((((((((((((((((((((((((( Files Created from 2009-09-03 to 2009-10-03 )))))))))))))))))))))))))))))))
.
2009-09-23 02:32 . 2009-09-23 02:32 -------- d-----w- c:\documents and settings\whos the b**** now\WINDOWS
2009-09-15 02:28 . 2009-09-15 02:28 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-09-14 19:45 . 2009-09-14 19:45 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-09-03 19:07 . 2009-09-03 19:07 30720 ----a-w- c:\windows\system32\7EE983E52D57964A.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-03 00:54 . 2009-08-16 16:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-02 20:23 . 2003-12-03 15:57 -------- d-----w- c:\program files\Steam
2009-09-23 03:13 . 2006-12-19 00:31 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-15 21:37 . 2009-08-21 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-12 03:24 . 2009-06-02 21:58 -------- d-----w- c:\program files\uTorrent
2009-09-10 18:54 . 2009-08-19 01:51 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 01:32 . 2009-08-08 02:00 -------- d-----w- c:\documents and settings\whos the b**** now\Application Data\Vso
2009-09-09 07:20 . 2009-07-15 00:55 -------- d-----w- c:\documents and settings\whos the b**** now\Application Data\uTorrent
2009-09-03 01:38 . 2009-09-03 01:38 -------- d-----w- c:\documents and settings\whos the b**** now\Application Data\AdobeUM
2009-09-02 15:39 . 2009-09-02 15:39 43008 ----a-w- c:\windows\system32\lupgh.dll
2009-08-23 16:43 . 2009-08-23 15:05 53760 ----a-w- c:\windows\system32\drivers\WZSZXserv.sys
2009-08-23 01:06 . 2009-08-23 01:06 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
2009-08-23 01:02 . 2009-08-23 01:02 -------- d-----w- c:\program files\SlySoft
2009-08-23 00:57 . 2009-08-23 00:57 -------- d-----w- c:\program files\Plato DVD to AVI Converter
2009-08-22 20:26 . 2009-08-22 20:26 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-08-22 20:26 . 2009-08-22 20:26 -------- d-----w- c:\program files\Zone Labs
2009-08-21 20:57 . 2009-08-21 20:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-21 20:57 . 2009-08-21 20:57 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-21 20:57 . 2009-08-21 20:57 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-21 20:57 . 2009-08-21 20:57 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-21 20:57 . 2009-08-21 20:57 -------- d-----w- c:\program files\AVG
2009-08-21 20:48 . 2007-04-06 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-21 20:28 . 2009-08-21 20:28 -------- d-----w- c:\documents and settings\whos the b**** now\Application Data\AVG8
2009-08-21 18:52 . 2009-08-15 02:50 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-08-19 20:51 . 2009-08-19 20:52 389120 ----a-w- c:\windows\system32\CF7512.exe
2009-08-19 20:48 . 2009-08-19 20:49 389120 ----a-w- c:\windows\system32\CF6937.exe
2009-08-19 20:45 . 2009-08-19 20:45 389120 ----a-w- c:\windows\system32\CF6238.exe
2009-08-19 20:35 . 2009-08-19 20:36 389120 ----a-w- c:\windows\system32\CF4364.exe
2009-08-19 20:33 . 2009-08-19 20:33 389120 ----a-w- c:\windows\system32\CF3877.exe
2009-08-19 20:32 . 2009-08-19 20:32 389120 ----a-w- c:\windows\system32\CF3655.exe
2009-08-19 20:30 . 2009-08-19 20:31 389120 ----a-w- c:\windows\system32\CF3404.exe
2009-08-19 20:26 . 2009-08-19 20:26 389120 ----a-w- c:\windows\system32\CF2535.exe
2009-08-19 20:13 . 2009-08-19 20:13 389120 ----a-w- c:\windows\system32\CF1.exe
2009-08-19 20:02 . 2009-08-19 20:03 389120 ----a-w- c:\windows\system32\CF30656.exe
2009-08-19 20:01 . 2009-08-19 20:01 389120 ----a-w- c:\windows\system32\CF30310.exe
2009-08-19 19:59 . 2009-08-19 19:59 389120 ----a-w- c:\windows\system32\CF30013.exe
2009-08-19 19:55 . 2009-08-19 19:55 389120 ----a-w- c:\windows\system32\CF29271.exe
2009-08-19 19:54 . 2009-08-19 19:55 389120 ----a-w- c:\windows\system32\CF29124.exe
2009-08-19 19:51 . 2009-08-19 19:52 389120 ----a-w- c:\windows\system32\CF28530.exe
2009-08-19 19:50 . 2009-08-19 19:50 389120 ----a-w- c:\windows\system32\CF28239.exe
2009-08-19 13:52 . 2003-12-03 01:50 -------- d-----w- c:\program files\Trend Micro
2009-08-19 13:49 . 2009-08-19 13:49 389120 ----a-w- c:\windows\system32\CF23033.exe
2009-08-19 13:26 . 2009-08-19 13:26 389120 ----a-w- c:\windows\system32\CF18543.exe
2009-08-19 13:25 . 2009-08-19 13:25 389120 ----a-w- c:\windows\system32\CF18341.exe
2009-08-19 13:23 . 2009-08-19 13:24 389120 ----a-w- c:\windows\system32\CF18037.exe
2009-08-19 12:47 . 2009-08-19 12:47 389120 ----a-w- c:\windows\system32\CF10830.exe
2009-08-19 12:44 . 2009-08-19 12:44 389120 ----a-w- c:\windows\system32\CF10222.exe
2009-08-19 03:54 . 2009-08-19 03:55 389120 ----a-w- c:\windows\system32\CF4805.exe
2009-08-19 03:41 . 2009-08-19 03:41 -------- d-----w- c:\documents and settings\whos the b**** now\Application Data\Malwarebytes
2009-08-19 02:18 . 2009-08-19 02:19 389120 ----a-w- c:\windows\system32\CF18796.exe
2009-08-19 02:18 . 2009-08-19 02:18 389120 ----a-w- c:\windows\system32\CF18662.exe
2009-08-19 02:05 . 2009-08-19 02:05 389120 ----a-w- c:\windows\system32\CF16229.exe
2009-08-19 01:41 . 2009-08-19 01:41 389120 ----a-w- c:\windows\system32\CF11429.exe
2009-08-16 16:23 . 2009-08-16 16:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-16 02:35 . 2004-01-28 15:26 -------- d-----w- c:\program files\Yahoo!
2009-08-16 02:20 . 2008-03-14 05:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-08-15 02:51 . 2009-08-15 02:51 -------- d-----w- c:\documents and settings\whos the b**** now\Application Data\AVS4YOU
2009-08-13 07:04 . 2007-09-21 03:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-11 03:48 . 2009-08-11 03:48 -------- d-----w- c:\documents and settings\whos the b**** now\Application Data\Media Player Classic
2009-08-08 16:31 . 2009-08-08 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk
2009-08-08 02:00 . 2009-08-08 02:00 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-08-08 02:00 . 2009-08-08 02:00 47360 ----a-w- c:\documents and settings\whos the b**** now\Application Data\pcouffin.sys
2009-08-08 02:00 . 2009-08-08 02:00 -------- d-----w- c:\program files\VSO
2009-08-08 01:15 . 2009-08-08 01:15 -------- d-----w- c:\documents and settings\whos the b**** now\Application Data\Ahead
2009-08-05 18:01 . 2009-08-05 18:01 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-08-05 16:20 . 2009-06-24 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\myitlab
2009-08-05 09:01 . 2005-12-30 16:08 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 17:36 . 2009-08-19 01:51 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-02 16:04 . 2009-07-11 15:18 78200 ----a-w- c:\documents and settings\whos the b**** now\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-17 19:01 . 2003-03-31 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 18:54 . 2009-07-24 15:13 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-07-14 18:54 . 2009-07-24 15:13 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-07-14 18:54 . 2009-07-24 15:13 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-07-14 18:54 . 2009-07-24 15:13 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-07-14 18:54 . 2007-03-28 05:37 485920 -c--a-w- c:\windows\system32\nvudisp.exe
2009-07-14 18:54 . 2006-10-22 16:22 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-07-14 18:54 . 2006-10-22 16:22 7741664 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-07-14 18:54 . 2006-10-22 16:22 5842816 ----a-w- c:\windows\system32\nv4_disp.dll
2009-07-14 18:54 . 2006-10-22 16:22 151552 ----a-w- c:\windows\system32\nvcodins.dll
2009-07-14 18:54 . 2006-10-22 16:22 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-07-14 18:54 . 2006-10-22 16:22 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-07-14 17:35 . 2009-07-14 17:35 2173472 ----a-w- c:\windows\system32\nvcplui.exe
2009-07-14 17:35 . 2009-07-14 17:35 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-07-14 17:35 . 2009-07-14 17:35 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-07-14 17:35 . 2009-07-14 17:35 3170304 ----a-w- c:\windows\system32\nvwss.dll
2009-07-14 17:34 . 2009-07-14 17:34 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-07-14 17:34 . 2009-07-14 17:34 4923392 ----a-w- c:\windows\system32\nvdisps.dll
