“Adrian Dudzinski” - 2007-07-06 10:40:20 - ComboFix 07-07-04.4 - Service Pack 2 (((((((((((((((((((((((((((((((((((((((((((( V Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\fmycfgfx.dll C:\WINDOWS\system32\legdepiq.dll C:\WINDOWS\system32\tlydeyvj.dll C:\WINDOWS\system32\qipedgel.ini * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\aqfnlgif.exe C:\WINDOWS\system32\iqoqeafq.exe C:\WINDOWS\system32\lhmcpkti.exe C:\WINDOWS\system32\lwnwsfjc.exe C:\WINDOWS\system32\lxafyfmq.exe C:\WINDOWS\system32\qtkslvvv.exe C:\WINDOWS\system32\tidlqkdx.exe C:\WINDOWS\system32\wianothn.exe C:\WINDOWS\system32\wjmhfcdk.exe C:\WINDOWS\system32\xfumwtcy.exe C:\WINDOWS\system32\ylbncqjf.exe ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_DOMAINSERVICE -------\DomainService ((((((((((((((((((((((((( Files Created from 2007-06-06 to 2007-07-06 ))))))))))))))))))))))))))))))) 2007-07-06 10:39 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-06 10:25 2007-07-05 22:08 2007-07-05 22:05 2007-07-05 22:04 2007-07-05 22:03 14,048 --------- C:\WINDOWS\system32\spmsg2.dll 2007-07-05 20:08 2007-07-05 20:03 2007-07-05 19:49 2007-06-26 12:30 2007-06-26 12:29 2007-06-24 19:29 2007-06-24 19:24 2007-06-24 19:15 2007-06-24 19:15 2007-06-24 12:19 2007-06-24 12:15 664 --a------ C:\WINDOWS\system32\d3d9caps.dat 2007-06-24 12:12 682,232 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-06-24 12:07 737,280 --a------ C:\WINDOWS\iun6002.exe 2007-06-24 11:36 2007-06-23 14:06 2007-06-23 09:08 31,254 --a------ C:\WINDOWS\system32\tuvvwvw.dll.vir 2007-06-23 09:08 2007-06-23 08:46 2007-06-23 07:53 2007-06-22 18:44 2007-06-22 17:29 2007-06-22 17:28 2007-06-22 17:28 2007-06-22 17:22 2007-06-22 17:04 2007-06-22 17:04 2007-06-22 17:04 2007-06-22 17:03 2007-06-22 16:02 740,442 --a------ C:\WINDOWS\system32\divx.dll 2007-06-22 16:02 73,728 --a------ C:\WINDOWS\system32\dpl100.dll 2007-06-22 16:02 593,920 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-06-22 16:02 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-06-22 16:02 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll 2007-06-22 16:02 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-06-22 16:02 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-06-22 16:02 2007-06-22 16:01 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys 2007-06-22 16:01 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys 2007-06-22 16:01 129,784 --------- C:\WINDOWS\system32\pxafs.dll 2007-06-22 16:00 2007-06-22 15:55 1,156 --a------ C:\WINDOWS\mozver.dat 2007-06-22 15:35 2007-06-22 15:19 2007-06-22 15:19 2007-06-22 15:19 2007-06-22 15:19 2007-06-22 15:14 2007-06-22 15:14 2007-06-22 15:13 2007-06-22 15:06 2007-06-22 15:06 2007-06-22 15:01 2007-06-22 15:01 2007-06-22 15:00 0 --a------ C:\WINDOWS\nsreg.dat 2007-06-22 14:47 2007-06-22 14:46 2007-06-22 14:39 2007-06-22 14:33 2007-06-22 14:23 2007-06-22 14:09 2007-06-22 14:04 2007-06-22 14:03 2007-06-22 14:01 2007-06-22 13:54 2007-06-22 13:42 53,248 --a------ C:\WINDOWS\setFireWall.exe 2007-06-22 13:41 50,007 --a------ C:\WINDOWS\system32\drivers\adildr.sys 2007-06-22 13:41 46,892 --a------ C:\WINDOWS\system32\adadix16.dll 2007-06-22 13:41 4,981 --a------ C:\WINDOWS\system32\adadix2k.dll 2007-06-22 13:41 155,648 --a------ C:\WINDOWS\system32\adadix32.dll 2007-06-22 13:41 127,456 --a------ C:\WINDOWS\system32\ipdetect.exe 2007-06-22 13:41 127,065 --a------ C:\WINDOWS\system32\drivers\adiusbaw.sys 2007-06-22 13:41 114,688 --a------ C:\WINDOWS\system32\unaddrv.exe 2007-06-22 13:41 106,496 --a------ C:\WINDOWS\system32\coclassfast.dll 2007-06-22 13:40 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin 2007-06-22 13:40 184 --a------ C:\setuplog.exe 2007-06-22 13:40 143,360 --a------ C:\WINDOWS\autoclk.exe 2007-06-22 13:40 2007-06-22 13:39 2007-06-22 13:31 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2007-06-22 13:26 2007-06-22 13:25 98,345 --a------ C:\WINDOWS\system32\IMHOST32.DLL 2007-06-22 13:25 339,968 --a------ C:\WINDOWS\system32\IMGMAN32.DLL 2007-06-22 13:25 2007-06-22 13:24 389,120 --a------ C:\WINDOWS\system32\dlcxinst.dll 2007-06-22 13:24 2007-06-22 13:24 2007-06-22 13:24 2007-06-22 13:23 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2007-06-22 13:23 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll 2007-06-22 13:23 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-06-22 13:23 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-06-22 13:23 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-06-22 12:29 2007-06-22 11:59 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-24 11:11:20 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-06-19 19:40:41 -------- d-----w C:\Program Files\Messenger 2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-16 21:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-16 21:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-16 21:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-16 21:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-16 21:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-16 21:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-16 21:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-16 21:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2006-01-12 20:38 63128 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{5CA3D70E-1895-11CF-8E15-001234567890}] 2004-12-06 01:05 118842 --a------ C:\WINDOWS\system32\dla\tfswshx.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] 2005-11-10 13:22 184423 --a------ C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{CA6319C0-31B7-401E-A518-A07C3DB8F777}] 2006-11-17 04:44 98304 --a------ C:\Program Files\BAE\BAE.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{E3652869-6A87-4289-B0F4-B4B39E84190C}] C:\WINDOWS\system32\vtsqr.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe” [2004-07-27 16:50] “PCMService”=“C:\Program Files\Dell\MediaDirect\PCMService.exe” [2007-05-02 18:16] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “VoipCheapCom”=“C:\Program Files\VoipCheapCom\VoipCheapCom.exe” [2007-02-20 14:23] “MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 17:24] “DAEMON Tools”=“C:\Program Files\DAEMON Tools\daemon.exe” [2007-04-03 23:29] ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-06 10:43:14 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-06 10:43:51 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-07-06 10:43 — E O F —