“pogromca” - 2007-06-01 19:53:14 Service Pack 4 ComboFix 07-05.27.BV - Running from: “D:\Programs” (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) “C:\WINNT\ctfmon.exe” “C:\Program Files\video access activex object” ((((((((((((((((((((((((((((((( Files Created from 2007-05-01 to 2007-06-01 )))))))))))))))))))))))))))))))))) 2007-06-01 19:09 2007-06-01 12:35 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_748.dat 2007-06-01 12:34 740,442 --a------ C:\WINNT\system32\divx.dll 2007-06-01 12:34 73,728 --a------ C:\WINNT\system32\dpl100.dll 2007-06-01 12:34 593,920 --a------ C:\WINNT\system32\xvidcore.dll 2007-06-01 12:34 3,596,288 --a------ C:\WINNT\system32\qt-dx331.dll 2007-06-01 12:34 217,088 --a------ C:\WINNT\system32\yv12vfw.dll 2007-06-01 12:34 180,224 --a------ C:\WINNT\system32\xvidvfw.dll 2007-06-01 12:34 10,752 --a------ C:\WINNT\system32\ff_vfw.dll 2007-06-01 12:34 1,415,680 --a------ C:\WINNT\system32\wmv9vcm.dll 2007-06-01 12:34 2007-06-01 05:45 2007-06-01 00:24 154,624 --a------ C:\WINNT\eraseme_51602.exe 2007-05-31 23:50 2007-05-31 23:50 2007-05-31 22:11 2007-05-31 22:02 3,723,776 --a------ C:\CJW2K42LP.EXE 2007-05-31 21:55 3,307,008 --a------ C:\CJXP42LE.exe 2007-05-26 09:50 2007-05-26 09:05 2007-05-25 09:35 2007-05-23 16:45 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_3b8.dat 2007-05-23 07:21 2007-05-22 21:28 2007-05-22 18:19 9,464 --------- C:\WINNT\system32\drivers\cdralw2k.sys 2007-05-22 18:19 9,336 --------- C:\WINNT\system32\drivers\cdr4_2k.sys 2007-05-22 18:19 43,528 --------- C:\WINNT\system32\drivers\PxHelp20.sys 2007-05-22 18:19 129,784 --------- C:\WINNT\system32\pxafs.dll 2007-05-20 15:47 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_4f8.dat 2007-05-19 21:32 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_3b4.dat 2007-05-18 06:18 2007-05-14 21:10 2007-05-12 22:29 2007-05-12 12:29 10,345 --a------ C:\WINNT\system32\drivers\hamachi.sys 2007-05-08 15:29 2007-05-02 11:20 2007-05-02 11:20 2007-05-02 08:32 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-01 17:34:35 41,232 ----a-w C:\WINNT\system32\ftp.exe 2007-06-01 17:34:35 17,680 ----a-w C:\WINNT\system32\tftp.exe 2007-06-01 17:23:52 -------- d-----w C:\Program Files\DC++ 2007-06-01 16:38:51 -------- d-----w C:\Program Files\mIRC 2007-05-27 16:30:41 1,956 ----a-w C:\WINNT\system32\d3d8caps.dat 2007-05-25 16:59:09 -------- d-----w C:\Program Files\Winamp 2007-05-25 07:35:33 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-05-22 19:28:52 -------- d-----w C:\DOCUME~1\pogromca\DANEAP~1\Opera 2007-05-19 22:18:20 2,068 ----a-w C:\WINNT\system32\d3d9caps.dat 2007-05-19 21:57:12 -------- d-----w C:\DOCUME~1\pogromca\DANEAP~1\Xfire 2007-05-19 21:36:06 -------- d-s—w C:\Program Files\Xfire 2007-05-19 13:37:58 43,520 ----a-w C:\WINNT\system32\CmdLineExt03.dll 