[*]Jotti / Virus total results
Eveything came us as 0 bytes...
[*]ComboFix Log
ComboFix 07-10-26.4 - Tom 2007-10-27 21:13:47.3 - NTFSx86
Running from: C:\Documents and Settings\Tom\My Documents\Virus Killers\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tom\Desktop\CFScript.txt
* Created a new restore point
FILE::
C:\134tmp.exe
C:\135tmp.exe
C:\13tmp.exe
C:\WINDOWS\system32\awtrrpo.dll
C:\WINDOWS\system32\cookie1.dat
C:\WINDOWS\system32\RabioSetup.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\134tmp.exe
C:\Documents and Settings\All Users\Application Data\Rabio
C:\WINDOWS\system32\cookie1.dat
C:\WINDOWS\system32\gugwuocq.dll
C:\WINDOWS\system32\ps1.dat
C:\WINDOWS\system32\RabioSetup.exe
C:\WINDOWS\system32\rc.dat
C:\WINDOWS\system32\vbmqmywp.dll
C:\WINDOWS\system32\yxlyosbu.dll
.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.
2007-10-27 20:43 <DIR> d----c--- C:\Documents and Settings\Tom\Application Data\AVG7
2007-10-27 20:42 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-27 20:42 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\avg7
2007-10-27 00:49 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-25 13:16 <DIR> d-------- C:\Program Files\Microsoft Calculator Plus
2007-10-22 23:23 <DIR> d-------- C:\Program Files\Microsoft IntelliType Pro
2007-10-22 22:52 2,440 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-22 22:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-22 22:49 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-22 19:47 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-22 19:47 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-22 19:47 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-22 19:47 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-22 19:47 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-22 13:18 <DIR> d-------- C:\Program Files\Adsense Helper Object
2007-10-22 00:50 <DIR> d----c--- C:\Documents and Settings\Tom\Application Data\Grisoft
2007-10-22 00:49 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-22 00:49 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-22 00:43 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-10-21 23:37 <DIR> d----c--- C:\VundoFix Backups
2007-10-21 23:22 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-10-21 23:14 <DIR> d----c--- C:\Documents and Settings\Tom\Application Data\GetRightToGo
2007-10-21 22:46 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-21 22:46 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-10-21 22:46 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-10-21 22:44 <DIR> d-------- C:\Program Files\Google
2007-10-21 19:01 <DIR> d--hs---- C:\WINDOWS\RFYgQ3VzdG9tZXI
2007-10-21 19:01 17,408 --a--c--- C:\psapi.dll
2007-10-19 21:27 <DIR> d-------- C:\Program Files\Xvid
2007-10-19 20:50 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-19 16:52 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-10-19 16:50 <DIR> d-------- C:\Program Files\MSBuild
2007-10-19 16:50 <DIR> d-------- C:\Program Files\Microsoft Works
2007-10-19 16:47 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-10-19 16:44 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-10-19 16:32 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-19 16:31 <DIR> dr-h-c--- C:\MSOCache
2007-10-19 15:42 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-10-19 15:32 <DIR> d-------- C:\WINDOWS\EHome
2007-10-17 12:55 <DIR> d----c--- C:\Temp
2007-10-17 12:32 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\shctxex.vb
2007-10-17 12:31 974,848 --a------ C:\WINDOWS\system32\mfc70.dll
2007-10-17 12:31 516,173 --a------ C:\WINDOWS\system32\msvcp60d.dll
2007-10-17 12:31 385,100 --a------ C:\WINDOWS\system32\MSVCRTD.DLL
2007-10-17 12:31 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-10-17 12:31 69,632 --a------ C:\WINDOWS\system32\vzcontextmenu.dll
2007-10-17 12:31 4,608 --a------ C:\WINDOWS\system32\W95INF32.DLL
2007-10-17 12:31 2,272 --a------ C:\WINDOWS\system32\W95INF16.DLL
2007-10-17 12:15 487,424 --a------ C:\WINDOWS\system32\msvcp70.dll
2007-10-17 11:53 <DIR> d----c--- C:\MediaCell
2007-10-17 11:21 <DIR> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-17 11:20 <DIR> d-------- C:\Program Files\Blaze Media Pro
