"Administrator" - 07-04-30 19:30:36 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\Administrator\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\download plugin\DlPlugin-MSIE_1.5.0.0\axdlplug.inf
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
C:\Program Files\install.log
C:\Program Files\download plugin
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
C:\Program Files\Common Files\{2CE8A~1
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-30 ))))))))))))))))))))))))))))))))))
2007-04-27 10:21 <DIR> d-------- C:\Program Files\EZShift
2007-04-09 18:28 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-04-09 11:22 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-04-09 11:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-04-09 11:22 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-04-09 11:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-04-09 11:12 123,972 --a------ C:\WINDOWS\system32\nmahqsfa.dll
2007-04-07 20:06 465,693 ---hs---- C:\WINDOWS\system32\gjkkj.ini2
2007-04-07 19:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-04-07 19:43 4,422,688 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-04-07 19:43 107,040 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-04-07 19:39 <DIR> d-------- C:\WINDOWS\system32\bak
2007-04-07 19:24 <DIR> d-------- C:\WINDOWS\Prefetch
2007-04-07 17:00 0 --a------ C:\AUTOEXEC.BAT
2007-04-07 16:58 81,920 --a------ C:\WINDOWS\system32\isign32.dll
2007-04-07 16:58 81,920 --a------ C:\WINDOWS\system32\ils.dll
2007-04-07 16:58 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2007-04-07 16:58 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys
2007-04-07 16:58 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2007-04-07 16:58 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-04-07 16:58 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2007-04-07 16:58 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2007-04-07 16:58 48,128 --a------ C:\WINDOWS\system32\inetres.dll
2007-04-07 16:58 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2007-04-07 16:58 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2007-04-07 16:58 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2007-04-07 16:58 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2007-04-07 16:58 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2007-04-07 16:58 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2007-04-07 16:58 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2007-04-07 16:58 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2007-04-07 16:58 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2007-04-07 16:58 274,944 --a------ C:\WINDOWS\system32\mstask.dll
2007-04-07 16:58 274,432 --a------ C:\WINDOWS\system32\inetcfg.dll
2007-04-07 16:58 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2007-04-07 16:58 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2007-04-07 16:58 190,976 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-04-07 16:58 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-04-07 16:58 170,496 --a------ C:\WINDOWS\system32\srsvc.dll
2007-04-07 16:58 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2007-04-07 16:58 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2007-04-07 16:56 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2007-04-07 16:56 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-04-07 16:56 93,696 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2007-04-07 16:56 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-04-07 16:56 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2007-04-07 16:56 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2007-04-07 16:56 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2007-04-07 16:56 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2007-04-07 16:56 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-04-07 16:56 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2007-04-07 16:56 60,416 --a------ C:\WINDOWS\system32\remotepg.dll
2007-04-07 16:56 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2007-04-07 16:56 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2007-04-07 16:56 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2007-04-07 16:56 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2007-04-07 16:56 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2007-04-07 16:56 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2007-04-07 16:56 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2007-04-07 16:56 538,624 --a------ C:\WINDOWS\system32\spider.exe
2007-04-07 16:56 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-04-07 16:56 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2007-04-07 16:56 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-04-07 16:56 407,552 --a------ C:\WINDOWS\system32\mstsc.exe
2007-04-07 16:56 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll
2007-04-07 16:56 347,136 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-04-07 16:56 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2007-04-07 16:56 295,424 --a------ C:\WINDOWS\system32\termsrv.dll
2007-04-07 16:56 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2007-04-07 16:56 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2007-04-07 16:56 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2007-04-07 16:56 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2007-04-07 16:56 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2007-04-07 16:56 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2007-04-07 16:56 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2007-04-07 16:56 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-04-07 16:56 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2007-04-07 16:56 140,800 --a------ C:\WINDOWS\system32\sessmgr.exe
2007-04-07 16:56 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2007-04-07 16:56 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2007-04-07 16:56 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2007-04-07 16:56 124,184 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-04-07 16:56 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2007-04-07 16:56 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2007-04-07 16:56 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-04-07 16:56 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2007-04-07 16:56 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2007-04-07 16:56 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2007-04-07 16:56 1,343,768 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-04-07 16:56 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-04-07 16:44 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-04-07 16:44 52,864 --a------ C:\WINDOWS\system32\drivers\dmusic.sys
2007-04-07 15:53 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-04-07 15:29 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll
2007-04-07 15:28 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-04-07 15:28 1,897,408 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-04-07 15:27 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2007-04-07 15:27 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-04-07 15:24 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2007-04-07 15:24 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-04-07 15:24 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-04-07 15:24 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2007-04-07 10:35 461,574 ---hs---- C:\WINDOWS\system32\gjkkj.bak2
2007-04-06 16:43 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-04-06 16:39 <DIR> d-------- C:\KAV
2007-04-06 12:22 460,404 ---hs---- C:\WINDOWS\system32\gjkkj.bak1
2007-04-06 12:22 377 ---hs---- C:\WINDOWS\system32\ayadd.ini2
2007-04-06 12:13 <DIR> d-------- C:\tmp
2007-04-02 14:21 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Idol file
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-21 22:35 -------- d-------- C:\Program Files\icq
2007-04-17 07:55 -------- d-------- C:\Program Files\emule
2007-04-13 17:49 -------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\utorrent
2007-04-08 16:52 -------- d-------- C:\Program Files\itunes
2007-04-07 19:39 -------- d-------- C:\Program Files\microsoft activesync
2007-04-07 19:39 -------- d-------- C:\Program Files\ipodhe
2007-04-07 18:42 -------- d-------- C:\Program Files\windows nt
2007-04-07 18:42 -------- d-------- C:\Program Files\movie maker
2007-04-07 16:57 22720 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-04-07 16:56 -------- d-------- C:\Program Files\online services
2007-04-06 12:32 -------- d-------- C:\Program Files\norton systemworks
2007-04-06 09:40 -------- d-------- C:\Program Files\sony
2007-04-06 09:39 -------- d--h----- C:\Program Files\installshield installation information
2007-04-06 09:36 -------- d-------- C:\Program Files\mirc
2007-04-06 09:34 -------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\lavasoft
2007-03-24 16:54 -------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\u3
2007-03-19 22:29 -------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\dvdcss
2007-03-17 15:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 17:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-02-21 17:16 15 --a------ C:\WINDOWS\popcinfo.dat
2007-02-05 22:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"Logitech Utility"="Logi_MwX.Exe"
"kav"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Device Detector"="DevDetect.exe -autorun"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"iPodHE SystemTray"="C:\\Program Files\\iPodHE\\iPodHE.exe /tray"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explor er]
"NoSMHelp"=hex:01,00,00,00
"NoLogoff"=hex:01,00,00,00
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explor er\run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shell executehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\ecrunXP.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-04-30 19:40:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-30 19:41:20 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-04-30 19:41