Wiegenlied
New member
ComboFix 07-12-09.1 - Ming 2007-12-14 18:28:45.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.470 [GMT -5:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\cjubpeig.exe
C:\WINDOWS\system32\msenmebo.ini
C:\WINDOWS\system32\xrcdteau.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\msenmebo.ini
C:\WINDOWS\system32\xrcdteau.ini
.
((((((((((((((((((((((((( Files Created from 2007-11-14 to 2007-12-14 )))))))))))))))))))))))))))))))
.
2007-12-13 22:08 . 2006-10-04 21:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-12-13 22:08 . 2006-10-04 21:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-12-13 22:05 . 2007-12-13 22:08 <DIR> d-------- C:\Program Files\Picasa2
2007-12-11 17:52 . 2007-12-14 18:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-11 17:52 . 2007-12-11 17:52 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-10 21:16 . 2007-12-10 21:16 1,596,353 --a------ C:\ComboFix.exe
2007-12-09 18:43 . 2007-12-09 18:44 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-07 18:32 . 2007-12-08 01:07 <DIR> d-------- C:\Program Files\Opera
2007-12-03 10:50 . 2007-12-03 10:50 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-03 10:50 . 2007-12-03 10:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-28 22:14 . 2006-10-18 05:29 102,400 --a------ C:\WINDOWS\system32\wdapi811.dll
2007-11-28 22:14 . 2007-01-10 14:23 17,424 --a------ C:\WINDOWS\system32\drivers\ezusb.sys
2007-11-28 22:13 . 2007-11-28 22:13 <DIR> d-------- C:\Program Files\Vernier Software
2007-11-28 22:07 . 2007-11-28 22:07 <DIR> d-------- C:\Documents and Settings\Ming\Application Data\InstallShield
2007-11-28 19:10 . 2007-11-28 19:10 4,128 --a------ C:\INFCACHE.1
2007-11-27 20:51 . 2007-11-27 20:51 <DIR> d-------- C:\Program Files\Common Files\TI Shared
2007-11-27 20:51 . 2006-10-16 03:19 194,362 --a------ C:\WINDOWS\system32\drivers\windrvr6.sys
2007-11-27 20:51 . 2005-03-21 04:05 110,592 --a------ C:\WINDOWS\system32\wd_utils.dll
2007-11-27 20:51 . 2004-02-04 11:27 49,536 --------- C:\WINDOWS\system32\drivers\tiehdusb.sys
2007-11-27 20:51 . 2003-11-14 15:53 11,520 --------- C:\WINDOWS\system32\drivers\wdmstub.sys
2007-11-27 20:50 . 2007-11-28 22:14 <DIR> d-------- C:\Program Files\Common Files\Vernier Software
2007-11-26 19:46 . 2007-11-26 19:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-22 22:47 . 2007-11-22 22:47 401,720 --a------ C:\Wiegenlied.exe
2007-11-21 18:20 . 2007-12-09 14:26 143 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-11-19 22:52 . 2007-11-24 17:33 686,405 --ahs---- C:\WINDOWS\system32\pkggetla.ini
2007-11-17 15:04 . 2007-11-17 15:04 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-14 03:06 --------- d-----w C:\Program Files\Google
2007-12-01 18:05 --------- d-----w C:\Documents and Settings\Ming\Application Data\LimeWire
2007-11-29 03:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-21 02:25 --------- d-----w C:\Documents and Settings\Ming\Application Data\U3
2007-11-21 01:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-20 02:49 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-06 03:40 --------- d-----w C:\Program Files\iTunes
2007-11-06 02:48 --------- d-----w C:\Program Files\iPod
2007-11-06 02:45 --------- d-----w C:\Program Files\QuickTime
2007-11-04 01:55 --------- d-----w C:\Program Files\Rogers
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2006-01-02 22:04 11,817,800 ----a-w C:\Program Files\GoogleEarth.exe
2006-06-29 17:41 56 --sh--r C:\WINDOWS\system32\42F1E6AC8F.sys
2006-06-29 17:41 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-12-12_19.00.21.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-04-25 08:03:00 20,640 ----a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
+ 2006-09-27 21:53:22 36,560 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
- 2007-11-07 02:16:06 55,132 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-13 05:30:46 54,614 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-07 02:16:07 385,806 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-13 05:30:46 384,930 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2005-05-05 19:50:06 372,736 ----a-w C:\WINDOWS\system32\Px.dll
+ 2006-09-27 21:53:22 514,808 ------w C:\WINDOWS\system32\Px.dll
- 2005-05-06 07:01:00 421,888 ----a-w C:\WINDOWS\system32\pxdrv.dll
+ 2006-09-27 21:53:22 477,944 ------w C:\WINDOWS\system32\pxdrv.dll
+ 2006-09-27 21:53:22 68,344 ------w C:\WINDOWS\system32\pxhpinst.exe
- 2005-05-05 19:49:08 172,032 ----a-w C:\WINDOWS\system32\PxMas.dll
