ComboFix 07-11-08.1 - HP_Owner 2007-11-15 16:03:59.9 - NTFSx86
Running from: C:\Documents and Settings\HP_Owner\My Documents\mozilla downloads\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\HP_Owner\Desktop\Live Safety Center.lnk
C:\Documents and Settings\HP_Owner\Desktop\Online Security Guide.lnk
C:\Documents and Settings\HP_Owner\Favorites\Online Security Guide.lnk
C:\WINDOWS\system32\onnmp.bak1
C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\pmnno.dll
C:\WINDOWS\system32\usysykju.dllbox
.
((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.
2007-11-15 15:32 <DIR> d-------- C:\Program Files\RegCure
2007-11-15 15:09 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-15 15:09 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-15 14:30 <DIR> d-------- C:\Program Files\Viewpoint
2007-11-15 14:06 <DIR> d-------- C:\Program Files\XoftSpySE
2007-11-15 01:32 144,480 --a------ C:\WINDOWS\system32\usysykju.dll
2007-11-15 01:32 144,480 --a--c--- C:\WINDOWS\system32\criktbeb.dll
2007-11-15 01:29 71,232 --a--c--- C:\WINDOWS\system32\qnggmrfw.exe
2007-11-14 02:37 6,058,496 --a------ C:\WINDOWS\system32\dllcache\ieframe.dll
2007-11-14 02:37 2,455,488 --a------ C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-11-14 02:37 459,264 --a------ C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-11-14 02:37 383,488 --a------ C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-11-14 02:37 267,776 --a------ C:\WINDOWS\system32\dllcache\iertutil.dll
2007-11-14 02:37 63,488 --a------ C:\WINDOWS\system32\dllcache\icardie.dll
2007-11-14 02:37 52,224 --a------ C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-11-14 02:37 13,824 --a------ C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-11-14 02:21 37,376 --a------ C:\WINDOWS\system32\nnnnkkk.dll
2007-11-14 02:13 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-11-14 01:47 <DIR> d----c--- C:\VundoFix Backups
2007-11-13 22:43 37,376 --a------ C:\WINDOWS\system32\khfcdba.dll
2007-11-13 22:43 336 --a------ C:\WINDOWS\17PHolmes1188.exe
2007-11-13 22:06 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-13 20:24 144,480 --a--c--- C:\WINDOWS\system32\aipbnwrm.dll
2007-11-13 20:21 85,056 --a--c--- C:\WINDOWS\system32\bwnknnrh.dll
2007-11-13 20:18 80,448 --a--c--- C:\WINDOWS\system32\jwwspdfs.dll
2007-11-13 20:12 71,232 --a--c--- C:\WINDOWS\system32\eoxejuqf.exe
2007-11-13 05:01 <DIR> d----c--- C:\Documents and Settings\HP_Owner\Application Data\Roxio
2007-11-13 02:24 <DIR> d-------- C:\Program Files\WinMX Fix v.3.0
2007-11-13 02:24 <DIR> d-------- C:\Program Files\iTunes
2007-11-13 02:24 <DIR> d-------- C:\Program Files\iPod
2007-11-13 02:23 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2007-11-13 02:23 <DIR> d-------- C:\Program Files\Roxio
2007-11-13 02:23 <DIR> d-------- C:\Program Files\Remove Empty Directories
2007-11-13 02:23 <DIR> d-------- C:\Program Files\Maxis
2007-11-13 02:23 <DIR> d-------- C:\Program Files\InterVideo
2007-11-13 02:23 <DIR> d-------- C:\Program Files\Disney
2007-11-13 02:23 <DIR> d-------- C:\Program Files\Cosmi
2007-11-13 02:23 <DIR> d-------- C:\Program Files\Clipmarks
2007-11-13 02:23 <DIR> d-------- C:\Program Files\BaDoink
2007-11-13 02:23 <DIR> d-------- C:\Program Files\AGEIA Technologies
2007-11-13 02:23 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Roxio
2007-11-13 02:22 <DIR> d-------- C:\Program Files\Viewpoint(3)
2007-11-13 02:22 <DIR> d-------- C:\Program Files\Tencent
2007-11-13 02:22 <DIR> d-------- C:\Program Files\MySpace
2007-11-13 02:22 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-13 02:22 <DIR> d-------- C:\audio
2007-11-13 02:05 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion(2)
2007-11-10 13:33 <DIR> d-------- C:\Program Files\AGEIA Technologies(2)
2007-11-09 19:19 <DIR> d-------- C:\Program Files\Aspyr
2007-11-09 15:18 <DIR> d-------- C:\Program Files\Apple Software Update
2007-11-08 23:11 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-11-08 23:09 134 --a--c--- C:\n.bat
2007-11-08 23:08 35,328 --a------ C:\WINDOWS\system32\yayxutq.dll
2007-11-08 23:08 0 --a--c--- C:\z.dat
2007-11-08 23:08 0 --a--c--- C:\x.dat
