.
((((((((((((((((((((((((( Files Created from 2007-12-14 to 2008-01-14 )))))))))))))))))))))))))))))))
.
2008-01-14 17:42 . 2000-08-31 08:00 51,200 --a------ C:\WINNT\NirCmd.exe
2008-01-14 12:22 . 2008-01-14 12:22 <DIR> d-------- C:\Program Files\CCleaner
2008-01-14 12:09 . 2008-01-14 12:09 3,079 --a------ C:\WINNT\system32\cvgjxinm.dll
2008-01-14 12:03 . 2008-01-14 12:03 3,079 --a------ C:\WINNT\system32\cafrvori.dll
2008-01-14 12:02 . 2008-01-14 12:02 3,079 --a------ C:\WINNT\system32\qwxdmtud.dll
2008-01-12 09:11 . 2008-01-12 09:11 <DIR> d-------- C:\WINNT\system32\Kaspersky Lab
2008-01-11 14:32 . 2008-01-11 15:15 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2008-01-11 14:24 . 2008-01-11 14:24 <DIR> d-------- C:\Program Files\a-squared HiJackFree
2008-01-11 13:58 . 2008-01-11 13:58 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-01-11 13:41 . 2005-08-25 18:19 115,920 --a------ C:\WINNT\system32\MSINET.OCX
2008-01-09 22:56 . 2008-01-12 11:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-09 22:18 . 2008-01-09 22:23 <DIR> d-------- C:\Program Files\RegCure
2008-01-09 21:58 . 2008-01-12 11:40 3,109,152 --ahs---- C:\WINNT\system32\drivers\fidbox.dat
2008-01-09 21:58 . 2008-01-12 11:40 436,512 --ahs---- C:\WINNT\system32\drivers\fidbox2.dat
2008-01-09 21:58 . 2008-01-12 11:40 42,716 --ahs---- C:\WINNT\system32\drivers\fidbox.idx
2008-01-09 21:58 . 2008-01-12 11:40 41,996 --ahs---- C:\WINNT\system32\drivers\fidbox2.idx
2008-01-09 21:55 . 2008-01-09 21:55 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-09 21:54 . 2008-01-09 21:54 <DIR> d-------- C:\KAV
2008-01-09 21:23 . 2008-01-09 21:23 <DIR> d-------- C:\WINNT\ERUNT
2008-01-09 21:10 . 2008-01-09 21:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-09 20:52 . 2008-01-11 16:40 <DIR> d-------- C:\VundoFix Backups
2008-01-09 20:13 . 2008-01-09 20:21 <DIR> d-------- C:\Program Files\XoftSpySE
2008-01-09 20:03 . 2008-01-09 20:36 <DIR> d-------- C:\Program Files\AdwareAlert
2008-01-09 20:03 . 2008-01-09 20:04 <DIR> d-------- C:\Documents and Settings\RI001SU\Application Data\AdwareAlert
2008-01-09 19:57 . 2008-01-09 20:34 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-09 19:56 . 2008-01-09 21:05 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-01-09 19:33 . 2008-01-09 19:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-09 16:46 . 2008-01-09 22:02 <DIR> d-------- C:\Program Files\Windows Defender
2008-01-07 13:18 . 2008-01-09 14:44 <DIR> d-------- C:\Documents and Settings\RI001SU\Application Data\AntiSpyware
2008-01-07 08:55 . 2008-01-09 20:32 1,846,679 --ahs---- C:\WINNT\system32\aruknmxt.ini
2007-12-22 16:49 . 2007-12-23 12:51 <DIR> d-------- C:\WINNT\SxsCaPendDel
2007-12-22 16:43 . 2007-12-27 20:58 77,824 --a------ C:\WINNT\system32\hkcmd .exe
2007-12-22 16:43 . 2007-12-22 16:43 1,024 --a------ C:\WINNT\system32\drivers\536391BB-0722-44CC-AA1F-5DD835B737EF.cxv
2007-12-22 16:42 . 2007-12-27 10:21 94,208 --a------ C:\WINNT\system32\igfxtray .exe
2007-12-22 16:36 . 2007-12-22 16:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-20 22:48 . 2008-01-12 09:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-20 22:04 . 2007-12-20 22:04 1,024 --a------ C:\WINNT\system32\drivers\25633D73-769E-4692-9C81-77B31F394BCB.cxv
2007-12-20 16:52 . 2007-12-22 16:49 <DIR> d-------- C:\Program Files\STOPzilla!