2007-10-05 12:31 159,744 --a------ C:\WINDOWS\system32\lfpng13n.dll
2007-10-03 18:18 <DIR> d-------- C:\Program Files\MSN Messenger
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-20 09:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-19 19:30 --------- d-----w C:\Program Files\Waves
2007-10-19 19:30 --------- d-----w C:\Program Files\FLAC
2007-10-19 19:30 --------- d-----w C:\Program Files\DivX
2007-09-21 17:41 --------- d-----w C:\Program Files\Queens of the Stone Age Active Desktop
2007-09-21 11:18 --------- dc----w C:\Documents and Settings\Tom\Application Data\MSN6
2007-09-21 10:25 --------- dc----w C:\Documents and Settings\All Users\Application Data\MSN6
2007-09-17 01:50 15,939 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2007-09-12 14:30 --------- d-----w C:\Program Files\InterActual
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\WINDOWS\RFYgQ3VzdG9tZXI ----
((((((((((((((((((((((((((((( snapshot@2007-10-27_15.24.01.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-10-27 19:42:41 821,728 ----a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2007-10-27 19:42:45 4,224 ----a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
+ 2007-10-27 19:42:45 27,776 ----a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
+ 2007-10-27 19:42:47 3,968 ----a-w C:\WINDOWS\system32\drivers\avgclean.sys
+ 2007-10-27 19:42:47 19,904 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18FA53D3-B7A8-4309-8045-D43D6AA2DCE9}]
2007-10-22 13:18 26112 --a------ C:\Program Files\Adsense Helper Object\aho.v5.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-10-28 22:10]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 08:06 C:\WINDOWS\system32\ptipbmf.dll]
"SoundMan"="SOUNDMAN.EXE" [2004-01-08 19:54 C:\WINDOWS\SOUNDMAN.EXE]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-16 00:41]
"DeltTray"="DeltTray.exe" [2002-12-06 17:19 C:\WINDOWS\system32\delttray.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 17:28]
"NWEReboot"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-14 13:35]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 09:18]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"workflow"="E:\installs\workflow.exe" []
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2003-05-16 00:45]
"74c2da49"="C:\WINDOWS\system32\gugwuocq.dll" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-27 20:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"Ooei"="C:\PROGRA~1\COMMON~1\SKS~1\netdde.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Fast Start.lnk
backup=C:\WINDOWS\pss\Microsoft Office Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Find Fast Indexer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Find Fast Indexer.lnk
backup=C:\WINDOWS\pss\Microsoft Office Find Fast Indexer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Shortcut Bar.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Shortcut Bar.lnk
backup=C:\WINDOWS\pss\Microsoft Office Shortcut Bar.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
R2 Belkin 54g Wireless USB Network Adapter Service;Belkin 54g Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
R3 Intels51;Intel(R) 536EP Modem;C:\WINDOWS\system32\DRIVERS\Intels51.sys
R3 NeroCd2k;NeroCd2k;C:\WINDOWS\system32\drivers\NeroCd2k.sys
S3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys
S3 UKS11LDR;M-Audio USB Keystation Loader;C:\WINDOWS\system32\drivers\uks11ldr.sys
S3 USBKT1X1;M-Audio USB Keystation;C:\WINDOWS\system32\drivers\usbkt1x1.sys
S3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\yukonx86.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-24 09:26:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 21:18:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-27 21:20:25 - machine was rebooted
C:\ComboFix2.txt ... 2007-10-27 15:24
.
--- E O F ---
[*]Contents of C:\Kresults.txt
Volume in drive C is System
Volume Serial Number is 74C2-DAE6
Directory of C:\Documents and Settings\Tom\Desktop
Volume in drive C is System
Volume Serial Number is 74C2-DAE6
Directory of C:\Documents and Settings\Tom\Desktop
Volume in drive C is System
Volume Serial Number is 74C2-DAE6
Directory of C:\Program Files
[.]