2007-05-18 21:36:45 -------- d-----w C:\DOCUME~1\pogromca\DANEAP~1\Skype 2007-05-12 10:36:02 -------- d-----w C:\Program Files\Hamachi 2007-05-12 10:11:49 -------- d-----w C:\DOCUME~1\pogromca\DANEAP~1\Hamachi 2007-05-08 16:27:45 2,661 ----a-w C:\WINNT\DIIUnin.dat 2007-04-24 18:36:10 -------- d-----w C:\Program Files\Common Files\Adobe Systems Shared 2007-04-21 21:43:22 4,233 ----a-w C:\WINNT\mozver.dat 2007-04-20 22:30:02 -------- d-----w C:\Program Files\Need For Speed III 2007-04-16 14:53:00 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_424.dat 2007-04-16 04:24:18 130 ----a-w C:\WINNT\system32\mehjdluu.bat 2007-04-16 04:00:58 106,496 ----a-w C:\WINNT\system32\alkcx.exe 2007-04-16 03:59:40 27,548 ----a-w C:\WINNT\system32\hyovm.exe 2007-04-16 03:50:29 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_3d8.dat 2007-04-16 03:46:27 126 ----a-w C:\WINNT\system32\fdwz.bat 2007-04-16 03:22:17 106,496 ----a-w C:\WINNT\system32\eszl.exe 2007-04-16 03:22:00 27,548 ----a-w C:\WINNT\system32\qshuz.exe 2007-04-15 16:00:53 27,548 ----a-w C:\WINNT\system32\dbph.exe 2007-04-15 14:56:45 106,496 ----a-w C:\WINNT\system32\yjvf.exe 2007-04-15 14:38:57 27,548 ----a-w C:\WINNT\system32\rrck.exe 2007-04-15 14:21:30 27,548 ----a-w C:\WINNT\system32\ugfyfy.exe 2007-04-15 14:13:28 106,496 ----a-w C:\WINNT\system32\tqlxpqr.exe 2007-04-15 14:12:24 26,694 ----a-w C:\WINNT\system32\yayxvwu.dll.vir 2007-04-15 14:12:21 27,548 ----a-w C:\WINNT\system32\ezfpvyi.exe 2007-04-15 13:57:45 106,496 ----a-w C:\WINNT\system32\twluusvt.exe 2007-04-15 13:57:24 27,548 ----a-w C:\WINNT\system32\sdbdiee.exe 2007-04-15 12:26:13 27,548 ----a-w C:\WINNT\system32\rntx.exe 2007-04-14 19:17:07 106,496 ----a-w C:\WINNT\system32\asckey.exe 2007-04-14 19:16:54 27,548 ----a-w C:\WINNT\system32\veaz.exe 2007-04-14 14:09:49 27,548 ----a-w C:\WINNT\system32\ehdcrf.exe 2007-04-14 14:02:33 27,548 ----a-w C:\WINNT\system32\wlurkbrj.exe 2007-04-14 12:20:57 68,608 —ha-w C:\WINNT\system32\xtnj.exe 2007-04-14 10:33:20 27,548 ----a-w C:\WINNT\system32\ffgytvsw.exe 2007-04-14 04:51:02 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_3a0.dat 2007-04-13 18:10:31 28,572 ----a-w C:\WINNT\system32\pouwf.exe 2007-04-13 18:01:59 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_440.dat 2007-04-13 18:01:45 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_5a0.dat 2007-04-13 16:48:57 -------- d-----w C:\Program Files\Belt Generator 2007-04-13 13:36:37 28,572 ----a-w C:\WINNT\system32\tnajmbvr.exe 2007-04-13 07:25:02 28,572 ----a-w C:\WINNT\system32\cyjrmv.exe 2007-04-13 06:38:12 50,853 —ha-w C:\WINNT\system32\fyixgu.exe 2007-04-13 06:26:24 28,572 ----a-w C:\WINNT\system32\yrxuss.exe 2007-04-12 18:30:39 4 ----a-w C:\WINNT\system32\proc-1262580707.bin 2007-04-12 18:30:39 -------- d-----w C:\DOCUME~1\pogromca\DANEAP~1\GanymedeNet 