.
((((((((((((((((((((((((( Files Created from 2008-01-20 to 2008-02-20 )))))))))))))))))))))))))))))))
.
2008-02-18 07:19 . 2008-02-18 07:19 <DIR> d--hs---- C:\FOUND.000
2008-02-16 21:09 . 2008-02-16 21:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-16 14:48 . 2008-02-16 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-16 14:47 . 2008-02-16 14:47 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-02-15 09:04 . 2008-02-18 13:10 6,014 --a------ C:\WINDOWS\BMd711e700.xml
2008-02-15 09:04 . 2008-02-19 07:11 22 --a------ C:\WINDOWS\pskt.ini
2008-02-15 08:33 . 2008-02-15 08:33 <DIR> d-------- C:\mGame
2008-02-07 18:15 . 2008-02-07 18:15 67 --a------ C:\WINDOWS\101_ASB.INI
2008-02-07 18:14 . 2008-02-07 18:14 <DIR> d-------- C:\DISNEY
2008-02-02 21:39 . 2008-02-02 21:39 <DIR> d-------- C:\Documents and Settings\fjw\DoctorWeb
2008-01-31 22:34 . 2008-01-31 22:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-25 16:27 . 2008-01-25 16:27 110 --a------ C:\WINDOWS\HandySnap.INI
2008-01-22 22:01 . 2008-01-22 22:01 <DIR> d-------- C:\OutputFolder
2008-01-22 21:59 . 2008-01-22 21:59 <DIR> d-------- C:\Program Files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 14:39 186,000 ----a-w C:\Documents and Settings\fjw\Application Data\GDIPFONTCACHEV1.DAT
2008-01-14 13:49 155,648 ----a-w C:\WINDOWS\SYSTEM32\NeroCheck.exe
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\SYSTEM32\dllcache\pngfilt.dll
2007-12-26 05:07 8,413 ----a-w C:\WINDOWS\system32\drivers\mcstrm.sys
2007-12-26 05:07 --------- d-----w C:\Program Files\Common Files\Real
2007-12-26 05:03 --------- d-----w C:\Program Files\Best Buy Rhapsody
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\SYSTEM32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\SYSTEM32\dllcache\mrxdav.sys
2007-12-14 17:32 12,632 ----a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
2007-12-08 05:21 3,592,192 ------w C:\WINDOWS\SYSTEM32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\SYSTEM32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\SYSTEM32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS\SYSTEM32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\SYSTEM32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\SYSTEM32\dllcache\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\SYSTEM32\oleaut32.dll
2006-12-23 16:04 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2006-01-11 02:13 159,312 ----a-w C:\Documents and Settings\Jeremy\Application Data\GDIPFONTCACHEV1.DAT
2005-11-05 03:58 33,750 ----a-w C:\WINDOWS\Internet Logs\GLB98_2nd_2005_11_04_21_58_33.dmp.zip
2005-11-05 03:58 33,668 ------w C:\WINDOWS\Internet Logs\GLB8F_2nd_2005_11_04_21_57_55.dmp.zip
2005-10-05 00:50 89,304 ------w C:\WINDOWS\Internet Logs\vsmon_2nd_2005_10_04_18_41_53_small.dmp.zip
2005-10-05 00:50 79,592 ------w C:\WINDOWS\Internet Logs\vsmon_2nd_2005_10_04_18_41_35_small.dmp.zip
2005-10-05 00:50 79,542 ------w C:\WINDOWS\Internet Logs\vsmon_2nd_2005_10_04_18_42_35_small.dmp.zip
2005-10-05 00:40 12,377,066 ------w C:\WINDOWS\Internet Logs\ZLCLIENT_2nd_2005_10_04_17_59_25_full.dmp.zip
2005-04-04 22:23 0 ---h--w C:\Program Files\AppUpdate.log
2004-09-21 20:07 86,016 ----a-w C:\Program Files\SPInstall.exe
2004-09-21 16:54 975 ----a-w C:\Program Files\ReadMe.txt
2004-09-21 16:05 1,841 ----a-w C:\Program Files\PackingList.txt
2004-09-21 15:36 908 ----a-w C:\Program Files\Setup.ini
2004-09-21 15:36 19,443,744 ----a-w C:\Program Files\Data1.cab
2004-09-21 15:36 1,591,952 ----a-w C:\Program Files\SundayPlus.msi
2004-09-21 15:35 225,280 ----a-w C:\Program Files\SPSetupHelper.exe
2004-09-15 02:35 49,152 ----a-w C:\Program Files\EnglishUI.dll
2004-04-23 00:02 560 ----a-w C:\Program Files\Global.sw
2004-01-10 02:34 266 --sh--w C:\Program Files\desktop.ini
2003-02-25 15:04 4,632 ----a-w C:\Program Files\
0x0409.ini
2006-03-27 03:50 3,766 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
2006-03-27 03:50 88 --sh--r C:\WINDOWS\SYSTEM32\D4B12B0226.sys
.
