ComboFix 07-12-21.4 - Owner 2007-12-29 18:05:21.1 - NTFSx86
Running from: E:\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Application Data\install.dat
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\Companion Wizard\compwiz.exe
C:\Program Files\Common Files\companion wizard\WapCHK.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{6345E889-7C9D-4D32-A648-4D0A87E85E52}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{815EB2F4-488D-4AD7-82AC-F75D7D6336D2}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{C64A7ED3-0730-4CFA-9566-164A20185252}.dll
C:\WINDOWS\system32\bwbkcnad
C:\WINDOWS\system32\bwbkcnad\bg1.gif
C:\WINDOWS\system32\bwbkcnad\bgtop.gif
C:\WINDOWS\system32\bwbkcnad\bottom1.gif
C:\WINDOWS\system32\bwbkcnad\bwbkcnad1.exe
C:\WINDOWS\system32\bwbkcnad\bwbkcnad2.exe
C:\WINDOWS\system32\bwbkcnad\bwbkcnad3.exe
C:\WINDOWS\system32\bwbkcnad\essentials.gif
C:\WINDOWS\system32\bwbkcnad\icon1.ico
C:\WINDOWS\system32\bwbkcnad\install1.gif
C:\WINDOWS\system32\bwbkcnad\left1.gif
C:\WINDOWS\system32\bwbkcnad\li.gif
C:\WINDOWS\system32\bwbkcnad\logo.gif
C:\WINDOWS\system32\bwbkcnad\main.htm
C:\WINDOWS\system32\bwbkcnad\mainframe.htm
C:\WINDOWS\system32\bwbkcnad\reinstall1.gif
C:\WINDOWS\system32\bwbkcnad\right1.gif
C:\WINDOWS\system32\bwbkcnad\s1.htm
C:\WINDOWS\system32\bwbkcnad\s2.htm
C:\WINDOWS\system32\bwbkcnad\s3.htm
C:\WINDOWS\system32\bwbkcnad\SMTop1.gif
C:\WINDOWS\system32\bwbkcnad\SMTop2.gif
C:\WINDOWS\system32\bwbkcnad\SMTop3.gif
C:\WINDOWS\system32\bwbkcnad\SMTop4.gif
C:\WINDOWS\system32\bwbkcnad\soft1_off.gif
C:\WINDOWS\system32\bwbkcnad\soft1_off_ext.gif
C:\WINDOWS\system32\bwbkcnad\soft1_on.gif
C:\WINDOWS\system32\bwbkcnad\soft1_on_ext.gif
C:\WINDOWS\system32\bwbkcnad\soft2_off.gif
C:\WINDOWS\system32\bwbkcnad\soft2_off_ext.gif
C:\WINDOWS\system32\bwbkcnad\soft2_on.gif
C:\WINDOWS\system32\bwbkcnad\soft2_on_ext.gif
C:\WINDOWS\system32\bwbkcnad\soft3_off.gif
C:\WINDOWS\system32\bwbkcnad\soft3_off_ext.gif
C:\WINDOWS\system32\bwbkcnad\soft3_on.gif
C:\WINDOWS\system32\bwbkcnad\soft3_on_ext.gif
C:\WINDOWS\system32\bwbkcnad\softbottom_off.gif
C:\WINDOWS\system32\bwbkcnad\softbottom_on.gif
C:\WINDOWS\system32\bwbkcnad\softleft_off.gif
C:\WINDOWS\system32\bwbkcnad\softleft_on.gif
C:\WINDOWS\system32\bwbkcnad\top1.gif
C:\WINDOWS\system32\bwbkcnad\top2.gif
C:\WINDOWS\system32\bwbkcnad\turnoff1.gif
C:\WINDOWS\system32\bwbkcnad\turnon1.gif
C:\WINDOWS\system32\conf.dat
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\xpdx.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_FOPN
-------\LEGACY_VSPF
-------\LEGACY_VSPF_HK
-------\xpdx
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
.
