza
2007-03-23 21:21 36,624 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-03-23 21:21 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-03-23 21:21 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-03-23 21:21 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-03-23 21:21 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-03-23 21:21 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-03-23 21:21 <DIR> d-------- C:\Program Files\DivX
2007-03-23 21:21 <DIR> d-------- C:\DOCUME~1\XIKEIY~1\APPLIC~1\DivX
2007-03-23 17:06 <DIR> d-------- C:\Program Files\World of Warcraft
2007-03-23 16:33 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-03-23 13:41 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-03-23 13:34 <DIR> d-------- C:\Program Files\WinMX
2007-03-23 13:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-03-23 13:28 0 --a------ C:\WINDOWS\nsreg.dat
2007-03-23 13:21 <DIR> d-------- C:\DOCUME~1\XIKEIY~1\APPLIC~1\AdobeUM
2007-03-23 13:21 <DIR> d-------- C:\DOCUME~1\XIKEIY~1\APPLIC~1\Adobe
2007-03-16 02:22 <DIR> d-------- C:\Program Files\Eidos Interactive
2007-03-16 01:04 <DIR> d-------- C:\Program Files\Winamp
2007-03-15 22:34 <DIR> d-------- C:\Program Files\Activision
2007-03-15 11:23 497,496 --a------ C:\WINDOWS\system32\XceedZip.dll
2007-03-15 11:19 526,184 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-03-14 23:18 <DIR> d-------- C:\Program Files\Bethesda Softworks
2007-03-14 17:56 <DIR> d-------- C:\Program Files\MagicDVDRipper
2007-03-05 10:56 <DIR> d-------- C:\Program Files\MSN Messenger
2007-03-02 15:18 <DIR> d--hs---- C:\DOCUME~1\XIKEIY~1\UserData
2007-03-02 15:05 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-03-02 15:05 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-03-02 15:05 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-03-01 12:54 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-02-28 13:56 <DIR> d-------- C:\Program Files\Lavasoft
2007-02-28 13:56 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-02-28 13:56 <DIR> d-------- C:\DOCUME~1\XIKEIY~1\APPLIC~1\Lavasoft
2007-02-28 11:15 <DIR> d--hs---- C:\RECYCLER
2007-02-28 02:01 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-02-28 02:01 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-02-28 02:01 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-02-28 02:01 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-02-28 02:01 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-02-28 02:01 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-02-28 02:01 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-02-28 02:01 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-02-28 02:01 171,776 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-02-28 02:01 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-02-28 02:00 917,504 --a------ C:\WINDOWS\system\cmids3d.dll
2007-02-28 02:00 712,704 --a------ C:\WINDOWS\system32\Audio3D.dll
2007-02-28 02:00 712,704 --a------ C:\WINDOWS\system32\a3d.dll
2007-02-28 02:00 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-02-28 02:00 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-02-28 02:00 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-02-28 02:00 32,768 --a------ C:\WINDOWS\system32\udaprop.dll
2007-02-28 02:00 28,672 --a------ C:\WINDOWS\system32\cmirmdrv.dll
2007-02-28 02:00 28,672 --a------ C:\WINDOWS\CMIRmDriver.dll
2007-02-28 02:00 266,240 --a------ C:\WINDOWS\CMIUninstall.exe
2007-02-28 02:00 233,472 --a------ C:\WINDOWS\system32\cmirmdrv.exe
2007-02-28 02:00 225,280 --a------ C:\WINDOWS\CmiRmRedundDir.exe
2007-02-28 02:00 172,032 --a------ C:\WINDOWS\system32\cmuda.dll
2007-02-28 02:00 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-02-28 02:00 1,458,176 --a------ C:\WINDOWS\system\SmWizard.exe
2007-02-28 02:00 1,373,120 --a------ C:\WINDOWS\system32\drivers\cmuda.sys
2007-02-28 02:00 <DIR> d-------- C:\Program Files\C-Media 3D Audio
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-30 22:47 -------- d-------- C:\Program Files\online services
2007-03-30 12:01 -------- d-------- C:\Program Files\messenger
2007-03-25 22:33 -------- d-------- C:\DOCUME~1\XIKEIY~1\APPLIC~1\ati
2007-03-21 19:33 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-03-21 19:24 -------- d--h----- C:\Program Files\installshield installation information
2007-02-27 19:32 -------- d-------- C:\Program Files\sis vga utilities v3.74
2007-02-27 19:31 -------- d-------- C:\Program Files\Common Files\installshield
2007-02-27 19:11 98304 --a------ C:\WINDOWS\system32cmdlineext.dll
2007-02-27 17:58 -------- d-------- C:\Program Files\ubisoft
2007-02-27 17:57 -------- d-------- C:\DOCUME~1\XIKEIY~1\APPLIC~1\installshield
2007-02-27 17:42 0 -rahs---- C:\MSDOS.SYS
2007-02-27 17:42 0 -rahs---- C:\IO.SYS
2007-02-27 17:42 0 --a------ C:\CONFIG.SYS
2007-02-27 17:42 0 --a------ C:\AUTOEXEC.BAT
2007-02-27 17:42 -------- d-------- C:\Program Files\microsoft frontpage
2007-02-27 17:40 -------- d--h----- C:\Program Files\windowsupdate
2007-02-27 17:39 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-02-27 17:39 -------- d-------- C:\Program Files\movie maker
2007-02-27 17:39 -------- d-------- C:\Program Files\Common Files\mssoap
2007-02-27 17:38 -------- d-------- C:\Program Files\msn gaming zone
2007-02-27 17:37 -------- d-------- C:\Program Files\windows nt
2007-02-27 11:06 -------- d-------- C:\Program Files\Common Files\speechengines
2007-02-27 11:06 -------- d-------- C:\Program Files\Common Files\odbc
2007-02-27 11:05 62 --ahs---- C:\DOCUME~1\XIKEIY~1\APPLIC~1\desktop.ini
2007-02-22 22:29 524288 --a------ C:\WINDOWS\system32\divxsm.exe
2007-02-22 22:29 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-02-22 22:29 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-02-22 22:29 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-02-22 22:25 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-02-22 22:25 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-02-22 22:25 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-02-22 22:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-02-22 22:25 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-02-22 22:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2007-02-22 22:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-02-22 22:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2007-02-22 22:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-02-22 22:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-02-22 22:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-02-22 22:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-02-15 19:40 124472 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-01-23 04:55 1571001 --a------ C:\WINDOWS\system32\sisgl.dll
2007-01-23 04:39 3514368 --a------ C:\WINDOWS\system32\sisgrv.dll
2007-01-23 04:34 9728 --a------ C:\WINDOWS\system32\sispins2.dll
2007-01-23 04:33 12288 --a------ C:\WINDOWS\instfunc.dll
2007-01-23 04:32 49152 --a------ C:\WINDOWS\system32\sisbase.dll
2007-01-23 04:32 258048 --a------ C:\WINDOWS\system32\sisparse.dll
2007-01-23 04:32 172032 --a------ C:\WINDOWS\system32\sisinst.dll
2007-01-19 12:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-08 19:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"AIM"="C:\\PROGRA~1\\AIM\\aim.exe -cnetwait.odl"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"IpWins"="C:\\Program Files\\Ipwindows\\ipwins.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"SiSPower"="Rundll32.exe SiSPower.dll,ModeAgent"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeluxeCommunications]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Dxc"
"hkey"="HKLM"
"command"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ C:\Program Files\Messenger\fsoxynid.html
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command D:\Autorun.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
Shell\AutoRun\command E:\autorun.exe
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-03-30 23:05:49