Part 2
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy of FOUND.025
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy of FOUND.024
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy of FOUND.021
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy (2) of FOUND.020
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy (2) of FOUND.016
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy (2) of FOUND.012
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy (2) of FOUND.009
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy of FOUND.020
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy of FOUND.016
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy of FOUND.012
2009-04-14 05:07 . 2009-04-14 05:07 -------- d-sh--w C:\Copy of FOUND.009
2009-04-14 05:06 . 2009-04-14 05:06 -------- d-sh--w C:\Copy of FOUND.023
2009-04-14 05:06 . 2009-04-14 05:06 -------- d-sh--w C:\Copy of FOUND.019
2009-04-14 05:06 . 2009-04-14 05:06 -------- d-sh--w C:\Copy of FOUND.015
2009-04-14 05:06 . 2009-04-14 05:06 -------- d-sh--w C:\Copy of FOUND.011
2009-04-14 05:06 . 2009-04-14 05:06 -------- d-sh--w C:\Copy of FOUND.007
2009-04-14 05:06 . 2009-04-14 05:06 -------- d-sh--w C:\Copy of FOUND.004
2009-04-14 05:06 . 2009-04-14 05:06 -------- d-sh--w C:\Copy of FOUND.003
2009-04-14 05:06 . 2009-04-14 05:06 -------- d-sh--w C:\Copy of FOUND.000
2009-04-14 03:54 . 2004-08-04 15:56 146432 ----a-w c:\windows\system32\dllcache\regedit.exe
2009-04-14 03:54 . 2004-08-04 15:56 146432 ----a-w c:\windows\regedit.exe
2009-04-14 01:44 . 2009-04-14 01:44 -------- d-----w c:\documents and settings\joe\Application Data\Malwarebytes
2009-04-14 01:44 . 2009-04-06 22:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-14 01:44 . 2009-04-06 22:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-14 01:44 . 2009-04-14 01:44 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-11 03:56 . 2009-04-13 04:00 1374 ----a-w c:\windows\imsins.BAK
2009-04-11 00:50 . 2001-08-17 19:48 36128 ------w c:\windows\system32\dllcache\banshee.sys
2009-04-11 00:50 . 2001-08-17 21:56 342336 ------w c:\windows\system32\dllcache\banshee.dll
2009-04-11 00:50 . 2001-08-17 19:13 89952 ------w c:\windows\system32\dllcache\b1cbase.sys
2009-04-11 00:50 . 2001-08-17 19:11 96640 ------w c:\windows\system32\dllcache\b57xp32.sys
2009-04-11 00:50 . 2001-08-17 19:19 36992 ------w c:\windows\system32\dllcache\aztw2320.sys
2009-04-11 00:50 . 2001-08-17 19:13 37568 ------w c:\windows\system32\dllcache\avmwan.sys
2009-04-11 00:50 . 2001-08-18 05:36 144384 ------w c:\windows\system32\dllcache\avmenum.dll
2009-04-11 00:50 . 2001-08-18 05:36 87552 ------w c:\windows\system32\dllcache\avmcoxp.dll
2009-04-11 00:50 . 2004-08-04 06:10 13696 ------w c:\windows\system32\dllcache\avcstrm.sys
2009-04-11 00:50 . 2001-08-17 21:01 36096 ------w c:\windows\system32\dllcache\avcaudio.sys
2009-04-11 00:50 . 2004-08-04 06:10 38912 ------w c:\windows\system32\dllcache\avc.sys
2009-04-11 00:48 . 2001-08-17 20:57 77568 ------w c:\windows\system32\dllcache\ati.sys
2009-04-11 00:48 . 2001-08-17 21:55 96128 ------w c:\windows\system32\dllcache\ati.dll
2009-04-11 00:48 . 2001-08-17 19:12 97354 ------w c:\windows\system32\dllcache\aspndis3.sys
2009-04-11 00:48 . 2001-08-17 20:52 22400 ------w c:\windows\system32\dllcache\asc3350p.sys
2009-04-11 00:48 . 2001-08-17 20:51 14848 ------w c:\windows\system32\dllcache\asc3550.sys
2009-04-11 00:48 . 2001-08-17 20:52 26496 ------w c:\windows\system32\dllcache\asc.sys
2009-04-11 00:48 . 2001-08-17 20:47 6272 ------w c:\windows\system32\dllcache\apmbatt.sys
2009-04-11 00:48 . 2004-08-04 05:31 36224 ------w c:\windows\system32\dllcache\an983.sys
2009-04-11 00:48 . 2001-08-17 20:52 12032 ------w c:\windows\system32\dllcache\amsint.sys
2009-04-11 00:47 . 2001-08-17 19:11 16969 ------w c:\windows\system32\dllcache\amb8002.sys
