Combofix Scan
ComboFix 07-12-02.7 - HP_Owner 2007-12-06 14:58:29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.803 [GMT -6:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-11-06 to 2007-12-06 )))))))))))))))))))))))))))))))
.
2007-12-05 22:02 . 2007-12-05 22:02 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-05 22:02 . 2007-12-05 22:02 <DIR> d-------- C:\WINDOWS\LastGood
2007-12-05 22:02 . 2007-12-05 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-05 18:28 . 2007-12-05 18:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-12-05 18:18 . 2007-12-05 18:18 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\Grisoft
2007-12-05 18:18 . 2007-12-05 18:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-05 18:18 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-05 14:10 . 2007-12-05 14:11 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-05 14:10 . 2007-12-05 14:10 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2007-12-05 14:10 . 2007-12-05 14:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-05 14:09 . 2007-12-05 14:09 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-05 01:40 . 2007-12-05 01:40 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 21:31 . 2007-12-05 20:59 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-04 21:29 . 2007-12-04 21:29 <DIR> d-------- C:\Program Files\Norton Security Scan
2007-12-04 16:56 . 2007-12-06 10:52 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-12-04 16:56 . 2007-12-04 16:56 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\PC Tools
2007-12-04 16:56 . 2007-10-04 17:10 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-04 16:56 . 2007-10-04 17:10 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-04 16:56 . 2007-10-04 17:10 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-04 16:56 . 2007-10-04 17:11 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-03 22:17 . 2007-12-03 22:17 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Lavasoft
2007-12-02 19:10 . 2007-12-02 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-02 14:33 . 2007-12-02 14:35 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-12-02 13:40 . 2007-12-02 14:31 <DIR> d-------- C:\Program Files\STOPzilla!
2007-12-02 13:40 . 2007-12-02 13:40 <DIR> d-------- C:\Program Files\Common Files\iS3
2007-12-02 13:40 . 2007-12-02 14:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2007-12-02 10:17 . 2007-12-02 10:17 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-12-01 21:29 . 2007-12-01 21:29 <DIR> d-------- C:\Program Files\Common Files\xing shared
2007-12-01 20:07 . 2007-12-05 21:45 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-01 20:07 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-01 20:06 . 2007-12-05 22:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2007-12-01 17:54 . 2007-12-06 15:06 166 --a------ C:\WINDOWS\out.html
2007-12-01 17:26 . 2007-12-01 17:23 1,082,590 --a------ C:\WINDOWS\system32\walg.exe
2007-12-01 17:26 . 2007-12-01 17:26 471,040 --a------ C:\WINDOWS\out.exe
2007-12-01 15:12 . 2007-12-01 15:12 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\Media Player Classic
2007-12-01 15:10 . 2007-12-01 15:10 <DIR> d-------- C:\Program Files\DomPlayer
2007-12-01 13:22 . 2007-12-01 19:21 <DIR> d-------- C:\Program Files\BitComet
2007-11-23 22:23 . 2007-11-23 22:23 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\muvee Technologies
2007-11-23 22:23 . 2007-11-23 22:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\muvee Technologies
2007-11-23 22:23 . 2007-11-23 22:23 0 --a------ C:\WINDOWS\muveeapp.INI
2007-11-09 16:55 . 2007-12-05 21:43 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-11-09 16:55 . 2007-11-09 16:55 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-09 16:54 . 2007-11-09 16:54 <DIR> d-------- C:\Program Files\iTunes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-06 05:06 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-05 22:47 --------- d-----w C:\Program Files\TrueAssistant
2007-12-02 19:16 --------- d--h--w C:\Documents and Settings\Sarah\Application Data\Move Networks
2007-12-02 19:10 --------- d--h--w C:\Documents and Settings\HP_Owner\Application Data\Move Networks
2007-12-02 17:26 --------- d-----w C:\Program Files\Eusing Free Registry Cleaner
2007-12-02 16:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-02 03:29 --------- d-----w C:\Program Files\Common Files\Real
2007-12-02 03:27 --------- d-----w C:\Program Files\Google
2007-12-02 00:02 --------- d-----w C:\Program Files\DivX
2007-11-09 22:54 --------- d-----w C:\Program Files\iPod
2007-11-09 22:48 --------- d-----w C:\Program Files\QuickTime
2007-10-31 20:09 30,464 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-26 01:00 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-10-26 01:00 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2007-10-26 00:58 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2007-10-20 00:56 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-10-20 00:56 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-10-20 00:56 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-10-20 00:56 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 19:25 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\SmartFTP
2007-10-18 09:06 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-10-08 02:29 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Snapfish
2007-10-07 04:18 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Yahoo!
2005-08-07 00:50 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 21:49]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 15:38]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 16:19]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 04:50]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 14:54]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 22:46]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 23:34]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-23 11:31]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2006-11-29 02:40]
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2006-11-29 02:40]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-01 21:28]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 15:38]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2006-11-30 21:49]
C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\
TrueAssistant.lnk - C:\Program Files\TrueAssistant\TrueAssistant.exe [2006-01-23 12:30:56]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-12-01 20:06:19]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 03:28:24]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\sslaunch.exe [2005-04-24 12:13:09]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-04-24 12:14:58]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2005-08-27 18:58:18]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ :\WINDOW
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys
Start Pending2 wlg;wlg;C:\WINDOWS\system32\walg.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-12-05 03:43:29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-05 03:29:34 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-12-06 09:30:00 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.exe
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-06 15:09:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-06 15:13:52
.