2007-04-12 17:19:28 106,496 ----a-w C:\WINNT\system32\rbdnt.exe 2007-04-12 08:17:18 50,853 —ha-w C:\WINNT\system32\csrqnm.exe 2007-04-12 08:08:46 28,572 ----a-w C:\WINNT\system32\lqwxpho.exe 2007-04-11 20:01:35 25,088 —ha-w C:\WINNT\system32\nbkfxr.exe 2007-04-11 19:35:46 28,976 ----a-w C:\WINNT\system32\cyjmkehv.exe 2007-04-11 15:32:53 21,048 —ha-w C:\WINNT\system32\gzlvg.exe 2007-04-11 15:32:20 0 ----a-w C:\WINNT\system32\fdd.exe 2007-04-11 15:30:08 41,468 —ha-w C:\WINNT\system32\lbhjnuz.exe 2007-04-11 15:29:18 3,584 —ha-w C:\WINNT\system32\fgsf.exe 2007-04-11 15:23:49 29,388 —ha-w C:\WINNT\system32\glkgznkf.exe 2007-04-11 14:53:39 28,976 ----a-w C:\WINNT\system32\zqstzwkl.exe 2007-04-11 13:56:03 50,853 —ha-w C:\WINNT\system32\pgtv.exe 2007-04-11 13:32:30 28,976 ----a-w C:\WINNT\system32\qqdwgb.exe 2007-04-11 06:10:42 28,976 ----a-w C:\WINNT\system32\qgavk.exe 2007-04-10 10:26:22 28,976 ----a-w C:\WINNT\system32\sdmx.exe 2007-04-10 10:08:14 50,853 —ha-w C:\WINNT\system32\drnph.exe 2007-04-10 09:53:04 106,496 ----a-w C:\WINNT\system32\vhrfo.exe 2007-04-10 09:52:49 28,976 ----a-w C:\WINNT\system32\gpjqad.exe 2007-04-09 22:15:25 25,600 ----a-w C:\WINNT\system32\issul.exe 2007-04-09 18:16:28 25,600 ----a-w C:\WINNT\system32\rofyhh.exe 2007-04-09 17:53:29 120 ----a-w C:\WINNT\system32\jwia.bat 2007-04-09 17:42:02 106,496 ----a-w C:\WINNT\system32\ipeubypx.exe 2007-04-09 17:40:44 25,600 ----a-w C:\WINNT\system32\wqihjc.exe 2007-04-09 16:23:26 106,496 ----a-w C:\WINNT\system32\bhwj.exe 2007-04-09 16:23:10 25,600 ----a-w C:\WINNT\system32\ulinfk.exe 2007-04-09 13:10:38 287 ----a-w C:\WINNT\EReg072.dat 2007-04-09 12:31:37 106,496 ----a-w C:\WINNT\system32\lsaemsnp.exe 2007-04-09 12:31:18 25,600 ----a-w C:\WINNT\system32\xmehf.exe 2007-04-09 09:12:51 25,600 ----a-w C:\WINNT\system32\thkxe.exe 2007-04-08 22:41:03 -------- d-----w C:\Program Files\Gadu-Gadu 2007-04-08 22:36:56 106,496 ----a-w C:\WINNT\system32\mmfmf.exe 2007-04-08 22:36:49 31,696 ----a-w C:\WINNT\system32\lbeccvhp.exe 2007-04-08 20:45:40 31,696 ----a-w C:\WINNT\system32\bnxk.exe 2007-04-08 20:34:10 106,496 ----a-w C:\WINNT\system32\oxrcneoo.exe 2007-04-08 20:34:03 31,696 ----a-w C:\WINNT\system32\obxriidz.exe 2007-04-08 20:08:40 106,496 ----a-w C:\WINNT\system32\qzidb.exe 2007-04-08 20:08:33 31,696 ----a-w C:\WINNT\system32\zgmbomxc.exe 2007-04-08 13:45:29 31,696 ----a-w C:\WINNT\system32\vyyx.exe 2007-04-08 13:36:23 31,696 ----a-w C:\WINNT\system32\ublkmx.exe 2007-04-08 13:12:14 31,696 ----a-w C:\WINNT\system32\wknar.exe 2007-04-08 09:27:40 30,000 ----a-w C:\WINNT\system32\eikbghv.exe 2007-04-07 22:04:44 30,000 ----a-w C:\WINNT\system32\tmpq.exe 2007-04-07 19:52:12 30,000 ----a-w C:\WINNT\system32\qzybhvs.exe 2007-04-07 19:42:00 30,000 ----a-w C:\WINNT\system32\zcssh.exe 2007-04-07 