[..]
[Adobe]
[Adsense Helper Object]
[ahead]
[Analog Devices]
[Apple Software Update]
[ATI Technologies]
[AviSynth 2.5]
[Belkin]
[Blaze Media Pro]
[CDisplay]
[Common Files]
[ComPlus Applications]
[CyberLink]
[Digital Design Ltd]
[DivX]
[DVD Decrypter]
[ffdshow]
[FLAC]
[FLVPlayer]
[Google]
[Grisoft]
[HighMAT CD Writing Wizard]
[Incomplete]
[InstallShield Installation Information]
[Intel]
[InterActual]
[Internet Explorer]
[iPod]
[IrfanView]
[iTunes]
[Java]
[LitexMedia]
[Marvell]
[Messenger]
[Microsoft Calculator Plus]
[microsoft frontpage]
[Microsoft IntelliPoint]
[Microsoft IntelliType Pro]
[Microsoft Office]
[Microsoft Visual Studio]
[Microsoft Works]
[Microsoft.NET]
[Movie Maker]
[Mozilla Firefox]
[MSBuild]
[MSN Gaming Zone]
[MSN Messenger]
[MuvAudio]
[MyWay]
[NetMeeting]
[Netscape]
[NoAdware3]
[Online Services]
[Outlook Express]
[Queens of the Stone Age Active Desktop]
[QuickTime]
[Real]
[Samsung]
[Spyware Nuker 2004]
[Steinberg]
[tunebite]
[TurnTool]
[Uninstall Information]
[Waves]
[Western Digital Technologies]
[Winamp]
[Windows Journal Viewer]
[Windows Media Player]
[Windows NT]
[WindowsUpdate]
[WinRAR]
[xerox]
[Xvid]
0 File(s) 0 bytes
75 Dir(s) 4,599,631,872 bytes free
Eveything came us as 0 bytes...
[*]ComboFix Log
ComboFix 07-10-26.4 - Tom 2007-10-27 21:13:47.3 - NTFSx86
Running from: C:\Documents and Settings\Tom\My Documents\Virus Killers\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tom\Desktop\CFScript.txt
* Created a new restore point
FILE::
C:\134tmp.exe
C:\135tmp.exe
C:\13tmp.exe
C:\WINDOWS\system32\awtrrpo.dll
C:\WINDOWS\system32\cookie1.dat
C:\WINDOWS\system32\RabioSetup.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\134tmp.exe
C:\Documents and Settings\All Users\Application Data\Rabio
C:\WINDOWS\system32\cookie1.dat
C:\WINDOWS\system32\gugwuocq.dll
C:\WINDOWS\system32\ps1.dat
C:\WINDOWS\system32\RabioSetup.exe
C:\WINDOWS\system32\rc.dat
C:\WINDOWS\system32\vbmqmywp.dll
C:\WINDOWS\system32\yxlyosbu.dll
.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.
