ComboFix 07-11-08.1 - Hanis 2007-11-12 12:33:03.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.486 [GMT 8:00]
Running from: C:\Documents and Settings\Hanis\Local Settings\Temporary Internet Files\Content.IE5\318KLK0R\ComboFix[1].exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\Guest\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\Guest\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log
C:\Documents and Settings\Guest\Application Data\WinAntiVirus Pro 2006\Logs\winav.log
C:\Documents and Settings\Hanis\Application Data\macromedia\Flash Player\#SharedObjects\UUTHLSXV\iforex.com
C:\Documents and Settings\Hanis\Application Data\macromedia\Flash Player\#SharedObjects\UUTHLSXV\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Hanis\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Hanis\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\Hanis\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\Hanis\Application Data\WinAntiVirus Pro 2006\Logs\update.log
C:\Documents and Settings\Hanis\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log
C:\Documents and Settings\Hanis\Application Data\WinAntiVirus Pro 2006\Logs\winav.log
C:\Documents and Settings\Hanis\Application Data\WinAntiVirus Pro 2006\PGE.dat
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\Companion Wizard\compwiz.exe
C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{231E135C-0BF8-41E8-9C33-1013B4881AFE}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{26DAD9D7-6890-42F7-B41B-ADCAD0552EDC}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{481186AC-E2A4-4E17-AE05-3CCB3C32900A}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{B5524BDB-295C-4CA7-89A6-E8981A57754B}.dll
C:\Program Files\Common Files\winantivirus pro 2006
C:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll
C:\Program Files\Instant Messenger Names
C:\Program Files\Instant Messenger Names\1.exe
C:\Program Files\Instant Messenger Names\2.exe
C:\Program Files\Instant Messenger Names\IM-svr.exe
C:\Program Files\Instant Messenger Names\IMNames.exe
C:\Program Files\Instant Messenger Names\main.exe
C:\Program Files\VideoAccessCodec
C:\Program Files\VideoAccessCodec\install.ico
C:\WINDOWS\cookies.ini
C:\WINDOWS\dat.txt
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\msvb.dll
C:\WINDOWS\NDNuninstall6_38.exe
C:\WINDOWS\NDNuninstall7_22.exe
C:\WINDOWS\NDNuninstall7_48.exe
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt
C:\WINDOWS\sysdx.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\bdeeg.bak1
C:\WINDOWS\system32\bdeeg.bak2
C:\WINDOWS\system32\bdeeg.ini
C:\WINDOWS\system32\bdeeg.ini2
C:\WINDOWS\system32\ciejeydj.exe
C:\WINDOWS\system32\dwbjsced.exe
C:\WINDOWS\system32\geedb.dll
C:\WINDOWS\system32\hgglcrvp.exe
C:\WINDOWS\system32\hhcteusm.dll
C:\WINDOWS\system32\internet.exe
C:\WINDOWS\system32\ndkqftvn.exe
C:\WINDOWS\system32\nudweanc.exe
C:\WINDOWS\system32\obwgwclu.exe
C:\WINDOWS\system32\ohprotig.exe
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\update.exe
C:\WINDOWS\system32\vevaqfcr.exe
C:\WINDOWS\system32\winpol.exe
C:\WINDOWS\wsremover.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_AUTO_HOTKEY_POLLER
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_FOPN
-------\LEGACY_VSPF
-------\LEGACY_VSPF_HK
-------\Auto HotKey Poller
-------\DomainService
-------\vspf
-------\vspf_hk
((((((((((((((((((((((((( Files Created from 2007-10-12 to 2007-11-12 )))))))))))))))))))))))))))))))
.