--- E O F ---
ComboFix 07-12-02.7 - HP_Owner 2007-12-06 14:58:29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.803 [GMT -6:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-11-06 to 2007-12-06 )))))))))))))))))))))))))))))))
.
2007-12-05 22:02 . 2007-12-05 22:02 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-05 22:02 . 2007-12-05 22:02 <DIR> d-------- C:\WINDOWS\LastGood
2007-12-05 22:02 . 2007-12-05 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-05 18:28 . 2007-12-05 18:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-12-05 18:18 . 2007-12-05 18:18 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\Grisoft
2007-12-05 18:18 . 2007-12-05 18:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-05 18:18 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-05 14:10 . 2007-12-05 14:11 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-05 14:10 . 2007-12-05 14:10 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2007-12-05 14:10 . 2007-12-05 14:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-05 14:09 . 2007-12-05 14:09 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-05 01:40 . 2007-12-05 01:40 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 21:31 . 2007-12-05 20:59 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-04 21:29 . 2007-12-04 21:29 <DIR> d-------- C:\Program Files\Norton Security Scan
2007-12-04 16:56 . 2007-12-06 10:52 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-12-04 16:56 . 2007-12-04 16:56 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\PC Tools
2007-12-04 16:56 . 2007-10-04 17:10 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-04 16:56 . 2007-10-04 17:10 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-04 16:56 . 2007-10-04 17:10 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-04 16:56 . 2007-10-04 17:11 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-03 22:17 . 2007-12-03 22:17 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Lavasoft
2007-12-02 19:10 . 2007-12-02 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-02 14:33 . 2007-12-02 14:35 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-12-02 13:40 . 2007-12-02 14:31 <DIR> d-------- C:\Program Files\STOPzilla!
2007-12-02 13:40 . 2007-12-02 13:40 <DIR> d-------- C:\Program Files\Common Files\iS3
2007-12-02 13:40 . 2007-12-02 14:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2007-12-02 10:17 . 2007-12-02 10:17 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-12-01 21:29 . 2007-12-01 21:29 <DIR> d-------- C:\Program Files\Common Files\xing shared
2007-12-01 20:07 . 2007-12-05 21:45 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-01 20:07 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-01 20:06 . 2007-12-05 22:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2007-12-01 17:54 . 2007-12-06 15:06 166 --a------ C:\WINDOWS\out.html
2007-12-01 17:26 . 2007-12-01 17:23 1,082,590 --a------ C:\WINDOWS\system32\walg.exe
2007-12-01 17:26 . 2007-12-01 17:26 471,040 --a------ C:\WINDOWS\out.exe
2007-12-01 15:12 . 2007-12-01 15:12 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\Media Player Classic
2007-12-01 15:10 . 2007-12-01 15:10 <DIR> d-------- C:\Program Files\DomPlayer
2007-12-01 13:22 . 2007-12-01 19:21 <DIR> d-------- C:\Program Files\BitComet
2007-11-23 22:23 . 2007-11-23 22:23 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\muvee Technologies
2007-11-23 22:23 . 2007-11-23 22:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\muvee Technologies
2007-11-23 22:23 . 2007-11-23 22:23 0 --a------ C:\WINDOWS\muveeapp.INI
2007-11-09 16:55 . 2007-12-05 21:43 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-11-09 16:55 . 2007-11-09 16:55 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-09 16:54 . 2007-11-09 16:54 <DIR> d-------- C:\Program Files\iTunes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-06 05:06 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-05 22:47 --------- d-----w C:\Program Files\TrueAssistant
2007-12-02 19:16 --------- d--h--w C:\Documents and Settings\Sarah\Application Data\Move Networks
2007-12-02 19:10 --------- d--h--w C:\Documents and Settings\HP_Owner\Application Data\Move Networks
2007-12-02 17:26 --------- d-----w C:\Program Files\Eusing Free Registry Cleaner
2007-12-02 16:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-02 03:29 --------- d-----w C:\Program Files\Common Files\Real
2007-12-02 03:27 --------- d-----w C:\Program Files\Google
2007-12-02 00:02 --------- d-----w C:\Program Files\DivX
2007-11-09 22:54 --------- d-----w C:\Program Files\iPod
2007-11-09 22:48 --------- d-----w C:\Program Files\QuickTime
2007-10-31 20:09 30,464 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-26 01:00 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-10-26 01:00 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2007-10-26 00:58 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2007-10-20 00:56 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-10-20 00:56 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-10-20 00:56 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-10-20 00:56 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 19:25 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\SmartFTP
2007-10-18 09:06 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-10-08 02:29 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Snapfish
2007-10-07 04:18 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Yahoo!
2005-08-07 00:50 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 21:49]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 15:38]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 16:19]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 04:50]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 14:54]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 22:46]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 23:34]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-23 11:31]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2006-11-29 02:40]
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2006-11-29 02:40]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-01 21:28]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 15:38]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2006-11-30 21:49]
C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\
TrueAssistant.lnk - C:\Program Files\TrueAssistant\TrueAssistant.exe [2006-01-23 12:30:56]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-12-01 20:06:19]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 03:28:24]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\sslaunch.exe [2005-04-24 12:13:09]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-04-24 12:14:58]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2005-08-27 18:58:18]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ :\WINDOW
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys
Start Pending2 wlg;wlg;C:\WINDOWS\system32\walg.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-12-05 03:43:29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-05 03:29:34 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-12-06 09:30:00 C:\WINDOWS\Tasks\RegClean Scheduled Scan.job"
- C:\Program Files\RegClean\RegClean.exe
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-06 15:09:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-06 15:13:52
.
--- E O F ---