Code:
<pre>
----a-w 1,743,360 2008-01-14 22:45:08 C:\RECYCLED\Dc6\StyleXP .exe
----a-w 1,372,160 2008-01-17 13:35:48 C:\RECYCLED\Dc6\StyleXP .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@={7D688A77-C613-11D0-999B-00C04FD655E1}
[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}]
2007-10-25 21:34 8460288 --a------ C:\WINDOWS\SYSTEM32\SHELL32.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:07 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 16:22 7618560]
"nwiz"="nwiz.exe" [2006-06-01 16:22 1519616 C:\WINDOWS\SYSTEM32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-06-01 16:22 86016]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 14:03 106544 C:\WINDOWS\SYSTEM32\TWEAKUI.CPL]
"ATIPTA"="atiptaxx.exe" [2001-09-27 01:39 245760 C:\WINDOWS\SYSTEM32\atiptaxx.exe]
C:\Documents and Settings\fjw\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-01-08 21:22:17 2746104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"<NO NAME>"= 00000000
"NoFavoritesMenu"= 01000000
"NoLogoff"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"<NO NAME>"= 00000000
"NoFavoritesMenu"= 01000000
"NoActiveDesktopChanges"= 0 (0x0)
"NoLogoff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Corel MEDIA FOLDERS INDEXER 8.LNK]
backup=C:\WINDOWS\pss\Corel MEDIA FOLDERS INDEXER 8.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Encoder Agent.lnk]
backup=C:\WINDOWS\pss\Encoder Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Cody^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiPTA]
--a------ 2001-09-27 01:39 245760 C:\WINDOWS\SYSTEM32\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AuthConsoleStart]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DesktopIconToy]
--a------ 2006-10-26 21:03 278528 C:\Program Files\Desktop Icon Toy\DesktopIconToy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ESP]
--a------ 2006-07-30 12:09 63008 C:\Program Files\Cox\Applications\app\start.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FolderShare]
C:\Program Files\FolderShare\FolderShare .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 15:49 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2003-03-26 05:34 172032 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-06-10 10:44 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-06-10 10:44 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogonStudio]
C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mobipocket Reader Notifications]
--a------ 2006-06-20 16:54 57344 C:\Program Files\Mobipocket.com\Mobipocket Reader\readernotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-02-13 18:24 2226688 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-01-14 07:49 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2008-02-16 14:49 2441216 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StarSkin]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
C:\Program Files\TGTSoft\StyleXP\StyleXP .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-05-14 17:22 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UPS"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
"LogitechSoftwareUpdate"="C:\PROGRAM FILES\LOGITECH\VIDEO\MANIFESTENGINE.EXE" boot
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"Tweak UI"=RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
"SiS Tray"=C:\WINDOWS\SYSTEM32\sistray.exe
"StillImageMonitor"=C:\WINDOWS\SYSTEM32\stimon.exe
R2 ppsio2;PPDevice;C:\WINDOWS\system32\drivers\ppsio2.sys [1999-04-01 19:16]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2001-09-27 00:32]
S3 BCM42XX;Broadcom iLine10(tm) Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [2001-08-17 12:11]
S3 dump_wmimmc;dump_wmimmc;C:\Program Files\Gpotato\Flyff\GameGuard\dump_wmimmc.sys []
S3 PhilCam8116;Logitech QuickCam Pro 3000 (08B0);C:\WINDOWS\system32\DRIVERS\CamDrO21.sys [2001-08-17 14:05]
S3 XDva090;XDva090;C:\WINDOWS\system32\XDva090.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\MmoptPreferredAudioDevices]
rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl,@0,SUSB\VID_046D&PID_08B0&MI_01\1USB&VID_046D&PID_08B0&INST_0
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-20 09:19:47
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-20 9:20:14
ComboFix-quarantined-files.txt 2008-02-20 15:20:14
ComboFix4.txt 2008-02-19 14:55:02
ComboFix3.txt 2008-02-19 18:44:16
ComboFix2.txt 2008-02-19 19:16:22
.
2008-02-15 05:58:29 --- E O F ---