2007-11-12 07:56 79,936 --a------ C:\WINDOWS\system32\eyugxeug.dll
2007-11-12 07:53 88,128 --a------ C:\WINDOWS\system32\keoegtlu.dll
2007-11-12 07:47 71,232 --a------ C:\WINDOWS\system32\hjgnevph.exe
2007-11-11 21:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-11 00:57 81,472 --a------ C:\WINDOWS\system32\clgdocwv.dll
2007-11-11 00:49 71,232 --a------ C:\WINDOWS\system32\wiulusyt.exe
2007-11-10 00:24 77,888 --a------ C:\WINDOWS\system32\cmsfaqlg.dll
2007-11-10 00:21 71,232 --a------ C:\WINDOWS\system32\ysjrtlne.exe
2007-11-09 19:43 <DIR> d-------- C:\Documents and Settings\Hanis\Incomplete
2007-11-09 10:47 80,448 --a------ C:\WINDOWS\system32\cwnhrwyv.dll
2007-11-09 10:46 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-09 02:30 <DIR> d-------- C:\Program Files\Else plus
2007-11-09 02:27 36,352 --a------ C:\WINDOWS\system32\efcywus.dll
2007-11-08 12:19 71,232 --a------ C:\WINDOWS\system32\npuqfrnn.exe
2007-11-07 11:45 71,232 --a------ C:\WINDOWS\system32\jyrgityy.exe
2007-11-07 11:14 71,232 --a------ C:\WINDOWS\system32\opsjgwlc.exe
2007-11-05 12:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-05 12:42 <DIR> d-------- C:\BackUpMSNCleaner
2007-11-03 22:54 36,352 --a------ C:\WINDOWS\system32\vtuuroo.dll
2007-11-03 22:50 36,352 --a------ C:\WINDOWS\system32\opnolii.dll
2007-11-02 22:21 33,280 --a------ C:\WINDOWS\system32\xxywwwt.dll
2007-11-02 22:20 33,280 --a------ C:\WINDOWS\system32\yaywvuu.dll
2007-11-02 11:14 <DIR> d-------- C:\WINDOWS\pss
2007-11-01 10:06 33,280 --a------ C:\WINDOWS\system32\xxyabxv.dll
2007-11-01 09:37 33,280 --a------ C:\WINDOWS\system32\nnnkhhi.dll
2007-11-01 09:36 33,280 --a------ C:\WINDOWS\system32\awtrstu.dll
2007-11-01 09:36 10,752 -r-hs---- C:\WINDOWS\system32\asrsvc.exe
2007-10-20 14:16 <DIR> d-------- C:\Program Files\mp3DirectCut
2007-10-16 22:53 <DIR> d-------- C:\Program Files\Windows Journal Viewer
2007-10-12 12:26 <DIR> d-------- C:\Documents and Settings\Hanis\Application Data\Apple Computer
2007-10-12 12:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-12 12:24 <DIR> d-------- C:\Program Files\Apple Software Update
2007-10-12 12:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-12 04:46 905 ----a-w C:\WINDOWS\Fonts\acrsecI.fon
2007-10-09 12:35 408,092 ----a-w C:\WINDOWS\system32\MSServx.exe
2007-10-08 05:18 --------- d-----w C:\Program Files\SystemDefender
2007-09-26 06:20 --------- d-----w C:\Documents and Settings\Hanis\Application Data\Netscape
2007-09-26 06:19 --------- d-----w C:\Program Files\Netscape
2007-09-17 12:01 --------- d-----w C:\Program Files\JustZIPit
2007-09-11 07:05 1,761 ----a-w C:\WINDOWS\Fonts\acrsecB.fon
2007-08-29 10:27 464,112 ----a-w C:\WINDOWS\daffy.scr
2007-08-29 10:27 461,308 ----a-w C:\WINDOWS\daffy.exe
2007-08-29 10:27 40,960 ----a-w C:\WINDOWS\daffy.dll
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-13 10:54 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll
2007-08-13 10:54 413,696 ----a-w C:\WINDOWS\system32\dllcache\vbscript.dll
2007-08-13 10:54 33,792 ----a-w C:\WINDOWS\system32\dllcache\custsat.dll
2007-08-13 10:54 191,488 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-13 10:54 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2007-08-13 10:54 156,160 ----a-w C:\WINDOWS\system32\dllcache\msls31.dll
2007-08-13 10:45 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2007-08-13 10:45 78,336 ----a-w C:\WINDOWS\system32\dllcache\ieencode.dll
2007-08-13 10:44 69,120 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-13 10:44 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-13 10:44 40,960 ----a-w C:\WINDOWS\system32\dllcache\licmgr10.dll
2007-08-13 10:39 92,672 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-13 10:39 71,680 ----a-w C:\WINDOWS\system32\dllcache\admparse.dll
2007-08-13 10:39 71,680 ----a-w C:\WINDOWS\system32\admparse.dll
2007-08-13 10:39 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2007-08-13 10:39 55,296 ----a-w C:\WINDOWS\system32\dllcache\iesetup.dll
2007-08-13 10:38 491,520 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-13 10:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-13 10:36 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2007-08-13 10:36 36,352 ----a-w C:\WINDOWS\system32\dllcache\imgutil.dll
2007-08-13 10:35 346,624 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-13 10:32 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2007-08-13 10:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\mshta.exe