2007-11-07 15:42 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2007-11-07 15:42 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-11-07 15:42 <DIR> d-------- C:\Program Files\Legacy Interactive
2007-11-07 15:42 <DIR> d-------- C:\Program Files\GameSpy
2007-11-07 15:42 <DIR> d-------- C:\Program Files\Firaxis Games
2007-11-07 15:42 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2007-11-07 15:41 <DIR> d--h----- C:\Program Files\Zero G Registry
2007-11-07 15:41 <DIR> d-------- C:\Program Files\VstPlugins
2007-11-07 15:41 <DIR> d-------- C:\Program Files\UltraISO
2007-11-07 15:41 <DIR> d-------- C:\Program Files\Symantec
2007-11-07 15:41 <DIR> d-------- C:\Program Files\SoundSpectrum
2007-11-07 15:41 <DIR> d-------- C:\Program Files\SD EnterNET
2007-11-07 00:03 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\MumboJumbo
2007-11-06 01:20 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-11-04 20:10 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2007-11-04 13:33 <DIR> d----c--- C:\c6616f9bfd906f1ad04bbed7e3dd4f
2007-11-04 13:30 <DIR> d-------- C:\Program Files\Common Files\Roxio Shared
2007-11-04 13:30 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Sonic
2007-11-04 01:28 <DIR> d----c--- C:\Documents and Settings\HP_Owner\Application Data\Sierra Entertainment
2007-11-04 01:28 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-11-03 17:00 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-10-30 01:47 <DIR> d----c--- C:\Documents and Settings\HP_Owner\Application Data\Super-Cow
2007-10-29 01:58 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2007-10-29 01:58 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll
2007-10-29 01:58 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll
2007-10-29 01:58 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2007-10-25 02:25 <DIR> d-------- C:\Program Files\MSECache
2007-10-25 02:05 <DIR> d-------- C:\Program Files\Download Manager
2007-10-24 01:58 143,872 --a------ C:\WINDOWS\system32\iacenc.dll
2007-10-24 01:58 56,832 --a------ C:\WINDOWS\system32\iyvu9_32.dll
2007-10-24 01:44 <DIR> d----c--- C:\Documents and Settings\HP_Owner\Application Data\QQ Games Plugin
2007-10-23 18:22 86,082 --a------ C:\WINDOWS\system32\ftdiunin.exe
2007-10-23 18:22 77,890 --a------ C:\WINDOWS\system32\FTLang.dll
2007-10-23 18:22 60,572 --a------ C:\WINDOWS\system32\drivers\ftser2k.sys
2007-10-23 18:22 48,625 --a------ C:\WINDOWS\system32\ftserui2.dll
2007-10-23 18:22 28,449 --a------ C:\WINDOWS\system32\drivers\ftdibus.sys
2007-10-20 12:32 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-10-20 12:32 53,760 --a------ C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2007-10-20 02:30 <DIR> d----c--- C:\Documents and Settings\HP_Owner\Application Data\iWin
2007-10-20 01:36 1,683,792 --a------ C:\WINDOWS\system32\wmvcore2.dll
2007-10-20 01:36 665,424 --a------ C:\WINDOWS\system32\wmv8dmoe.dll
2007-10-20 01:36 572,752 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2007-10-20 01:36 438,608 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2007-10-20 01:35 <DIR> d-------- C:\Program Files\coolpro2
2007-10-19 19:01 <DIR> d-------- C:\Program Files\Nero
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 20:20 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-15 20:07 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-15 06:41 --------- d-----w C:\Program Files\Google
2007-11-14 07:28 --------- d-----w C:\Program Files\Trend Micro
2007-11-14 03:07 --------- d-----w C:\Program Files\Java
2007-11-13 22:35 --------- d-----w C:\Program Files\Hewlett-Packard
2007-11-13 07:32 --------- d-----w C:\Program Files\Microsoft Games
2007-11-13 07:23 --------- d-----w C:\Program Files\QuickTime
2007-11-13 07:23 --------- d-----w C:\Program Files\LimeWire
2007-11-12 01:31 9,046 -c--a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2007-11-10 18:52 --------- d-----w C:\Program Files\InterActual
2007-11-10 00:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-09 23:12 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\IGN_DLM
2007-11-07 23:53 --------- d-----w C:\Program Files\Common Files\aolshare
2007-11-07 23:53 --------- d-----w C:\Program Files\Common Files\AOL
2007-11-07 20:42 --------- d-----w C:\Program Files\HPQ
2007-11-07 19:22 --------- d-----w C:\Program Files\Yahoo!