15:37:22 -------- d-----w C:\Program Files\Real Alternative 2007-04-07 15:37:09 -------- d-----w C:\Program Files\Media Player Classic 2007-04-07 15:37:05 -------- d-----w C:\DOCUME~1\pogromca\DANEAP~1\Real 2007-04-07 14:08:16 30,000 ----a-w C:\WINNT\system32\azddhqf.exe 2007-04-07 09:28:33 -------- d-----w C:\Program Files\eMule 2007-04-07 09:28:16 -------- d-----w C:\Program Files\BitTorrent 2007-04-07 09:04:34 30,000 ----a-w C:\WINNT\system32\sdeu.exe 2007-04-07 08:22:29 30,000 ----a-w C:\WINNT\system32\cyhuvpbt.exe 2007-04-07 06:55:12 30,000 ----a-w C:\WINNT\system32\izptsbp.exe 2007-04-06 17:37:15 50,853 —ha-w C:\WINNT\system32\wmxkaqmc.exe 2007-04-06 17:12:10 30,000 ----a-w C:\WINNT\system32\yorw.exe 2007-04-06 16:52:42 30,000 ----a-w C:\WINNT\system32\jmwkd.exe 2007-04-06 15:43:47 30,000 ----a-w C:\WINNT\system32\biuijb.exe 2007-04-06 07:58:35 30,000 ----a-w C:\WINNT\system32\xyieeq.exe 2007-04-06 04:05:00 30,000 ----a-w C:\WINNT\system32\slnnoa.exe 2007-04-05 10:00:40 30,000 ----a-w C:\WINNT\system32\dzsva.exe 2007-04-05 09:06:50 30,000 ----a-w C:\WINNT\system32\arfcmt.exe 2007-04-05 08:10:48 30,000 ----a-w C:\WINNT\system32\xybjzwj.exe 2007-04-05 07:47:39 30,000 ----a-w C:\WINNT\system32\logmm.exe 2007-04-05 06:00:02 30,000 ----a-w C:\WINNT\system32\atwvyvi.exe 2007-04-05 04:29:36 30,000 ----a-w C:\WINNT\system32\jiswj.exe 2007-04-04 16:15:46 29,648 ----a-w C:\WINNT\system32\qqnv.exe 2007-04-04 10:43:43 29,648 ----a-w C:\WINNT\system32\chylt.exe 2007-04-04 09:43:50 48,828 —ha-w C:\WINNT\system32\btujqd.exe 2007-04-04 03:51:57 29,648 ----a-w C:\WINNT\system32\nvovj.exe 2007-04-03 04:29:01 29,648 ----a-w C:\WINNT\system32\jcubrda.exe 2007-04-02 14:33:26 130 ----a-w C:\WINNT\system32\hxcikpyb.bat 2007-04-02 11:04:42 29,648 ----a-w C:\WINNT\system32\bgphcnyz.exe 2007-04-02 10:17:07 50,853 —ha-w C:\WINNT\system32\lgmdf.exe 2007-04-02 09:33:41 29,648 ----a-w C:\WINNT\system32\mhrmwcx.exe 2007-04-02 05:40:27 29,648 ----a-w C:\WINNT\system32\mrjspzc.exe 2007-04-01 17:11:02 50,853 —ha-w C:\WINNT\system32\btaqo.exe 2007-04-01 17:00:02 29,648 ----a-w C:\WINNT\system32\ijqprbu.exe 2007-04-01 15:59:27 57,856 ----a-w C:\WINNT\system32\lpogucxm.exe 2007-04-01 15:59:10 29,648 ----a-w C:\WINNT\system32\vaauzyk.exe 2007-04-01 12:45:08 50,853 —ha-w C:\WINNT\system32\kmfnwg.exe 2007-04-01 12:08:45 29,648 ----a-w C:\WINNT\system32\ogjhhdkw.exe 2007-03-31 19:15:08 23,280 ----a-w C:\WINNT\system32\rbeury.exe 2007-03-31 13:58:56 23,280 ----a-w C:\WINNT\system32\fxcici.exe 2007-03-31 09:29:12 23,280 ----a-w C:\WINNT\system32\gmtsxw.exe 2007-03-31 08:01:53 23,280 ----a-w C:\WINNT\system32\rwote.exe 2007-03-31 06:53:59 23,280 ----a-w C:\WINNT\system32\zysqmrht.exe 2007-03-31 04:21:10 57,856 ----a-w C:\WINNT\system32\pfgcjmrh.exe 2007-03-31 04:20:51 23,280 ----a-w C:\WINNT\system32\uprj.exe 