2009-04-11 00:47 . 2001-08-17 20:51 5248 ------w c:\windows\system32\dllcache\aliide.sys
2009-04-11 00:47 . 2001-08-17 20:49 26624 ------w c:\windows\system32\dllcache\alifir.sys
2009-04-11 00:47 . 2001-08-17 19:11 27678 ------w c:\windows\system32\dllcache\ali5261.sys
2009-04-11 00:47 . 2001-08-17 21:07 56960 ------w c:\windows\system32\dllcache\aic78xx.sys
2009-04-11 00:47 . 2001-08-17 21:07 55168 ------w c:\windows\system32\dllcache\aic78u2.sys
2009-04-11 00:47 . 2001-08-17 20:52 12800 ------w c:\windows\system32\dllcache\aha154x.sys
2009-04-11 00:47 . 2001-08-18 05:37 24576 ------w c:\windows\system32\dllcache\agcgauge.ax
2009-04-11 00:43 . 2001-08-17 21:56 66048 ------w c:\windows\system32\dllcache\s3legacy.dll
2009-04-10 05:05 . 2009-04-10 05:05 335 ------w c:\windows\nsreg.dat
2009-04-10 04:34 . 2009-04-10 04:34 -------- d-----w c:\documents and settings\joe\Application Data\MYFBTOOLBAR
2009-04-09 16:53 . 2009-03-14 13:48 5120 ------w c:\windows\system32\drivers\Start1Driver.SYS
2009-04-08 13:58 . 2009-04-08 13:58 -------- d--h--w C:\$AVG8.VAULT$
2009-04-08 12:33 . 2009-04-08 12:33 10520 ------w c:\windows\system32\avgrsstx.dll
2009-04-08 12:32 . 2009-04-08 12:33 108552 ------w c:\windows\system32\drivers\avgtdix.sys
2009-04-08 12:32 . 2009-04-08 12:32 325640 ------w c:\windows\system32\drivers\avgldx86.sys
2009-04-08 12:32 . 2009-04-08 12:32 -------- d-----w c:\windows\system32\drivers\Avg
2009-04-08 12:31 . 2009-04-08 12:31 -------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-04-08 10:49 . 2009-04-08 10:49 -------- d-----w c:\documents and settings\joe\Application Data\GlarySoft
2009-04-07 17:50 . 2009-04-07 17:50 129 ----a-w C:\Shortcut to 3½ Floppy (A).lnk
2009-04-07 13:59 . 2009-04-07 13:59 -------- d-----w c:\documents and settings\joe\Application Data\Auslogics
2009-04-07 13:41 . 2009-04-07 13:41 -------- d-----w c:\documents and settings\joe\Application Data\IObit
2009-04-07 13:04 . 2009-04-07 13:04 1507328 ----a-w C:\ffastunT.ffl
2009-04-07 12:58 . 2009-04-07 12:58 -------- d-----w c:\documents and settings\NetworkService\Application Data\MYFBTOOLBAR
2009-04-07 11:44 . 2009-04-07 11:44 -------- d-----w c:\windows\system32\config\systemprofile\Application Data\MYFBTOOLBAR
2009-04-03 00:30 . 2009-04-03 00:30 30720 ------w c:\windows\winkpst.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 04:11 . 2009-04-15 04:11 1024 ---ha-w C:\ntuser.dat.LOG
2009-04-14 01:44 . 2009-04-14 01:44 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-13 22:17 . 2009-04-13 22:17 -------- d-----w c:\program files\Trend Micro
2009-04-10 04:50 . 2009-04-10 04:50 -------- d-----w c:\program files\McAfee
2009-04-08 17:16 . 2009-04-08 17:16 -------- d-----w c:\program files\ACW
2009-04-08 12:31 . 2009-04-08 12:31 -------- d-----w c:\program files\AVG
2009-04-07 20:51 . 2009-04-07 20:51 -------- d-----w c:\program files\Thomson
2009-04-07 16:06 . 2009-04-07 16:06 -------- d-----w c:\program files\Alwil Software
2009-04-07 15:42 . 2009-04-07 15:42 -------- d-----w c:\program files\SpeedTouch
2009-04-07 13:59 . 2009-04-07 13:59 -------- d-----w c:\program files\Auslogics
2009-04-07 13:41 . 2009-04-07 13:41 -------- d-----w c:\program files\IObit
2009-04-04 21:51 . 2007-02-25 00:18 4790 ---ha-w C:\ffastun.ffa
2009-04-04 21:51 . 2007-02-25 00:18 569344 ---ha-w C:\ffastun.ffo
2009-04-04 21:51 . 2007-02-25 00:18 1622016 ---ha-w C:\ffastun0.ffx
2009-04-04 21:51 . 2007-02-25 00:16 1507328 ---ha-w C:\ffastun.ffl
2009-04-04 14:28 . 2007-02-06 15:19 268 ---ha-w C:\sqmdata19.sqm
2009-04-04 14:28 . 2007-02-06 15:19 244 ---ha-w C:\sqmnoopt19.sqm
2009-03-05 15:07 . 2009-04-10 18:54 2260480 ----a-w c:\program files\TeaTimer.exe
2009-02-09 10:19 . 2007-03-08 13:47 1846272 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 10:19 . 1980-01-01 07:00 1846272 ------w c:\windows\system32\win32k.sys
2008-10-30 19:35 . 2008-10-30 19:35 17918 ----a-w c:\documents and settings\joe\Application Data\wacuvokax.dat
