memory
Daemon Poster
- Messages
- 992
- Location
- Southern Indiana
Okay, I have done what you said. Here is the Combofix log:
ComboFix 08-06-01.6 - Ken Graf 2008-06-04 19:28:26.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.448 [GMT -4:00]
Running from: C:\Documents and Settings\Ken Graf\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ken Graf\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\blackster.scr
C:\WINDOWS\system32\fccbXrOH.dll
C:\WINDOWS\system32\qaovuxif.dll
C:\WINDOWS\system32\tuvVNhec.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\06_Winter_031208.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\06_Winter_121807.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\06_Winter_121807_Mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\06_Winter_Mask_031208.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_Allergy.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_Allergy2.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_BeachAndBoating.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_Disney_Chance2Win.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_DisneyRoadTrip.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_GrHog_tile.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96PlusMobile.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60_blueyellow.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60_blueyellow_mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60_Generic200_Spring_Mask_031908.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60_Generic2007_Spring_031908.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_Hardware-PYP0508.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_Hardware-PYP0508.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_Hardware_Dig.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_Hardware_Dig.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_HelpMyHome.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_HelpMyHome.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-AceHardware_Leap.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-AceHardware_Leap.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-2nghtOvrl0508.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-2nghtOvrl0508.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-MonReg0508.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-MonReg0508.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-TmrOvrl0508.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-TmrOvrl0508.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ChantixAge_0108.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ChantixAge_0108.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ChantixDMA_0108.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ChantixDMA_0108.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-KraftHoneyBunches.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-KraftHoneyBunches.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Orlando.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Orlando_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Vicks1007.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Vicks1007.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales_Alaway_mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales_Alaway_shell.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales_Sudafed_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales_Sudafed_shell.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\GoToMeeting.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\GoToMeeting_Mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Hartford_Insurance_Approved.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Hartford_Insurance_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Kmart.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Kmart_Mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\LocalWeather.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\LocalWeather_Mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Lowes_APPROVED.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Lowes_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Lowes_Mask_NoShadow.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Lowes_Skin_NoShadow.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\nav_07182007.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Take-Me-Fishing_APPROVED.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Take Me Fishing_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\topnav_Business.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Verizon_Bubble_0208.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Verizon_Bubble_0208_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\WeatherAlert.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\WeatherAlert_Mask.bmp
C:\Program Files\MyWebSearchWB
C:\Program Files\MyWebSearchWB\bar\1.bin\NPMYSRWB.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6FFXTBR.JAR
C:\Program Files\MyWebSearchWB\bar\1.bin\W6NTSTBR.JAR
C:\Program Files\MyWebSearchWB\bar\1.bin\W6PLUGIN.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6WBTEMP.DLL
C:\Program Files\MyWebSearchWB\bar\Cache\0000F1E1.bin
C:\Program Files\MyWebSearchWB\bar\Cache\000175C7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00022E0B.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00024D89.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0002BA8C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\000720E3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00078D69.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00089D71.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00190834.bin
C:\Program Files\MyWebSearchWB\bar\Cache\001C481C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\001E4D72.bin
C:\Program Files\MyWebSearchWB\bar\Cache\001EE760.bin
C:\Program Files\MyWebSearchWB\bar\Cache\001FA253.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0020112A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0037C43E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00393533.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A6CF8.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A6E7F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A6FB7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A7044.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A71AB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003CED88.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0053CF62.bin
C:\Program Files\MyWebSearchWB\bar\Cache\005450C7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0058BBA3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\006D62EE.bin
C:\Program Files\MyWebSearchWB\bar\Cache\006D63F7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\006D75AA.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00704EFA.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0070509F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\008F22B3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00D87C59.bin
C:\Program Files\MyWebSearchWB\bar\Cache\010B8FF8.bin
C:\Program Files\MyWebSearchWB\bar\Cache\01800DEE.bin
C:\Program Files\MyWebSearchWB\bar\Cache\01C12A05.bin
C:\Program Files\MyWebSearchWB\bar\Cache\02122CBB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\02302A09.bin
C:\Program Files\MyWebSearchWB\bar\Cache\02896906.bin
C:\Program Files\MyWebSearchWB\bar\Cache\028E3C31.bin
C:\Program Files\MyWebSearchWB\bar\Cache\03750A8E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\05309280
C:\Program Files\MyWebSearchWB\bar\Cache\05753C33.bin
C:\Program Files\MyWebSearchWB\bar\Cache\05C6C483.bin
C:\Program Files\MyWebSearchWB\bar\Cache\063F4E2E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\06C8CF3A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\06FB2C8A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0AF87BEC.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0B519494.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0D72CF31.bin
C:\Program Files\MyWebSearchWB\bar\Cache\11D62087.bin
C:\Program Files\MyWebSearchWB\bar\Cache\18F6935D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1BD6DDF7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\23D3D793.bin
C:\Program Files\MyWebSearchWB\bar\Cache\24AFA683.bin
C:\Program Files\MyWebSearchWB\bar\Cache\files.ini
C:\Program Files\MyWebSearchWB\bar\History\search
C:\Program Files\MyWebSearchWB\bar\Settings\prevcfg.htm
C:\WINDOWS\system32\blackster.scr
.