2007-03-30 19:49:50 23,280 ----a-w C:\WINNT\system32\huasad.exe 2007-03-30 18:29:26 57,856 ----a-w C:\WINNT\system32\lvatqm.exe 2007-03-30 18:29:16 23,280 ----a-w C:\WINNT\system32\rrkxebob.exe 2007-03-30 18:26:46 75,776 —ha-w C:\WINNT\system32\rirgth.exe 2007-03-30 15:48:34 23,280 ----a-w C:\WINNT\system32\fsibk.exe 2007-03-30 15:26:58 127 ----a-w C:\WINNT\system32\djdoe.bat 2007-03-30 15:26:44 50,853 —ha-w C:\WINNT\system32\avtzpycu.exe 2007-03-30 15:15:49 127 ----a-w C:\WINNT\system32\dgorx.bat 2007-03-30 15:15:34 50,853 —ha-w C:\WINNT\system32\kozqvgtz.exe 2007-03-30 15:05:54 115 ----a-w C:\WINNT\system32\yqgvp.bat 2007-03-30 15:05:38 50,853 —ha-w C:\WINNT\system32\hsik.exe 2007-03-30 14:56:44 118 ----a-w C:\WINNT\system32\xsxpc.bat 2007-03-30 14:56:29 50,853 —ha-w C:\WINNT\system32\fupes.exe 2007-03-30 14:45:48 115 ----a-w C:\WINNT\system32\xsdoy.bat 2007-03-30 14:45:34 50,853 —ha-w C:\WINNT\system32\hylw.exe 2007-03-30 14:36:22 124 ----a-w C:\WINNT\system32\meyooltj.bat 2007-03-30 14:36:06 50,853 —ha-w C:\WINNT\system32\jjojim.exe 2007-03-30 13:48:33 0 ----a-r C:\logwmemory.bin 2007-03-30 13:32:54 23,280 ----a-w C:\WINNT\system32\axfyuryg.exe 2007-03-30 07:30:25 57,856 ----a-w C:\WINNT\system32\yeyzbrqr.exe 2007-03-30 07:30:05 23,280 ----a-w C:\WINNT\system32\bhxy.exe 2007-03-29 20:03:51 48,128 —ha-w C:\WINNT\system32\abui.exe 2007-03-29 19:14:51 75,776 —ha-w C:\WINNT\system32\dcmdsyi.exe 2007-03-29 18:26:12 57,856 ----a-w C:\WINNT\system32\wyzvdfue.exe 2007-03-29 18:25:54 23,280 ----a-w C:\WINNT\system32\jwafm.exe 2007-03-29 15:23:27 23,280 ----a-w C:\WINNT\system32\lftjekqp.exe 2007-03-29 15:19:57 49,845 —ha-w C:\WINNT\system32\ktmesk.exe 2007-03-29 14:13:54 23,280 ----a-w C:\WINNT\system32\fmyqg.exe 2007-03-29 12:39:55 57,856 ----a-w C:\WINNT\system32\tahiztsj.exe 2007-03-29 12:39:39 23,280 ----a-w C:\WINNT\system32\bapkpnxn.exe 2007-03-28 19:34:42 57,856 ----a-w C:\WINNT\system32\dxktpn.exe 2007-03-28 19:34:26 29,136 ----a-w C:\WINNT\system32\edwqes.exe 2007-03-28 19:03:57 57,856 ----a-w C:\WINNT\system32\wgot.exe 2007-03-28 19:03:44 29,136 ----a-w C:\WINNT\system32\mpivntaq.exe 2007-03-28 16:51:03 57,856 ----a-w C:\WINNT\system32\mnnqerg.exe 2007-03-28 16:50:46 29,136 ----a-w C:\WINNT\system32\evdhfo.exe 2007-03-28 13:33:18 29,136 ----a-w C:\WINNT\system32\ciffgel.exe 2007-03-27 13:23:23 53,569 —ha-w C:\WINNT\system32\btzcl.exe 2007-03-27 12:39:00 29,136 ----a-w C:\WINNT\system32\jsom.exe 2007-03-26 16:06:38 53,569 —ha-w C:\WINNT\system32\gocfoc.exe 2007-03-26 14:55:23 29,488 ----a-w C:\WINNT\system32\jobb.exe 2007-03-26 14:55:18 57,856 ----a-w C:\WINNT\system32\wzprm.exe 2007-03-26 12:38:52 29,488 ----a-w C:\WINNT\system32\wpimun.exe 2007-03-25 11:19:39 29,488 ----a-w C:\WINNT\system32\soxoyh.exe 2007-03-25 09:54:04 29,488 ----a-w C:\WINNT\system32\pnfemunr.exe 2007-03-24 17:04:32 53,569 —ha-w C:\WINNT\system32\ghlxob.exe 2007-03-24 16:38:58 29,488 ----a-w C:\WINNT\system32\scxyy.exe 2007-03-24 14:42:54 57,856 ----a-w C:\WINNT\system32\yurbojz.exe 2007-03-24 14:40:03 57,856 ----a-w C:\WINNT\system32\uivqtxqu.exe 2007-03-24 14:25:38 57,856 ----a-w C:\WINNT\system32\jhnxerwk.exe 2007-03-24 14:11:59 57,856 ----a-w C:\WINNT\system32\kozlbqvl.exe 2007-03-24 14:04:33 57,856 ----a-w C:\WINNT\system32\fpbl.exe 2007-03-24 12:58:05 29,488 ----a-w C:\WINNT\system32\tsgif.exe 2007-03-24 12:46:32 29,488 ----a-w C:\WINNT\system32\ztalcfl.exe 2007-03-24 12:24:18 29,488 ----a-w C:\WINNT\system32\fwoyzo.exe 2007-03-24 12:05:48 29,488 ----a-w C:\WINNT\system32\yghz.exe 2007-03-24 09:20:19 29,488 ----a-w C:\WINNT\system32\ityyui.exe 2007-03-23 14:56:49 29,488 ----a-w C:\WINNT\system32\vqym.exe 2007-03-23 08:49:55 29,488 ----a-w C:\WINNT\system32\vkarjg.exe 2007-03-22 13:39:45 29,488 ----a-w C:\WINNT\system32\hhcenij.exe 2007-03-22 08:35:17 29,488 ----a-w C:\WINNT\system32\ufpu.exe 2007-03-21 18:11:44 29,488 ----a-w C:\WINNT\system32\iwxgi.exe 2007-03-21 18:06:10 29,488 ----a-w C:\WINNT\system32\slsecyjw.exe 2007-03-21 18:03:51 29,488 ----a-w C:\WINNT\system32\leyae.exe 2007-03-21 17:26:51 29,488 ----a-w C:\WINNT\system32\housyh.exe 2007-03-21 14:03:53 29,488 ----a-w C:\WINNT\system32\amqofnj.exe 2007-03-21 12:32:57 29,488 ----a-w C:\WINNT\system32\wzmnmlkl.exe 2007-03-20 21:21:45 22,016 —ha-w C:\WINNT\system32\bagvql.exe 2007-03-20 19:27:28 28,976 ----a-w C:\WINNT\system32\yhoxx.exe 2007-03-20 18:21:49 28,976 ----a-w C:\WINNT\system32\kktxitc.exe 2007-03-20 17:26:13 28,976 ----a-w C:\WINNT\system32\bwlasgv.exe 2007-03-20 13:38:57 28,976 ----a-w C:\WINNT\system32\stcqcfed.exe 2007-03-19 15:11:49 53,569 —ha-w C:\WINNT\system32\ittow.exe 2007-03-19 15:03:49 53,569 —ha-w C:\WINNT\system32\myjor.exe 2007-03-19 13:38:38 28,976 ----a-w C:\WINNT\system32\ihnk.exe 2007-03-17 18:32:48 21,503 ----a-w C:\WINNT\system32\wixfrs.exe 2007-03-17 18:30:33 16,896 —ha-w C:\WINNT\system32\iaqai.exe 2007-03-17 18:03:49 21,503 ----a-w C:\WINNT\system32\qfyshiqf.exe 2007-03-17 17:52:33 21,503 ----a-w C:\WINNT\system32\wwshe.exe 2007-03-17 17:47:59 21,503 ----a-w C:\WINNT\system32\niwf.exe 2007-03-17 17:42:22 21,503 ----a-w C:\WINNT\system32\yxjpcez.exe 2007-03-17 17:40:09 21,503 ----a-w C:\WINNT\system32\wzrlpi.exe 2007-03-17 17:24:19 21,503 ----a-w C:\WINNT\system32\ntem.exe 2007-03-17 12:36:03 50,853 —ha-w C:\WINNT\system32\bnasx.exe 2007-03-17 12:29:18 21,503 ----a-w C:\WINNT\system32\phwgbwrc.exe 2007-03-17 11:58:23 21,503 ----a-w C:\WINNT\system32\qwzz.exe 2007-03-17 11:44:12 21,503 ----a-w C:\WINNT\system32\kilet.exe 2007-03-17 08:05:15 21,503 ----a-w C:\WINNT\system32\pgktd.exe 2007-03-16 18:23:04 21,503 ----a-w C:\WINNT\system32\birwtm.exe 