"Mia" - 07-04-17 18:06:37 Service Pack 2 [SAFE MODE]
ComboFix 07-04-18.V - Running from: C:\Documents and Settings\Mia\Desktop\
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\qpsxaijw.dll
C:\WINDOWS\system32\ssttr.dll
C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\hggefed.dll
C:\WINDOWS\system32\iiffdef.dll
C:\WINDOWS\system32\xbadd.bak1
C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\rttss.ini
C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\efccyay.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Mia\Desktop\internet.lnk
((((((((((((((((((((((((((((((( Files Created from 2007-03-17 to 2007-04-17 ))))))))))))))))))))))))))))))))))
2007-04-17 17:52 125,460 --a------ C:\WINDOWS\system32\ocirsurf.dll
2007-04-17 17:20 <DIR> d-------- C:\VundoFix Backups
2007-04-17 16:18 125,460 --a------ C:\WINDOWS\system32\udlrrjir.dll
2007-04-17 16:18 1,365,385 ---hs---- C:\WINDOWS\system32\qttss.bak1
2007-04-16 22:28 <DIR> d-------- C:\Program Files\DATCHICK-8254D9
2007-04-16 22:06 <DIR> d-------- C:\DOCUME~1\Will\APPLIC~1\Google
2007-04-15 20:12 2,210 --a------ C:\WINDOWS\system32\tmp.reg
2007-04-15 20:11 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-04-15 20:11 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-04-15 20:11 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-04-15 20:11 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-04-15 20:11 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-04-15 20:11 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-04-13 19:42 125,460 --a------ C:\WINDOWS\system32\yefecsyc.dll
2007-04-13 07:38 <DIR> d-------- C:\Program Files\Windows Defender
2007-04-12 20:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
2007-04-12 20:17 <DIR> d-------- C:\Program Files\Lavasoft
2007-04-12 20:17 <DIR> d-------- C:\DOCUME~1\Mia\APPLIC~1\Lavasoft
2007-04-12 20:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-04-12 20:01 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
2007-04-12 13:52 <DIR> d-------- C:\Program Files\Electric Rain
2007-04-12 13:51 <DIR> d-------- C:\Data1
2007-04-12 00:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Autodesk
2007-04-12 00:51 <DIR> d-------- C:\Program Files\Autodesk
2007-04-12 00:45 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-04-12 00:33 <DIR> d-------- C:\3dsmax9Trial
2007-04-09 21:47 <DIR> d--h----- C:\WINDOWS\PIF
2007-03-24 20:17 360 --ah----- C:\DOCUME~1\Mia\APPLIC~1\hpothb07.dat
2007-03-24 19:15 <DIR> d-------- C:\DOCUME~1\Mia\APPLIC~1\Opera
2007-03-24 00:50 <DIR> d-------- C:\DOCUME~1\Mia\APPLIC~1\Ahead
2007-03-22 15:16 <DIR> d-------- C:\Program Files\Globe7
2007-03-19 08:58 0 --ah----- C:\DOCUME~1\Mia\hpothb07.dat
2007-03-17 02:25 <DIR> d-------- C:\DOCUME~1\Mia\.jIRC
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-17 16:23 -------- d-------- C:\Program Files\java
2007-04-14 16:09 -------- d-------- C:\Program Files\google
2007-04-12 19:54 -------- d--h----- C:\Program Files\installshield installation information
2007-04-09 22:17 -------- d-------- C:\DOCUME~1\Mia\APPLIC~1\limewire
2007-03-24 20:17 511 --ah----- C:\DOCUME~1\Mia\APPLIC~1\hpothb07.tif
2007-03-24 12:04 -------- d-------- C:\Program Files\microsoft works
2007-03-21 20:42 5278 --a------ C:\DOCUME~1\Mia\APPLIC~1\wklnhst.dat
2007-03-17 06:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 16:56 -------- d-------- C:\DOCUME~1\Mia\APPLIC~1\sony
2007-03-08 16:25 -------- d-------- C:\Program Files\vstplugins
2007-03-08 16:25 -------- d-------- C:\DOCUME~1\Mia\APPLIC~1\publish providers
2007-03-08 12:48 -------- d-------- C:\Program Files\sony setup
2007-03-08 12:48 -------- d-------- C:\Program Files\sony
2007-03-08 08:48 578048 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 08:48 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 08:48 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 06:49 1843968 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-02 19:00 -------- d-------- C:\DOCUME~1\Mia\APPLIC~1\apple computer
2007-02-28 21:21 335 --a------ C:\WINDOWS\nsreg.dat
2007-02-28 21:21 -------- d-------- C:\Program Files\viewpoint
2007-02-25 11:49 -------- d-------- C:\Program Files\yahoo!
2007-02-08 20:02 30496 --a------ C:\DOCUME~1\Mia\APPLIC~1\gdipfontcachev1.dat
2007-02-05 13:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-01-30 01:53 12249807 --------- C:\AVG7QT.DAT
2007-01-28 15:23 49152 --a------ C:\WINDOWS\system32\cfperfmon_mx.dll
2007-01-28 05:00 22 --ah----- C:\qpmd8378.bin
2007-01-28 02:38 22 --a------ C:\qpmd8376.bin
2007-01-08 20:28 62 --ahs---- C:\DOCUME~1\Mia\APPLIC~1\desktop.ini
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{3903E7D4-9948-4BA5-B954-AE82988C2B0c} C:\WINDOWS\system32\ocirsurf.dll
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} C:\Program Files\BitComet\tools\BitCometBHO.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar1.dll
{BB697F63-A637-4555-9764-CFD52ED8EA6A} C:\WINDOWS\system32\ssttq.dll [x]
{F9A95281-1C05-44D8-B07A-AA953FD0880E} C:\WINDOWS\system32\mllml.dll [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"Video Driver"="C:\\Program Files\\DATCHICK-8254D9\\svchost.exe"
"Windows LSSS Service"="C:\\Program Files\\DATCHICK-8254D9\\svchost.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1168411203.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-17 18:16:41 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-04-17 18:16
Logfile of HijackThis v1.99.1
Scan saved at 6:19:38 PM, on 4/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DATCHICK-8254D9\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3903E7D4-9948-4BA5-B954-AE82988C2B0c} - C:\WINDOWS\system32\ocirsurf.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {BB697F63-A637-4555-9764-CFD52ED8EA6A} - C:\WINDOWS\system32\ssttq.dll (file missing)
O2 - BHO: (no name) - {F9A95281-1C05-44D8-B07A-AA953FD0880E} - C:\WINDOWS\system32\mllml.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Video Driver] C:\Program Files\DATCHICK-8254D9\svchost.exe
O4 - HKLM\..\Run: [Windows LSSS Service] C:\Program Files\DATCHICK-8254D9\svchost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofi...
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windows...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microso...
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://memory-of.com/Uploads/ImageU...
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe