.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 14:28 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-02 14:08 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-02 14:08 --------- d-----w c:\program files\SpywareBlaster
2008-12-02 13:11 90,112 ----a-w c:\windows\DUMP2c4f.tmp
2008-12-02 13:05 90,112 ----a-w c:\windows\DUMP4536.tmp
2008-12-02 12:46 90,112 ----a-w c:\windows\DUMP399e.tmp
2008-12-02 12:42 90,112 ----a-w c:\windows\DUMP3eed.tmp
2008-12-02 12:41 90,112 ----a-w c:\windows\DUMP38e2.tmp
2008-12-02 12:39 90,112 ----a-w c:\windows\DUMP3da5.tmp
2008-12-02 12:08 5,154,304 ----a-w c:\program files\WindowsDefender.msi
2008-12-02 10:12 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-02 05:09 --------- d-----w c:\program files\World of Warcraft
2008-12-01 15:28 --------- d-----w c:\program files\Java
2008-11-26 07:25 --------- d-----w c:\documents and settings\david\Application Data\Corel
2008-11-26 07:25 --------- d-----w c:\documents and settings\david\Application Data\Apple Computer
2008-11-26 07:25 --------- d-----w c:\documents and settings\david\Application Data\AdobeUM
2008-11-26 07:25 --------- d-----w c:\documents and settings\david\Application Data\AdobeAUM
2008-11-25 23:44 --------- d-----w c:\program files\Dell
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-21 20:25 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-20 06:47 --------- d-----w c:\program files\QuickTime
2008-10-20 06:46 --------- d-----w c:\program files\Common Files\Apple
2008-10-20 06:45 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-20 06:44 --------- d-----w c:\program files\Apple Software Update
2008-10-20 06:44 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-10-20 06:43 27,288,880 ----a-w c:\program files\QuickTimeInstaller.exe
2008-10-20 06:37 318,904 ----a-w c:\program files\wmpfirefoxplugin.exe
2008-10-16 21:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 21:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 21:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 21:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 21:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 21:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 21:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 21:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 21:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 21:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 16:34 337,408 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-14 22:21 --------- d-----w c:\documents and settings\All Users\Application Data\Blizzard
2008-10-06 10:31 0 ---ha-w c:\windows\system32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
2008-10-06 10:31 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2008-10-06 10:28 0 ---ha-w c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2008-10-06 06:49 --------- d-----w c:\program files\Zune
2008-10-04 09:30 --------- d-----w c:\program files\Common Files\Real
2008-10-04 06:00 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-04 04:35 1,144,400 ----a-w c:\program files\WoW-2.4.3.8568-to-3.0.2.8916-enUS-downloader.exe
2008-10-03 17:41 6,066,176 ----a-w c:\windows\system32\dllcache\ieframe.dll
2008-10-02 20:26 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-02 12:53 --------- d-----w c:\documents and settings\david\Application Data\HouseCall 6.6
2008-09-30 23:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\dllcache\win32k.sys
2008-09-13 01:48 245,664 ----a-w c:\windows\system32\ZuneWlanCfgSvc.exe
2008-09-13 01:46 61,856 ----a-w c:\windows\system32\ZuneBusEnum.exe
2008-09-13 01:32 73,216 ----a-w c:\windows\system32\ZuneUsbTransport.dll
2008-09-13 01:32 57,344 ----a-w c:\windows\system32\ZuneRegUtil.dll
2008-09-13 01:32 310,272 ----a-w c:\windows\system32\ZuneNetProxy.dll
2008-09-13 01:32 18,944 ----a-w c:\windows\system32\ZuneTcp2Udp.dll
2008-09-13 01:32 145,920 ----a-w c:\windows\system32\ZuneMTPZ.dll
2008-09-13 01:32 12,800 ----a-w c:\windows\system32\ZunePTDNS.dll
2008-09-11 10:39 7,520 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\dllcache\msxml6.dll
2008-09-10 01:14 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\dllcache\srv.sys
2008-09-06 06:23 508,411 ----a-w c:\program files\Decursive-2.2.0.zip
2008-09-05 11:47 1,206,366 ----a-w c:\program files\wrar371.exe
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\dllcache\msxml3.dll
2008-08-08 07:21 2,400,784 ----a-w c:\program files\WLinstaller.exe
2008-07-27 17:13 812,344 ----a-w c:\program files\HJTInstall.exe
2008-07-27 15:00 2,869,536 ----a-w c:\program files\spywareblastersetup41.exe
2008-07-27 14:54 19,153,264 ----a-w c:\program files\aaw2008.exe
2008-07-27 14:53 15,083,520 ----a-w c:\program files\spybotsd160.exe
.
((((((((((((((((((((((((((((( snapshot@2008-12-02_ 6.43.09.25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-02 10:59:10 64,200 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-02 13:42:23 64,200 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-02 10:59:20 407,670 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-02 13:42:23 407,670 ----a-w c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-01 136600]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 169984]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^david^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2008-07-29 23:59 344064 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2004-12-06 00:05 127035 c:\windows\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-09-29 13:01 67584 c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPsetm]
c:\documents and settings\david\Application Data\Google\ijdkq13324484.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
--a------ 2008-07-29 23:59 221184 c:\program files\Intel\Modem Event Monitor\IntelMEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2008-07-29 23:59 249856 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2008-07-29 23:59 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---hs---- 2008-04-13 17:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
--a------ 2008-07-08 16:41 2828184 c:\program files\Registry Mechanic\RegMech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB2Check]
--a------ 2004-04-06 19:05 61440 c:\windows\system32\PCLECoInst.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
--a------ 2008-09-12 18:46 160160 c:\program files\Zune\ZuneLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2008-07-30 00:00 339968 c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneWlanCfgSvc"=3 (0x3)
"ZuneNetworkSvc"=2 (0x2)
"ZuneBusEnum"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Alerter"=3 (0x3)
"Messenger"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:wow2
"6999:TCP"= 6999:TCP:gggg
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
S3 CV2K1;CommView Network Monitor;c:\windows\system32\DRIVERS\cv2k1.sys []
*Newly Created Service* - WINDEFEND
.
Contents of the 'Scheduled Tasks' folder
2008-11-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-12-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-USBToolTip - c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\david\Application Data\Mozilla\Firefox\Profiles\8cm2vhdb.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.myspace.comFF -: plugin - c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-02 07:36:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\aawservice]
"ImagePath"="\"c:\program files\Lavasoft\Ad-Aware\aawservice.exe\""
.
Completion time: 2008-12-02 7:39:04
ComboFix-quarantined-files.txt 2008-12-02 14:38:22
Pre-Run: 34,509,049,856 bytes free
Post-Run: 34,489,331,712 bytes free
367 --- E O F --- 2008-11-13 04:10:31