(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 14:41 . 2009-05-06 14:55 -------- d-----w- c:\program files\uTorrent
2009-06-27 14:41 . 2009-04-29 15:13 -------- d-----w- c:\users\aarons\AppData\Roaming\uTorrent
2009-06-27 06:53 . 2009-04-29 15:44 -------- d-----w- c:\program files\DivX
2009-06-27 06:53 . 2009-02-07 20:05 151136729 ----a-w- c:\windows\DUMP3fec.tmp
2009-06-27 06:40 . 2008-11-25 18:06 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-06-27 03:31 . 2009-05-17 21:14 -------- d-----w- c:\users\aarons\AppData\Roaming\gtk-2.0
2009-06-24 14:59 . 2008-11-25 17:54 -------- d-----w- c:\program files\Java
2009-06-23 16:32 . 2009-04-29 15:57 -------- d-----w- c:\programdata\Roxio
2009-06-11 13:23 . 2009-06-11 13:23 -------- d-----w- c:\programdata\AVG Security Toolbar
2009-06-11 13:22 . 2009-06-11 13:23 826344 ----a-w- c:\programdata\avg8\update\backup\AVGToolbarInstall.exe
2009-06-11 13:22 . 2009-06-11 13:23 3298072 ----a-w- c:\programdata\avg8\update\backup\setup.exe
2009-06-11 13:22 . 2009-06-11 13:23 1261344 ----a-w- c:\programdata\avg8\update\backup\avgwd.dll
2009-06-11 13:22 . 2009-06-11 13:23 829208 ----a-w- c:\programdata\avg8\update\backup\avgcfgx.dll
2009-06-11 13:19 . 2009-06-04 13:17 1452312 ----a-w- c:\programdata\avg8\update\backup\avgupd.dll
2009-06-11 07:09 . 2008-11-25 18:04 -------- d-----w- c:\program files\Microsoft Works
2009-06-11 07:08 . 2009-04-29 15:43 -------- d-----w- c:\programdata\Microsoft Help
2009-06-09 22:26 . 2009-02-07 19:11 70176 ----a-w- c:\users\aarons\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-04 13:19 . 2009-06-04 11:42 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-06-04 13:17 . 2009-06-04 13:17 1085208 ----a-w- c:\programdata\avg8\update\backup\avgupd.exe
2009-06-04 11:42 . 2009-06-04 13:20 10520 ----a-w- c:\programdata\avg8\update\backup\avgrsstx.dll
2009-06-04 11:42 . 2009-06-04 13:20 12936 ----a-w- c:\programdata\avg8\update\backup\avgrkx86.sys
2009-06-04 11:42 . 2009-06-04 13:20 90632 ----a-w- c:\programdata\avg8\update\backup\avgtdix.sys
2009-06-04 11:41 . 2009-06-04 13:20 287000 ----a-w- c:\programdata\avg8\update\backup\avgrsx.exe
2009-06-04 11:41 . 2009-06-04 13:17 443672 ----a-w- c:\programdata\avg8\update\backup\avgiproxy.exe
2009-06-04 11:41 . 2009-06-04 13:17 584472 ----a-w- c:\programdata\avg8\update\backup\avginet.dll
2009-06-04 11:39 . 2008-11-25 17:57 -------- d-----w- c:\program files\Google
2009-05-25 17:01 . 2008-11-25 17:56 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-17 21:12 . 2009-05-17 21:12 -------- d-----w- c:\program files\GIMP-2.0
2009-05-14 21:55 . 2009-05-14 21:55 245408 ----a-w- c:\windows\system32\unicows.dll
2009-05-13 07:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-04 01:00 . 2009-05-03 23:12 -------- d-----w- c:\users\aarons\AppData\Roaming\Paltalk
2009-05-03 23:14 . 2009-05-03 23:14 -------- d-----w- c:\program files\AskBarDis
2009-04-29 15:57 . 2009-04-29 15:57 -------- d-----w- c:\users\aarons\AppData\Roaming\Roxio
2009-04-29 15:56 . 2008-11-25 18:06 -------- d-----w- c:\programdata\Sonic
2009-04-29 15:53 . 2009-04-29 15:50 -------- d-----w- c:\users\aarons\AppData\Roaming\DivX
2009-04-29 15:50 . 2009-04-29 15:18 -------- d-----w- c:\users\aarons\AppData\Roaming\GetRightToGo
2009-04-29 15:48 . 2009-04-29 15:48 -------- d-----w- c:\program files\Microsoft.NET
2009-04-28 04:11 . 2009-04-28 04:11 7040776 ----a-w- c:\users\aarons\AppData\Roaming\MySpace\IM\Install\MSIMClientSetup.1.0.789.0-static-A.exe
2009-04-24 16:05 . 2009-06-10 14:08 827904 ----a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-10 14:08 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-10 14:08 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:42 . 2009-06-10 14:08 636928 ----a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 14:08 2033152 ----a-w- c:\windows\system32\win32k.sys
