.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-03 18:09 . 2009-02-25 20:04 -------- d-----w- c:\program files\DNA
2009-06-03 18:09 . 2009-02-25 20:04 -------- d-----w- c:\documents and settings\Owner\Application Data\DNA
2009-06-03 04:03 . 2009-04-28 01:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-03 03:17 . 2009-03-02 19:11 -------- d-----w- c:\documents and settings\Owner\Application Data\BitTorrent
2009-06-02 22:10 . 2009-02-26 00:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-02 21:06 . 2009-03-02 23:56 -------- d-----w- c:\documents and settings\Owner\Application Data\Move Networks
2009-05-31 08:35 . 2009-02-25 18:44 13496 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-30 14:44 . 2009-02-25 18:21 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-29 01:20 . 2009-05-01 06:30 4183416 ----a-w- c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071500000347.dll
2009-05-15 04:02 . 2009-02-26 00:32 -------- d-----w- c:\program files\Google
2009-05-12 12:30 . 2009-02-26 00:35 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-12 12:30 . 2009-02-26 00:35 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-12 12:30 . 2009-02-26 00:35 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-12 12:30 . 2009-02-26 00:35 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-11 21:58 . 2009-04-21 17:13 -------- d-----w- c:\documents and settings\Owner\Application Data\HPAppData
2009-05-06 22:00 . 2009-04-14 05:02 -------- d-----w- c:\documents and settings\Owner\Application Data\Ahead
2009-05-01 06:30 . 2009-05-01 06:30 97144 ----a-w- c:\documents and settings\Owner\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-04-28 01:41 . 2009-04-28 01:41 -------- d-----w- c:\documents and settings\Owner\Application Data\acccore
2009-04-28 01:39 . 2009-04-28 01:37 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL OCP
2009-04-28 01:38 . 2009-04-28 01:36 -------- d-----w- c:\program files\AIM6
2009-04-28 01:38 . 2009-04-28 01:38 -------- d-----w- c:\documents and settings\All Users\Application Data\acccore
2009-04-28 01:37 . 2009-04-28 01:37 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-04-28 01:37 . 2009-04-28 01:37 -------- d-----w- c:\program files\Common Files\AOL
2009-04-15 19:27 . 2009-04-14 04:24 157280 ----a-w- c:\windows\hphins26.dat
2009-04-15 19:27 . 2009-04-15 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2009-04-15 17:31 . 2009-04-15 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-04-14 19:02 . 2009-04-14 19:02 -------- d-----w- c:\documents and settings\Owner\Application Data\HP
2009-04-14 04:59 . 2009-04-14 04:59 -------- d-----w- c:\program files\Common Files\LightScribe
2009-04-14 04:56 . 2009-04-14 04:56 -------- d-----w- c:\program files\Nero
2009-04-14 04:56 . 2009-04-14 04:56 -------- d-----w- c:\program files\Common Files\Ahead
2009-04-14 04:27 . 2009-04-14 04:26 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-04-14 04:26 . 2009-04-14 04:26 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-04-14 04:26 . 2009-04-14 04:25 -------- d-----w- c:\program files\HP
2009-04-14 04:25 . 2009-04-14 04:25 -------- d-----w- c:\program files\Common Files\HP
2009-04-11 20:54 . 2009-04-11 20:54 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-04-11 20:53 . 2009-04-11 20:53 -------- d-----w- c:\program files\Common Files\Adobe
2009-03-22 04:57 . 2009-03-22 05:08 331776 ----a-w- c:\documents and settings\Owner\Application Data\InstallShield Installation Information\{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}\SetupUT3.exe
2009-03-21 22:45 . 2009-03-21 22:45 0 ----a-w- c:\windows\ativpsrm.bin
2009-03-21 15:25 . 2009-03-21 15:25 62304 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-03-19 17:59 . 2009-03-19 17:59 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-03-06 14:44 . 2006-02-28 12:00 283648 ------w- c:\windows\system32\pdh.dll
2009-03-06 14:22 . 2009-04-15 04:40 284160 ------w- c:\windows\system32\SET2061.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 22:24 325000 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-02-25 321344]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-12 1947928]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-01 148888]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15360]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-12 12:30 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\Torrent Files\\Complete\\BitTorrent.exe"=
"c:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/25/2009 8:35 PM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/25/2009 8:35 PM 108552]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2/25/2009 2:34 PM 13696]
R1 BS_I2cIo;BS_I2cIo;c:\windows\system32\drivers\BS_I2cIo.sys [3/21/2009 1:56 PM 8192]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2/25/2009 8:35 PM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/25/2009 8:35 PM 298776]
S2 gupdate1c997a9ce12b68e;Google Update Service (gupdate1c997a9ce12b68e);c:\program files\Google\Update\GoogleUpdate.exe [2/25/2009 8:33 PM 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-06-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-26 05:03]
2009-06-03 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-26 00:32]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-tempo-setup2.exe - c:\windows\system32\tempo-setup2.exe
HKLM-Run-NWEReboot - (no file)
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\farkdf6c.default\
FF - prefs.js: browser.startup.homepage -
www.google.comFF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-03 14:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3312)
c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll
c:\program files\Common Files\Ahead\Lib\NeroSearchTrayHook.dll
c:\program files\Common Files\Ahead\Lib\MFC71U.DLL
c:\program files\Common Files\Ahead\Lib\BCGCBPRO800u.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\ALCFDRTM.EXE
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2009-06-03 14:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-03 18:12
Pre-Run: 136,656,646,144 bytes free
Post-Run: 137,460,752,384 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
990 --- E O F --- 2009-05-31 07:01