ComboFix 08-10-21.05 - TheOnlyBigDog 2008-10-22 9:46:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1576 [GMT -7:00]
Running from: C:\Documents and Settings\TheOnlyBigDog\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\TheOnlyBigDog\Application Data\inst.exe
C:\WINDOWS\21794.exe
C:\WINDOWS\system32\cmqlcfgc.exe
C:\WINDOWS\system32\dpvpbxep.ini
C:\WINDOWS\system32\swsguhab.exe
C:\WINDOWS\system32\TCKmTvut.ini
C:\WINDOWS\system32\TCKmTvut.ini2
C:\WINDOWS\system32\tmmuveub.ini
C:\WINDOWS\system32\vfcrcgmf.ini
C:\WINDOWS\system32\WwxIlnmp.ini
C:\WINDOWS\system32\WwxIlnmp.ini2
M:\autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-09-22 to 2008-10-22 )))))))))))))))))))))))))))))))
.
2008-10-20 15:04 . 2008-10-20 15:04 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-20 11:18 . 2008-10-20 11:18 153 --a------ C:\WINDOWS\wininit.ini
2008-10-19 12:35 . 2008-10-19 12:36 <DIR> d-------- C:\Program Files\Galleon 3D Screensaver
2008-10-19 12:26 . 2008-10-19 12:26 <DIR> d-------- C:\Program Files\Ancient Castle 3D Screensaver
2008-10-18 22:25 . 2008-10-19 18:22 0 --a------ C:\FileOut.Cns
2008-10-18 22:25 . 2008-10-19 18:22 0 --a------ C:\FileIn.Cns
2008-10-17 22:58 . 2008-10-17 22:58 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-10-17 22:57 . 2008-10-17 22:57 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-10-14 14:56 . 2008-10-14 15:09 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Contacts
2008-10-14 14:46 . 2008-10-14 14:46 <DIR> d-------- C:\Program Files\Windows Live Favorites
2008-10-14 14:46 . 2008-10-14 14:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-10-14 14:45 . 2008-10-14 14:46 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-10-14 14:44 . 2008-10-14 14:44 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-10-14 14:44 . 2008-10-14 14:44 <DIR> d-------- C:\Program Files\MSN Messenger
2008-10-14 12:12 . 2008-10-14 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-10-14 12:03 . 2008-10-14 12:03 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\Yahoo!
2008-10-14 12:03 . 2008-10-14 12:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-14 12:02 . 2008-10-14 12:12 <DIR> d-------- C:\Program Files\Yahoo!
2008-10-13 00:43 . 2008-10-13 00:43 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\EAST Technologies
2008-10-13 00:42 . 2008-10-13 00:42 <DIR> d-------- C:\Program Files\East-Tec Eraser 2008
2008-10-10 19:00 . 2005-06-15 03:00 102,400 --a------ C:\WINDOWS\system32\tsccvid.dll
2008-10-10 18:59 . 2008-10-10 19:02 <DIR> d-------- C:\Program Files\eXtreme Movie Manager
2008-10-10 18:59 . 2000-05-21 23:00 1,009,336 --a------ C:\WINDOWS\system32\Mschrt20.ocx
2008-10-10 18:56 . 2008-10-10 18:56 <DIR> d-------- C:\Program Files\Cucusoft
2008-10-10 18:52 . 2008-10-10 18:52 <DIR> d-------- C:\Program Files\Deskshare
2008-10-10 18:52 . 2008-10-10 18:52 352,256 --a------ C:\WINDOWS\eSellerateEngine.dll
2008-10-09 17:07 . 2008-06-23 09:57 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-10-09 17:07 . 2007-04-17 02:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-10-09 17:07 . 2007-03-07 22:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-10-09 17:07 . 2008-06-23 09:57 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-10-09 17:07 . 2008-06-23 09:57 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-10-09 17:07 . 2008-06-23 09:57 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-10-09 17:07 . 2008-06-23 09:57 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-10-09 17:07 . 2008-06-23 09:57 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-10-09 17:07 . 2008-06-23 02:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-10-05 02:32 . 2008-10-17 20:02 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\settingsbytewindow
2008-10-05 02:32 . 2008-10-05 10:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Drv Audio Dog About
2008-10-04 00:15 . 2008-10-04 00:15 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-10-03 12:49 . 2008-10-05 10:22 <DIR> d-------- C:\Program Files\NOS
2008-10-03 12:49 . 2008-10-05 10:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NOS
