ComboFix 09-10-16.02 - DooHan Kim 2009-10-16 16:31.1.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.949.82.1033.18.511.225 [GMT -5:00]
Running from: c:\documents and settings\DooHan Kim\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning enabled* (Outdated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\01d00098f732f640c6a5c8d431515b46.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\049497fd8947e722ae04b02eab871c18.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\067a9fd1541da872bb757c3da6a33d92.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\0783fa07a21528ab730a1df23334399c.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\0999dc9d92e75202025b885f39592438.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\0ba4ed06c78b5997716890d067fe2f51.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\0bb985ae9fc3a38262b3fd4c5cb03a3e.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\0ccc70e9bd23465e9e97d9445314fa13.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\0d5b5b246d05342352b6c776e1cf5212.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\11e75649feaf8ef009c4ed99aafe8310.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\1ba01a94a454af76ad1d723478b7127d.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\1ec397e7e85d3c521dc4c849c4e3ea0f.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\1f840d5d0d14655c624d157818b7003d.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\24c8b24d8a5c9889dac59d968fa1b8d8.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\251f27bb0e06e757f562bc1dc84a615f.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\25e9c02c9d769d249732f66e042c290e.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\28358b19588cf08bbb5de8b51850fe3a.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\288a0b7430370eb282f72b7e015c3c9a.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\28e51fb50e37beadbd134e4ae50e8f63.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\2a066ba87c16f28ec9819e3285252403.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\2c5a2cabd3b78548df720c3ee90efb41.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\2c86ccbe1c6e19b40bb8de244b0ba1e7.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\2d0afc3654f0a438f23598fb84be758c.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\2dfb42d5ca2c7ccc627743d095dfbac9.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\2eacacaddf4a71fe74de2b3f14074ac6.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\354c633ff9bf6fb3ecfad0ad65113c47.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\366a8f1bc352313a1074df76fdbce056.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\393e4d90773d8bbc9b905d903b618bdf.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\397bc65516fb1e815aa106a3d14d5305.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\3c1498e5ef362e757dc43d17482960f3.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\3ca41046bcb79924498d631f343d4371.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\461b3a8e7cfacb0c812e36aed9447c6d.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\46ceb001bfdc384ffe00657d8c567973.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\46eb2cd25804a00a1f22c69c4020c7e5.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\47d1dba34092ceb5412ac6f70c51e606.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\485d27cb769c9983f17e3d9eb5d03c5c.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\4b377d6eea3966e34c9a3ac2c647e5e5.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\4e216d83dc7da9779966ea4d31e236dd.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\4e6865e0bf7cf90244ce414917cc6556.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\51303604fcc7ede3ff317e6daac0c19a.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\52b483be9d71439ea530fb17638e5382.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\56613b7bd5cb1c3e01ecaa7a811022a9.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\59a83ef1238e50bddcc7caeb618d1824.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\59d3e0ea0c210c7674fea90f5382090c.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\5af1fa38e21413b7b2f5c6371f706543.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\5c5edcfe25ff895bc5c6a8d734710c5c.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\5f45a68915125fa8ad11a60ebffe29ee.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\6166b09fdf1ac1eaa1ae57a6eb20c03b.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\63eb5d17d60101356a7bbfdaae9afa57.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\654f8818ae39026c29f34808452fb02f.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\69482b1568b01b43c70d0ace76055f7e.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\6ab204a5ef9f916fe93d527a421ffdda.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\741983fb8768fa4d118c8ca59f82bb83.