2007-10-27 20:43 <DIR> d----c--- C:\Documents and Settings\Tom\Application Data\AVG7
2007-10-27 20:42 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-27 20:42 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\avg7
2007-10-27 00:49 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-25 13:16 <DIR> d-------- C:\Program Files\Microsoft Calculator Plus
2007-10-22 23:23 <DIR> d-------- C:\Program Files\Microsoft IntelliType Pro
2007-10-22 22:52 2,440 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-22 22:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-22 22:49 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-22 19:47 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-22 19:47 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-22 19:47 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-22 19:47 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-22 19:47 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-22 13:18 <DIR> d-------- C:\Program Files\Adsense Helper Object
2007-10-22 00:50 <DIR> d----c--- C:\Documents and Settings\Tom\Application Data\Grisoft
2007-10-22 00:49 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-22 00:49 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-22 00:43 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-10-21 23:37 <DIR> d----c--- C:\VundoFix Backups
2007-10-21 23:22 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-10-21 23:14 <DIR> d----c--- C:\Documents and Settings\Tom\Application Data\GetRightToGo
2007-10-21 22:46 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-21 22:46 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-10-21 22:46 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-10-21 22:44 <DIR> d-------- C:\Program Files\Google
2007-10-21 19:01 <DIR> d--hs---- C:\WINDOWS\RFYgQ3VzdG9tZXI
2007-10-21 19:01 17,408 --a--c--- C:\psapi.dll
2007-10-19 21:27 <DIR> d-------- C:\Program Files\Xvid
2007-10-19 20:50 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-19 16:52 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-10-19 16:50 <DIR> d-------- C:\Program Files\MSBuild
2007-10-19 16:50 <DIR> d-------- C:\Program Files\Microsoft Works
2007-10-19 16:47 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-10-19 16:44 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-10-19 16:32 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-19 16:31 <DIR> dr-h-c--- C:\MSOCache
2007-10-19 15:42 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-10-19 15:32 <DIR> d-------- C:\WINDOWS\EHome
2007-10-17 12:55 <DIR> d----c--- C:\Temp
2007-10-17 12:32 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\shctxex.vb
2007-10-17 12:31 974,848 --a------ C:\WINDOWS\system32\mfc70.dll
2007-10-17 12:31 516,173 --a------ C:\WINDOWS\system32\msvcp60d.dll
2007-10-17 12:31 385,100 --a------ C:\WINDOWS\system32\MSVCRTD.DLL
2007-10-17 12:31 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-10-17 12:31 69,632 --a------ C:\WINDOWS\system32\vzcontextmenu.dll
2007-10-17 12:31 4,608 --a------ C:\WINDOWS\system32\W95INF32.DLL
2007-10-17 12:31 2,272 --a------ C:\WINDOWS\system32\W95INF16.DLL
2007-10-17 12:15 487,424 --a------ C:\WINDOWS\system32\msvcp70.dll
2007-10-17 11:53 <DIR> d----c--- C:\MediaCell
2007-10-17 11:21 <DIR> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-17 11:20 <DIR> d-------- C:\Program Files\Blaze Media Pro
2007-10-05 12:31 159,744 --a------ C:\WINDOWS\system32\lfpng13n.dll
2007-10-03 18:18 <DIR> d-------- C:\Program Files\MSN Messenger
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-20 09:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-19 19:30 --------- d-----w C:\Program Files\Waves
2007-10-19 19:30 --------- d-----w C:\Program Files\FLAC
2007-10-19 19:30 --------- d-----w C:\Program Files\DivX
2007-09-21 17:41 --------- d-----w C:\Program Files\Queens of the Stone Age Active Desktop
2007-09-21 11:18 --------- dc----w C:\Documents and Settings\Tom\Application Data\MSN6
2007-09-21 10:25 --------- dc----w C:\Documents and Settings\All Users\Application Data\MSN6
2007-09-17 01:50 15,939 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2007-09-12 14:30 --------- d-----w C:\Program Files\InterActual
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\WINDOWS\RFYgQ3VzdG9tZXI ----