2008-10-03 12:33 . 2008-10-07 12:09 <DIR> d-------- C:\Program Files\LimeWire
2008-10-03 12:33 . 2008-10-07 12:09 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\LimeWire
2008-09-29 09:31 . 2008-09-29 09:31 <DIR> d--h----- C:\WINDOWS\PIF
2008-09-28 19:08 . 2008-09-28 19:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-28 01:23 . 2008-04-13 11:45 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-09-28 01:23 . 2008-04-13 11:45 32,128 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-09-27 09:00 . 2008-09-27 09:00 3,568,756 --a------ C:\WINDOWS\system32\xa107106953.exe
2008-09-27 09:00 . 2008-09-27 09:00 3,568,756 --a------ C:\WINDOWS\system32\xa107106593.exe
2008-09-27 09:00 . 2008-09-27 09:00 172,032 --a------ C:\WINDOWS\system32\xwr12179.dll
2008-09-27 09:00 . 2008-09-27 09:00 172,032 --a------ C:\WINDOWS\system32\wr12179.dll
2008-09-27 08:48 . 2008-09-27 08:48 <DIR> d-------- C:\Program Files\Act-3D
2008-09-27 08:48 . 2008-09-27 08:48 2,825,407 --a------ C:\WINDOWS\system32\xa106367609.exe
2008-09-27 08:48 . 2008-09-27 08:48 2,825,407 --a------ C:\WINDOWS\system32\xa106367328.exe
2008-09-27 08:48 . 2008-09-27 08:48 172,032 --a------ C:\WINDOWS\system32\xwr84718.dll
2008-09-27 08:48 . 2008-09-27 08:48 172,032 --a------ C:\WINDOWS\system32\wr84718.dll
2008-09-27 08:44 . 2008-09-27 09:01 <DIR> d-------- C:\Program Files\thriXXX
2008-09-27 08:44 . 2008-09-27 08:44 28,962,712 --a------ C:\WINDOWS\system32\xa106137906.exe
2008-09-27 08:44 . 2008-09-27 08:44 28,962,712 --a------ C:\WINDOWS\system32\xa106137328.exe
2008-09-27 08:44 . 2008-09-27 08:44 28,962,712 --a------ C:\WINDOWS\system32\xa106131421.exe
2008-09-27 08:44 . 2008-09-27 08:44 28,962,712 --a------ C:\WINDOWS\system32\xa106124546.exe
2008-09-27 08:44 . 2008-09-27 08:44 172,032 --a------ C:\WINDOWS\system32\xwr47437.dll
2008-09-27 08:44 . 2008-09-27 08:44 172,032 --a------ C:\WINDOWS\system32\wr47437.dll
2008-09-26 19:10 . 2008-09-26 19:10 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\Jasc
2008-09-26 19:08 . 2008-09-26 19:08 <DIR> d-------- C:\Program Files\Jasc Software Inc
2008-09-26 19:03 . 2008-09-26 19:03 80 -r-hs---- C:\WINDOWS\ICSET20.BIN
2008-09-26 18:21 . 2008-09-26 18:21 <DIR> d-------- C:\Program Files\MagicISO
2008-09-26 17:07 . 2008-09-26 19:02 <DIR> d-------- C:\Program Files\Reallusion
2008-09-26 17:07 . 2008-09-26 17:07 80 -r-hs---- C:\WINDOWS\CT5PRET.BIN
2008-09-26 17:05 . 2008-09-26 17:05 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\InstallShield
2008-09-26 17:03 . 2008-09-26 17:04 <DIR> d-------- C:\Program Files\Digital Photo Software
2008-09-26 17:03 . 2008-10-17 10:44 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-26 10:36 . 2008-09-21 18:52 7,336,328 --a------ C:\WINDOWS\40175.exe
2008-09-26 04:57 . 2008-09-26 04:57 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\Reallusion
2008-09-26 03:05 . 2008-09-26 03:05 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-26 01:22 . 2008-09-26 01:22 <DIR> d-------- C:\Program Files\ALCATech
2008-09-26 00:27 . 2008-09-26 00:27 <DIR> d-------- C:\Program Files\QuickTime
2008-09-26 00:27 . 2008-09-26 00:27 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-26 00:27 . 2008-09-26 00:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-26 00:26 . 2008-09-26 00:26 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-26 00:26 . 2008-09-26 00:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-25 14:54 . 2008-09-25 14:54 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\LocalLow
2008-09-25 14:54 . 2008-09-25 14:54 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\TVU Networks
2008-09-25 14:54 . 2008-09-25 14:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-09-25 14:43 . 2008-09-25 14:43 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-25 13:34 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-25 13:34 . 2008-07-18 22:07 210,976 --a------ C:\WINDOWS\system32\muweb.dll
2008-09-25 13:34 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-25 10:36 . 2008-10-09 13:24 47 --a------ C:\WINDOWS\popcinfo.dat
2008-09-25 10:32 . 2008-09-25 10:47 <DIR> d-------- C:\Program Files\PopCap Games