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\7cef98e862160d452cf773da8f4e2064.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\7f1d8b588793a67a9e8271b309c497c8.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\82724e37ddf746e5c798c9541a83d990.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\877d5ef68d1b6d7922fd09e955289803.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\8abcdf24b4bfa351f3b767c4232c6d02.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\91a1315c3d05215b1504e5899d32b936.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\9a40bf533c72981026081869543bbde2.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\9a846edeab464b62f0f2a74c54059f0b.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\9c5178781b9775c8036205fa67727330.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\9f9c2aa3ed1b1b0f922524c5a5260d1c.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\a26ba057241a8c2ae219a8db7335f51c.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\a67e0c2d6a842bf89983192c7e42d7c7.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\a9583053db1a9b326763e99e2321c517.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\ad63fa05a8e976a9e0939831eb5ba308.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\b2c8a6ebad81932fcbe8461599d71865.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\b527594c48bbaad67924ced89a416e20.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\b86745632d1223fab788478c41828d9a.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\b88e5980318f9688b4348228079f4f04.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\c25b7660062dfaf312f7142d2126cf2e.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\c2a9bad2a6f3c5b8aba800c2646abbf0.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\c36f2f770b74dd9e49947e924f85eeea.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\c636b5bf68f8ea6811c91dd569143b63.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\c73959eceda75ddf82609033ed2756e9.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\ccbebc209ee7342ed2a62b6d6e996645.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\d0d1583aaf54f587014b422167bddd89.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\d41d8cd98f00b204e9800998ecf8427e.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\d7c0d1ef6446382c3f7bb71308ba122f.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\d8c72d47eaed4bf47aa5d4f291a7c350.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\d909bf9e40d3de9bfa779059a90ff834.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\dc973701a6a9f218f60e389f479684db.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\dcc3ea4461b925db5858951892b5fa12.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\df0ea822d926c8fa5e9401e70f2cea67.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\e09d50f5972f50e03ca6be41cf66e0b5.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\e261f32b2da3462f5a3f10d0e3cb11c7.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\e52ee3c662672a47bf85d717ebb4ae8e.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\e5c061252396f14b1dca59f288bf9c20.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\ebc4635e6aeb6c62f3801a378bdfaa4d.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\ecb246b7273dc7466b406d7b8b10c09e.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\f63720489499e58792f33295e3dfbf29.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\f9531b586c797615c6b11c5d9e8b7302.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\fd44d831ab115f692f560f8ea07c9868.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\fe5046d3ac6595d8f385d8a45126456e.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\fe6d388665fbc8cdfabaa8dc587839f7.bmp
c:\documents and settings\DooHan Kim\Local Settings\Temporary Internet Files\hgstarter_verinfo.dat
c:\documents and settings\DooHan Kim\Start Menu\Programs\Startup\Logitech . 제품 등록.lnk
c:\program files\AWS\WEATHE~1\MINIBU~1.DLL
c:\program files\Common Files\Companion Wizard
c:\program files\Common Files\companion wizard\compwiz.exe
c:\program files\Common Files\Companion Wizard\WapCHK.dll
c:\program files\Common Files\Companion Wizard\WapCHK{57D5F504-A70E-475F-A40F-82E2E2DD1A63}.dll
c:\program files\Common Files\Companion Wizard\WapCHK{AE2A07FD-C21E-486B-A26E-FF85FE745A0B}.dll
c:\program files\internet optimizer
c:\recycler\S-1-5-21-484763869-1935655697-1343024091-1003
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\fCOe
c:\temp\fCOe\tOasF.log
c:\temp\fse
c:\temp\fse\tmpZTF.log
c:\windows\system32\H7
c:\windows\system32\oTt06e
c:\windows\system32\wnsxs~1
c:\windows\ymbols~1
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NWCWORKSTATION
-------\Service_NWCWorkstation
((((((((((((((((((((((((( Files Created from 2009-09-16 to 2009-10-16 )))))))))))))))))))))))))))))))
.