((((((((((((((((((((((((( Files Created from 2008-05-04 to 2008-06-04 )))))))))))))))))))))))))))))))
.
2008-06-04 19:31 . 2008-06-04 19:33 <DIR> d-------- C:\Documents and Settings\Ken Graf\Application Data\WeatherBug
2008-05-28 16:03 . 2008-05-28 16:07 191 --a------ C:\WINDOWS\wininit.ini
2008-05-28 15:38 . 2008-05-28 15:38 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-28 15:38 . 2008-05-28 16:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-28 14:15 . 2008-05-28 14:15 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-28 14:15 . 2008-05-28 14:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-24 21:52 . 2008-05-24 21:52 <DIR> d-------- C:\Documents and Settings\Ken Graf\LocalLow
2008-05-24 21:52 . 2008-05-24 21:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-05-24 21:46 . 2008-05-24 21:46 <DIR> d-------- C:\Program Files\SopCast
2008-05-24 21:46 . 2008-05-24 21:47 <DIR> d-------- C:\Documents and Settings\Ken Graf\Application Data\SopCast
2008-05-04 13:38 . 2008-05-28 14:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-04 23:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-05-14 20:12 --------- d-----w C:\Program Files\Songbird
2008-04-21 20:37 --------- d-----w C:\Program Files\iTunes
2008-04-21 20:37 --------- d-----w C:\Program Files\iPod
2008-04-21 20:36 --------- d-----w C:\Program Files\QuickTime
2008-04-21 20:33 --------- d-----w C:\Program Files\Apple Software Update
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-04 22:52 286,720 ----a-w C:\WINDOWS\system32\libcurl.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Documents and Settings\Ken Graf\LocalLow ----
2008-05-24 22:48 194414 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\ChannelList.xml
2008-05-24 22:33 228 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\PeerList.xml
2008-05-24 22:17 2614272 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\TVU
2008-05-24 21:53 898 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\5225.png
2008-05-24 21:53 851 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\5455.png
2008-05-24 21:53 619 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\MAVTV.png
2008-05-24 21:53 585 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\9000.png
2008-05-24 21:53 574 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\640.png
2008-05-24 21:53 547 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\620.png
2008-05-24 21:53 536 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\CNA.png
2008-05-24 21:53 502 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\8670.png
2008-05-24 21:53 485 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\212.png
2008-05-24 21:53 474 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\CNTV.png
2008-05-24 21:53 402 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\Nostalgia.png
2008-05-24 21:53 317 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\5933.png
2008-05-24 21:53 1434 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\570.png
2008-05-24 21:53 1339 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\530.png
2008-05-24 21:53 13312 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\DownDatabase.Xml
2008-05-24 21:53 1285 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\TV9.gif
2008-05-24 21:53 1175 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\ETTV.png
2008-05-24 21:52 611 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\5500.png
2008-05-24 21:52 566 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\4000.png
2008-05-24 21:52 510 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\ANTV.png
2008-05-24 21:52 409 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\PDTV.png
2008-05-24 21:52 3684 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\OCJ.png
2008-05-24 21:52 1348 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\270.png
((((((((((((((((((((((((((((( snapshot@2008-06-03_17.56.50.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-03 21:51:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-04 23:31:15 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-04-02 21:07 389120]
"Weather"="C:\PROGRA~1\AWS\WEATHE~1\Weather.exe" [2006-04-07 16:02 1343488]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-30 16:40 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 18:42 1404928]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-19 15:53 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-26 18:51 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-20 23:15:54 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCPxpsp2res.dll,-22009
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2002-08-28 18:59]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-31 12:17:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-04 19:31:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-06-04 19:37:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-04 23:37:23
ComboFix2.txt 2008-06-03 21:57:04
Pre-Run: 71,640,195,072 bytes free
Post-Run: 71,800,778,752 bytes free
277 --- E O F --- 2008-06-03 13:00:49
It turns out I can't post both logs in the same post because there is too many characters.
