"Owner" - 07-04-03 12:11:17 Service Pack 2
ComboFix 07-04-03.5 - Running from: "C:\Documents and Settings\Owner\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\bund1\temp.txt
C:\WINDOWS\system32\system\msxml4.dll
C:\WINDOWS\system32\system\msxml4r.dll
C:\DOCUME~1\Owner\Desktop\internet.lnk
C:\install.log
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\system
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_MCHINJDRV
((((((((((((((((((((((((((((((( Files Created from 2007-03-03 to 2007-04-03 ))))))))))))))))))))))))))))))))))
2007-04-03 10:07 <DIR> d-------- C:\WINDOWS\LastGood
2007-04-02 17:32 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-04-02 17:32 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-04-02 17:32 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-04-02 17:32 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-04-02 17:32 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-04-02 17:32 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-04-02 09:50 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Sun
2007-04-02 00:00 95,760 --a------ C:\WINDOWS\system32\isafeif.dll
2007-04-02 00:00 75,280 --a------ C:\WINDOWS\system32\vetredir.dll
2007-04-02 00:00 75,280 --a------ C:\WINDOWS\system32\isafprod.dll
2007-04-02 00:00 629,216 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2007-04-02 00:00 32,528 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-04-02 00:00 26,640 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2007-04-02 00:00 21,648 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-04-02 00:00 21,392 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2007-04-02 00:00 108,544 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2007-04-02 00:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CA
2007-04-01 21:23 767,488 --a------ C:\WINDOWS\system32\WMVSENCD.dll
2007-04-01 21:23 75,280 --a------ C:\WINDOWS\system32\vetredir(4).dll
2007-04-01 21:23 75,280 --a------ C:\WINDOWS\system32\vetredir(3).dll
2007-04-01 21:23 75,280 --a------ C:\WINDOWS\system32\vetredir(2).dll
2007-04-01 21:23 733,696 --a------ C:\WINDOWS\system32\qedwipes.dll
2007-04-01 21:23 656,896 --a------ C:\WINDOWS\system32\WMVXENCD.dll
2007-04-01 21:23 65,536 --a------ C:\WINDOWS\system32\eSellerateControl200.dll
2007-04-01 21:23 64,000 --a------ C:\WINDOWS\system32\E_FBCB9FA.DLL
2007-04-01 21:23 61,440 --a------ C:\WINDOWS\system32\ldamfilt.dll
2007-04-01 21:23 498,742 --a------ C:\WINDOWS\system32\dxmasf.dll
2007-04-01 21:23 48,640 --a------ C:\WINDOWS\system32\pnrpnsp.dll
2007-04-01 21:23 48,128 --a------ C:\WINDOWS\system32\mshtmler.dll
2007-04-01 21:23 34,304 --a------ C:\WINDOWS\system32\E_FBCH9FA.DLL
2007-04-01 21:23 331,776 --a------ C:\WINDOWS\system32\CTMedEng.DLL
2007-04-01 21:23 139,264 --a------ C:\WINDOWS\system32\hpicon.dll
2007-04-01 21:23 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2007-04-01 21:23 12,288 --a------ C:\WINDOWS\system32\odbcp32r.dll
2007-04-01 21:23 101,376 --a------ C:\WINDOWS\system32\txflog.dll
2007-04-01 21:19 9,216 --a------ C:\WINDOWS\system32\lprmonui.dll
2007-04-01 21:19 51,200 --a------ C:\WINDOWS\system32\dfrgres.dll
2007-04-01 21:18 <DIR> d-------- C:\WINDOWS\DLLArchive
2007-04-01 19:58 <DIR> d-------- C:\Program Files\AnalogX
2007-04-01 18:58 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-04-01 13:43 93,736 --a------ C:\WINDOWS\VTTC.exe
2007-04-01 12:59 1,944 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-30 13:45 <DIR> d-------- C:\TEMP\tn3
2007-03-27 11:00 45,056 --a------ C:\WINDOWS\wbun.exe
2007-03-27 01:27 72,064 --a------ C:\WINDOWS\system32\drivers\core.sys
2007-03-23 08:53 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Backyard Baseball 2007
2007-03-20 09:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
2007-03-17 15:39 <DIR> d-------- C:\Program Files\Pando Networks
2007-03-17 15:05 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Viewpoint
2007-03-16 09:31 <DIR> d-------- C:\DOCUME~1\Owner\browser - logitech
2007-03-16 09:30 <DIR> d-------- C:\DOCUME~1\Owner\Logitech
2007-03-16 09:29 <DIR> d-------- C:\Program Files\Common Files\Remote Control Software Shared
2007-03-16 09:24 118,784 -r------- C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe
2007-03-16 09:24 <DIR> d-------- C:\Program Files\Logitech
2007-03-16 00:21 138 --a------ C:\WINDOWS\UNDEL.BAT
2007-03-15 10:12 <DIR> d-------- C:\Program Files\ItsDeductible2006
2007-03-15 10:08 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\InstallShield
2007-03-14 17:28 87,424 --a------ C:\WINDOWS\system32\drivers\irda.sys
2007-03-14 17:28 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2007-03-14 17:28 27,136 --a------ C:\WINDOWS\system32\irmon.dll
2007-03-14 17:28 19,584 --a------ C:\WINDOWS\system32\drivers\rasirda.sys
2007-03-14 17:28 18,688 --a------ C:\WINDOWS\system32\drivers\irsir.sys
2007-03-14 17:28 152,576 --a------ C:\WINDOWS\system32\irftp.exe
2007-03-14 14:37 <DIR> d-------- C:\Program Files\Common Files\EasyInfo
2007-03-11 02:32 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Publish Providers