2007-08-13 10:18 60,416 ----a-w C:\WINDOWS\system32\dllcache\hmmapi.dll
2007-08-13 10:01 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-13 10:01 48,128 ----a-w C:\WINDOWS\system32\dllcache\mshtmler.dll
2006-11-13 12:39 84 ----a-w C:\Documents and Settings\Hanis\cmd2.cmd
2006-11-13 12:39 110,592 ----a-w C:\Documents and Settings\Hanis\mtr.exe
2004-08-03 21:00 774,144 ----a-w C:\Documents and Settings\dotnetfx\XPSPUI.DLL
2004-08-03 21:00 647,168 ----a-w C:\Documents and Settings\dotnetfx\SITSETUP.DLL
2004-08-03 21:00 487,424 ----a-w C:\Documents and Settings\dotnetfx\MSVCP70.DLL
2004-08-03 21:00 40,960 ----a-w C:\Documents and Settings\dotnetfx\CMNRES.DLL
2004-08-03 21:00 36,864 ----a-w C:\Documents and Settings\dotnetfx\SUITE.DLL
2004-08-03 21:00 36,864 ----a-w C:\Documents and Settings\dotnetfx\DELTEMP.EXE
2004-08-03 21:00 344,064 ----a-w C:\Documents and Settings\dotnetfx\MSVCR70.DLL
2004-08-03 21:00 339,968 ----a-w C:\Documents and Settings\dotnetfx\TEMPLMGR.DLL
2004-08-03 21:00 335,872 ----a-w C:\Documents and Settings\dotnetfx\GENCOMP.DLL
2004-08-03 21:00 308 ----a-w C:\Documents and Settings\dotnetfx\DFFACT.DAT
2004-08-03 21:00 286,720 ----a-w C:\Documents and Settings\dotnetfx\XPSPSCEN.DLL
2004-08-03 21:00 274,432 ----a-w C:\Documents and Settings\dotnetfx\UIMGR.DLL
2004-08-03 21:00 24,265,736 ----a-w C:\Documents and Settings\dotnetfx\DOTNETFX.EXE
2004-08-03 21:00 233,472 ----a-w C:\Documents and Settings\dotnetfx\DFDEPUI.DLL
2004-08-03 21:00 200,704 ----a-w C:\Documents and Settings\dotnetfx\XPSPREQS.DLL
2004-08-03 21:00 200,704 ----a-w C:\Documents and Settings\dotnetfx\SVRGRMGR.DLL
2004-08-03 21:00 192,512 ----a-w C:\Documents and Settings\dotnetfx\DEPMGR.DLL
2004-08-03 21:00 163,840 ----a-w C:\Documents and Settings\dotnetfx\DFCHGFLD.DLL
2004-08-03 21:00 155,648 ----a-w C:\Documents and Settings\dotnetfx\SETUPDB.DLL
2004-08-03 21:00 147,456 ----a-w C:\Documents and Settings\dotnetfx\CDMGR.DLL
2004-08-03 21:00 143,360 ----a-w C:\Documents and Settings\dotnetfx\DISKMGR.DLL
2004-08-03 21:00 143,360 ----a-w C:\Documents and Settings\dotnetfx\ACCMGR.DLL
2004-08-03 21:00 139,264 ----a-w C:\Documents and Settings\dotnetfx\SETLOG.DLL
2004-08-03 21:00 135,168 ----a-w C:\Documents and Settings\dotnetfx\VALIDATE.DLL
2004-08-03 21:00 135,168 ----a-w C:\Documents and Settings\dotnetfx\DFFACT.DLL
2004-08-03 21:00 131,072 ----a-w C:\Documents and Settings\dotnetfx\HTMLLITE.DLL
2004-08-03 21:00 129,720 ----a-w C:\Documents and Settings\dotnetfx\SETUP.EXE
2004-08-03 21:00 122,880 ----a-w C:\Documents and Settings\dotnetfx\DEFHELP.DLL
2004-08-03 21:00 118,784 ----a-w C:\Documents and Settings\dotnetfx\REBOOTST.EXE
2004-08-03 21:00 10,694,464 ----a-w C:\Documents and Settings\dotnetfx\NDPSP.EXE
2004-08-03 21:00 1,773 ----a-w C:\Documents and Settings\dotnetfx\BASELINE.DAT
2007-01-23 13:35:10 3,140 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-01-23 13:33:40 8 --sh--r C:\WINDOWS\system32\21D33CA5AB.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-90F0-F66AB581A933}]
C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59879FA4-4790-461c-A1CC-4EC4DE4CA483}]
C:\Program Files\RXToolBar\sfcont.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{634BBAB7-3F60-4426-944F-A62B9007F67F}]
2007-11-03 22:50 36352 --a------ C:\WINDOWS\system32\opnolii.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b0da615c-848d-40bd-a95f-22796762fdc8}]
2007-11-12 07:56 79936 --a------ C:\WINDOWS\system32\eyugxeug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-07 16:17]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-07 16:16]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" []
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-22 19:31]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-15 01:07]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-24 21:22]
"nwiz"="nwiz.exe" [2005-03-24 21:22 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-03-24 21:22]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 15:54 C:\WINDOWS\soundman.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-15 11:45 C:\WINDOWS\AGRSMMSG.exe]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-04-21 10:13]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [2005-03-15 10:03]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2005-10-14 15:38]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 C:\WINDOWS\system32\bthprops.cpl]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 16:54]
