[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Administrator^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a------ 2007-04-18 01:49 50736 c:\program files\AOL 9.0\aol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-07-16 16:54 961536 c:\program files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2007-05-25 12:16 42032 c:\program files\Common Files\aol\1183234732\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-19 02:33 1233920 c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-19 02:33 202240 c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2007-03-09 15:28 598016 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2BE0F908-8E44-42D4-969A-035EF76121C7}"= UDP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{87E3941E-7C46-45A6-BA18-3F9E8F3A893D}"= TCP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{3726EC3C-A64E-4EB4-972B-EF3055B5B8E9}"= UDP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{D7F46A65-353D-4D64-B478-B0BD0E362CB0}"= TCP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{0CDCC2B2-BE42-47FF-9034-BEFDABA7BD0A}"= UDP:c:\program files\Common Files\aol\1183234732\ee\aolsoftware.exe:AOL Shared Components
"{B75F5C2B-F4E9-49C2-8289-E72D43DF753D}"= TCP:c:\program files\Common Files\aol\1183234732\ee\aolsoftware.exe:AOL Shared Components
"{CF005D1F-EC1E-4125-BA2F-C7C0C7B83505}"= UDP:c:\program files\AOL 9.0\waol.exe:AOL
"{26F3926A-B65E-4B9A-8E87-F8E21756308C}"= TCP:c:\program files\AOL 9.0\waol.exe:AOL
"{9B35FB2F-ABFA-421B-BE25-D3B45994E069}"= UDP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{BD2355BD-B617-42CC-82AA-3BD397643392}"= TCP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{65641844-56CC-4CD5-9EB1-069F6952C613}"= UDP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{CB064EE3-BF9F-4AAE-BA4F-8053DB9A51EF}"= TCP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{0D8F85A9-6F83-4C58-909C-DBFC6848BB83}"= UDP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{5DB7C3B0-1A50-48AB-8BF7-3414E22F42DD}"= TCP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{E761F8D5-CBA8-4AB8-9E17-CE6BCDB74E0B}"= UDP:990:LocalSubnet:LocalSubnet|IF={C16CFDDB-16C1-45F9-98D0-D64BB6BF3769}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"TCP Query User{DEFB3D4C-FEB2-4C17-9CA7-7868517F1CCE}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{59A1A900-66DC-43CB-824C-4384F0C3789A}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{7F58DA40-0997-49D4-AA4C-D727730FD186}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{4C6D4146-FD3C-4207-8E71-FA87C9301389}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{73D98EB5-4895-46F4-96A4-D5F65A64B051}c:\\program files\\alibaba\\trademanager\\trademanager.exe"= UDP:c:\program files\alibaba\trademanager\trademanager.exe:TradeManager
"UDP Query User{4C169394-B4F5-46D6-B20C-41C378464D67}c:\\program files\\alibaba\\trademanager\\trademanager.exe"= TCP:c:\program files\alibaba\trademanager\trademanager.exe:TradeManager
"{29BA6322-7915-4E94-AB66-E409DF46E2C8}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{24938BEA-8865-45B6-B2D3-CE4509EA43A1}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{12E779FE-9B8E-4046-B199-ACFBCB4D4C49}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{44598517-3607-4CBC-BFCD-399C4DC855A9}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{90DCA162-E18F-486F-B23E-50700291722B}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{2B19F71E-739A-4B7F-A105-29C36EF49522}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{38250A48-3916-45F9-B29E-75FED3CD18C4}"= UDP:c:\program files\AOL 9.1\waol.exe:AOL
"{C81FB904-2195-4534-A6ED-05B06E7E05A3}"= TCP:c:\program files\AOL 9.1\waol.exe:AOL
"{77E921A0-057D-4F5D-B262-A775BB050E0F}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{4FA0185E-E659-4BB7-8E4E-CA48B8D00EAC}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{1092FA29-A6A2-4B79-A925-4B9D893636B0}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{162F33DA-6493-4AB9-BA6E-3797EDD304A4}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{4F4F7BBF-B39C-4104-B36D-AE89FE398458}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{46142228-989A-4FD3-9D6E-FA6419933BAA}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{00F6391B-6E19-4E38-9C98-202DDEF48D9C}"= UDP:990:LocalSubnet:LocalSubnet|IF={C16CFDDB-16C1-45F9-98D0-D64BB6BF3769}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{7BAF213E-A7DC-477C-9A34-7385C5E52EE2}"= UDP:990:LocalSubnet:LocalSubnet|IF={C16CFDDB-16C1-45F9-98D0-D64BB6BF3769}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"TCP Query User{3B078D35-B4E1-43E6-8944-09149EF344C3}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{386DC190-F248-4F79-B918-2976196DBFFB}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{27252682-AE06-4347-9A87-8C65438111C4}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{842572F7-5266-42E0-AB28-A3FD56F865DE}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{771E3ED7-C1FB-43F2-9F51-805D5E53667E}"= UDP:c:\program files\Brother\Brmfl07b\FAXRX.exe:FAXRX.EXE
"{9597B370-A37C-4BBC-B7CB-B8991A03393C}"= TCP:c:\program files\Brother\Brmfl07b\FAXRX.exe:FAXRX.EXE
"{ADBEF1A8-19C4-4940-9929-2E70FA8B45BD}"= TCP:54925:Brother Network Scanner
"TCP Query User{E6275D83-F459-4068-B44D-E6B1E5763287}c:\\program files\\counterpath\\eyebeam 1.5\\eyebeam.exe"= UDP:c:\program files\counterpath\eyebeam 1.5\eyebeam.exe:eyeBeam
"UDP Query User{9E7FCD50-5535-45A5-8C96-8B8ECBFA4AE4}c:\\program files\\counterpath\\eyebeam 1.5\\eyebeam.exe"= TCP:c:\program files\counterpath\eyebeam 1.5\eyebeam.exe:eyeBeam
"{284FA8B1-4457-4267-93FA-638BB1D4F4D8}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{AEE2479A-69E4-4C63-BBD3-52DA29AE1DAA}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 QuickBooksDB18;QuickBooksDB18;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB18 []
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\Drivers\ICDUSB2.sys [2008-07-14 39048]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2008-11-29 38496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50d84c62-ba46-11dd-854a-00038a000015}]
\shell\AutoRun\command - I:\PortableRoboForm.exe
\shell\RoboForm2Go\command - I:\PortableRoboForm.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{537e44eb-adaa-11dd-b70b-00038a000015}]
\shell\AutoRun\command - I:\PortableRoboForm.exe
\shell\RoboForm2Go\command - I:\PortableRoboForm.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-29 18:50:45
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(504)
c:\program files\Mouse Driver\Mouse Driver\5.2\MOUDL32A.DLL
.
Completion time: 2008-11-29 18:51:53
ComboFix-quarantined-files.txt 2008-11-29 23:51:50
ComboFix2.txt 2008-11-29 23:31:03
Pre-Run: 176,894,201,856 bytes free
Post-Run: 176,864,903,168 bytes free
272 --- E O F --- 2008-11-27 17:36:07