2008-09-25 10:32 . 2000-12-08 21:59 122,880 --a------ C:\WINDOWS\UnGins.exe
2008-09-25 10:23 . 2008-09-25 10:24 <DIR> d-------- C:\Program Files\Microsoft Expression
2008-09-25 10:17 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-09-25 10:16 . 2008-09-25 10:16 <DIR> d-------- C:\Program Files\MSBuild
2008-09-25 10:16 . 2008-09-25 10:16 <DIR> d-------- C:\Program Files\Microsoft Works
2008-09-25 10:15 . 2008-09-25 10:15 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-09-25 10:14 . 2008-10-17 23:02 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-09-25 10:14 . 2008-09-25 10:14 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-09-25 10:14 . 2008-10-18 14:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-25 10:13 . 2008-09-25 10:13 <DIR> dr-h----- C:\MSOCache
2008-09-25 01:33 . 2008-09-25 01:33 <DIR> d-------- C:\Program Files\Musicmatch
2008-09-25 01:33 . 2008-09-25 01:33 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\Musicmatch
2008-09-25 01:33 . 2006-01-19 12:05 108,544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-09-25 01:33 . 2006-01-19 12:05 104,960 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-09-24 10:25 . 2008-09-24 10:25 0 --a------ C:\WINDOWS\WB.ini
2008-09-24 09:18 . 2008-09-24 09:23 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\Stardock
2008-09-24 09:18 . 2008-09-24 09:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Stardock
2008-09-24 09:14 . 2008-04-26 16:14 42,672 --a------ C:\WINDOWS\system32\wbsys.dll
2008-09-24 09:13 . 2008-09-24 09:32 <DIR> d-------- C:\Program Files\Stardock
2008-09-24 09:13 . 2008-09-24 17:24 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-09-23 16:09 . 2008-09-23 16:18 <DIR> d-------- C:\Program Files\CompuHost
2008-09-23 14:59 . 2008-09-23 14:59 <DIR> d-------- C:\Program Files\MagicDVDCopier
2008-09-23 14:59 . 2008-09-23 14:59 <DIR> d-------- C:\Documents and Settings\TheOnlyBigDog\Application Data\Vso
2008-09-23 14:59 . 2008-09-23 14:59 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-09-23 14:59 . 2008-09-23 14:59 47,360 --a------ C:\Documents and Settings\TheOnlyBigDog\Application Data\pcouffin.sys
2008-09-23 14:53 . 2008-09-23 14:53 <DIR> d-------- C:\Program Files\MagicDVDRipper
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-21 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-20 18:11 --------- d-----w C:\Program Files\BitTorrent
2008-10-20 06:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-10-20 00:20 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-10-20 00:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-20 00:19 --------- d-----w C:\Program Files\Macromedia
2008-10-18 22:41 --------- d-----w C:\Program Files\Gateway151 Karaoke Zip Player
2008-10-18 21:17 --------- d-----w C:\Program Files\MP3 WAV Converter
2008-10-18 20:01 --------- d-----w C:\Program Files\Winamp
2008-10-18 07:49 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\U3
2008-10-14 06:05 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\Ahead
2008-10-10 00:15 --------- d-----w C:\Program Files\Norton AntiVirus
2008-10-05 17:20 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-03 19:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Babylon
2008-10-03 08:20 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\Babylon
2008-09-30 06:08 --------- d-----w C:\Program Files\Kjpro
2008-09-25 00:25 --------- d-----w C:\Program Files\Eraser
2008-09-20 01:47 --------- d-----w C:\Program Files\Debs Karaoke Renamer
2008-09-20 01:47 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\Debs Karaoke Renamer
2008-09-20 01:40 --------- d-----w C:\Program Files\Gateway151 File-2-Folder
2008-09-20 01:29 --------- d-----w C:\Program Files\Java
2008-09-20 01:28 --------- d-----w C:\Program Files\Common Files\Java
2008-09-18 05:03 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-09-18 05:03 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-17 09:28 --------- d-----w C:\Program Files\Doblon
2008-09-16 22:56 --------- d-----w C:\Program Files\Karaoke Zip Scanner
2008-09-15 18:32 --------- d-----w C:\Program Files\Access 97 Runtime
2008-09-14 19:08 --------- d-----w C:\Program Files\Damar Systems