2007-11-07 19:22 --------- d-----w C:\Program Files\Support.com
2007-11-07 19:21 --------- d-----w C:\Program Files\Real
2007-11-07 19:21 --------- d-----w C:\Program Files\Online Backup
2007-11-07 19:21 --------- d-----w C:\Program Files\MSN Toolbar Suite
2007-11-07 19:21 --------- d-----w C:\Program Files\MSN Messenger
2007-11-07 19:21 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-11-07 19:21 --------- d-----w C:\Program Files\ICOO Loader
2007-11-07 19:20 --------- d-----w C:\Program Files\GameSpy Arcade
2007-11-04 18:29 --------- d-----w C:\Program Files\Sonic
2007-10-24 06:43 --------- dc----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-22 22:54 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
2007-10-20 22:35 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\muvee Technologies
2007-10-20 22:05 --------- d-----w C:\Program Files\AskTBar
2007-10-20 17:52 --------- d-----w C:\Program Files\Common Files\muvee Technologies
2007-10-20 00:11 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\Nero
2007-10-20 00:01 --------- dc----w C:\Documents and Settings\All Users\Application Data\Nero
2007-10-19 20:13 --------- d-----w C:\Program Files\AusLogics Disk Defrag
2007-10-19 19:47 --------- d-----w C:\Program Files\Common Files\Ahead
2007-10-19 17:47 --------- d-----w C:\Program Files\PConPoint
2007-10-19 17:07 --------- d-----w C:\Program Files\Easy Internet signup
2007-10-19 16:06 --------- dc----w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-19 15:52 --------- d-----w C:\Program Files\IncrediMail
2007-10-19 05:37 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\Intuit
2007-10-19 05:36 --------- dc----w C:\Documents and Settings\All Users\Application Data\Intuit
2007-10-19 05:20 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-10-19 05:20 --------- d-----w C:\Program Files\Common Files\Real
2007-10-19 05:18 --------- d-----w C:\Program Files\AOL Computer Check-Up
2007-10-19 05:18 --------- d-----w C:\Program Files\America Online 9.0f
2007-10-19 05:18 --------- d-----w C:\Program Files\America Online 9.0e
2007-10-19 05:18 --------- d-----w C:\Program Files\America Online 9.0b
2007-10-19 05:18 --------- d-----w C:\Program Files\America Online 9.0
2007-10-19 04:49 --------- dc----w C:\Documents and Settings\All Users\Application Data\QuickTime
2007-10-19 04:40 --------- d-----w C:\Program Files\HP
2007-10-19 04:33 1,716 --sha-r C:\WINDOWS\system32\drivers\103C_HP_CPC_PY208AV-ABA a1030e_YC_0Pavi_QMXG530_E53NAheBLU5_47_ISalmon_SASUSTek Computer INC._V1.04_B3.15_T051019_WXH2_L409_M896_J80_7AMD_8Sempron_91.81_#050913_N10390900_Z11C1048C_G10396330.MRK
2007-10-19 04:30 --------- d---a-w C:\Program Files\Common Files\LightScribe
2007-10-19 03:44 --------- d-----w C:\Program Files\Webshots
2007-10-19 02:54 --------- d-----w C:\Program Files\Rhapsody
2007-10-19 02:13 --------- d-----w C:\Program Files\BellSouth
2007-10-19 02:10 132,675 ----a-w C:\Program Files\INSTALL.LOG
2007-10-19 02:01 --------- dc----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-19 00:17 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\BellSouth
2007-10-19 00:17 --------- dc----w C:\Documents and Settings\All Users\Application Data\BellSouth
2007-10-19 00:04 --------- d-----w C:\Program Files\Common Files\Motive
2007-10-18 23:50 4 -c--a-w C:\WINDOWSRegDefrag.dat
2007-10-17 18:12 --------- d-----w C:\Program Files\DFX
2007-10-17 08:43 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\Move Networks
2007-10-17 08:43 --------- dc----w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-10-17 08:43 --------- d--h--r C:\Documents and Settings\HP_Owner\Application Data\yahoo!
