"HP_Owner" - 2007-05-13 10:22:14 Service Pack 2
ComboFix 07-05.13.V - Running from: "C:\Documents and Settings\HP_Owner\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\ieak400.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\tmp1.tmp.dll
C:\WINDOWS\system32\tmp5.tmp.dll
C:\WINDOWS\system32\tmpA.tmp.dll
C:\DOCUME~1\HP_Owner\Desktop\internet.lnk
C:\WINDOWS\system32\lsasss.exe
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-13 ))))))))))))))))))))))))))))))))))
2007-05-13 10:25 106,768 --a------ C:\WINDOWS\effcax.dll
2007-05-12 20:44 d-------- C:\VundoFix Backups
2007-05-11 23:02 d-------- C:\Program Files\Spybot - Search & Destroy2
2007-05-11 22:55 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-11 14:00 d-------- C:\WINDOWS\system32\bak
2007-04-30 20:43 d-------- C:\DOCUME~1\HP_Owner\APPLIC~1\ArcSoft
2007-04-30 20:41 163,840 --a------ C:\WINDOWS\system32\PhotoImpression Screen Saver.scr
2007-04-30 20:18 73,728 --a------ C:\WINDOWS\system32\mr310ipc.dll
2007-04-30 20:18 36,864 --a------ C:\WINDOWS\system32\mr310exv.dll
2007-04-30 20:18 352,256 --a------ C:\WINDOWS\system32\ijl15.dll
2007-04-30 20:18 28,672 --a------ C:\WINDOWS\system32\mr310exd.dll
2007-04-30 20:18 127,574 --a------ C:\WINDOWS\system32\drivers\MR97310c.sys
2007-04-30 20:18 102,400 --a------ C:\WINDOWS\system32\mr310ifc.dll
2007-04-22 11:06 76,800 --a------ C:\WINDOWS\system32\vgpix32d.dll
2007-04-22 11:06 299,520 --a------ C:\WINDOWS\uninst.exe
2007-04-22 11:06 29,184 --a------ C:\WINDOWS\system32\icmyuy2.dll
2007-04-22 11:06 107,328 --a------ C:\WINDOWS\system32\drivers\weeCamke.sys
2007-04-22 11:06 d-------- C:\Program Files\QuickVideo weeCam
2007-04-16 08:22 d-------- C:\DOCUME~1\HP_Owner\APPLIC~1\OpenOffice.org2
2007-04-16 08:18 d-------- C:\Program Files\OpenOffice.org 2.2
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-11 21:07:09 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-05-11 21:00:40 -------- d-----w C:\Program Files\Verizon
2007-05-11 21:00:36 -------- d-----w C:\Program Files\Norton Internet Security
2007-05-11 21:00:34 -------- d-----w C:\Program Files\Messenger
2007-05-11 20:59:22 37,450 ----a-w C:\WINDOWS\system32\hkcmd.exe
2007-05-07 22:52:57 -------- d-----w C:\DOCUME~1\HP_Owner\APPLIC~1\AdobeUM
2007-04-11 23:55:50 -------- d-----w C:\Program Files\Yahoo!
2007-04-11 22:00:20 -------- d-----w C:\Program Files\Audacity
2007-04-11 14:55:02 -------- d-----w C:\Program Files\Google
2007-04-11 04:44:11 -------- d-----w C:\Program Files\Microsoft Works
2007-04-11 03:28:08 -------- d-----w C:\Program Files\Easy Internet signup
2007-04-10 06:26:10 -------- d-----w C:\DOCUME~1\HP_Owner\APPLIC~1\Motive
2007-04-10 06:16:03 -------- d-----w C:\Program Files\Common Files\Motive
2007-04-10 03:55:54 -------- d-----w C:\DOCUME~1\HP_Owner\APPLIC~1\Symantec
2007-04-10 03:55:54 -------- d-----w C:\DOCUME~1\HP_Owner\APPLIC~1\Real
2007-04-10 01:57:21 -------- d-----w C:\Program Files\Windows NT
2007-04-10 01:57:17 -------- d-----w C:\Program Files\Movie Maker
2007-04-09 18:59:18 1,168 ----a-w C:\WINDOWS\mozver.dat
2007-04-09 18:19:06 -------- d-----w C:\Program Files\Spyware Doctor
2007-04-08 22:06:55 -------- d-----w C:\DOCUME~1\HP_Owner\APPLIC~1\PC Tools
2007-04-08 21:57:07 0 ----a-w C:\WINDOWS\nsreg.dat
2007-04-08 21:42:37 -------- d-----w C:\Program Files\Trend Micro
2007-04-06 21:42:26 79,272 ----a-w C:\WINDOWS\hpfins05.dat
2007-04-06 21:25:36 -------- d-----w C:\DOCUME~1\HP_Owner\APPLIC~1\HP
2007-04-02 23:23:55 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-03-19 19:24:48 -------- d-----w C:\Program Files\Blaze Media Pro
2007-03-14 19:45:41 -------- d-----w C:\Program Files\Power Tab Software
2007-02-28 23:40:25 737,280 ----a-w C:\WINDOWS\iun6002.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 10:28]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 22:17]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy2\SDHelper.dll [2005-05-31 01:04]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2007-01-19 23:55]
{BDF3E430-B101-42AD-A544-FADC6B084872}=c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll [2004-08-30 18:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"ccApp"="\"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"URLLSTCK.exe"="c:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"Verizon_McciTrayApp"="C:\\Program Files\\Verizon\\McciTrayApp.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-05-11 13:59]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-05-11 13:59]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2007-05-11 13:59]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2007-05-11 13:59]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2007-05-11 13:59]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-11 13:59]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-05-11 13:59]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-05-11 13:59]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy2\TeaTimer.exe" [2005-05-31 01:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy2\\TeaTimer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 07:13]
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter HTTPFilter\0\0
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
DcomLaunch DcomLaunch\0TermService\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e29e2fbc-b976-11d9-bac2-806d6172696f}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-13 10:28:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-13 10:29:22 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-13 10:29