PART 2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_KRDPDRE
-------\Service_krdpdre
((((((((((((((((((((((((( Files Created from 2009-05-04 to 2009-06-04 )))))))))))))))))))))))))))))))
.
2009-06-03 22:15 . 2009-06-03 22:15 361472 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\OneCare Protection\LocalCopy\{995E55E8-E724-4913-5D35-F2FDBFD1C3FE}-tempo-setup2.exe
2009-06-03 22:15 . 2009-06-03 22:15 361472 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\OneCare Protection\LocalCopy\{F267AA9E-64C6-7D0F-5356-FBDE2CC7A2CD}-tempo-setup2.exe
2009-06-03 17:44 . 2009-06-04 18:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-03 17:07 . 2009-06-03 17:07 -------- d-----w- c:\program files\Trend Micro
2009-06-03 16:52 . 2009-05-26 12:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-03 16:52 . 2009-06-03 16:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-03 16:52 . 2009-06-03 16:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-03 16:52 . 2009-05-26 12:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-03 16:41 . 2008-12-11 07:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-06-03 16:40 . 2009-03-06 15:45 130424 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-06-03 16:40 . 2008-12-18 11:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-06-03 16:40 . 2009-06-03 16:41 -------- d-----w- c:\program files\Common Files\PC Tools
2009-06-03 16:40 . 2008-12-10 11:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-06-03 16:40 . 2009-06-03 17:44 -------- d-----w- c:\program files\Spyware Doctor
2009-06-03 16:40 . 2009-06-03 16:40 -------- d-----w- c:\documents and settings\RICHARD\Application Data\PC Tools
2009-06-03 16:40 . 2009-06-03 16:40 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-06-02 23:41 . 2009-06-02 23:41 -------- d-----w- c:\program files\PlayAllDVD
2009-06-02 23:37 . 2009-06-02 23:37 -------- d-----w- c:\program files\WinBlueSoft Software
2009-06-02 18:20 . 2009-06-02 18:20 -------- d-----w- c:\documents and settings\RICHARD\Application Data\UseNeXT
2009-06-02 18:20 . 2009-06-02 18:20 -------- d-----w- c:\program files\UseNeXT
2009-06-01 23:06 . 2009-06-01 23:07 -------- d-----w- c:\documents and settings\RICHARD\Application Data\TigerPlayer
2009-06-01 23:05 . 2009-06-01 23:05 -------- d-----w- c:\program files\MpcStar
2009-05-31 21:42 . 2009-05-31 21:42 390664 ----a-w- c:\documents and settings\RICHARD\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-29 03:35 . 2008-11-05 09:14 1048576 ----a-w- c:\documents and settings\RICHARD\Application Data\Mozilla\Firefox\Profiles\c5kqd84s.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash\components\IBitCometExtension.dll
2009-05-27 16:37 . 2009-05-27 16:37 -------- d-----w- c:\program files\DivxFree
2009-05-23 12:04 . 2009-05-23 12:04 -------- d-----w- c:\program files\UltraVideo
2009-05-20 14:44 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-05-20 14:44 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-05-20 14:44 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-05-20 14:44 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-05-20 14:44 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-05-20 14:44 . 2009-02-09 12:10 729088 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-05-20 14:44 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-20 14:44 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-05-20 14:44 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-05-20 14:42 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-05-20 14:42 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-05-20 14:40 . 2008-04-14 00:11 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2009-05-20 14:40 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-05-20 14:40 . 2008-04-13 18:39 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-05-20 14:40 . 2008-04-13 18:39 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-04 18:09 . 2007-09-16 16:44 -------- d-----w- c:\program files\Microsoft Windows OneCare Live
2009-06-03 17:57 . 2007-07-17 17:52 -------- d-----w- c:\program files\Java
2009-05-27 22:38 . 2006-09-23 16:57 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-26 22:52 . 2008-09-23 18:24 -------- d-----w- c:\program files\Nokia
2009-05-25 19:20 . 2006-09-13 17:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2003-12-19 19:36 . 2006-09-23 17:05 40960 ----a-w- c:\program files\Uninstall_CDS.exe
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-03_22.42.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-04 18:25 . 2009-06-04 18:25 16384 c:\windows\Temp\Perflib_Perfdata_d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"AGEIA PhysX SysTray"="c:\program files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 331776]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 517768]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2009-03-22 63864]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-05-01 185896]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2006-08-11 17920]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2006-08-11 18944]
"C-Media Mixer"="Mixer.exe" - c:\windows\mixer.exe [2002-10-15 1818624]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-12-05 1626112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-9-23 155648]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [23/09/2006 18:09 9344]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [03/06/2009 17:40 130424]
R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [22/03/2009 10:59 24936]
R2 sfmgr;CaReTaKeR-CT NetMgr 1.2.1;c:\sfmgr\sfmgr.exe [15/03/2007 13:16 171008]
S3 ni_avs;ni_avs;c:\windows\system32\Drivers\ni_avs.sys --> c:\windows\system32\Drivers\ni_avs.sys [?]
S3 ni_usb;ni_usb;c:\windows\system32\Drivers\ni_usb.sys --> c:\windows\system32\Drivers\ni_usb.sys [?]
S3 USB22LDR;M-Audio USB MIDISPORT 2x2 Loader;c:\windows\system32\drivers\usb22ldr.sys [03/04/2008 20:45 20936]
.
Contents of the 'Scheduled Tasks' folder
2009-06-04 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.co.uk/uSearchMigratedDefaultURL =
hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) =
hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBRIE: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabFF - ProfilePath - c:\documents and settings\RICHARD\Application Data\Mozilla\Firefox\Profiles\c5kqd84s.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/FF - component: c:\documents and settings\RICHARD\Application Data\Mozilla\Firefox\Profiles\c5kqd84s.default\extensions\bkmrksync@nokia.com\components\BkMrkExt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstrlnk.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-04 19:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-823518204-725345543-910916986-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3c,9c,6c,23,db,93,6c,2e,e2,51,78,77,2a,83,44,ea,ac,a2,8d,7a,5c,d2,9b,
d3,4c,fe,7c,18,bb,af,e8,59,c4,98,ca,57,50,a5,ea,eb,97,d2,f8,b2,09,8c,85,b4,\
"??"=hex:d5,b6,d8,0c,d2,ce,a5,b1,06,09,a9,bf,cb,2d,2a,b8
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3344)
c:\windows\system32\ctagent.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
c:\windows\system32\DVDRAMSV.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
c:\program files\Microsoft Windows OneCare Live\winss.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\searchprotocolhost.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2009-06-04 19:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-04 18:28
ComboFix2.txt 2009-06-03 22:45
Pre-Run: 1,525,243,904 bytes free
Post-Run: 1,425,149,952 bytes free
327 --- E O F --- 2009-05-21 18:25