shades9323
Baseband Member
- Messages
- 59
ComboFix 08-05-21.3 - Scott 2008-05-23 22:07:00.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.220 [GMT -4:00]
Running from: C:\Documents and Settings\Scott\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Scott\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Program Files\Internet Explorer\kyzeqe.html
C:\Program Files\Online Services\howynyka.html
C:\WINDOWS\system32\barseek.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Brooke\Application Data\ECURIT~1
C:\Documents and Settings\Brooke\Application Data\FNTS~1
C:\Documents and Settings\Brooke\My Documents\RACLE~1
C:\Documents and Settings\Brooke\My Documents\SSEMBL~1
C:\Documents and Settings\Brooke\My Documents\WNSXS~1
C:\Documents and Settings\Scott\Application Data\ErrorProtector Free
C:\Documents and Settings\Scott\Application Data\install.dat
C:\Documents and Settings\Scott\Application Data\WinTouch
C:\Documents and Settings\Scott\Application Data\YSTEM3~1
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\Scott\My Documents\ICROSO~1
C:\Documents and Settings\Scott\My Documents\STEM~1
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-119
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-145
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-199
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-261
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-266
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-273
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-284
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-300
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-328
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-332
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-356
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-358
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-371
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-407
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-422
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-423
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-428
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-453-Z_Start.lnk
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-453
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-456
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-526
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-542
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-544
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-545
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-598
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-621
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-622
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-650
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-661
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-703
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-752
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-755
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-756
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-776
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-779
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-894
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-929
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-962
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-974
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-998
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\default.xex
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\HijackThis.exe
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\hijackthis.log
C:\Documents and Settings\Scott\My Documents\YSTEM3~1
C:\PROGRA~1\COMMON~1\miiu
C:\PROGRA~1\COMMON~1\miiu\miiua.lck
C:\PROGRA~1\COMMON~1\miiu\miiud\class-barrel
C:\PROGRA~1\COMMON~1\miiu\miiul.lck
C:\PROGRA~1\COMMON~1\miiu\miium.lck
C:\PROGRA~1\COMMON~1\miiu\miiup.lck
C:\Program Files\Common Files\{B4BDA~1
C:\Program Files\Common Files\{B4BDA~2
C:\Program Files\Common Files\{B4BDA~3
C:\Program Files\Common Files\simtest
C:\Program Files\Common Files\sks~1
C:\Program Files\inetget2
C:\Program Files\JavaCore
C:\Program Files\JavaCore\JavaCore.exe
C:\Program Files\outerinfo
C:\Program Files\Router
C:\Program Files\stem32~1
C:\Program Files\windows
C:\WINDOWS\ms011262639300-2006.exe
C:\WINDOWS\ssembl~1
C:\WINDOWS\system32\cemetrix.dll
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\wnsintit.exe
C:\WINDOWS\system32\wnsintsv32.exe
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\system32\ystem~1\?ystem\
C:\WINDOWS\system32\ystem~1\wowexec.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_COM+_MESSAGES
-------\Legacy_NETWORK_MONITOR
-------\Legacy_WINDOWS_OVERLAY_COMPONENTS
((((((((((((((((((((((((( Files Created from 2008-04-24 to 2008-05-24 )))))))))))))))))))))))))))))))
.