ComboFix 08-06-01.6 - Ken Graf 2008-06-04 19:28:26.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.448 [GMT -4:00]
Running from: C:\Documents and Settings\Ken Graf\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ken Graf\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\blackster.scr
C:\WINDOWS\system32\fccbXrOH.dll
C:\WINDOWS\system32\qaovuxif.dll
C:\WINDOWS\system32\tuvVNhec.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\06_Winter_031208.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\06_Winter_121807.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\06_Winter_121807_Mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\06_Winter_Mask_031208.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_Allergy.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_Allergy2.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_BeachAndBoating.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_Disney_Chance2Win.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_DisneyRoadTrip.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96_GrHog_tile.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\102x96PlusMobile.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60_blueyellow.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60_blueyellow_mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60_Generic200_Spring_Mask_031908.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60_Generic2007_Spring_031908.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_Hardware-PYP0508.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_Hardware-PYP0508.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_Hardware_Dig.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_Hardware_Dig.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_HelpMyHome.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ACE_HelpMyHome.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-AceHardware_Leap.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-AceHardware_Leap.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-2nghtOvrl0508.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-2nghtOvrl0508.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-MonReg0508.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-MonReg0508.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-TmrOvrl0508.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Andromeda-TmrOvrl0508.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ChantixAge_0108.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ChantixAge_0108.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ChantixDMA_0108.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-ChantixDMA_0108.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-KraftHoneyBunches.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-KraftHoneyBunches.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Orlando.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Orlando_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Vicks1007.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales-Vicks1007.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales_Alaway_mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales_Alaway_shell.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales_Sudafed_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\60Sales_Sudafed_shell.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\GoToMeeting.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\GoToMeeting_Mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Hartford_Insurance_Approved.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Hartford_Insurance_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Kmart.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Kmart_Mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\LocalWeather.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\LocalWeather_Mask.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Lowes_APPROVED.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Lowes_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Lowes_Mask_NoShadow.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Lowes_Skin_NoShadow.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\nav_07182007.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Take-Me-Fishing_APPROVED.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Take Me Fishing_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\topnav_Business.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Verizon_Bubble_0208.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\Verizon_Bubble_0208_MASK.bmp
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\WeatherAlert.jpg
C:\Documents and Settings\Ken Graf\Application Data\WeatherBug\WeatherAlert_Mask.bmp
C:\Program Files\MyWebSearchWB
C:\Program Files\MyWebSearchWB\bar\1.bin\NPMYSRWB.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6FFXTBR.JAR
C:\Program Files\MyWebSearchWB\bar\1.bin\W6NTSTBR.JAR
C:\Program Files\MyWebSearchWB\bar\1.bin\W6PLUGIN.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6WBTEMP.DLL
C:\Program Files\MyWebSearchWB\bar\Cache\0000F1E1.bin
C:\Program Files\MyWebSearchWB\bar\Cache\000175C7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00022E0B.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00024D89.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0002BA8C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\000720E3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00078D69.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00089D71.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00190834.bin
C:\Program Files\MyWebSearchWB\bar\Cache\001C481C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\001E4D72.bin
C:\Program Files\MyWebSearchWB\bar\Cache\001EE760.bin
C:\Program Files\MyWebSearchWB\bar\Cache\001FA253.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0020112A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0037C43E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00393533.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A6CF8.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A6E7F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A6FB7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A7044.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003A71AB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\003CED88.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0053CF62.bin
C:\Program Files\MyWebSearchWB\bar\Cache\005450C7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0058BBA3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\006D62EE.bin
C:\Program Files\MyWebSearchWB\bar\Cache\006D63F7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\006D75AA.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00704EFA.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0070509F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\008F22B3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\00D87C59.bin
C:\Program Files\MyWebSearchWB\bar\Cache\010B8FF8.bin
C:\Program Files\MyWebSearchWB\bar\Cache\01800DEE.bin
C:\Program Files\MyWebSearchWB\bar\Cache\01C12A05.bin
C:\Program Files\MyWebSearchWB\bar\Cache\02122CBB.bin
C:\Program Files\MyWebSearchWB\bar\Cache\02302A09.bin
C:\Program Files\MyWebSearchWB\bar\Cache\02896906.bin
C:\Program Files\MyWebSearchWB\bar\Cache\028E3C31.bin
C:\Program Files\MyWebSearchWB\bar\Cache\03750A8E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\05309280
C:\Program Files\MyWebSearchWB\bar\Cache\05753C33.bin
C:\Program Files\MyWebSearchWB\bar\Cache\05C6C483.bin
C:\Program Files\MyWebSearchWB\bar\Cache\063F4E2E.bin
C:\Program Files\MyWebSearchWB\bar\Cache\06C8CF3A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\06FB2C8A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0AF87BEC.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0B519494.bin
C:\Program Files\MyWebSearchWB\bar\Cache\0D72CF31.bin
C:\Program Files\MyWebSearchWB\bar\Cache\11D62087.bin
C:\Program Files\MyWebSearchWB\bar\Cache\18F6935D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1BD6DDF7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\23D3D793.bin
C:\Program Files\MyWebSearchWB\bar\Cache\24AFA683.bin
C:\Program Files\MyWebSearchWB\bar\Cache\files.ini
C:\Program Files\MyWebSearchWB\bar\History\search
C:\Program Files\MyWebSearchWB\bar\Settings\prevcfg.htm
C:\WINDOWS\system32\blackster.scr
.