2007-03-16 04:39:24 21,503 ----a-w C:\WINNT\system32\yybx.exe 2007-03-15 21:30:20 14,848 —ha-w C:\WINNT\system32\ucmapn.exe 2007-03-15 20:53:40 21,503 ----a-w C:\WINNT\system32\yecmkd.exe 2007-03-15 20:40:10 21,503 ----a-w C:\WINNT\system32\dwwb.exe 2007-03-15 20:33:59 21,503 ----a-w C:\WINNT\system32\enphtf.exe 2007-03-15 20:26:21 21,503 ----a-w C:\WINNT\system32\dumxcj.exe 2007-03-15 19:43:06 21,503 ----a-w C:\WINNT\system32\vwvb.exe 2007-03-15 19:29:44 21,503 ----a-w C:\WINNT\system32\uzxg.exe 2007-03-15 19:20:03 21,503 ----a-w C:\WINNT\system32\ixuhkhv.exe 2007-03-15 18:53:58 21,503 ----a-w C:\WINNT\system32\ovqp.exe 2007-03-15 18:29:23 21,503 ----a-w C:\WINNT\system32\sqyevgo.exe 2007-03-15 18:02:03 21,503 ----a-w C:\WINNT\system32\wrbkjf.exe 2007-03-15 15:37:59 21,503 ----a-w C:\WINNT\system32\unqldnw.exe 2007-03-15 15:15:27 21,503 ----a-w C:\WINNT\system32\xlto.exe 2007-03-15 14:50:03 21,503 ----a-w C:\WINNT\system32\duqam.exe 2007-03-15 14:27:38 21,503 ----a-w C:\WINNT\system32\tayrrjhg.exe 2007-03-15 14:23:30 21,503 ----a-w C:\WINNT\system32\bsdfq.exe 2007-03-15 14:00:21 21,503 ----a-w C:\WINNT\system32\eqdlspvm.exe 2007-03-15 13:35:44 21,503 ----a-w C:\WINNT\system32\vxuy.exe 2007-03-15 13:13:12 21,503 ----a-w C:\WINNT\system32\ygpbv.exe 2007-03-15 12:48:29 21,503 ----a-w C:\WINNT\system32\eemfcsrr.exe 2007-03-15 09:19:46 21,503 ----a-w C:\WINNT\system32\bygb.exe 2007-03-15 08:57:14 21,503 ----a-w C:\WINNT\system32\jycmlm.exe 2007-03-15 08:46:09 21,503 ----a-w C:\WINNT\system32\dyci.exe 2007-03-15 08:23:36 21,503 ----a-w C:\WINNT\system32\xcwpemzu.exe 2007-03-15 08:01:02 21,503 ----a-w C:\WINNT\system32\nbahatc.exe 2007-03-15 07:38:24 21,503 ----a-w C:\WINNT\system32\aoskfb.exe 2007-03-15 07:15:58 21,503 ----a-w C:\WINNT\system32\ysiqjthd.exe 2007-03-15 06:53:19 21,503 ----a-w C:\WINNT\system32\boeapg.exe 2007-03-15 06:28:15 21,503 ----a-w C:\WINNT\system32\ekzypp.exe 2007-03-15 05:51:52 21,503 ----a-w C:\WINNT\system32\ynvp.exe 2007-03-15 05:25:17 21,503 ----a-w C:\WINNT\system32\vbwxio.exe 2007-03-15 04:39:36 21,503 ----a-w C:\WINNT\system32\msypbva.exe 2007-03-14 20:53:14 21,503 ----a-w C:\WINNT\system32\gopmfwt.exe 2007-03-14 20:12:09 21,503 ----a-w C:\WINNT\system32\ftpxo.exe 2007-03-14 19:46:21 21,503 ----a-w C:\WINNT\system32\lyqr.exe 2007-03-14 18:11:22 21,503 ----a-w C:\WINNT\system32\idebli.exe 2007-03-14 07:13:25 21,503 ----a-w C:\WINNT\system32\lratuakd.exe 2007-03-14 06:56:57 21,503 ----a-w C:\WINNT\system32\aqurhcg.exe 2007-03-14 05:13:25 21,503 ----a-w C:\WINNT\system32\oasdn.exe 2007-03-14 04:39:29 21,503 ----a-w C:\WINNT\system32\sfmocbh.exe 2007-03-13 21:15:19 21,503 ----a-w C:\WINNT\system32\pulp.exe 2007-03-13 17:45:17 21,503 ----a-w C:\WINNT\system32\pqptej.exe 2007-03-13 06:41:31 21,503 ----a-w C:\WINNT\system32\nygvyyo.exe 