continued...
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-30 21:02 --------- d-----w C:\Program Files\Mailtraq
2008-01-30 10:57 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-01-30 00:00 --------- d-----w C:\Program Files\DynDNS Updater
2008-01-28 23:58 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2008-01-28 19:46 5,632 ----a-w C:\WINDOWS\system32\drivers\avgarkt.sys
2008-01-27 23:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Comodo
2008-01-26 13:43 --------- d-----w C:\Program Files\Comodo
2008-01-25 23:33 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-25 23:05 --------- d-----w C:\Program Files\UPHClean
2008-01-25 23:05 --------- d-----w C:\Program Files\PDF Printer Pilot SE
2008-01-25 23:04 --------- d-----w C:\Program Files\BT Voyager 105 ADSL Modem
2008-01-25 23:03 --------- d-----w C:\Program Files\DLMage
2008-01-25 18:57 --------- d-----w C:\Program Files\eMule
2008-01-25 15:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-25 15:41 --------- d-----w C:\Documents and Settings\james.TIGGER\Application Data\ICQ
2008-01-24 16:53 --------- d-----w C:\Documents and Settings\lisa.TIGGER\Application Data\Image Zone Express
2008-01-23 21:57 --------- d-----w C:\Program Files\HP
2008-01-23 21:57 --------- d-----w C:\Program Files\Hewlett-Packard
2008-01-23 17:14 --------- d-----w C:\Documents and Settings\james.TIGGER\Application Data\AVG7
2008-01-19 12:10 --------- d-----w C:\Documents and Settings\james.TIGGER\Application Data\Ethereal
2008-01-18 15:49 --------- d-----w C:\Program Files\ICQ
2007-12-29 20:50 12,739,313 ----a-w C:\AVG7QT.DAT
2007-12-28 02:29 --------- d-----w C:\Documents and Settings\james.TIGGER\Application Data\Camfrog
2007-12-22 11:19 --------- d-----w C:\Program Files\Windows Defender
2007-12-22 11:18 --------- d-----w C:\Program Files\SmartFTP
2007-12-22 11:18 --------- d-----w C:\Program Files\Microsoft Virtual PC
2007-12-22 11:18 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2007-12-19 17:09 --------- d-----w C:\Documents and Settings\lisa.TIGGER\Application Data\AVG7
2007-12-16 22:03 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2007-12-05 17:30 4,632,576 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2007-12-04 17:02 --------- d-----w C:\Program Files\PET
2007-12-03 00:50 --------- d-----w C:\Documents and Settings\james.TIGGER\Application Data\OfficeUpdate12
2007-11-30 18:42 16,858,624 ----a-w C:\WINDOWS\RTHDCPL.exe
2007-11-28 17:40 --------- d-----w C:\Program Files\Java
2007-11-20 18:15 1,826,816 ----a-w C:\WINDOWS\SkyTel.exe
2007-11-07 17:31 1,191,936 ----a-w C:\WINDOWS\RtlUpd.exe
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-01 08:50 3,264 ----a-w C:\drmHeader.bin
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-24 01:47 96,760 ----a-w C:\WINDOWS\system32\dfshim.dll
2007-10-24 01:47 84,480 ----a-w C:\WINDOWS\system32\mscories.dll
2007-10-24 01:47 282,112 ----a-w C:\WINDOWS\system32\mscoree.dll
2007-10-24 01:47 158,720 ----a-w C:\WINDOWS\system32\mscorier.dll
2007-10-11 09:55 88,576 ----a-w C:\WINDOWS\system32\infocardapi.dll
2007-10-11 09:55 579,584 ----a-w C:\WINDOWS\system32\icardagt.exe
2007-10-11 09:55 11,776 ----a-w C:\WINDOWS\system32\icardres.dll
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-10-09 13:03 779,800 ----a-w C:\WINDOWS\system32\PresentationNative_v0300.dll
2007-10-09 13:03 73,752 ----a-w C:\WINDOWS\system32\dxva2.dll
2007-10-09 13:03 493,080 ----a-w C:\WINDOWS\system32\evr.dll
2007-10-09 13:03 350,744 ----a-w C:\WINDOWS\system32\PresentationHost.exe
2007-10-09 13:03 33,304 ----a-w C:\WINDOWS\system32\PresentationHostProxy.dll
2007-10-09 13:03 161,304 ----a-w C:\WINDOWS\system32\UIAutomationCore.dll
2007-10-09 13:03 106,520 ----a-w C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2007-10-09 13:03 1,986,072 ----a-w C:\WINDOWS\system32\milcore.dll
2007-10-09 12:58 16,896 ----a-w C:\WINDOWS\system32\tswpfwrp.exe
2007-10-08 23:51 315,392 ----a-w C:\WINDOWS\HideWin.exe
2006-11-17 20:16 850 ----a-w C:\Program Files\INSTALL.LOG
2003-06-27 08:05 271 --sha-w C:\Program Files\desktop.ini
2003-06-27 08:05 21,952 ---ha-w C:\Program Files\folder.htt
1998-11-17 12:09 24,576 ----a-w C:\WINDOWS\inf\Vizpnpin.exe
1998-10-12 12:23 40,960 ----a-w C:\WINDOWS\inf\vizPnP\Vipersti.dll
1998-07-30 13:44 19,112 ----a-w C:\WINDOWS\inf\vizPnP\Pmxscan.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 12:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 13:03 106544 C:\WINDOWS\system32\tweakui.cpl]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"RegistryMechanic"="" []
"PP7600usb"="C:\PROGRA~1\VISION~1\PAPERP~1\FBDirect.exe" [ ]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-08-14 14:38 94208]
"PDFPrinterPilotAgent"="C:\Program Files\PDF Printer Pilot SE\PDFPRPRXY.EXE" [2003-11-10 15:21 6144]
"PaperPort PTD"="c:\progra~1\vision~1\paperp~1\pptd40nt.exe" [1999-04-13 03:13 29184]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2003-09-30 07:09 425984]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 15:50 81920]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 15:50 221184]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-08-14 14:39 98304]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-12-10 00:19 188416]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-08-14 14:41 114688]
