"laura" - 2007-06-01 5:44:14 Service Pack 2
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\laura\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))) )))))
C:\WINDOWS\system32\nyicegvt.dll
C:\WINDOWS\system32\pprqamkj.dll
C:\WINDOWS\system32\urfposte.dll
C:\WINDOWS\system32\vohrwijs.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
"C:\Temp\17O7\tmpTF.log"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\ball_3.jpg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\ball_5.jpg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\map_e.jpg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\map_h.jpg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\sfx_explosion.ogg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\sfx_startlevel.ogg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\_explosion1.jpg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\_hrzarrows.png"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\_pw_cbb.alpha.jpg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\_pw_reverse.jpg"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24\asset s\_pw_speedshot.jpg"
"C:\WINDOWS\system32\nvs2.inf"
"C:\WINDOWS\system32\smpi1"
"C:\Temp\17O7"
"C:\WINDOWS\DOWNLO~1.\PiratePoppers.1.0.0.24"
((((((((((((((((((((((((((((((( Files Created from 2007-05-01 to 2007-06-01 ))))))))))))))))))))))))))))))))))
2007-06-01 03:47 <DIR> d-------- C:\VundoFix Backups
2007-05-31 01:08 32,768 --a------ C:\WINDOWS\system\plugin.dll
2007-05-31 01:07 210,944 --a------ C:\WINDOWS\system\MSVCRT10.DLL
2007-05-30 21:58 <DIR> d-------- C:\Program Files\Common Files\Jasc Software Inc
2007-05-30 21:57 <DIR> d-------- C:\Program Files\Jasc Software Inc
2007-05-30 21:57 <DIR> d-------- C:\DOCUME~1\laura\APPLIC~1\Jasc Software Inc
2007-05-30 20:10 <DIR> d-------- C:\DOCUME~1\laura\APPLIC~1\uTorrent
2007-05-30 19:56 14,868 --a------ C:\WINDOWS\system32\htjycqrr.exe
2007-05-30 19:56 10,752 --a------ C:\WINDOWS\system32\j0291032.dll
2007-05-30 19:37 14,868 --a------ C:\WINDOWS\system32\behcljuo.exe
2007-05-30 19:37 10,752 --a------ C:\WINDOWS\system32\j4201536.dll
2007-05-30 19:25 14,868 --a------ C:\WINDOWS\system32\cifkgdsx.exe
2007-05-30 19:25 10,752 --a------ C:\WINDOWS\system32\j4291733.dll
2007-05-30 19:23 14,868 --a------ C:\WINDOWS\system32\evcxydnw.exe
2007-05-30 19:23 10,752 --a------ C:\WINDOWS\system32\j2291831.dll
2007-05-30 19:21 14,868 --a------ C:\WINDOWS\system32\pdlyfkpv.exe
2007-05-30 19:21 10,752 --a------ C:\WINDOWS\system32\j6201038.dll
2007-05-30 19:14 88 -r-hs---- C:\WINDOWS\system32\FAB3C8B792.sys
2007-05-30 19:13 <DIR> d-------- C:\DOCUME~1\laura\APPLIC~1\Corel
2007-05-30 19:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-05-30 19:11 3,350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-05-30 18:30 14,868 --a------ C:\WINDOWS\system32\swqembbr.exe
2007-05-30 18:24 14,868 --a------ C:\WINDOWS\system32\hiqcuusn.exe
2007-05-30 18:24 14,868 --a------ C:\WINDOWS\system32\crumvydh.exe
2007-05-30 18:24 10,752 --a------ C:\WINDOWS\system32\j9271335.dll
2007-05-30 18:24 10,752 --a------ C:\WINDOWS\system32\j7211435.dll
2007-05-30 18:22 14,868 --a------ C:\WINDOWS\system32\krkfvxnr.exe
2007-05-30 18:22 10,752 --a------ C:\WINDOWS\system32\j1281438.dll
2007-05-30 18:21 14,868 --a------ C:\WINDOWS\system32\dfeqscrb.exe
2007-05-30 18:21 10,752 --a------ C:\WINDOWS\system32\j5291739.dll
2007-05-28 04:26 124,436 --a------ C:\WINDOWS\system32\brigvtlt.dll
2007-05-28 03:59 124,436 --a------ C:\WINDOWS\system32\tkpibaae.dll
2007-05-28 01:14 124,436 --a------ C:\WINDOWS\system32\pajafuhd.dll
2007-05-23 23:06 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2007-05-23 23:06 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-05-23 22:19 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-05-22 16:32 4,262 --a------ C:\WINDOWS\system32\uhlrgtocma.dat
2007-05-22 16:32 356,352 --a------ C:\WINDOWS\system32\uhlrgtocma.exe
2007-05-22 16:32 294 --a------ C:\WINDOWS\system32\uhlrgtocma_navps.dat
2007-05-22 16:32 259,113 --a------ C:\WINDOWS\system32\uhlrgtocma_nav.dat
2007-05-16 19:11 <DIR> d-------- C:\Poker
2007-05-14 16:07 <DIR> d-------- C:\Program Files\AHK BBCodeWriter
2007-05-11 19:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\iolo
2007-05-11 18:54 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-05-11 18:41 <DIR> d-------- C:\Program Files\PCPitstop
2007-05-11 18:14 <DIR> d-------- C:\DOCUME~1\laura\APPLIC~1\True Sword
2007-05-11 18:13 <DIR> d-------- C:\Program Files\True Sword 4
2007-05-11 05:37 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-05-11 05:37 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-05-11 05:37 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-05-11 05:37 740,442 --a------ C:\WINDOWS\system32\DivX.dll
2007-05-05 20:17 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\TuneUp Software
2007-05-05 19:34 <DIR> d-------- C:\WINDOWS\CSC
2007-05-05 19:02 <DIR> d-------- C:\Inetpub
2007-05-05 16:32 6,553,600 --a------ C:\Documents and Settings\laura\ntuser.dat
2007-05-05 16:32 6,553,600 --a------ C:\DOCUME~1\laura\ntuser.dat
2007-05-04 14:46 <DIR> d-------- C:\DOCUME~1\laura\APPLIC~1\Viewpoint
2007-05-04 14:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-05-04 14:41 <DIR> d-------- C:\Program Files\AIM6
2007-05-04 09:15 167 --a------ C:\Documents and Settings\laura\5126.bat
2007-05-04 09:15 167 --a------ C:\DOCUME~1\laura\5126.bat
2007-05-04 08:59 <DIR> d-------- C:\DOCUME~1\NETWOR~1\APPLIC~1\McAfee.com Personal Firewall
2007-05-03 19:17 271,574 --a------ C:\Temp\gorPEURO.exe
2007-05-03 19:17 167 --a------ C:\WINDOWS\system32\5914.bat
2007-05-03 19:17 <DIR> d-------- C:\WINDOWS\system32\SBO
2007-05-03 19:17 <DIR> d-------- C:\Temp
2007-05-03 19:16 32,768 --a------ C:\WINDOWS\system32\setup9x.exe
2007-05-03 19:16 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )))
2007-06-01 04:11:10 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-01 02:45:32 -------- d-----w C:\Program Files\MxMonitor
2007-06-01 02:43:40 -------- d-----w C:\Program Files\Web Page Maker V2
2007-05-30 21:15:18 -------- d-----w C:\Program Files\PartyGaming
2007-05-30 18:12:58 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-05-21 21