((((((((((((((((((((((((((((( snapshot@2007-10-27_15.24.01.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-10-27 19:42:41 821,728 ----a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2007-10-27 19:42:45 4,224 ----a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
+ 2007-10-27 19:42:45 27,776 ----a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
+ 2007-10-27 19:42:47 3,968 ----a-w C:\WINDOWS\system32\drivers\avgclean.sys
+ 2007-10-27 19:42:47 19,904 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18FA53D3-B7A8-4309-8045-D43D6AA2DCE9}]
2007-10-22 13:18 26112 --a------ C:\Program Files\Adsense Helper Object\aho.v5.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-10-28 22:10]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 08:06 C:\WINDOWS\system32\ptipbmf.dll]
"SoundMan"="SOUNDMAN.EXE" [2004-01-08 19:54 C:\WINDOWS\SOUNDMAN.EXE]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2003-05-16 00:41]
"DeltTray"="DeltTray.exe" [2002-12-06 17:19 C:\WINDOWS\system32\delttray.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 17:28]
"NWEReboot"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-14 13:35]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 09:18]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"workflow"="E:\installs\workflow.exe" []
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2003-05-16 00:45]
"74c2da49"="C:\WINDOWS\system32\gugwuocq.dll" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-27 20:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"Ooei"="C:\PROGRA~1\COMMON~1\SKS~1\netdde.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Fast Start.lnk
backup=C:\WINDOWS\pss\Microsoft Office Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Find Fast Indexer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Find Fast Indexer.lnk
backup=C:\WINDOWS\pss\Microsoft Office Find Fast Indexer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Shortcut Bar.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office Shortcut Bar.lnk
backup=C:\WINDOWS\pss\Microsoft Office Shortcut Bar.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
R2 Belkin 54g Wireless USB Network Adapter Service;Belkin 54g Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
R3 Intels51;Intel(R) 536EP Modem;C:\WINDOWS\system32\DRIVERS\Intels51.sys
R3 NeroCd2k;NeroCd2k;C:\WINDOWS\system32\drivers\NeroCd2k.sys
S3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys
S3 UKS11LDR;M-Audio USB Keystation Loader;C:\WINDOWS\system32\drivers\uks11ldr.sys
S3 USBKT1X1;M-Audio USB Keystation;C:\WINDOWS\system32\drivers\usbkt1x1.sys
S3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\yukonx86.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-24 09:26:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 21:18:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-27 21:20:25 - machine was rebooted
C:\ComboFix2.txt ... 2007-10-27 15:24
.
--- E O F ---
[*]Contents of C:\Kresults.txt
Volume in drive C is System
Volume Serial Number is 74C2-DAE6
Directory of C:\Documents and Settings\Tom\Desktop
Volume in drive C is System
Volume Serial Number is 74C2-DAE6
Directory of C:\Documents and Settings\Tom\Desktop
Volume in drive C is System
Volume Serial Number is 74C2-DAE6
Directory of C:\Program Files
[.]
[..]
[Adobe]
[Adsense Helper Object]
[ahead]
[Analog Devices]
[Apple Software Update]
[ATI Technologies]
[AviSynth 2.5]
[Belkin]
[Blaze Media Pro]
[CDisplay]
[Common Files]
[ComPlus Applications]
[CyberLink]
[Digital Design Ltd]
[DivX]
[DVD Decrypter]
[ffdshow]
[FLAC]
[FLVPlayer]
[Google]
[Grisoft]
[HighMAT CD Writing Wizard]
[Incomplete]
[InstallShield Installation Information]
[Intel]
[InterActual]
[Internet Explorer]
[iPod]
[IrfanView]
[iTunes]
[Java]
[LitexMedia]
[Marvell]
[Messenger]
[Microsoft Calculator Plus]
[microsoft frontpage]
[Microsoft IntelliPoint]
[Microsoft IntelliType Pro]
[Microsoft Office]
[Microsoft Visual Studio]
[Microsoft Works]
[Microsoft.NET]
[Movie Maker]
[Mozilla Firefox]
[MSBuild]
[MSN Gaming Zone]
[MSN Messenger]
[MuvAudio]
[MyWay]
[NetMeeting]
[Netscape]
[NoAdware3]
[Online Services]
[Outlook Express]
[Queens of the Stone Age Active Desktop]
[QuickTime]
[Real]
[Samsung]
[Spyware Nuker 2004]
[Steinberg]
[tunebite]
[TurnTool]
[Uninstall Information]
[Waves]
[Western Digital Technologies]
[Winamp]
[Windows Journal Viewer]
[Windows Media Player]
[Windows NT]
[WindowsUpdate]
[WinRAR]
[xerox]
[Xvid]
0 File(s) 0 bytes
75 Dir(s) 4,599,631,872 bytes free