"Anna" - 07-04-06 14:23:21 Service Pack 2
ComboFix 07-04-05 - Running from: "C:\Documents and Settings\Anna\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2007-03-06 to 2007-04-06 ))))))))))))))))))))))))))))))))))
2007-04-06 11:55 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-04-06 11:55 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-04-06 11:55 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-04-06 11:55 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-04-06 11:55 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-04-06 11:55 2,214 --a------ C:\WINDOWS\system32\tmp.reg
2007-04-06 11:55 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-04-06 09:34 <DIR> d-------- C:\Program Files\IObit
2007-04-05 23:41 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-05 23:16 <DIR> d-------- C:\WINDOWS\pss
2007-04-05 23:01 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-04-05 23:01 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-04-05 23:01 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-04-05 23:01 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-04-05 23:01 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-03-17 17:23 56,912 --a------ C:\DOCUME~1\Anna\g2mdlhlpx.exe
2007-03-17 17:23 <DIR> d-------- C:\Program Files\Citrix
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-29 20:06 -------- d-------- C:\Program Files\microsoft works
2007-03-26 20:56 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\wholesecurity
2007-03-25 14:05 -------- d--h----- C:\Program Files\installshield installation information
2007-03-25 14:05 -------- d-------- C:\Program Files\paypal
2007-03-09 12:05 -------- d-------- C:\Program Files\stamps.com internet postage
2007-03-08 11:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-02 16:07 -------- d-------- C:\Program Files\wizards of the coast
2007-03-02 10:01 -------- d-------- C:\Program Files\kodak
2007-03-02 09:56 -------- d-------- C:\Program Files\Common Files\kodak
2007-02-28 15:09 -------- d-------- C:\Program Files\ebay
2007-02-28 15:06 -------- d-------- C:\Program Files\Common Files\installshield
2007-02-27 15:42 -------- d-------- C:\Program Files\microsoft money 2007
2007-02-26 16:16 -------- dr-h----- C:\DOCUME~1\Anna\APPLIC~1\yahoo!
2007-02-26 16:16 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\talkback
2007-02-26 16:16 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\symantec
2007-02-26 16:16 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\smartdraw
2007-02-26 16:16 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\roxio
2007-02-26 16:16 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\real
2007-02-26 16:16 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\my games
2007-02-26 16:13 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\lavasoft
2007-02-26 16:13 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\juniper networks
2007-02-26 16:13 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\installshield installation information
2007-02-26 14:30 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\firaxis games
2007-02-26 14:30 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\download manager
2007-02-26 14:30 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\corel
2007-02-26 14:30 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\alien skin
2007-02-26 14:30 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\adobeum
2007-02-26 09:52 -------- d-------- C:\Program Files\irfanview
2007-02-23 16:58 -------- d-------- C:\Program Files\Common Files\l&h
2007-02-21 17:06 -------- d-------- C:\Program Files\the classified connection demo
2007-02-21 16:57 -------- d-------- C:\Program Files\myfree classifieds demo
2007-02-21 15:36 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\help
2007-02-21 11:50 -------- d-------- C:\Program Files\flock
2007-02-21 11:50 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\flock
2007-02-21 11:16 12 --a------ C:\WINDOWS\system32\vcklib.sys
2007-02-21 10:17 12 --a------ C:\WINDOWS\system32\vchklib.sys
2007-02-21 10:17 -------- d-------- C:\Program Files\dominant ad creator
2007-02-18 10:40 -------- d-------- C:\Program Files\overstock
2007-02-17 22:00 -------- d-------- C:\Program Files\msxml 4.0
2007-02-16 07:22 -------- d-------- C:\Program Files\google
2007-02-15 15:23 -------- d-------- C:\Program Files\yahoo!
2007-02-15 15:20 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\google
2007-02-15 10:16 -------- d-------- C:\DOCUME~1\Anna\APPLIC~1\hewlett-packard
2007-02-15 10:12 20454 --------- C:\WINDOWS\hpoins01.dat
2007-02-15 10:12 -------- d-------- C:\Program Files\hewlett-packard
2007-02-15 09:54 -------- d-------- C:\Program Files\java
2007-01-30 17:15 49152 -ra------ C:\WINDOWS\system32\inetwh32.dll
2007-01-30 17:15 1044480 -ra------ C:\WINDOWS\system32\roboex32.dll
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
2007-01-02 14:05 17107 --a------ C:\DOCUME~1\Anna\APPLIC~1\.googlewebacchosts
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"Carbonite Backup"="C:\\Program Files\\Carbonite\\Carbonite Backup\\CarboniteUI.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\READER~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Synchronizer.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Synchronizer.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\READER~1.0\\Reader\\ADOBEC~1.EXE "
"item"="Adobe Reader Synchronizer"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\hpoddt01.exe.lnk"
"backup"="C:\\WINDOWS\\pss\\hpoddt01.exe.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hpotdd01.exe "
"item"="hpoddt01.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk"
"backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -hx"
"item"="Kodak EasyShare software"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\KODAK Software Updater.lnk"
"backup"="C:\\WINDOWS\\pss\\KODAK Software Updater.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE "
"item"="KODAK Software Updater"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^officejet 6100.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\officejet 6100.lnk"
"backup"="C:\\WINDOWS\\pss\\officejet 6100.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HEWLET~1\\DIGITA~1\\bin\\hposol08.exe "
"item"="officejet 6100"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /installquiet"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PayPal Virtual Debit Card]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="OToolbar"
"hkey"="HKLM"
"command"="rundll32.exe C:\\PROGRA~1\\PayPal\\PAYPAL~1\\OToolbar.dll,StartUp /dontopenmycards"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=dword:00000000
"NoResolveSearch"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\EasyShare Registration Task.job
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1171548899.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-06 14:25:40
C:\ComboFix-quarantined-files.txt ... 07-04-06 14:25