((((((((((((((((((((((((( Files Created from 2008-05-04 to 2008-06-04 )))))))))))))))))))))))))))))))
.
2008-06-04 19:31 . 2008-06-04 19:33 <DIR> d-------- C:\Documents and Settings\Ken Graf\Application Data\WeatherBug
2008-05-28 16:03 . 2008-05-28 16:07 191 --a------ C:\WINDOWS\wininit.ini
2008-05-28 15:38 . 2008-05-28 15:38 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-28 15:38 . 2008-05-28 16:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-28 14:15 . 2008-05-28 14:15 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-28 14:15 . 2008-05-28 14:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-24 21:52 . 2008-05-24 21:52 <DIR> d-------- C:\Documents and Settings\Ken Graf\LocalLow
2008-05-24 21:52 . 2008-05-24 21:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-05-24 21:46 . 2008-05-24 21:46 <DIR> d-------- C:\Program Files\SopCast
2008-05-24 21:46 . 2008-05-24 21:47 <DIR> d-------- C:\Documents and Settings\Ken Graf\Application Data\SopCast
2008-05-04 13:38 . 2008-05-28 14:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-04 23:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-05-14 20:12 --------- d-----w C:\Program Files\Songbird
2008-04-21 20:37 --------- d-----w C:\Program Files\iTunes
2008-04-21 20:37 --------- d-----w C:\Program Files\iPod
2008-04-21 20:36 --------- d-----w C:\Program Files\QuickTime
2008-04-21 20:33 --------- d-----w C:\Program Files\Apple Software Update
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-04 22:52 286,720 ----a-w C:\WINDOWS\system32\libcurl.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Documents and Settings\Ken Graf\LocalLow ----
2008-05-24 22:48 194414 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\ChannelList.xml
2008-05-24 22:33 228 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\PeerList.xml
2008-05-24 22:17 2614272 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\TVU
2008-05-24 21:53 898 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\5225.png
2008-05-24 21:53 851 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\5455.png
2008-05-24 21:53 619 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\MAVTV.png
2008-05-24 21:53 585 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\9000.png
2008-05-24 21:53 574 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\640.png
2008-05-24 21:53 547 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\620.png
2008-05-24 21:53 536 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\CNA.png
2008-05-24 21:53 502 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\8670.png
2008-05-24 21:53 485 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\212.png
2008-05-24 21:53 474 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\CNTV.png
2008-05-24 21:53 402 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\Nostalgia.png
2008-05-24 21:53 317 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\5933.png
2008-05-24 21:53 1434 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\570.png
2008-05-24 21:53 1339 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\530.png
2008-05-24 21:53 13312 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\DownDatabase.Xml
2008-05-24 21:53 1285 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\TV9.gif
2008-05-24 21:53 1175 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\ETTV.png
2008-05-24 21:52 611 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\5500.png
2008-05-24 21:52 566 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\4000.png
2008-05-24 21:52 510 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\ANTV.png
2008-05-24 21:52 409 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\PDTV.png
2008-05-24 21:52 3684 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\OCJ.png
2008-05-24 21:52 1348 --a------ C:\Documents and Settings\Ken Graf\LocalLow\TVU Networks\TVUPlayer\logo\270.png
((((((((((((((((((((((((((((( snapshot@2008-06-03_17.56.50.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-03 21:51:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-04 23:31:15 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-04-02 21:07 389120]
"Weather"="C:\PROGRA~1\AWS\WEATHE~1\Weather.exe" [2006-04-07 16:02 1343488]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-30 16:40 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 18:42 1404928]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-19 15:53 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-26 18:51 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-20 23:15:54 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCPxpsp2res.dll,-22009
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2002-08-28 18:59]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-31 12:17:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-04 19:31:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-06-04 19:37:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-04 23:37:23
ComboFix2.txt 2008-06-03 21:57:04
Pre-Run: 71,640,195,072 bytes free
Post-Run: 71,800,778,752 bytes free
277 --- E O F --- 2008-06-03 13:00:49
It turns out I can't post both logs in the same post because there is too many characters.