2007-10-11 00:55 . 2004-11-16 19:17 74736 ----a-w c:\documents and settings\joe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-01-26 02:43 . 2007-02-12 08:23 47456 ----a-w c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-08-06 18:55 . 2003-10-31 02:11 46680 ----a-w c:\documents and settings\joe\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((
SnapShot@2009-04-13_21.15.09.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 1980-01-01 07:00 . 2004-08-04 15:56 24576 c:\windows\system32\userinit.exe
+ 1980-01-01 07:00 . 2004-08-04 15:56 24576 c:\windows\system32\dllcache\userinit.exe
- 2009-04-14 04:02 . 2005-10-21 03:02 163328 c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-04-15 04:50 . 2005-10-21 03:02 163328 c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-04-15 04:45 . 2005-10-21 03:02 163328 c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2009-04-14 03:56 . 2005-10-21 03:02 163328 c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
c:\documents and settings\joe\Start Menu\Programs\Startup\
Office Startup.lnk.disabled [2007-02-24 644]
Microsoft Find Fast.lnk.disabled [2007-02-24 669]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk.disabled [2007-04-22 1638]
Adobe Reader Speed Launch.lnk.disabled [2008-01-09 1665]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-08 05:33 10520 c:\windows\system32\avgrsstx.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" /background
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" /startup
"AdwareAlert"=c:\program files\AdwareAlert\AdwareAlert.exe -boot
"McAfee.InstantUpdate.Monitor"="c:\program files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"STManager"="c:\program files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
"SmartRAM"="c:\program files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LtMoh"=c:\program files\ltmoh\Ltmoh.exe
"LaunchApp"=LaunApp
"IgfxTray"=c:\windows\System32\igfxtray.exe
"HotKeysCmds"=c:\windows\System32\hkcmd.exe
"AGRSMMSG"=AGRSMMSG.exe
"REGSHAVE"=c:\program files\REGSHAVE\REGSHAVE.EXE /AUTORUN
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
"SynTPLpr"=c:\program files\Synaptics\SynTP\SynTPLpr.exe
"MSConfig"=c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"Imonitor"="c:\program files\McAfee\QuickClean\Plguni.exe" /START
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\msncall.exe"=
"c:\\Program Files\\Microsoft Office\\Office\\FINDFAST.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R3 DCamUSBPremier;USB Video Camera;c:\windows\system32\Drivers\mpixvid.sys [2004-07-01 81921]
R3 USBCamera;DIGITAL CAMERA; [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-08 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-08 108552]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-08 298264]
S3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;c:\windows\system32\drivers\A310.sys [2002-09-16 32823]
.
Contents of the 'Scheduled Tasks' folder
2009-04-15 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.comuSearchMigratedDefaultURL =
hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}uSearchURL,(Default) =
hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBRIE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-14 21:53
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1411836344-1228227115-425876749-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2424)
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\AVGWDSVC.EXE
c:\program files\AVG\AVG8\AVGRSX.EXE
c:\program files\AVG\AVG8\AVGNSX.EXE
.
**************************************************************************
.
Completion time: 2009-04-14 21:57 - machine was rebooted [joe]
ComboFix-quarantined-files.txt 2009-04-15 04:57
ComboFix2.txt 2009-04-14 04:17
Pre-Run: 2,367,684,608 bytes free
Post-Run: 2,363,400,192 bytes free
356