((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.
2009-06-07 22:18 . 2009-06-07 22:18 -------- d-sh--w- \$RECYCLE.BIN
2009-06-07 22:15 . 2009-06-07 22:18 -------- d-----w- c:\users\Ryan Wyatt\AppData\Local\temp
2009-06-07 22:15 . 2009-06-07 22:15 -------- d-----w- C:\temp
2009-06-07 22:15 . 2009-06-07 22:15 -------- d-----w- \temp
2009-06-07 22:11 . 2009-06-07 22:18 -------- d-s---w- \Combo-Fix
2009-06-07 20:05 . 2009-06-07 22:12 -------- d-----w- \Qoobox
2009-06-07 19:53 . 2009-06-07 19:53 -------- d-----w- c:\program files\Trend Micro
2009-06-07 19:16 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-07 19:16 . 2009-06-07 19:16 -------- d-----w- c:\programdata\Malwarebytes
2009-06-07 19:16 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-27 12:28 . 2009-05-27 12:29 34 ----a-w- c:\users\Ryan Wyatt\jagex_runescape_preferences.dat
2009-05-27 12:28 . 2009-05-27 12:30 -------- d-----w- C:\.jagex_cache_32
2009-05-27 12:28 . 2009-05-27 12:30 -------- d-----w- \.jagex_cache_32
2009-05-10 16:44 . 2009-03-19 20:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-10 16:44 . 2008-04-17 16:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-05-10 16:44 . 2009-05-10 16:44 -------- d-----w- c:\program files\iPod
2009-05-10 16:44 . 2009-06-07 18:16 -------- d-----w- c:\program files\iTunes
2009-05-10 16:44 . 2009-05-10 16:44 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-10 16:39 . 2009-05-10 16:39 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 22:16 . 2008-09-07 05:05 3208683520 --sha-w- \hiberfil.sys
2009-06-07 22:16 . 2008-07-27 04:27 3524546560 --sha-w- \pagefile.sys
2009-06-07 19:57 . 2008-11-15 22:00 -------- d-----w- c:\users\Ryan Wyatt\AppData\Roaming\DNA
2009-06-07 19:13 . 2008-02-22 10:32 672380 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-07 19:13 . 2008-02-22 10:32 127578 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-07 19:07 . 2008-12-07 19:21 5648 ----a-w- c:\users\Ryan Wyatt\AppData\Local\d3d9caps.dat
2009-06-07 18:16 . 2009-01-11 18:04 -------- d-----w- c:\program files\WinSCP
2009-06-07 18:16 . 2008-09-06 21:07 -------- d-----w- c:\program files\Common Files\LightScribe
2009-06-07 18:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-06-07 18:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-06-07 18:16 . 2009-03-21 06:47 -------- d-----w- c:\program files\Bonjour
2009-06-07 18:16 . 2008-07-27 04:43 -------- d-----w- c:\program files\Apoint2K
2009-05-10 16:44 . 2008-10-12 20:26 -------- d-----w- c:\program files\Common Files\Apple
2009-04-23 01:46 . 2009-04-23 01:46 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-04-18 20:24 . 2009-04-11 19:20 -------- d-----w- c:\program files\PokerStars.NET
2009-03-22 17:48 . 2009-03-22 17:40 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-03-19 20:32 . 2009-03-19 20:32 23400 ----a-w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-07_20.21.11 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-06 23:55 . 2009-03-15 01:03 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-06 23:55 . 2009-06-07 21:57 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-06 23:55 . 2009-03-15 01:03 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-06 23:55 . 2009-06-07 21:57 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-06 23:55 . 2009-03-15 01:03 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-06 23:55 . 2009-06-07 21:57 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 02:24 . 2008-01-21 02:24 9728 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\lsass.exe
+ 2009-06-07 22:16 . 2009-06-07 22:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-06-07 20:20 . 2009-06-07 20:20 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-07 22:16 . 2009-06-07 22:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-01-21 02:24 . 2008-01-21 02:24 441400 c:\windows\winsxs\x86_microsoft-windows-lsa_31bf3856ad364e35_6.0.6001.18215_none_a644c0145ccecd28\ksecdd.sys
+ 2008-09-06 23:58 . 2009-06-07 22:15 119240 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2006-11-02 10:22 . 2009-06-07 22:16 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-04-05 20:33 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-06-07 22:12 . 2009-06-07 22:12 6328320 c:\windows\ERDNT\Hiv-backup\schema.dat
+ 2008-02-08 06:54 . 2009-06-07 20:34 100161884 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-06 39408]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-02 1783136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-28 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-28 137752]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-06-30 159744]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-20 468264]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-12-06 202032]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-22 148888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1115059687-4206018883-815105962-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DBB1980F-B43B-4F6F-A8BC-8368F659B6B3}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{C5FC5CF4-94D2-4A9C-A03B-2C4090AE5219}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{5D496620-6886-42D4-96FA-75EAE7E4FEB1}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E6D4A71A-174F-45E9-9908-B0EC464DE667}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{8BFBDBCE-C215-44A8-8416-1C0520349372}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{23E14C05-75AD-4956-90BB-5AA8B098B6E7}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8A47A03B-C727-429B-BD2E-7AD81D693181}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{74283465-2ED3-489F-9F6E-4830CFE3BF6D}c:\\program files\\air mouse\\air mouse\\air mouse.exe"= UDP:c:\program files\air mouse\air mouse\air mouse.exe:AirMouse
"UDP Query User{BACD740D-DC59-445B-BF0B-DFFE4496B14C}c:\\program files\\air mouse\\air mouse\\air mouse.exe"= TCP:c:\program files\air mouse\air mouse\air mouse.exe:AirMouse
"TCP Query User{683382EB-3C2D-4855-8F95-E20E73C741D5}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"{C5BC1BE2-3D33-40BC-B77A-CF132B641E68}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B20F5C8B-D8AE-46B0-B97E-E4DBFCC8C8C6}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{ADE786F8-2C76-4893-87CC-D492EC101B54}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{161D05A3-05D9-41F0-9EE9-B3BFCCFAC399}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-06-07 c:\windows\Tasks\User_Feed_Synchronization-{CB602B6E-5D7E-4468-9E4C-DBC233FA4B27}.job
- c:\windows\system32\msfeedssync.exe [2009-04-05 10:01]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Presario&pf=laptopuInternet Settings,ProxyOverride = *.local
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-07 18:18
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4736)
c:\program files\WinSCP\DragExt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\System32\conime.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Apoint2K\ApMsgFwd.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Apoint2K\ApntEx.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\windows\System32\Macromed\Flash\FlashUtil10a.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-06-07 18:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-07 22:24
ComboFix2.txt 2009-06-07 20:31
Pre-Run: 73,663,045,632 bytes free
Post-Run: 73,355,427,840 bytes free
372 --- E O F --- 2009-06-07 20:35