58 -------- d-----w C:\Program Files\MSN Messenger
2007-05-21 21

58 -------- d-----w C:\Program Files\Messenger Plus! Live
2007-05-13 14:06:57 -------- d-----w C:\Program Files\DivX
2007-05-11 18:10:57 -------- d-----w C:\Program Files\WinAce
2007-05-11 18:10:57 -------- d-----w C:\Program Files\Microsoft Works
2007-05-05 02:36:47 -------- d-----w C:\Program Files\Common Files\AOL
2007-05-04 13:55:39 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-05-04 13:42:12 -------- d-----w C:\Program Files\Viewpoint
2007-05-02 12:19:12 -------- d-----w C:\DOCUME~1\laura\APPLIC~1\IMVU
2007-05-02 12:19:06 -------- d-----w C:\Program Files\IMVU
2007-04-25 20:45:47 -------- d-----w C:\Program Files\McAfee.com
2007-04-24 16:58:42 -------- d-----w C:\Program Files\LimeWire
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:34 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:34 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-22 16:28:25 -------- d-----w C:\Program Files\WinMX
2007-04-22 16:07:40 -------- d-----w C:\Program Files\Yahoo!
2007-04-22 15

24 -------- d-----w C:\DOCUME~1\laura\APPLIC~1\iolo
2007-04-20 17:19:33 -------- d-----w C:\Program Files\Panicware
2007-04-19 19:24:17 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 20:40:29 -------- d-----w C:\DOCUME~1\laura\APPLIC~1\McAfee
2007-04-17 14:41:14 -------- d-----w C:\DOCUME~1\laura\APPLIC~1\Google
2007-04-16 21:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 21:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 21:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 21:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 21:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 21:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-15 17:00:45 -------- d-----w C:\DOCUME~1\laura\APPLIC~1\McAfee.com Personal Firewall
2007-04-15 15:14:01 -------- d-----w C:\DOCUME~1\laura\APPLIC~1\Lavasoft
2007-04-15 15:13:49 -------- d-----w C:\Program Files\Lavasoft
2007-04-14 22:18:50 -------- d-----w C:\Program Files\McAfee
2007-04-13 00:46:31 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-04-07 16:58:45 -------- d-----w C:\Program Files\Super Granny 3
2007-04-06 18:53:08 -------- d-----w C:\Program Files\Belarc
2007-04-05 22:49:03 -------- d-----w C:\Program Files\Sky Broadband
2007-04-04 17:51:31 -------- d-----w C:\DOCUME~1\laura\APPLIC~1\FunWebProducts
2007-03-27 13:12:19 0 ----a-w C:\WINDOWS\css020.dat
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2004-08-10 20:00:00 849,089 --sh--w C:\WINDOWS\Fonts\lsass.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll [2006-10-26 12:28]
{332914D4-1277-445F-AF05-C43ECC6FE71A}=C:\WINDOWS\system32\mljge.dll []
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{6CA8244F-EF9B-4AB2-9C55-352526B88F48}=C:\WINDOWS\system32\brigvtlt.dll [2007-05-28 04:26]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-07-07 13:29]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"@"="" []
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent .exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupda te.exe" [2006-01-11 12:05]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray. exe" [2005-11-11 17:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\PO P-UP~1\PSFree.exe" [2005-03-17 11:10]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\R oyale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale. theme
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run-]
"WindowsUpdate"=rundll32.exe "C:\WINDOWS\system32\qrffjetv.dll",realset
"setup"=rundll32.exe "C:\WINDOWS\system32\ccinwyql.dll",realset
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
UxTuneUp
Contents of the 'Scheduled Tasks' folder
2007-05-31 13:35:20 C:\WINDOWS\tasks\User_Feed_Synchronization-{AA698DD4-09EC-48A3-9C02-BF0C55E70BC9}.job
************************************************** ******************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-01 05:45:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ******************
Completion time: 2007-06-01 5:45:35
C:\ComboFix-quarantined-files.txt ... 2007-06-01 05:45
--- E O F ---