2008-09-14 00:49 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\AdobeUM
2008-09-14 00:11 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ
2008-09-13 23:29 --------- d-----w C:\Program Files\Mp3+G Toolz
2008-09-13 18:17 --------- d-----w C:\Program Files\Sax & Dottys Karaoke Zip Player
2008-09-13 09:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-13 03:06 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\Paltalk
2008-09-13 03:05 --------- d-----w C:\Program Files\Paltalk Messenger
2008-09-12 21:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Macrovision
2008-09-12 20:46 --------- d-----w C:\Program Files\Common Files\Macromedia Shared
2008-09-12 20:45 --------- d-----w C:\Program Files\Common Files\Vbox
2008-09-12 20:45 --------- d-----w C:\Program Files\Bradbury
2008-09-12 19:51 --------- d-----w C:\Program Files\MySurvey Messenger
2008-09-11 23:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-11 23:16 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-09-11 23:16 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-11 23:16 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\SUPERAntiSpyware.com
2008-09-11 23:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-11 05:48 --------- d-----w C:\Program Files\KJ Pro
2008-09-11 05:46 --------- d-----w C:\Program Files\Microsoft Access Runtime
2008-09-11 05:46 --------- d-----w C:\Program Files\Common Files\Damar Systems
2008-09-11 05:37 --------- d-----w C:\Program Files\Common Files\Doblon
2008-09-11 04:32 --------- d-----w C:\Program Files\Common Files\Ahead
2008-09-11 04:31 --------- d-----w C:\Program Files\Nero
2008-09-11 04:28 --------- d-----w C:\Program Files\Ahead
2008-09-10 23:06 --------- d-----w C:\Program Files\The_Pirate_Bay
2008-09-10 09:58 --------- d-----w C:\Program Files\myBabylon
2008-09-10 09:58 --------- d-----w C:\Program Files\Conduit
2008-09-10 09:58 --------- d-----w C:\Program Files\Babylon
2008-09-10 09:44 --------- d-----w C:\Program Files\Google
2008-09-10 09:41 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\NeroVision
2008-09-10 09:37 --------- d-----w C:\Program Files\DVD Shrink
2008-09-10 09:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-09-10 09:33 --------- d-----w C:\Program Files\CDRWIN3
2008-09-10 09:09 --------- d-----w C:\Program Files\RoxBox
2008-09-10 09:06 --------- d-----w C:\Program Files\Common Files\cdrdao
2008-09-10 08:45 --------- d-----w C:\Program Files\CAVS
2008-09-10 08:41 --------- d-----w C:\Program Files\Common Files\Borland Shared
2008-09-10 08:41 --------- d-----w C:\Program Files\CD+G AutoName
2008-09-10 08:40 --------- d-----w C:\Program Files\WinCDG Pro 2
2008-09-10 08:37 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-09-10 08:33 --------- d-----w C:\Program Files\Micro Technology Unlimited
2008-09-10 08:25 --------- d-----w C:\Program Files\Gaa Moa's Plugins for Cool Edit Pro
2008-09-10 08:25 --------- d-----w C:\Program Files\coolpro2
2008-09-10 08:23 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\Syntrillium
2008-09-09 21:36 --------- d-----w C:\Program Files\MP3+G Toolz .NET
2008-09-09 09:37 --------- d-----w C:\Program Files\Winamp Toolbar
2008-09-09 09:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-09-09 09:27 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Symantec
2008-09-09 08:53 --------- d-----w C:\Program Files\SymNetDrv
2008-09-09 08:53 --------- d-----w C:\Program Files\Symantec
2008-09-09 08:44 4,608 ----a-w C:\WINDOWS\system32\drivers\symlcbrd.sys
2008-09-09 08:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-09-09 08:31 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\Symantec
2008-09-09 08:20 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-09-09 08:20 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-09 08:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-09-08 23:00 --------- d-----w C:\Program Files\MSI
2008-09-08 22:48 --------- d-----w C:\Documents and Settings\TheOnlyBigDog\Application Data\Creative
2008-09-08 22:40 --------- d-----w C:\Program Files\Creative
2008-09-08 21:46 --------- d-----w C:\Program Files\microsoft frontpage
.