+ 2006-09-27 21:53:22 183,032 ------w C:\WINDOWS\system32\PxMas.dll
- 2005-05-05 19:48:40 339,968 ----a-w C:\WINDOWS\system32\PxWave.dll
+ 2006-09-27 21:53:23 379,640 ------w C:\WINDOWS\system32\PxWave.dll
- 2005-01-12 07:00:00 28,672 ----a-w C:\WINDOWS\system32\VXBLOCK.dll
+ 2006-09-27 21:53:23 39,672 ------w C:\WINDOWS\system32\VXBLOCK.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8DAA3596-B635-4B47-912F-145073B8C320}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-04-25 09:46]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 17:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 15:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 21:15]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 20:05]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 19:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 08:48]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:00]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 06:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 06:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 09:22]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 13:46]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 14:04]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 16:14]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2004-11-11 21:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 06:00]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk.disabled [2006-07-04 14:23:38]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-12-14 10:06:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebbxyy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R3 WinDriver6;WinDriver6;C:\WINDOWS\system32\drivers\windrvr6.sys
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1ff62b5-d32f-11db-8d73-001422e427a4}]
\Shell\AutoRun\command - E:\Installer.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-07 23:04:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-12-20 14:35:50 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-12-14 01:16:16 C:\WINDOWS\Tasks\User_Feed_Synchronization-{8F6927C2-9DCB-4003-BF52-5AF45CCC4EBA}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-14 18:31:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-14 18:32:43
C:\ComboFix2.txt ... 2007-12-12 19:01
.
--- E O F ---
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.470 [GMT -5:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\cjubpeig.exe
C:\WINDOWS\system32\msenmebo.ini
C:\WINDOWS\system32\xrcdteau.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\msenmebo.ini
C:\WINDOWS\system32\xrcdteau.ini
.
((((((((((((((((((((((((( Files Created from 2007-11-14 to 2007-12-14 )))))))))))))))))))))))))))))))
.
2007-12-13 22:08 . 2006-10-04 21:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-12-13 22:08 . 2006-10-04 21:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-12-13 22:05 . 2007-12-13 22:08 <DIR> d-------- C:\Program Files\Picasa2
2007-12-11 17:52 . 2007-12-14 18:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-11 17:52 . 2007-12-11 17:52 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-10 21:16 . 2007-12-10 21:16 1,596,353 --a------ C:\ComboFix.exe
2007-12-09 18:43 . 2007-12-09 18:44 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-07 18:32 . 2007-12-08 01:07 <DIR> d-------- C:\Program Files\Opera
2007-12-03 10:50 . 2007-12-03 10:50 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-03 10:50 . 2007-12-03 10:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-28 22:14 . 2006-10-18 05:29 102,400 --a------ C:\WINDOWS\system32\wdapi811.dll
2007-11-28 22:14 . 2007-01-10 14:23 17,424 --a------ C:\WINDOWS\system32\drivers\ezusb.sys
2007-11-28 22:13 . 2007-11-28 22:13 <DIR> d-------- C:\Program Files\Vernier Software
2007-11-28 22:07 . 2007-11-28 22:07 <DIR> d-------- C:\Documents and Settings\Ming\Application Data\InstallShield
2007-11-28 19:10 . 2007-11-28 19:10 4,128 --a------ C:\INFCACHE.1
2007-11-27 20:51 . 2007-11-27 20:51 <DIR> d-------- C:\Program Files\Common Files\TI Shared
2007-11-27 20:51 . 2006-10-16 03:19 194,362 --a------ C:\WINDOWS\system32\drivers\windrvr6.sys
2007-11-27 20:51 . 2005-03-21 04:05 110,592 --a------ C:\WINDOWS\system32\wd_utils.dll
2007-11-27 20:51 . 2004-02-04 11:27 49,536 --------- C:\WINDOWS\system32\drivers\tiehdusb.sys
2007-11-27 20:51 . 2003-11-14 15:53 11,520 --------- C:\WINDOWS\system32\drivers\wdmstub.sys
2007-11-27 20:50 . 2007-11-28 22:14 <DIR> d-------- C:\Program Files\Common Files\Vernier Software
