-------\Legacy_$SYS$ARIES
-------\Legacy_$SYS$COR
-------\Legacy_CD_PROXY
-------\Legacy_DMSKSSRH
-------\Legacy_NPF
-------\Service_$sys$cor
-------\Service_$sys$crater
-------\Service_DMSKSSRh
((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 )))))))))))))))))))))))))))))))
.
2009-05-16 19:45 . 2009-05-16 19:45 552 ----a-w c:\windows\system32\d3d8caps.dat
2009-05-16 18:03 . 2009-05-16 18:03 -------- d-----w c:\program files\Trend Micro
2009-05-14 13:00 . 2009-05-14 13:00 -------- d-----w c:\documents and settings\Alexis Aiken\Local Settings\Application Data\AIM Toolbar
2009-05-14 12:42 . 2009-05-14 12:42 -------- d-----w c:\program files\Enigma Software Group
2009-05-14 12:18 . 2009-05-14 19:18 -------- d-----w c:\program files\Exterminate It!
2009-05-10 18:38 . 2009-05-14 13:03 -------- d-----w c:\documents and settings\Alexis Aiken\Application Data\GetRightToGo
2009-05-10 18:30 . 2009-05-14 19:21 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-10 13:45 . 2009-05-10 13:45 17946 ----a-w c:\windows\2358hacztool3549.dll
2009-05-01 15:37 . 2009-05-01 15:37 -------- d-----w c:\program files\HDQuality
2009-05-01 07:03 . 2009-05-01 07:03 17313 ----a-w c:\windows\system32\31199pywa5ez842.bin
2009-04-27 14:58 . 2009-04-27 14:58 5570 ----a-w c:\windows\system32\5z897spa9bot361.dll
2009-04-27 07:04 . 2009-04-27 07:04 15848 ----a-w c:\windows\15617no9-a-virzs5d.bin
2009-04-26 19:18 . 2009-04-26 19:18 15243 ----a-w c:\windows\system32\18155z5r94a3.exe
2009-04-25 06:40 . 2009-04-25 06:40 9162 ----a-w c:\windows\system32\557addware929z.bin
2009-04-24 17:27 . 2009-04-24 17:27 4754 ----a-w c:\windows\30570z5rm393.bin
2009-04-24 03:38 . 2009-04-24 03:38 3835 ----a-w c:\windows\system32\6c99vzr2415.bin
2009-04-22 13:31 . 2009-04-22 13:31 13397 ----a-w c:\windows\system32\2154spzr9e330.bin
2009-04-19 19:05 . 2009-04-19 19:05 3392 ----a-w c:\windows\129z9ha5ktool759.exe
2009-04-19 12:23 . 2009-04-19 12:23 13921 ----a-w c:\windows\4479sparsz615.exe
2009-04-18 13:47 . 2009-04-18 13:47 6092 ----a-w c:\windows\system32\45149ot5a-virusz48.bin
2009-04-17 00:18 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-17 00:18 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-17 00:18 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-17 00:18 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-17 00:18 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-17 00:18 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-17 00:18 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-17 00:18 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-17 00:18 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-17 00:18 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-17 00:18 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-17 00:18 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 20:50 . 2009-02-28 01:24 -------- d-----w c:\program files\Symantec AntiVirus
2009-05-16 18:30 . 2005-12-07 16:49 -------- d-----w c:\program files\Viewpoint
2009-05-14 23:04 . 2007-07-09 16:26 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-05-10 13:45 . 2009-05-10 13:45 8820 ----a-w c:\windows\system32\5bf2st5al1952z.dll
2009-05-07 23:33 . 2006-01-14 03:56 104 --sh--r c:\windows\system32\B993D92FBE.sys
2009-05-07 23:33 . 2006-01-14 03:56 7518 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-04-13 01:40 . 2009-04-13 01:40 8230 ----a-w c:\windows\system32\1805not-z-vi9u589.exe
2009-04-11 18:25 . 2009-04-11 18:25 9422 ----a-w c:\windows\system32\174059ozmf5.dll
2009-04-11 18:18 . 2005-12-07 16:41 -------- d-----w c:\program files\Java
2009-04-10 21:36 . 2009-04-10 21:36 6077 ----a-w c:\windows\system32\21650viru599dz.dll
2009-04-09 17:20 . 2009-04-09 17:20 6406 ----a-w c:\windows\52327hac9tool667z.dll
2009-04-09 02:32 . 2009-04-09 02:32 6522 ----a-w c:\windows\system32\5519spa5bot5f4z.exe
2009-04-08 16:56 . 2009-04-08 16:56 7491 ----a-w c:\windows\100cadz59re1811.bin
2009-04-07 16:27 . 2009-04-07 16:27 2767 ----a-w c:\windows\zb93addware2564.exe
2009-04-07 03:03 . 2009-04-07 03:03 16839 ----a-w c:\windows\system32\673fad5warez94.exe
2009-04-07 00:17 . 2009-04-07 00:16 -------- d-----w c:\program files\iTunes
2009-04-07 00:16 . 2007-06-30 15:39 -------- d-----w c:\program files\Common Files\Apple
2009-04-06 08:54 . 2009-04-06 08:54 16725 ----a-w c:\windows\system32\6e57s5eal9195z.bin
2009-04-05 00:37 . 2009-04-05 00:37 17306 ----a-w c:\windows\system32\2ac6zp5rs91684.dll
2009-04-02 11:14 . 2009-04-02 11:14 13554 ----a-w c:\windows\system32\78225iz491.bin
