(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 03:05 . 2009-03-19 00:58 -------- dc----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-02 02:04 . 2005-12-28 23:13 3558 -csha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-02 02:04 . 2005-12-28 23:13 56 -csh--r- c:\windows\system32\CDFA64DBDF.sys
2009-05-30 03:16 . 2005-12-08 02:45 -------- dc----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-30 03:16 . 2005-12-08 02:45 -------- dc----w- c:\documents and settings\All Users\Application Data\AOL
2009-05-30 03:16 . 2005-12-08 02:44 -------- dc----w- c:\program files\Common Files\AOL
2009-05-30 03:14 . 2005-12-28 23:47 -------- dc----w- c:\program files\AIM
2009-05-28 18:03 . 2009-03-03 01:10 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-26 17:20 . 2009-03-03 01:10 40160 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2009-03-03 01:10 19096 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-05-22 22:28 . 2006-07-07 01:43 -------- dc----w- c:\program files\Bethesda Softworks
2009-05-22 21:54 . 2008-08-18 21:06 -------- dc----w- c:\documents and settings\Josh Kelley\Application Data\U3
2009-05-20 05:05 . 2005-12-08 02:39 -------- dc----w- c:\program files\Java
2009-05-20 04:53 . 2006-01-19 23:59 -------- dc----w- c:\program files\Common Files\Adobe
2009-05-20 01:19 . 2006-02-01 23:25 -------- dc----w- c:\program files\iPod
2009-05-20 01:19 . 2007-07-04 01:36 -------- dc----w- c:\program files\Common Files\Apple
2009-05-20 01:18 . 2007-02-11 02:20 -------- dc----w- c:\program files\Bonjour
2009-05-20 01:03 . 2008-03-24 20:00 -------- dc----w- c:\program files\Safari
2009-05-19 21:52 . 2008-08-30 01:58 -------- dc----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-19 21:52 . 2008-08-30 01:58 -------- dc----w- c:\program files\Spybot - Search & Destroy
2009-05-17 15:26 . 2009-03-19 00:58 -------- dc----w- c:\documents and settings\Josh Kelley\Application Data\AVGTOOLBAR
2009-05-15 20:21 . 2009-02-22 00:50 -------- dc----w- c:\program files\Diablo II
2009-04-29 11:46 . 2009-04-29 11:46 -------- dc----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-04-29 11:31 . 2009-04-29 11:31 -------- dc----w- c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR
2009-04-25 03:15 . 2009-04-25 03:15 -------- dc----w- c:\documents and settings\Josh Kelley\Application Data\QuosaDDM
2009-03-19 20:32 . 2009-03-19 20:32 23400 -c--a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 -c--a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-08 08:34 . 2004-08-10 18:51 914944 -c--a-w- c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2004-08-10 18:51 43008 -c--a-w- c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2004-08-10 18:50 18944 -c--a-w- c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2004-08-10 18:51 420352 -c--a-w- c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2004-08-10 18:50 72704 -c--a-w- c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2004-08-10 18:51 71680 -c--a-w- c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2004-08-10 18:51 34816 -c--a-w- c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2004-08-10 18:51 48128 -c--a-w- c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2004-08-10 18:51 45568 -c--a-w- c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2004-08-10 18:51 156160 -c--a-w- c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-10 18:51 284160 -c--a-w- c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-15 148888]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 517768]
"ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2008-11-04 86016]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 106496]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [BU]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
PI Monitor.lnk - c:\program files\ArcSoft\PhotoImpression 5\PI Monitor.exe [2007-1-9 86016]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ruckus Player\\Ruckus.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/24/2007 7:15 PM 24652]
S2 WUSB54Gv42SVC;WUSB54Gv42SVC;c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [8/18/2008 5:08 PM 53307]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\kbt6e9da.default\
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-02 13:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,62,ec,86,bb,8c,b6,03,41,a1,a5,8d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,62,ec,86,bb,8c,b6,03,41,a1,a5,8d,\
[HKEY_USERS\S-1-5-21-2350805228-3028851994-2295997966-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,19,f4,28,60,3c,1d,c5,46,b8,4c,14,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,19,f4,28,60,3c,1d,c5,46,b8,4c,14,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1480)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
Completion time: 2009-06-02 13:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-02 17:16
ComboFix2.txt 2009-06-02 03:33
Pre-Run: 75,850,256,384 bytes free
Post-Run: 75,854,647,296 bytes free
298