2007-11-26 19:46 . 2007-11-26 19:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-22 22:47 . 2007-11-22 22:47 401,720 --a------ C:\Wiegenlied.exe
2007-11-21 18:20 . 2007-12-09 14:26 143 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-11-19 22:52 . 2007-11-24 17:33 686,405 --ahs---- C:\WINDOWS\system32\pkggetla.ini
2007-11-17 15:04 . 2007-11-17 15:04 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-14 03:06 --------- d-----w C:\Program Files\Google
2007-12-01 18:05 --------- d-----w C:\Documents and Settings\Ming\Application Data\LimeWire
2007-11-29 03:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-21 02:25 --------- d-----w C:\Documents and Settings\Ming\Application Data\U3
2007-11-21 01:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-20 02:49 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-06 03:40 --------- d-----w C:\Program Files\iTunes
2007-11-06 02:48 --------- d-----w C:\Program Files\iPod
2007-11-06 02:45 --------- d-----w C:\Program Files\QuickTime
2007-11-04 01:55 --------- d-----w C:\Program Files\Rogers
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2006-01-02 22:04 11,817,800 ----a-w C:\Program Files\GoogleEarth.exe
2006-06-29 17:41 56 --sh--r C:\WINDOWS\system32\42F1E6AC8F.sys
2006-06-29 17:41 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-12-12_19.00.21.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-04-25 08:03:00 20,640 ----a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
+ 2006-09-27 21:53:22 36,560 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
- 2007-11-07 02:16:06 55,132 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-13 05:30:46 54,614 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-07 02:16:07 385,806 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-13 05:30:46 384,930 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2005-05-05 19:50:06 372,736 ----a-w C:\WINDOWS\system32\Px.dll
+ 2006-09-27 21:53:22 514,808 ------w C:\WINDOWS\system32\Px.dll
- 2005-05-06 07:01:00 421,888 ----a-w C:\WINDOWS\system32\pxdrv.dll
+ 2006-09-27 21:53:22 477,944 ------w C:\WINDOWS\system32\pxdrv.dll
+ 2006-09-27 21:53:22 68,344 ------w C:\WINDOWS\system32\pxhpinst.exe
- 2005-05-05 19:49:08 172,032 ----a-w C:\WINDOWS\system32\PxMas.dll
+ 2006-09-27 21:53:22 183,032 ------w C:\WINDOWS\system32\PxMas.dll
- 2005-05-05 19:48:40 339,968 ----a-w C:\WINDOWS\system32\PxWave.dll
+ 2006-09-27 21:53:23 379,640 ------w C:\WINDOWS\system32\PxWave.dll
- 2005-01-12 07:00:00 28,672 ----a-w C:\WINDOWS\system32\VXBLOCK.dll
+ 2006-09-27 21:53:23 39,672 ------w C:\WINDOWS\system32\VXBLOCK.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8DAA3596-B635-4B47-912F-145073B8C320}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-04-25 09:46]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 17:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 15:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 21:15]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 20:05]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 19:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 08:48]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:00]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 06:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 06:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 09:22]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 13:46]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 14:04]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 16:14]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2004-11-11 21:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 06:00]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk.disabled [2006-07-04 14:23:38]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-12-14 10:06:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebbxyy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R3 WinDriver6;WinDriver6;C:\WINDOWS\system32\drivers\windrvr6.sys
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1ff62b5-d32f-11db-8d73-001422e427a4}]
\Shell\AutoRun\command - E:\Installer.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-07 23:04:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-12-20 14:35:50 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-12-14 01:16:16 C:\WINDOWS\Tasks\User_Feed_Synchronization-{8F6927C2-9DCB-4003-BF52-5AF45CCC4EBA}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-14 18:31:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-14 18:32:43
C:\ComboFix2.txt ... 2007-12-12 19:01
.
--- E O F ---