"SemanticInsight"="C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"SurfNavigator"="C:\WINDOWS\system32\SurferClient.exe" [2007-01-28 12:14]
"AutomatedSurfer"="C:\WINDOWS\system32\SurferClient.exe" [2007-01-28 12:14]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"AltnetPointsManager"="c:\program files\altnet\points manager\points manager.exe" [2006-07-19 17:01]
"MicrosoftUpdate"="C:\WINDOWS\system32\MSServx.exe" [2007-10-09 20:35]
"Application Layer Services"="asrsvc.exe" [2007-11-01 00:50 C:\WINDOWS\system32\asrsvc.exe]
"Option Bib Logo Log"="C:\Documents and Settings\All Users\Application Data\LICENSE ADMIN OPTION BIB\Logo Start.exe" [2007-11-12 12:46]
"320d18a1"="C:\WINDOWS\system32\keoegtlu.dll" [2007-11-12 07:53]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"SurfNavigator"="C:\WINDOWS\system32\SurferClient.exe" [2007-01-28 12:14]
"AutomatedSurfer"="C:\WINDOWS\system32\SurferClient.exe" [2007-01-28 12:14]
"book ante"="C:\DOCUME~1\Hanis\APPLIC~1\ELSEPL~1\AXISNEW.exe" [2007-11-09 02:29]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AutomatedSurfer"=C:\WINDOWS\system32\SurferClient.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 04:05:56]
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-05-27 13:41:44]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2005-08-16 14:06:22]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{634BBAB7-3F60-4426-944F-A62B9007F67F}"= C:\WINDOWS\system32\opnolii.dll [2007-11-03 22:50 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnolii]
opnolii.dll 2007-11-03 22:50 36352 C:\WINDOWS\system32\opnolii.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\geedb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messaging]
C:\Program Files\Instant Messenger Names\IM-svr.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
R2 EpmPsd;Acer EPM Power Scheme Driver;\??\C:\WINDOWS\system32\drivers\epm-psd.sys
R2 EpmShd;Acer EPM System Hardware Driver;\??\C:\WINDOWS\system32\drivers\epm-shd.sys
R2 osaio;osaio;\??\C:\WINDOWS\system32\drivers\osaio.sys
R2 osanbm;osanbm;\??\C:\WINDOWS\system32\drivers\osanbm.sys
R2 SurferService;AutomatedSurfer;C:\WINDOWS\system32\srvany.exe
R3 DKbFltr;Dritek Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
R3 EMSCR;EMSCR;C:\WINDOWS\system32\DRIVERS\EMS7SK.sys
R3 ESDCR;ESDCR;C:\WINDOWS\system32\DRIVERS\ESD7SK.sys
R3 ESMCR;ESMCR;C:\WINDOWS\system32\DRIVERS\ESM7SK.sys
R4 DritekPortIO;Dritek General Port I/O;\??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys
S3 SE2Bbus;Sony Ericsson Device 043 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Bbus.sys
S3 SE2Bmdfl;Sony Ericsson Device 043 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Bmdfl.sys
S3 SE2Bmdm;Sony Ericsson Device 043 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Bmdm.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-06 15:55:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-12 03:00:06 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-11-12 03:00:02 C:\WINDOWS\Tasks\ADADC1DD918A7E25.job"
- c:\docume~1\hanis\applic~1\elsepl~1\Thunkdeafgreat.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-12 12:45:36
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MicrosoftUpdate = C:\WINDOWS\system32\MSServx.exe????????|???B???|????????8)5?8k%????w?g%?H)5?|?#????w??????#???#?9????R??H"5???????EventWrite?d?er?%
[email protected]????g%????|??%
[email protected]?????????%???#????????????|???BD?#?l??|,?#?????4?#????????|?&5???#?Q??|??5?m??|??#??&5????????|p?#??2?|9??????????? ??????B??#????B???w???B?????2?|????????p??|???BH???????X??????|?2?|?????2?|???|??????????5???#???5???????#?(?#?????????<???????D?#????|??#????|p??|????m??|???|??5??????&5?(?#?\??|?&5??&5?9??\??#????|?s?|
[email protected]?????|
[email protected]?|FA?|???|????????????????????p 5?(&5?T&5????|?????????????????&5?x%5?T&5??&5?????????T&5??!5?P??|??#??%5?T&5? &5????|?&5????|?!5?9??\
[email protected]??????????????T&5?T&5??&5???#??&5?4?#???????#????|?r?|?????s?|?a?|???\?`?|
[email protected]?????|0???????????????????????????????????????????????0???????????????????????????????????????????????????????8%?|??????????#
[email protected]???????????0?#???????#??????%?|?????#?|????0????????#?|D?F?$???J?L??"%?(??????|
[email protected]?>
[email protected]?????>???????????????????????Ct?|??5? ??????????????????????????????????????|????"??????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-12 12:47:10 - machine was rebooted
.
--- E O F ---