2007-12-20 16:52 . 2007-12-20 16:52 <DIR> d-------- C:\Program Files\Common Files\iS3
2007-12-20 16:52 . 2007-12-22 16:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 16:05 --------- d-----w C:\Program Files\Pitney Bowes SmartMailer
2008-01-10 15:39 --------- d-----w C:\Program Files\notes
2008-01-10 03:03 --------- d-----w C:\Program Files\Novadigm
2008-01-10 01:36 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-06 23:59 --------- d-----w C:\Program Files\AT&T Global Network Client
2008-01-02 14:53 491,520 ----a-w C:\WINNT\system32\enstart.exe
2008-01-02 14:53 491,520 ----a-w C:\WINNT\system32\_enstart.exe
2008-01-02 14:53 31,616 ----a-w C:\WINNT\system32\enstart_.sys
2007-12-11 14:23 --------- d-----w C:\Program Files\Interwise
2007-12-03 16:18 --------- d-----w C:\Program Files\MATCast
2007-11-29 21:06 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-29 21:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-11-27 01:00 59,904 ----a-w C:\WINNT\system32\drivers\mvstdi5x.sys
2007-11-27 01:00 36,922 ----a-w C:\WINNT\system32\entapi.dll
2007-11-27 01:00 117,024 ----a-w C:\WINNT\system32\drivers\naiavf5x.sys
2007-11-20 15:00 --------- d-----w C:\Program Files\Common Files\PitneyBowes Shared
2007-11-14 07:26 450,560 ----a-w C:\WINNT\system32\dllcache\jscript.dll
2007-11-13 17:27 184,897 ----a-w C:\WINNT\system32\atasnt40.dll
2007-11-07 09:26 721,920 ----a-w C:\WINNT\system32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\WINNT\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ----a-w C:\WINNT\system32\dllcache\tcpip.sys
2007-10-30 10:16 3,058,688 ----a-w C:\WINNT\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINNT\system32\quartz.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINNT\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 ----a-w C:\WINNT\system32\wmasf.dll
2007-10-27 22:40 222,720 ----a-w C:\WINNT\system32\dllcache\wmasf.dll
2007-10-26 03:36 8,454,656 ----a-w C:\WINNT\system32\dllcache\shell32.dll
2007-10-24 15:40 28,672 ----a-w C:\WINNT\system32\CPRN00.DLL
2007-10-24 15:29 40,960 ----a-w C:\WINNT\system32\CONTAN01.DLL
2007-10-24 15:29 28,672 ----a-w C:\WINNT\system32\PSOEL00.DLL
2007-10-24 15:29 24,576 ----a-w C:\WINNT\system32\CONTAN00.DLL
.
Code:
<pre>
----a-w 1,816,208 2008-01-11 20:06:11 C:\Program Files\a-squared Anti-Malware\a2guard .exe
----a-w 6,366,448 2008-01-10 01:34:42 C:\Program Files\AdwareAlert\AdwareAlert .exe
----a-w 24,576 2007-12-23 23:43:29 C:\Program Files\AT&T Global Network Client\NetSP .exe
----a-w 147,514 2007-12-29 12:48:07 C:\Program Files\Common Files\Network Associates\TalkBack\tbmon .exe
----a-w 28,672 2008-01-10 03:03:43 C:\Program Files\Common Files\XCPCSync\Translators\LtNts4\NtsAgent .exe
----a-w 2,080,857 2008-01-03 17:40:33 C:\Program Files\EFI\PrintMessenger\dsfhost .exe
----a-w 847,872 2008-01-11 20:06:10 C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3 .exe
----a-w 6,731,312 2008-01-10 02:37:29 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
----a-w 696,320 2008-01-10 03:03:43 C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
----a-w 802,816 2008-01-09 18:43:11 C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
----a-w 132,496 2008-01-10 02:37:08 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
----a-w 231,952 2008-01-12 16:34:23 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
----a-w 136,512 2007-12-31 16:51:54 C:\Program Files\Network Associates\Common Framework\UdaterUI .exe
----a-w 98,304 2008-01-10 03:03:38 C:\Program Files\Network Associates\VirusScan\SHSTAT .EXE