2007-12-29 01:53 . 2007-12-29 01:53 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-28 12:27 . 2007-12-28 12:27 268 --ah----- C:\sqmdata04.sqm
2007-12-28 12:27 . 2007-12-28 12:27 244 --ah----- C:\sqmnoopt04.sqm
2007-12-28 01:32 . 2007-12-28 01:32 1,158 --a------ C:\WINDOWS\mozver.dat
2007-12-28 00:52 . 2007-12-28 00:52 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-27 13:38 . 2007-12-27 13:38 244 --ah----- C:\sqmnoopt03.sqm
2007-12-27 13:38 . 2007-12-27 13:38 232 --ah----- C:\sqmdata03.sqm
2007-12-21 18:41 . 2007-12-21 18:46 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-20 16:52 . 2007-12-20 16:52 21,035 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-12-20 16:38 . 2007-03-27 04:30 49,904 -ra------ C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
2007-12-20 16:27 . 2007-12-20 16:52 <DIR> d-------- C:\Netgear
2007-12-13 20:14 . 2007-12-13 21:49 273 --a------ C:\WINDOWS\game.ini
2007-12-09 09:35 . 2007-12-09 09:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-09 09:34 . 2007-12-09 09:34 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-09 09:31 . 2007-12-29 17:37 <DIR> d-------- C:\VundoFix Backups
2007-12-08 12:13 . 2007-12-15 13:21 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-12-06 19:15 . 2007-12-24 11:04 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVG7
2007-12-06 19:15 . 2007-12-06 19:15 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-06 19:14 . 2007-12-06 19:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-06 19:14 . 2007-12-28 23:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-12-05 19:25 . 2007-12-05 19:26 <DIR> d-------- C:\WINDOWS\~cua
2007-12-05 19:25 . 2007-12-05 19:25 94,208 --a------ C:\WINDOWS\system32\SSW32N50.dll
2007-12-05 19:25 . 2007-12-05 19:25 31,929 --a------ C:\WINDOWS\system32\SSNDIS3.VXD
2007-12-05 19:25 . 2007-12-05 19:25 17,169 --a------ C:\WINDOWS\system32\SSNDIS5.sys
2007-12-05 19:25 . 2007-12-05 19:25 16,544 --a------ C:\WINDOWS\system32\SSNDIS4.sys
2007-12-05 18:53 . 2007-12-06 15:43 834 ---hs---- C:\WINDOWS\system32\kncilimj.ini
2007-12-04 18:53 . 2007-12-05 17:26 714 --ahs---- C:\WINDOWS\system32\anugtsoq.ini
2007-12-04 17:47 . 2007-12-04 18:08 474 ---hs---- C:\WINDOWS\system32\qpfcedxa.ini
2007-12-03 17:45 . 2007-12-04 17:46 414 ---hs---- C:\WINDOWS\system32\wghtcgtr.ini
2007-12-02 20:49 . 2007-12-03 19:16 <DIR> d-------- C:\Program Files\Symantec
2007-12-02 20:49 . 2007-12-02 20:49 <DIR> d-------- C:\Program Files\New Folder
2007-12-02 11:12 . 2007-12-06 18:44 102,031 ---hs---- C:\WINDOWS\system32\jjllm.bak2
2007-12-01 23:57 . 2007-12-06 19:16 100,437 ---hs---- C:\WINDOWS\system32\jjllm.ini
2007-12-01 23:57 . 2007-12-01 23:57 6,496 ---hs---- C:\WINDOWS\system32\jjllm.bak1
2007-12-01 23:13 . 2007-12-01 23:13 107 --a------ C:\WINDOWS\wininit.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 12:37 --------- d-----w C:\Documents and Settings\Owner\Application Data\Hamachi
2007-12-22 06:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-20 05:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-03 08:16 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-03 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-01 13:21 --------- d--h--w C:\Program Files\ie-improver
2007-11-22 20:23 --------- d-----w C:\Program Files\Activision
2007-11-22 11:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-19 05:06 --------- d-----w C:\Documents and Settings\Owner\Application Data\uTorrent
2007-11-16 04:40 --------- d-----w C:\Program Files\Java
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 02:15 --------- d-----w C:\Program Files\Common Files\Adobe
2006-11-14 07:34 315,624 ----a-w C:\Program Files\direct x 9.0c.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{32222621-EF56-4313-9737-AABD357B2C3B}]
C:\WINDOWS\system32\mlljj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{abfcc82f-69ac-41a3-8f48-985463515148}]
C:\WINDOWS\system32\yalynbub.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"="" []
"Steam"="e:\steam\steam.exe" [2007-11-30 16:20]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23:00]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-04-17 13:49]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 16:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"Cmaudio"="RunDll32 cmicnfg.cpl" []
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 18:35]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-13 15:52]
"WinFixer helper"="C:\Program Files\WinFixer 2006\wfxcwr.exe" []
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-04-17 13:49]
"NI.WFX6_0001_N57C0912"="C:\Documents and Settings\Owner\Desktop\WinFixer2006Install.exe" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 12:11]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 12:13]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 12:10]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 23:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" []
"Lexmark X6100 Series"="C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe" [2003-09-23 17:01]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 04:48]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 23:00 C:\WINDOWS\system32\rundll32.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"d0b45b06"="C:\WINDOWS\system32\qostguna.dll" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 13:00]
"OptusNet DSL Setup"="D:\OptusNet.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-06 19:14]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\d_kmd.sys]
@="Driver"
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-29 18:09:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ?W?????????????????????????????????????????????????????????????|p??|????m??|?`?w?????????W????@?8?@??????W??c"?s???s??????@?????N'?s?W2?L|?s????????????u??s????????c"?s???s??????@?8?@?N'?s?W2??$@?8?@?8?@??????????W2??B2????s?B2??V2??B2??B2?0i?s????????(W2????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\RtlGina2.dll
.
Completion time: 2007-12-29 18:10:42 - machine was rebooted
.
2007-12-13 10:54:42 --- E O F ---