2007-03-12 19:06:41 4,380 —ha-w C:\WINNT\system32\ipgem.exe 2007-03-12 18:55:33 45,056 ----a-w C:\WINNT\system32\iexpl0re.exe 2007-03-12 18:51:26 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_70c.dat 2007-03-12 13:39:48 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_28c.dat 2007-03-10 17:34:58 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_290.dat 2007-03-07 17:51:22 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_298.dat 2007-03-05 18:28:03 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_394.dat 2007-03-05 18:13:24 0 —ha-w C:\WINNT\system32\pcbhxbu.exe 2007-03-04 10:58:22 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_3bc.dat 2007-03-03 21:02:50 17,408 —ha-w C:\WINNT\system32\wnyxi.exe 2007-03-03 20:58:59 12,288 —ha-w C:\WINNT\system32\vtyuo.exe 2007-03-03 12:10:14 12,344 —ha-w C:\WINNT\system32\vtefqbcy.exe 2007-03-03 08:18:00 6,144 —ha-w C:\WINNT\system32\ehutsu.exe 2007-03-03 06:20:19 249,856 ------w C:\WINNT\Setup1.exe 2007-03-03 06:20:15 73,216 ----a-w C:\WINNT\ST6UNST.EXE 2007-03-02 18:46:33 38,512 —ha-w C:\WINNT\system32\hmlpve.exe 2007-03-02 06:19:50 16,384 ----atw C:\WINNT\system32\Perflib_Perfdata_388.dat 2007-03-01 20:28:45 512 —ha-w C:\WINNT\system32\xocndxh.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [01-04-16 16:39] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Zone Labs Client”=“C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe” [05-11-15 01:51] “Synchronization Manager”=“mobsync.exe” [03-06-19 14:05 C:\WINNT\system32\mobsync.exe] “avgnt”=“C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe” [06-08-21 13:06] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0\bin\jusched.exe” [07-05-13 17:57] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “internat.exe”=“internat.exe” [00-03-21 03:00 C:\WINNT\system32\internat.exe] [HKEY_USERS.default\software\microsoft\windows\currentversion\runonce] “^SetupICWDesktop”=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “internat.exe”=internat.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk backup=C:\WINNT\pss\Adobe Gamma Loader.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^pogromca^Menu Start^Programy^Autostart^Adobe Gamma.lnk] path=C:\Documents and Settings\pogromca\Menu Start\Programy\Autostart\Adobe Gamma.lnk backup=C:\WINNT\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray] C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs* ******************************************************************** catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-01 19:57:15 Windows 5.0.2195 Service Pack 4 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ******************************************************************** Completion time: 2007-06-01 19:58:55 C:\ComboFix-quarantined-files.txt … 07-06-01 19:58 — E O F —