----a-w 250,036 2008-01-10 03:03:41 C:\Program Files\Novadigm\radskman .exe
----a-w 1,103,752 2008-01-10 01:30:17 C:\Program Files\Spyware Doctor\pctsTray .exe
----a-w 866,584 2008-01-10 02:37:14 C:\Program Files\Windows Defender\MSASCui .exe
----a-w 151,322 2008-01-06 23:58:41 C:\WINNT\PBCache\ATTGlobal680\ATTGlobal .exe
----a-w 77,824 2007-12-28 01:58:45 C:\WINNT\system32\hkcmd .exe
----a-w 94,208 2007-12-27 15:21:56 C:\WINNT\system32\igfxtray .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" [ ]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINNT\system32\bthprops.cpl]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AT&T Global Network Client Monitor.lnk - C:\WINNT\Installer\{706CD0EB-D191-4821-A2FA-471CB1C6292A}\NetGM_1B536450052A4C0BA1B8FC31F1D473F7.exe [2007-08-21 09:41:33]
HotSync Manager.lnk - C:\Palm\HOTSYNC.EXE [2007-08-27 10:37:43]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54]
Push Client.LNK - C:\Program Files\Interwise\Participant\pull.exe [2007-12-11 09:23:44]
RUMBA Lightning.lnk - C:\Program Files\WallData\SYSTEM\BrskStrt.exe [1996-10-28 02:17:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggefcd]
hggefcd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-11 16:30 249856 c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-11 16:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MATCast]
--a------ 2007-11-16 12:23 655360 C:\Program Files\MATCast\MATCast.exe
R0 a320raid;a320raid;C:\WINNT\system32\DRIVERS\a320raid.sys [2004-06-15 12:06]
R1 enstart_;enstart_;C:\WINNT\system32\enstart_.sys [2008-01-02 09:53]
R2 agnwifi;AT&T Wi-Fi Support Driver;C:\WINNT\system32\DRIVERS\agnwifi.sys [2004-04-29 16:19]
R2 enstart;enstart;C:\WINNT\system32\enstart.exe [2008-01-02 09:53]
R2 radexecd;Radia Notify Daemon;"C:\Program Files\Novadigm\radexecd.exe" [2005-05-04 15:35]
R2 radsched;Radia Scheduler Daemon;"C:\Program Files\Novadigm\radsched.exe" [2004-08-25 12:05]
R2 Radstgms;Radia MSI Redirector;"C:\Program Files\Novadigm\Radstgms.exe" [2006-06-07 09:58]
R3 agnfilt;AGN Filter Interface;C:\WINNT\system32\DRIVERS\agnfilt.sys [2006-05-19 08:46]
R3 RadiaMsi;RadiaMsi;C:\WINNT\system32\DRIVERS\radiamsi.sys [2006-05-15 11:20]
S3 avpnnic;AGN Virtual Network Adapter;C:\WINNT\system32\DRIVERS\avpnnic.sys [2003-04-04 11:48]
S3 COAX;COAX;C:\WINNT\system32\drivers\COAX.sys [1997-12-22 12:43]
S3 GTIPCI21;GTIPCI21;C:\WINNT\system32\DRIVERS\gtipci21.sys [2004-05-03 09:26]
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINNT\system32\DRIVERS\ozscr.sys [2002-11-08 13:13]
S3 PCX500;Cisco Wireless LAN Adapters Driver;C:\WINNT\system32\DRIVERS\pcx500.sys [2004-08-03 22:06]
S3 RMBS;RMBS;C:\WINNT\system32\drivers\RMBS.sys [1998-02-06 16:04]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-10 08:00:00 C:\WINNT\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert .ex
- C:\Program Files\AdwareAlert
"2008-01-10 08:00:00 C:\WINNT\Tasks\AntiSpyware Scheduled Scan.job"
- C:\Program Files\AntiSpywareApp\AntiSpyware.ex
- C:\Program Files\AntiSpywareApp
"2008-01-10 07:22:27 C:\WINNT\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-14 23:11:36 C:\WINNT\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-10 13:02:26 C:\WINNT\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-14 23:11:36 C:\WINNT\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-01-10 01:13:53 C:\WINNT\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-14 18:12:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-14 18:14:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-14 23:14:55