2009-10-16 21:45 . 2009-10-16 21:45 -------- d-----w- c:\windows\LastGood
2009-10-14 00:38 . 2009-10-14 00:38 -------- d-----w- c:\program files\Trend Micro
2009-10-13 01:58 . 2009-10-13 01:58 -------- d-----w- c:\documents and settings\DooHan Kim\Application Data\Malwarebytes
2009-10-13 01:58 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-13 01:58 . 2009-10-13 01:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-13 01:58 . 2009-10-13 01:58 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-10-13 01:58 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-13 01:42 . 2009-10-13 01:42 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-05 02:13 . 2009-10-05 02:13 -------- d-----w- C:\2009-10-04
2009-10-02 02:11 . 2009-10-02 02:11 -------- d-----w- c:\windows\system32\DRVSTORE
2009-10-02 02:10 . 2009-10-02 02:10 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Logishrd
2009-10-02 02:10 . 2009-10-02 02:10 -------- d-----w- c:\windows\CAVTemp
2009-10-02 02:10 . 2009-10-02 02:10 -------- d-----w- c:\program files\MSXML 4.0
2009-09-28 20:38 . 2008-07-26 15:26 465432 ----a-r- c:\windows\system32\LVUI2RC.dll
2009-09-28 20:38 . 2008-07-26 15:26 41752 ----a-r- c:\windows\system32\drivers\LVUSBSta.sys
2009-09-28 20:38 . 2008-07-26 15:26 490008 ----a-r- c:\windows\system32\LVUI2.dll
2009-09-28 20:38 . 2008-07-26 15:23 195096 ----a-r- c:\windows\system32\lvci11801048.dll
2009-09-28 20:38 . 2008-07-26 15:23 416280 ----a-r- c:\windows\system32\lvcodec2.dll
2009-09-28 20:37 . 2008-07-26 15:22 2570520 ----a-r- c:\windows\system32\drivers\LV302V32.SYS
2009-09-28 20:37 . 2004-08-04 05:56 53760 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2009-09-28 20:37 . 2004-08-04 05:56 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-09-28 20:35 . 2009-09-28 20:35 -------- d-----w- c:\documents and settings\DooHan Kim\Application Data\Leadertech
2009-09-28 20:31 . 2009-10-02 02:08 -------- d-----w- c:\program files\Common Files\LogiShrd
2009-09-28 20:31 . 2009-09-28 20:31 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Logitech
2009-09-28 20:31 . 2009-09-28 20:31 -------- d-----w- c:\program files\Logitech
2009-09-28 00:57 . 2009-09-28 00:58 -------- d-----w- c:\documents and settings\DooHan Kim\Application Data\ooVoo Details
2009-09-28 00:56 . 2009-10-02 02:09 -------- d-----w- c:\program files\ooVoo
2009-09-19 06:11 . 2009-10-16 21:37 -------- d-----w- c:\documents and settings\DooHan Kim\Application Data\CallingID
2009-09-19 05:52 . 2009-09-19 06:05 -------- d-----w- c:\program files\Common Files\Scanner
2009-09-19 05:50 . 2008-08-22 23:33 111856 ----a-w- c:\windows\system32\wbem\canvprov.dll
2009-09-19 05:50 . 2009-09-19 05:52 -------- d-----w- c:\program files\CA
2009-09-19 05:48 . 2009-09-19 06:04 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\CA
2009-09-19 05:41 . 2009-10-02 03:02 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\gwr
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-02 02:10 . 2008-01-07 23:50 -------- d-----w- c:\program files\fwceqxbt
2009-10-02 02:10 . 2007-11-17 15:19 -------- d-----w- c:\program files\Nzwlnrip
2009-10-02 02:10 . 2007-11-17 15:18 -------- d-----w- c:\program files\raxurcvs
2009-10-02 02:10 . 2007-09-06 22:21 -------- d-----w- c:\program files\Common Files\wqim
2009-09-28 00:55 . 2004-12-30 14:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-05 09:11 . 2004-08-12 13:23 204800 ----a-w- c:\windows\system32\mswebdvd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"ALPass"="c:\program files\ESTsoft\ALPass\ALPass.exe" [2008-11-12 2335416]
"oovoo.exe"="c:\program files\ooVoo\oovoo.exe" [2009-09-03 17385144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-12 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-12 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-12 455168]
"SigmaTel StacMon"="c:\program files\SigmaTel\SigmaTel AC97 오디오 드라이버\stacmon.exe" [2004-04-29 90169]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-05-28 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" [2009-09-19 374000]
"cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2009-09-19 1512688]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2009-09-19 636144]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2009-09-19 337136]
"CAPPActiveProtection"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe" [2009-09-19 333040]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-12 15360]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll" [2009-06-23 1422776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-12 12:55 110592 ----a-w- c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-06-06 21:46 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\UmxSbxExw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\ooVoo\\ooVoo.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:ooVoo TCP 포트 443
"443:UDP"= 443:UDP:ooVoo UDP 포트 443
"37674:TCP"= 37674:TCP:ooVoo TCP 포트 37674
"37674:UDP"= 37674:UDP:ooVoo UDP 포트 37674
"37675:UDP"= 37675:UDP:ooVoo UDP 포트 37675
S0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2009-06-25 오후 2:10 108024]
S1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2009-06-25 오후 2:10 73720]
S1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2009-06-25 오후 2:10 55288]
S1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2009-06-25 오후 2:10 115704]
S2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [2009-09-19 오전 12:50 128240]
S2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2009-06-25 오후 2:10 145912]
S2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-07-30 오후 1:38 58872]
S2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2009-06-25 오후 2:10 875000]
S2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2009-06-25 오후 2:10 760664]
S2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2009-06-25 오후 2:10 207352]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-12-18 오후 10:23 24652]
S3 JRSKD24;JRSKD24;c:\windows\system32\JRSKD24.sys [2008-12-17 오전 11:59 34744]
S3 JRSUKD24;JRSUKD24;c:\windows\system32\JRSUKD24.sys [2008-12-17 오전 11:59 6784]
S3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2009-06-25 오후 2:10 205304]
S3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2009-09-19 오전 12:52 222448]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.naver.com/
mStart Page = hxxp://www.naver.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: 네이버 검색 - c:\program files\naver\NaverToolbar\NaverTB_3_1_1_107.dll /SEARCH.HTML
IE: 네이버 북마크하기 - c:\program files\naver\NaverToolbar\NaverTB_3_1_1_107.dll /BOOKMARK.HTML
IE: 네이버 블로그 담기 - c:\program files\naver\NaverToolbar\NaverTB_3_1_1_107.dll /BLOG.HTML
IE: 네이버 사전 검색 - c:\program files\naver\NaverToolbar\NaverTB_3_1_1_107.dll /DIC.HTML
IE: 네이버 일한 번역 - c:\program files\naver\NaverToolbar\NaverTB_3_1_1_107.dll /JKTRANS.HTML
IE: 알툴바 빠른검색(&Q) - c:\program files\ESTsoft\ALToolbar\ALToolBand_1300.dll/23/SEARCH.HTML
IE: {{572E3910-4764-4E88-8929-176B2B192FF7} - c:\program files\ESTsoft\ALPass\ALPass.exe
FF - ProfilePath - c:\documents and settings\DooHan Kim\Application Data\Mozilla\Firefox\Profiles\d6z58l8b.default\
FF - component: c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\Firefox\components\CallingIDLinkAdvisorGecko.dll
FF - component: c:\program files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\Firefox\components\CIDDomFx3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPGomtvx_nie.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-HookURL - (no file)
URLSearchHooks-Rank - (no file)
Notify-AtiExtEvent - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-16 16:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(384)
c:\windows\system32\UmxWnp.Dll
c:\windows\system32\LgNotify.dll
- - - - - - - > 'explorer.exe'(1324)
c:\windows\system32\WININET.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ZCfgSvc.exe
.
**************************************************************************
.
Completion time: 2009-10-16 16:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-16 21:52
Pre-Run: 2,799,960,064 bytes free
Post-Run: 6,465,245,184 bytes free
292 --- E O F --- 2009-09-20 06:13