"DSLSTATEXE"="C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe" [2003-06-28 16:10 1658965]
"DSLAGENTEXE"="C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe" [2003-08-19 13:47 16384]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 05:33 122941]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-02-28 12:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-01-28 19:48 579072]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57 282624]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 15:02 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 15:06 2027792]
"RTHDCPL"="RTHDCPL.EXE" [2007-11-30 18:42 16858624 C:\WINDOWS\RTHDCPL.exe]
"HPHUPD08"="C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2006-07-11 20:27 49152]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-08-18 22:00 49152]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2008-01-27 00:47 6731312]
"BOC-425"="C:\PROGRA~1\Comodo\CBOClean\BOC425.exe" [2007-11-26 10:38 342272]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\cfp.exe" [2008-01-28 19:44 1481472]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-02-28 12:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2008-01-28 19:44 219136]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 19:29 39264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 08:48 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\james.TIGGER\Start Menu\Programs\Startup\
Disk Detector.lnk - C:\Program Files\Creative\ShareDLL\CTNotify.exe [2006-10-21 13:26:41 189952]
Download Mage.lnk - C:\Program Files\DLMage\DnloadMage.exe [2006-10-21 13:26:29 323584]
Iolo Macro Magic.lnk - C:\Program Files\Iolo\Macro Magic\Macros.exe [2006-10-21 13:22:42 345600]
TeleSA.lnk - C:\Program Files\AVer Teletext\AVerSA.exe [2006-12-05 17:06:16 28672]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-21 13:29:56 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2006-10-21 13:39:30 29696]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2006-10-21 13:29:38 10872]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-08-14 13:28:28 499773]
devldr32.exe [2001-08-31 12:44:30 25600]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-08-18 22:20:30 282624]
QuickTV.lnk - C:\AVERTV2K\QuickTV.exe [2006-12-05 16:45:42 122880]
TeleSA.lnk - C:\Program Files\AVer Teletext\AVerSA.exe [2006-12-05 17:06:16 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 2002-02-15 09:51 24638 C:\WINDOWS\system32\pcanotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
R0 hotcore2;hotcore2;C:\WINDOWS\system32\drivers\hotcore2.sys [2006-10-02 10:39]
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 10:02]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2001-07-16 10:01]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2001-07-16 10:01]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [1999-07-21 17:28]
R2 DynDNS_Updater_Service;DynDNS Updater Service;C:\Program Files\DynDNS Updater\DynDNS.exe [2006-09-17 10:32]
R2 io.sys;IO.DLL Driver;C:\WINDOWS\system32\drivers\io.sys [2006-11-13 19:51]
R2 MailtraqServer;MailtraqServer;"C:\Program Files\Mailtraq\mtqsvc.exe" [2003-10-28 08:44]
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 07:41]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 04:29]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\WINDOWS\system32\DRIVERS\ManyCam.sys [2007-03-22 12:17]
R3 pmxscan;Visioneer USB Service;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-01-28 19:46]
S1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-01-28 19:46]
S2 PGPmemlock;PGPmemlock;C:\WINDOWS\system32\drivers\PGPmemlock.sys []
S3 DrvFltIp;DrvFltIp;C:\Program Files\BulletProofSoft.com\AdvancedPersonalFirewall\DrvFltIp.sys []
S3 LUPLET;LUPLET;C:\DOCUME~1\JAMES~1.TIG\LOCALS~1\Temp\LUPLET.exe [2008-01-29 00:03]
S3 n558;N558 Bluetooth USB Filter Driver;C:\WINDOWS\system32\Drivers\n558.sys [2007-08-15 07:27]
S3 PORTMON;PORTMON;C:\Program Files\Port Monitor\PORTMSYS.SYS []
S3 TOKENMON;TOKENMON;C:\WINDOWS\system32\drivers\TOKENM.SYS []
S3 usb2vcom;USB to Serial Bridge Controller;C:\WINDOWS\system32\Drivers\usb2vcom.sys [2005-09-02 17:49]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 15:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 15:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 15:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 15:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 15:50]
S4 UMRUZDR;UMRUZDR;C:\DOCUME~1\JAMES~1.TIG\LOCALS~1\Temp\UMRUZDR.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 21:05:02 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-27 20:31:10 C:\WINDOWS\Tasks\User_Feed_Synchronization-{E1039185-2C1A-41D5-841F-FD1F7A14777C}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-30 21:20:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\guard32.dll
.
Completion time: 2008-01-30 21:22:47
ComboFix-quarantined-files.txt 2008-01-30 21:22:45
.
2007-12-19 15:26:09 --- E O F ---