2008-05-23 18:30 . 2008-05-23 18:30 <DIR> d-------- C:\Deckard
2008-05-14 20:00 . 2008-05-14 20:00 <DIR> d-------- C:\CB_3075
2008-05-14 19:57 . 2008-05-14 19:57 <DIR> d-------- C:\WINDOWS\A5W_DATA
2008-05-14 19:57 . 2008-05-14 19:57 28,042 --a------ C:\WINDOWS\Run32A50.mch
2008-05-14 19:57 . 2008-05-14 19:57 35 --a------ C:\WINDOWS\A5W.INI
2008-05-14 19:56 . 2008-05-14 19:56 <DIR> d-------- C:\CB_3058
2008-05-14 19:50 . 2008-05-14 19:50 <DIR> d-------- C:\Program Files\EpiCalc 2000
2008-05-14 19:50 . 2008-05-21 12:34 4,840 --a------ C:\WINDOWS\EpiCalc.ini
2008-05-14 19:49 . 1996-11-05 16:13 299,008 --a------ C:\WINDOWS\uninst.exe
2008-05-13 07:27 . 2008-05-13 07:27 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-13 07:27 . 2008-05-13 07:27 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-02 00:05 . 2008-05-02 00:05 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-05-01 23:53 . 2008-05-01 23:54 <DIR> d-------- C:\Program Files\Ruckus Player
2008-05-01 23:53 . 2008-05-01 23:55 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-05-01 23:53 . 2008-05-01 23:53 <DIR> d-------- C:\Documents and Settings\Scott\.realobjects
2008-04-30 19:01 . 2008-04-30 19:01 <DIR> d-------- C:\Program Files\ESET
2008-04-30 19:01 . 2008-04-30 19:01 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\Uniblue
2008-04-30 19:01 . 2008-04-30 19:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-04-27 11:57 . 2008-04-27 11:58 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-26 19:47 . 2008-05-01 23:55 <DIR> d-------- C:\Program Files\Spyware Doctor
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-24 02:16 --------- d-----w C:\Documents and Settings\Scott\Application Data\AVG7
2008-05-20 22:26 --------- d-----w C:\Documents and Settings\Brooke\Application Data\AVG7
2008-05-14 00:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-02 04:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-02 04:04 --------- d--h--w C:\Documents and Settings\Scott\Application Data\Move Networks
2008-05-02 04:04 --------- d-----w C:\Program Files\McAfee.com
2008-05-02 04:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-05-02 03:55 --------- d-----w C:\Program Files\WAV to MP3 Encoder
2008-05-02 03:55 --------- d-----w C:\Program Files\MP3 to WAV Decoder
2008-05-02 03:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-02 03:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-02 02:16 --------- d-----w C:\Program Files\Winamp
2008-05-02 02:15 --------- d-----w C:\Program Files\BitLord
2008-04-27 13:36 --------- d-----w C:\Program Files\ewido anti-malware
2008-04-02 10:02 --------- d-----w C:\Program Files\NetRatingsNetSight
2008-03-30 02:11 --------- d-----w C:\Documents and Settings\Scott\Application Data\Viewpoint
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2006-01-07 05:16 120 -c--a-w C:\Documents and Settings\Scott\Application Data\wklnhst.dat
2005-07-29 21:24 472 -csha-r C:\WINDOWS\U2NvdHQg\oZhSxJk0.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 03:32 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"Microsoft Location Finder"="C:\Program Files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 18:25 101080]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 20:04 139264]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-01 21:03 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-01 20:59 126976]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 19:17 88358 C:\WINDOWS\agrsmmsg.exe]
"NDSTray.exe"="NDSTray.exe" []
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2005-04-20 23:38 28672]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-25 18:59 65536]
"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2005-02-22 16:51 24576]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-04-28 23:08 675840]
"TPSMain"="TPSMain.exe" [2004-12-28 19:02 270336 C:\WINDOWS\system32\TPSMain.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 17:03 1077301]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-15 19:51 122880]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-30 00:06 53248]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-04-05 19:25 73728]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 19:37 151552]
"ACU"="C:\Program Files\Atheros\ACU.exe" [2005-03-28 17:28 290816]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"ZoomingHook"="ZoomingHook.exe" [2004-05-01 02:03 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 18:22 35328]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-04 12:43 185896]
"TFncKy"="TFncKy.exe" []
"TCtryIOHook"="TCtrlIOHook.exe" [2004-05-01 17:03 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-05-23 17:49 98304]
"Notebook Maximizer"="C:\Program Files\Notebook Maximizer\maximizer_startup.exe" [2004-05-25 17:35 28672]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 12:05 212992]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29 303104]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2004-03-24 01:40 196608]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-27 15:06 579584]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-13 18:04 219136]
C:\Documents and Settings\Scott\Start Menu\Programs\Startup\
Microsoft Office Groove.lnk - C:\Program Files\Microsoft Office\Office12\GROOVE.EXE [2006-10-27 16:37:44 338216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-05-23 16:39:01 155648]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\MSN Gaming Zone\profsyvyra.html
FriendlyName=
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B9E618A2-A4FE-11D4-83C2-005004636C96}"= C:\Program Files\Metamail Inc\Metamail Reader\OESHook.dll [2005-04-26 18:26 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-02 19:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2005-09-19 16:25:53 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-23 22:13:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\WINDOWS\explorer.exe [1408] 0x81D983E8
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\acs.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDANTSRV.EXE
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\PROGRA~1\McAfee.com\Agent\McTskshd.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
C:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Apoint2K\ApntEx.exe
.