2008-11-25 19:23 . 2008-11-25 19:21 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-01-02 15:06 365960 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 13:29 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-25 39408]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Weather"="c:\program files\AWS\WeatherBug\Weather.exe" [2009-01-30 1347584]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-22 133656]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-24 148888]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-05-11 4452352]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
c:\users\aarons\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-24 1295656]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-11-25 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-11-25 18:07 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{81186C55-8290-4E1E-85B5-69D0AD14CBA4}"= Profile=Private|c:\program files\CyberLink\PowerDVD DX\PowerDVD.exe:CyberLink PowerDVD DX
"{6E3A746A-CDF0-4A4D-8F9F-0572A747B857}"= Profile=Private|c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:CyberLink PowerDVD DX Resident Program
"{425EEA46-5ADA-4A36-BF73-76B673E6DBDD}"= Disabled:c:\program files\CyberLink\PowerDVD DX\PowerDVD.exe:CyberLink PowerDVD DX
"{D9F9FCCB-04A6-4D34-8B0D-18D1FD488E56}"= Disabled:c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:CyberLink PowerDVD DX Resident Program
"{551BA63F-3E78-4F4E-97F5-BE1E912BB91D}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{1DB5984E-7B3F-4A01-8A39-6833677F9C26}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{E0BC8556-31A3-4CAE-BF8F-567EC035762A}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{3D50022B-A903-4745-BF0D-65FFE60D888B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EF17B71D-495D-40D6-B4EF-E74F46BF74EB}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{BAB6847C-AFD7-436B-B2DA-8355E9FA0B72}"= c:\program files\AVG\AVG8\avgam.exe:avgam.exe
"{F4966AC4-B997-40B1-9D9B-A9C12CB4118A}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{02FB4692-277D-4FF1-A94B-4B7F1FA2DCB7}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{ED706661-0A1B-46F8-ADE4-EB28E95566D0}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [6/4/2009 7:42 AM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [6/4/2009 7:41 AM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [6/4/2009 7:42 AM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/4/2009 9:19 AM 906520]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/4/2009 9:20 AM 298776]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [9/24/2008 12:09 AM 155648]
S2 gupdate1c9c8e179cb1940;Google Update Service (gupdate1c9c8e179cb1940);c:\program files\Google\Update\GoogleUpdate.exe [4/29/2009 11:45 AM 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
2009-06-27 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 15:44]
.
.
------- Supplementary Scan -------
.
mStart Page =
hxxp://www.yahoo.com/mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.htmluSearchURL,(Default) =
hxxp://www.google.com/search/?q=%sIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} -
hxxp://lads.myspace.com/upload/MySpaceUploader2.cabFF - ProfilePath - c:\users\aarons\AppData\Roaming\Mozilla\Firefox\Profiles\hjh50uc7.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.live.com/results.aspx?FORM=IEFM1&q=FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.yahoo.comFF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?FORM=IEFM1&q=FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
pref(dom.disable_open_during_load, true); .
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-27 17:11
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-27 17:13
ComboFix-quarantined-files.txt 2009-06-27 21:12
Pre-Run: 175,948,288,000 bytes free
Post-Run: 176,394,309,632 bytes free
243 --- E O F --- 2009-06-26 04:58