2009-07-14 17:34 . 2009-07-14 17:34 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-07-14 17:34 . 2009-07-14 17:34 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-07-14 17:34 . 2009-07-14 17:34 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-07-14 17:34 . 2009-07-14 17:34 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-07-14 17:34 . 2009-07-14 17:34 13877248 ----a-w- c:\windows\system32\nvcpl.dll
2009-07-14 17:34 . 2009-07-14 17:34 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-07-14 17:34 . 2009-07-14 17:34 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-07-14 03:43 . 2004-04-06 11:29 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 22:18 . 2009-05-08 06:48 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2009-07-10 11:01 . 2007-03-28 05:24 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-13 16:27 . 2006-02-09 18:04 5632 -csha-w- c:\program files\Thumbs.db
2000-06-05 21:47 . 2007-09-17 07:05 32768 -c--a-w- c:\program files\mozilla firefox\plugins\AppSub32.dll
.
------- Sigcheck -------
[7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\eventlog.dll
[7] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
c:\windows\system32\eventlog.dll ... is missing !!
c:\windows\system32\ctfmon.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTStartup"="c:\program files\Creative\Splash Screen\CTEaxSpl.EXE" [2001-12-20 28672]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-07-09 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-14 13877248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-21 2007832]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]
"7EE983E52D57964A"="c:\windows\system32\7EE983E52D57964A.exe" [2009-09-03 30720]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-21 20:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^OneNote Table Of Contents.onetoc2]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2
backup=c:\windows\pss\OneNote Table Of Contents.onetoc2Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_04\\bin\\javaw.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Steam\\SteamApps\\bongreaper\\counter-strike\\hl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\SteamApps\\bongreaper\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\mIRC2\\mirc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5100:TCP"= 5100:TCP:*:Disabled:webcam.yahoo.com
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/21/2009 4:57 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/21/2009 4:57 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/21/2009 4:57 PM 297752]
R2 NProtectService;Norton Unerase Protection;c:\program files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE [1/19/2006 2:18 PM 135168]
S1 65ef9f3e;65ef9f3e;c:\windows\system32\drivers\65ef9f3e.sys --> c:\windows\system32\drivers\65ef9f3e.sys [?]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [7/10/2009 6:12 PM 99352]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [7/10/2009 6:12 PM 99352]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [7/10/2009 6:19 PM 79360]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [7/10/2009 6:12 PM 555032]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [7/10/2009 6:12 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [7/10/2009 6:12 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [7/10/2009 6:12 PM 100888]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [7/10/2009 6:12 PM 566296]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [7/10/2009 6:12 PM 566296]
S4 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe --> c:\program files\AskBarDis\bar\bin\AskService.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {5445BE81-B796-11D2-B931-002018654E2E} -
hxxp://support.cengage.com/system/web/view/live/messaging/ie/SecMgr.cabFF - ProfilePath - c:\documents and settings\whos the b**** now\Application Data\Mozilla\Firefox\Profiles\t38hce12.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.comFF - prefs.js: keyword.URL -
hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NpIpx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\