Code:
<pre>
----a-w 6,596,329 2002-02-17 21:02:02 C:\Need to Edit\Programs To Check\PROGRAMS 2\Apps-Programs-Utilities\cd+g_autoname_v1_0_full_\CD+G AutoName v1_0 Full .exe
----a-w 6,596,329 2002-02-17 20:02:02 C:\unzipped\cd+g_autoname_v1_0_full_\CD+G AutoName v1_0 Full .exe
----a-w 23,510,720 2007-12-12 00:59:50 C:\unzipped\Microsoft .NET Framework Version 2.0\Microsoft .NET Framework Version 2.0 Redistributable Package (x86)\Microsoft .NET Framework Version 2.0 .exe
----a-w 7,608,700 2003-03-08 08:09:06 C:\unzipped\traktor_studio_mixer_best_dj_software_ever_\TRAKTOR STUDIO MIXER BEST DJ SOFTWARE EVER .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
"CursorFX"="C:\Program Files\Stardock\CursorFX\CursorFX.exe" [2008-07-07 416768]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-10 39408]
"Messenger (Yahoo!)"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Eraser RiskMonitor"="" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 8466432]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-17 58728]
"YMailAdvisor"="C:\Program Files\Yahoo!\Common\YMailAdvisor.exe" [2008-06-05 125208]
"nwiz"="nwiz.exe" [2007-06-28 C:\WINDOWS\system32\nwiz.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 15:13 49152 C:\PROGRA~1\COMMON~1\Stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-09-17 08:05 210168 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll rqzreg.dll dvytvt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"VIDC.ZLIB"= avizlib.dll
"VIDC.CSCD"= camcodec.dll
"vidc.ffds"= C:\PROGRA~1\ffdshow\ffdshow.ax
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DualCoreCenter.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DualCoreCenter.lnk
backup=C:\WINDOWS\pss\DualCoreCenter.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SecureDoc.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SecureDoc.lnk
backup=C:\WINDOWS\pss\SecureDoc.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^TheOnlyBigDog^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\TheOnlyBigDog\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\40175]
--a------ 2008-09-21 18:52 7336328 C:\WINDOWS\40175.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 16:25 94208 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative MediaSource Go]
--a------ 2003-05-29 09:50 131072 C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
--a------ 2003-07-25 11:15 536576 C:\Program Files\Eraser\eraser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 07:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveMonitor]
--a------ 2006-09-05 16:45 497152 C:\Program Files\MSI\Live Update 3\LMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a------ 2006-01-19 11:06 11776 C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 17:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando]
C:\Program Files\Pando Networks\Pando\pando.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Plus Cake]
C:\DOCUME~1\THEONL~1\APPLIC~1\SETTIN~1\Dvd Media Active.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteCenter]
--a------ 2003-06-12 09:47 135168 C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-09-16 12:16 1833296 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-09-10 01:50 39408 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-28 09:43 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\RealmEX\\mIRC.ExCurSioN.exe"=
"C:\\Need to Edit\\Pando Networks\\Pando\\pando.exe"=
"C:\\EZ-2-Serve\\mirc.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57890:TCP"= 57890:TCP:Pando P2P TCP Listening Port
"57890:UDP"= 57890:UDP:Pando P2P UDP Listening Port
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [2008-09-17 2368]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4e3cde5a-9302-11dd-a383-001d604b2cb3}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com c:
\Shell\Open\command - K:\resycled\boot.com c:
.
Contents of the 'Scheduled Tasks' folder
2008-10-18 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-10-22 C:\WINDOWS\Tasks\BF450B8182A2B679.job
- c:\docume~1\theonl~1\applic~1\settin~1\Bend Third Locks.exe []
2008-10-22 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 17:39]
2008-10-18 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - TheOnlyBigDog.job
- C:\PROGRA~1\NORTON~1\Navw32.exe [2005-10-19 12:54]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{34ea1c70-42cc-42c5-aa29-ec58b95a343e} - (no file)
URLSearchHooks-{a33fa729-d155-4b23-842b-2c665ecabdb6} - (no file)
BHO-{4F958CA7-9035-41E1-B5BF-EF8F336C1A23} - C:\WINDOWS\system32\pmnlIxwW.dll
Toolbar-{34ea1c70-42cc-42c5-aa29-ec58b95a343e} - (no file)
Toolbar-{a33fa729-d155-4b23-842b-2c665ecabdb6} - (no file)
WebBrowser-{34EA1C70-42CC-42C5-AA29-EC58B95A343E} - (no file)
WebBrowser-{A33FA729-D155-4B23-842B-2C665ECABDB6} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\TheOnlyBigDog\Application Data\Mozilla\Firefox\Profiles\4u0oqdty.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-amo&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://my.yahoo.com/
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-22 09:51:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ginamsi.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
.
**************************************************************************
.
Completion time: 2008-10-22 10:00:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-22 17:00:09
Pre-Run: 265,997,393,920 bytes free
Post-Run: 265,922,007,040 bytes free
425 --- E O F --- 2008-10-10 08:02:49