2007-03-11 02:24 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Sony
2007-03-11 02:22 <DIR> d-------- C:\Program Files\Vstplugins
2007-03-11 02:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony
2007-03-10 22:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-03-10 22:24 65,536 --a------ C:\WINDOWS\system32\a1.dll
2007-03-10 22:24 520,192 --a------ C:\WINDOWS\system32\wscma2u.exe
2007-03-10 22:24 278,528 --a------ C:\WINDOWS\system32\ammpp.dll
2007-03-09 11:19 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-03-09 10:48 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-03-08 16:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\IMSI
2007-03-08 16:28 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\IMSI
2007-03-08 01:22 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-03-08 01:22 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-03-08 01:22 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-03-08 01:22 115,880 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-03-08 01:22 <DIR> d-------- C:\Program Files\Winamp
2007-03-07 22:15 <DIR> d-------- C:\Program Files\Nero
2007-03-06 19:42 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Systweak
2007-03-05 08:24 77,000 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-03 10:17 -------- d--h----- C:\Program Files\windowsupdate
2007-04-03 10:17 -------- d-------- C:\Program Files\online services
2007-04-03 09:38 -------- d-------- C:\Program Files\msn encarta plus
2007-04-03 09:38 -------- d-------- C:\Program Files\flac
2007-04-03 09:29 -------- d-------- C:\Program Files\symantec
2007-04-03 09:29 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-03-30 21:23 -------- d-------- C:\Program Files\windows media connect 2
2007-03-30 21:23 -------- d-------- C:\Program Files\movie maker
2007-03-30 21:23 -------- d-------- C:\Program Files\messenger
2007-03-30 21:23 -------- d-------- C:\Program Files\mailfrontier
2007-03-30 21:23 -------- d-------- C:\Program Files\capital flash casino
2007-03-27 11:01 -------- d--h----- C:\Program Files\installshield installation information
2007-03-27 10:54 -------- d-------- C:\Program Files\interactual
2007-03-25 20:04 -------- d-------- C:\DOCUME~1\Owner\APPLIC~1\bittorrent
2007-03-23 16:56 -------- d-------- C:\DOCUME~1\Owner\APPLIC~1\vso
2007-03-22 19:51 -------- d-------- C:\Program Files\itunes
2007-03-22 19:50 -------- d-------- C:\Program Files\ipod
2007-03-16 00:21 -------- d-------- C:\Program Files\intel
2007-03-14 14:09 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-03-13 19:09 -------- d-------- C:\Program Files\bittorrent
2007-03-08 10:30 -------- d-------- C:\Program Files\recordnow
2007-03-08 10:30 -------- d-------- C:\Program Files\powerpoint viewer
2007-03-08 10:29 -------- d-------- C:\Program Files\punch! pro - platinum
2007-03-08 10:29 -------- d-------- C:\Program Files\performancetest
2007-03-08 10:29 -------- d-------- C:\Program Files\mozilla thunderbird
2007-03-02 12:59 53248 --a------ C:\WINDOWS\uni_eh10.exe
2007-02-28 16:05 86016 --a------ C:\WINDOWS\system32\elbycdio.dll
2007-02-28 13:56 15440 --a------ C:\WINDOWS\system32\drivers\ElbyCDIO.sys
2007-02-16 12:59 110592 --a------ C:\TTC.dll
2007-02-15 17:56 11984 --a------ C:\WINDOWS\system32\drivers\RegKill.sys
2007-01-31 15:15 87608 --a------ C:\DOCUME~1\Owner\APPLIC~1\ezpinst.exe
2007-01-31 15:15 7824 --a------ C:\DOCUME~1\Owner\APPLIC~1\pcouffin.cat
2007-01-31 15:15 47360 --a------ C:\DOCUME~1\Owner\APPLIC~1\pcouffin.sys
2007-01-31 15:15 34 --a------ C:\DOCUME~1\Owner\APPLIC~1\pcouffin.log
2007-01-31 15:15 1144 --a------ C:\DOCUME~1\Owner\APPLIC~1\pcouffin.inf
2007-01-16 12:57 0 --a------ C:\Autoexec.bat
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
2007-01-07 10:40 85 ---hs---- C:\DOCUME~1\Owner\APPLIC~1\.zreglib
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce\CTStartup]
"CTStartup"="\"C:\\Program Files\\Creative\\Splash Screen\\CTEaxSpl.EXE\" /play"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Run StartupMonitor"="StartupMonitor.exe"
"cctray"="\"d:\\Program Files\\CA\\CA Internet Security Suite\\cctray\\cctray.exe\""
"QOELOADER"="\"d:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Spam\\QSP-5.0.419.0\\QOELoader.exe\""
"CAVRID"="\"d:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus\\CAVRID.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
"key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows"
"item"="???
?"
"hkey"="HKCU"
"command"="???
?"
"inimapping"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
"key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows"
"item"="???
?"
"hkey"="HKCU"
"command"="???
?"
"inimapping"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=""
"NoCDBurning"=dword:00000001
"BackupNoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ C:\Program Files\Online Services\rtene.html
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Owner at 11 37 AM.job
C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Owner at 2 54 PM.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-03 12:14:36
C:\ComboFix-quarantined-files.txt ... 07-04-03 12:14