.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 02:44 . 2009-03-22 02:07 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-06-15 18:16 . 2008-04-10 05:58 97576 ----a-w- c:\documents and settings\John Tasinas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-15 18:02 . 2009-06-15 18:02 -------- d-----w- c:\windows\Fonts\Fonts
2009-06-15 18:00 . 2008-04-10 19:24 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-15 05:32 . 2008-04-11 23:44 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\Azureus
2009-06-15 05:12 . 2008-04-10 05:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-15 05:06 . 2008-06-15 00:35 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\InstallShield
2009-06-15 04:09 . 2008-04-10 17:54 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\mIRC
2009-06-15 04:08 . 2008-04-10 17:54 -------- d-----w- c:\program files\mIRC
2009-06-15 00:24 . 2008-04-10 16:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-08 19:48 . 2008-09-16 22:22 -------- d-----w- c:\program files\iTunes
2009-06-08 06:15 . 2008-09-16 22:15 -------- d-----w- c:\program files\Common Files\Apple
2009-06-04 02:19 . 2009-03-22 02:26 256 ----a-w- c:\windows\system32\pool.bin
2009-05-30 17:31 . 2008-06-17 03:14 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\U3
2009-05-25 23:10 . 2008-05-13 13:35 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\Move Networks
2009-05-24 00:34 . 2008-10-19 01:11 34 ----a-w- c:\documents and settings\John Tasinas\jagex_runescape_preferences.dat
2009-05-21 20:17 . 2008-04-30 15:43 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-05-21 20:06 . 2008-04-30 15:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2009-05-15 17:51 . 2008-04-10 17:58 -------- d-----w- c:\program files\Winamp
2009-05-12 19:25 . 2009-05-12 02:41 -------- d-----w- c:\program files\Exact Audio Copy
2009-05-12 02:41 . 2009-05-12 02:41 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\AccurateRip
2009-05-09 18:09 . 2009-05-09 18:07 -------- d-----w- c:\program files\AoA Audio Extractor
2009-05-09 18:07 . 2009-05-09 18:07 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-09 18:01 . 2009-05-09 18:01 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\FLV Extract
2009-05-09 05:49 . 2009-04-14 15:58 -------- d-----w- c:\program files\Trillian
2009-05-07 15:32 . 2004-08-03 22:56 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 00:13 . 2009-03-22 17:08 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-05-02 16:52 . 2009-05-02 16:52 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\Amazon
2009-05-02 05:27 . 2008-05-22 01:07 -------- d-----w- c:\program files\Motorola
2009-05-02 05:25 . 2008-06-14 23:33 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-05-02 05:24 . 2008-07-30 16:06 -------- d-----w- c:\program files\QPST
2009-05-02 05:00 . 2008-04-21 02:58 -------- d-----w- c:\documents and settings\John Tasinas\Application Data\LimeWire
2009-04-29 04:56 . 2004-08-03 22:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-03 22:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-23 19:33 . 2009-04-23 19:33 -------- d-----r- c:\program files\Norton Support
2009-04-23 00:43 . 2008-04-11 23:43 -------- d-----w- c:\program files\Azureus
2009-04-17 12:26 . 2004-08-03 21:17 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-03 22:56 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-04 05:15 . 2009-04-04 05:15 152576 ----a-w- c:\documents and settings\John Tasinas\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-03 18:20 . 2009-04-01 17:00 9618 ----a-w- c:\documents and settings\All Users\Application Data\DVDXStudio\CloneDVD4\MainApp.dll
2009-04-01 17:00 . 2009-04-01 17:00 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-04-01 17:00 . 2009-04-01 17:00 47360 ----a-w- c:\documents and settings\John Tasinas\Application Data\pcouffin.sys
2009-04-01 17:00 . 2009-04-01 17:00 47360 ----a-w- c:\documents and settings\John Tasinas\Application Data\pcouffin.sys
2009-04-01 16:45 . 2009-04-01 16:45 643072 ----a-w- c:\documents and settings\John Tasinas\Application Data\RipIt4Me\updater\ri4mupdater.exe
2009-03-28 20:17 . 2009-03-28 20:16 27655688 ----a-w- c:\documents and settings\All Users\Application Data\TaxCut\2008\Update\US62016801cupd.exe
2009-03-19 20:32 . 2009-03-19 20:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-12-19 02:50 . 2008-11-07 01:20 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 02:50 . 2008-11-07 01:20 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 02:50 . 2008-11-07 01:20 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 02:50 . 2008-11-07 01:20 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 02:50 . 2008-11-07 01:20 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-04-22 37888]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2006-07-11 49152]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-06-05 615696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-13 518488]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2008-06-09 397456]
c:\documents and settings\John Tasinas\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-8-18 282624]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\English\\setup.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/13/2009 1:08 AM 64160]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.086\SymEFA.sys [3/3/2009 5:24 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.086\BHDrvx86.sys [3/3/2009 5:24 PM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.086\cchpx86.sys [3/3/2009 5:23 PM 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys [6/12/2009 3:35 PM 276344]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [9/16/2008 2:02 PM 163840]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.134\ccSvcHst.exe [3/3/2009 5:24 PM 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/26/2009 8:30 PM 101936]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1005904]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\DRIVERS\CSVirtA.sys --> c:\windows\system32\DRIVERS\CSVirtA.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [7/23/2008 10:54 PM 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [7/23/2008 10:54 PM 7680]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [7/23/2008 10:54 PM 42112]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [7/23/2008 10:54 PM 23680]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ADOBEACTIVEFILEMONITOR7.0
*NewlyCreated* - FLEXNET_LICENSING_SERVICE
.
Contents of the 'Scheduled Tasks' folder
2009-06-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 05:05]
2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-06-16 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 15:20]
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{851895F6-3FCC-4F98-94BF-83BFCA8185B3}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 22:36]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-P2kAutostart - (no file)
HKLM-Run-RoxWatchTray - c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://dell.myway.com/uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: Garmin Communicator Plug-In -
hxxps://my.garmin.com/mygarmin/m/GarminAxControl.CABDPF: {EE2499C3-FE60-11D3-996B-0060081C6822} -
hxxp://fspprodweb.corp.circuitcity.net/ikbweb/PscViewer.cabFF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-16 14:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
P2kAutostart = ???
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.134\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.134\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
Completion time: 2009-06-16 14:28
ComboFix-quarantined-files.txt 2009-06-16 18:28
Pre-Run: 21,082,923,008 bytes free
Post-Run: 23,485,251,584 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
284 --- E O F --- 2009-06-15 00:24