2009-04-01 11:15 . 2009-04-01 11:15 6417 ----a-w c:\windows\5cdaspy9ar5111z.dll
2009-03-28 21:21 . 2009-03-28 21:21 10181 ----a-w c:\windows\20692hackt5ol11z.exe
2009-03-26 21:25 . 2009-03-26 21:25 6848 ----a-w c:\windows\system32\12681not9a-viru563z.dll
2009-03-25 03:18 . 2009-03-25 03:18 16199 ----a-w c:\windows\system32\519zadd9are1511.bin
2009-03-24 15:10 . 2009-03-24 15:10 4085 ----a-w c:\windows\system32\193995acztool4c6.dll
2009-03-24 10:46 . 2009-03-24 10:46 15603 ----a-w c:\windows\system32\2302vi928z5.exe
2009-03-24 03:32 . 2009-03-24 03:32 14796 ----a-w c:\windows\system32\3ff9thi5f26z4.bin
2009-03-22 15:58 . 2009-03-22 15:58 3405 ----a-w c:\windows\51964spyz92.exe
2009-03-20 10:59 . 2009-03-20 10:59 8986 ----a-w c:\windows\789a95arsz2235.exe
2009-03-19 21:32 . 2008-01-29 17:01 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-15 13:46 . 2009-03-15 13:46 8759 ----a-w c:\windows\30729zars5793.dll
2009-03-14 21:21 . 2009-03-14 21:21 5197 ----a-w c:\windows\b9fzir9095.exe
2009-03-14 12:28 . 2009-03-14 12:28 3043 ----a-w c:\windows\5c58addwaze9299.dll
2009-03-11 03:40 . 2009-03-11 03:40 15784 ----a-w c:\windows\13c5i9z113.exe
2009-03-09 20:15 . 2009-03-09 20:15 15513 ----a-w c:\windows\system32\241adz9nloader2305.bin
2009-03-09 10:19 . 2008-12-07 00:51 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 16:20 . 2009-03-08 16:20 16135 ----a-w c:\windows\z6353hac5too963d.bin
2009-03-06 14:22 . 2005-08-16 10:18 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-04 09:49 . 2009-03-04 09:49 10618 ----a-w c:\windows\99z5spy416.exe
2009-03-03 00:18 . 2005-08-16 10:18 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-02 00:28 . 2009-03-02 00:28 13526 ----a-w c:\windows\5f58thief9809z.exe
2009-03-01 05:13 . 2009-03-01 05:13 16469 ----a-w c:\windows\system32\1e2t5iez9396.exe
2009-02-28 13:28 . 2009-02-28 13:28 6237 ----a-w c:\windows\system32\65f2bzckdoo93507.bin
2009-02-28 10:01 . 2009-02-28 10:01 17300 ----a-w c:\windows\system32\69cethief27z5.dll
2009-02-25 02:56 . 2009-02-25 02:56 8954 ----a-w c:\windows\system32\569ddownloadz9177.exe
2009-02-20 18:09 . 2005-08-16 10:18 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-18 00:54 . 2009-02-18 00:54 14097 ----a-w c:\windows\6z5f5ddwar93091.exe
2009-02-17 23:42 . 2009-02-17 23:42 5981 ----a-w c:\windows\22761tzoj9a25.bin
2009-02-16 17:36 . 2009-02-16 17:36 17330 ----a-w c:\windows\system32\1f2bbac9d5oz2043.exe
2006-06-19 21:05 . 2006-05-13 14:28 88 --sh--r c:\windows\system32\BE2FD993B9.sys
2006-01-05 23:38 . 2006-01-05 23:23 214722 --sha-w c:\windows\system32\vybeg.tmp
.
(((((((((((((((((((((((((((((
SnapShot@2009-05-16_20.00.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-16 20:49 . 2009-05-16 20:49 16384 c:\windows\temp\Perflib_Perfdata_780.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-31 50480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell QuickSet"="c:\progra~1\Dell\QuickSet\quickset.exe" [2005-09-01 684032]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-06-15 124656]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-12-7 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 ----a-w c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [6/15/2006 2:40 AM 115952]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 9:10 PM 101936]
--- Other Services/Drivers In Memory ---
*Deregistered* - SSDPSRV
*Deregistered* - Symantec AntiVirus
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - w32time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WLANKEEPER
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder
2009-04-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
www.aol.com/mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.htmluInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.comIE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Alexis Aiken\Start Menu\Programs\IMVU\Run IMVU.lnk
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-16 15:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3032532240-2312588317-637582772-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1092)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(2352)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\documents and settings\Alexis Aiken\My Documents\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-05-16 16:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-16 21:03
ComboFix2.txt 2009-05-16 20:10
Pre-Run: 4,314,927,104 bytes free
Post-Run: 3,726,856,192 bytes free
572 --- E O F --- 2009-04-18 13:03