2007-10-17 08:42 --------- d-----w C:\Program Files\Common Files\Nullsoft
2007-10-17 08:41 --------- dc----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-17 08:41 --------- d-----w C:\Program Files\Multimedia Transcoding Tool
2007-10-17 08:40 --------- d-----w C:\Program Files\AOL 9.0a
2007-10-17 08:37 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\AOL
2007-10-17 05:37 --------- d-----w C:\Program Files\web-radio
2007-10-17 04:09 --------- dc----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-12 04:03 --------- dc----w C:\Documents and Settings\All Users\Application Data\HipSoft
2007-10-11 19:08 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\AdobeUM
2007-10-10 16:50 --------- d-----w C:\Program Files\ACNielsen
2007-10-06 17:11 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-10-06 08:43 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\WeatherBug
2007-09-29 19:48 --------- dc----w C:\Documents and Settings\All Users\Application Data\DFX
2007-09-28 18:34 --------- dc----w C:\Documents and Settings\HP_Owner\Application Data\Babylon
2007-09-24 13:05 132,904 ----a-w C:\WINDOWS\system32\drivers\imagesrv.sys
2007-09-24 13:05 11,304 ----a-w C:\WINDOWS\system32\drivers\imagedrv.sys
2007-09-20 13:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2007-09-20 13:55 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2007-01-10 17:15 839,684 ----a-w C:\WINDOWS\Fonts\Crack.exe
2007-01-10 17:15 839,683 --sh--w C:\WINDOWS\Fonts\svchost.exe
2006-11-12 18:42 0 ----a-w C:\Program Files\Common Files\err.log
2006-09-19 18:10 1 -c--a-w C:\Documents and Settings\HP_Owner\SI.bin
2006-05-10 18:26 299 -c--a-w C:\Documents and Settings\HP_Owner\Application Data\internaldb1942.dat
2006-01-26 20:53 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-01-10 17:15:15 839,683 --sh--w C:\WINDOWS\Fonts\svchost.exe
2005-11-15 21:39:10 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-15 01:32 144480 --a------ C:\WINDOWS\system32\usysykju.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d91edfd0-519c-4707-8869-95221c3f4bc3}]
2007-11-13 20:18 80448 --a--c--- C:\WINDOWS\system32\jwwspdfs.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E0B54BEC-9209-4B5D-94E5-A8906DE18FFB}]
2007-11-14 02:21 37376 --a------ C:\WINDOWS\system32\nnnnkkk.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\usysykju.dll [2007-11-15 01:32 144480]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\usysykju.dll [2007-11-15 01:32 144480]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSPower"="SiSPower.dll" [2005-01-05 01:54 C:\WINDOWS\system32\SiSPower.dll]
"CTHelper"="CTHELPER.EXE" [2003-11-14 03:18 C:\WINDOWS\system32\CTHELPER.EXE]
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 10:00]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2004-04-07 11:07]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 13:14]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 12:12]
"AT&T Internet Security Suite"="C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe" [2007-06-28 15:09]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-18 21:47]
"HostManager"="C:\Program Files\Common Files\AOL\1192809728\ee\AOLSoftware.exe" [2007-04-12 16:23]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-08-30 13:04]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 16:32]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 18:14]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 00:34]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-11-16 13:55]
"Host Process"="C:\WINDOWS\Fonts\svchost.exe" [2007-01-10 12:15]
"combofix"="C:\WINDOWS\system32\cmd.exe" [2004-08-03 23:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-10-09 11:02]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 16:57]
"AOL Fast Start"="C:\Program Files\AOL 9.0b\AOL.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:00]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-01 17:11]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-10-18 22:05]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-11-14 12:32]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"SetDefaultMIDI"=MIDIDEF.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E0B54BEC-9209-4B5D-94E5-A8906DE18FFB}"= C:\WINDOWS\system32\nnnnkkk.dll [2007-11-14 02:21 37376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnkkk]
nnnnkkk.dll 2007-11-14 02:21 37376 C:\WINDOWS\system32\nnnnkkk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\usysykju]
usysykju.dll 2007-11-15 01:32 144480 C:\WINDOWS\system32\usysykju.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\pmnno.dll
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e29e2fbc-b976-11d9-bac2-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder
"2007-11-12 19:06:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-03 03:55:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2007-11-12 13:57:00 C:\WINDOWS\Tasks\Find Duplicate Files.job"
- C:\PROGRA~1\ADVANC~1\finddupe.exe
"2007-11-09 21:45:01 C:\WINDOWS\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe
"2007-05-23 02:40:25 C:\WINDOWS\Tasks\HubTask 1 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- c:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe
"2007-05-28 00:35:29 C:\WINDOWS\Tasks\HubTask 2 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- c:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe
"2007-11-15 21:15:20 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-11-15 20:35:48 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-11-15 21:17:03 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
"2007-11-15 21:15:21 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2007-11-15 19:06:20 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-15 16:15:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-15 16:22:04 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-15 13:19
C:\ComboFix3.txt ... 2007-11-15 12:54
.
--- E O F ---

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Back to top











