.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 21:32 --------- d-----w c:\program files\DNA
2008-12-11 21:32 --------- d-----w c:\documents and settings\San\Application Data\LimeWire
2008-12-11 21:32 --------- d-----w c:\documents and settings\San\Application Data\DNA
2008-12-11 20:11 --------- d-----w c:\documents and settings\San\Application Data\Xfire
2008-12-11 19:21 --------- d-----w c:\program files\LimeWire
2008-12-11 17:35 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-10 17:00 31 ----a-w c:\documents and settings\San\jagex_runescape_preferences.dat
2008-12-08 23:13 --------- d-----w c:\program files\Xfire
2008-11-21 21:47 9,464 ------w c:\windows\system32\drivers\cdralw2k.sys
2008-11-21 21:47 9,336 ------w c:\windows\system32\drivers\cdr4_xp.sys
2008-11-21 21:47 43,528 ------w c:\windows\system32\drivers\PxHelp20.sys
2008-11-21 21:47 129,784 ------w c:\windows\system32\pxafs.dll
2008-11-21 21:47 120,056 ------w c:\windows\system32\pxcpyi64.exe
2008-11-21 21:47 118,520 ------w c:\windows\system32\pxinsi64.exe
2008-11-09 16:32 --------- d-----w c:\documents and settings\San\Application Data\Ventrilo
2008-11-09 16:31 --------- d-----w c:\program files\Ventrilo
2008-11-09 15:13 --------- d-----w c:\program files\Windows Journal Viewer
2008-11-09 10:21 --------- d-----w c:\documents and settings\San\Application Data\Thinstall
2008-11-08 19:39 --------- d-----w c:\program files\iTunes
2008-11-08 19:39 --------- d-----w c:\documents and settings\San\Application Data\Apple Computer
2008-11-08 19:39 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-08 19:38 --------- d-----w c:\program files\QuickTime
2008-11-08 19:38 --------- d-----w c:\program files\iPod
2008-11-08 19:38 --------- d-----w c:\program files\Bonjour
2008-11-08 19:37 --------- d-----w c:\program files\Common Files\Apple
2008-11-08 19:37 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-08 19:36 --------- d-----w c:\program files\Apple Software Update
2008-11-08 19:35 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-11-05 19:03 --------- d-----w c:\program files\NudgeMania
2008-11-01 15:14 --------- d-----w c:\program files\Common Files\DirectX
2008-10-31 23:28 --------- d-----w c:\documents and settings\San\Application Data\BitTorrent
2008-10-31 22:10 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2008-10-31 22:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-31 22:03 --------- d-----w c:\program files\Gravity
2008-10-31 22:03 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-31 17:53 --------- d-----w c:\program files\eFusion
2008-10-31 17:52 --------- d-----w c:\program files\SD EnterNET
2008-10-30 00:51 --------- d-----w c:\program files\BitTorrent
2008-10-29 23:17 --------- d-----w c:\documents and settings\San\Application Data\MSNInstaller
2008-10-27 20:08 --------- d-----w c:\documents and settings\San\Application Data\Gadu-Gadu
2008-10-27 20:05 --------- d-----w c:\program files\Gadu-Gadu
2008-10-27 18:33 410,976 ----a-w c:\windows\system32\deploytk.dll
2008-10-27 18:33 --------- d-----w c:\program files\Java
2008-10-26 21:16 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-10-26 15:50 --------- d-----w c:\program files\Windows Live
2008-10-26 15:49 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-10-26 15:43 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 14:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-04-14 12:00 717,312 ----a-r c:\documents and settings\anyone\Application Data\ntos.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-11-12 342336]
"NudgeMania"="c:\program files\NudgeMania\NudgeMania.exe" [2007-02-25 65821]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-11 1028096]
"MGSysCtrl"="c:\program files\System Control Manager\MGSysCtrl.exe" [2008-04-23 778240]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-27 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\San\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-09-18 147456]
Xfire.lnk - c:\program files\Xfire\xfire.exe [2008-11-20 2986320]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mmctl.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56762:TCP"= 56762:TCP:Pando Media Booster
"56762:UDP"= 56762:UDP:Pando Media Booster
R1 mmctl;DRAM Cash Driver;c:\windows\system32\mmctl.sys [2008-12-05 8544]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 Micro Star SCM;Micro Star SCM;c:\program files\System Control Manager\MSIService.exe [2008-05-30 159744]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTS5121.sys [2008-05-30 153600]
R3 rtl8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\DRIVERS\rtl8187Se.sys [2008-05-30 263680]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
.
Contents of the 'Scheduled Tasks' folder
2008-11-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
Notify-ctlsys - ctlsys.dll
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.thetechguys.comuInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\San\Application Data\Mozilla\Firefox\Profiles\92yo5lqw.default\
FF - plugin: c:\documents and settings\San\Application Data\Mozilla\Firefox\Profiles\92yo5lqw.default\extensions\iaplayer@instantaction.com\plugins\npiaplayer.dll
FF - plugin: c:\program files\DNA\plugins\npbtdna.dll
FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-11 21:31:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(956)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\docume~1\San\LOCALS~1\temp\nse4.tmp\NM.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-12-11 21:34:50 - machine was rebooted [San]
ComboFix-quarantined-files.txt 2008-12-11 21:34:45
Pre-Run: 44,425,789,440 bytes free
Post-Run: 44,399,394,816 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
272 --- E O F --- 2008-11-13 19:48:02