**************************************************************************
.
Completion time: 2008-05-23 22:22:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-24 02:22:09
Pre-Run: 34,318,012,416 bytes free
Post-Run: 34,549,694,464 bytes free
263 --- E O F --- 2008-05-14 00:04:39
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.220 [GMT -4:00]
Running from: C:\Documents and Settings\Scott\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Scott\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Program Files\Internet Explorer\kyzeqe.html
C:\Program Files\Online Services\howynyka.html
C:\WINDOWS\system32\barseek.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Brooke\Application Data\ECURIT~1
C:\Documents and Settings\Brooke\Application Data\FNTS~1
C:\Documents and Settings\Brooke\My Documents\RACLE~1
C:\Documents and Settings\Brooke\My Documents\SSEMBL~1
C:\Documents and Settings\Brooke\My Documents\WNSXS~1
C:\Documents and Settings\Scott\Application Data\ErrorProtector Free
C:\Documents and Settings\Scott\Application Data\install.dat
C:\Documents and Settings\Scott\Application Data\WinTouch
C:\Documents and Settings\Scott\Application Data\YSTEM3~1
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\Scott\My Documents\ICROSO~1
C:\Documents and Settings\Scott\My Documents\STEM~1
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-119
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-145
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-199
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-261
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-266
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-273
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-284
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-300
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-328
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-332
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-356
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-358
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-371
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-407
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-422
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-423
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-428
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-453-Z_Start.lnk
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-453
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-456
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-526
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-542
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-544
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-545
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-598
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-621
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-622
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-650
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-661
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-703
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-752
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-755
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-756
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-776
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-779
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-894
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-929
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-962
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-974
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\backups\backup-20060627-222517-998
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\default.xex
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\HijackThis.exe
C:\Documents and Settings\Scott\My Documents\STEM~1\New Folder\hijackthis.log
C:\Documents and Settings\Scott\My Documents\YSTEM3~1
C:\PROGRA~1\COMMON~1\miiu
C:\PROGRA~1\COMMON~1\miiu\miiua.lck
C:\PROGRA~1\COMMON~1\miiu\miiud\class-barrel
C:\PROGRA~1\COMMON~1\miiu\miiul.lck
C:\PROGRA~1\COMMON~1\miiu\miium.lck
C:\PROGRA~1\COMMON~1\miiu\miiup.lck
C:\Program Files\Common Files\{B4BDA~1
C:\Program Files\Common Files\{B4BDA~2
C:\Program Files\Common Files\{B4BDA~3
C:\Program Files\Common Files\simtest
C:\Program Files\Common Files\sks~1
C:\Program Files\inetget2
C:\Program Files\JavaCore
C:\Program Files\JavaCore\JavaCore.exe
C:\Program Files\outerinfo
C:\Program Files\Router
C:\Program Files\stem32~1
C:\Program Files\windows
C:\WINDOWS\ms011262639300-2006.exe
C:\WINDOWS\ssembl~1
C:\WINDOWS\system32\cemetrix.dll
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\wnsintit.exe
C:\WINDOWS\system32\wnsintsv32.exe
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\system32\ystem~1\?ystem\
C:\WINDOWS\system32\ystem~1\wowexec.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_COM+_MESSAGES
-------\Legacy_NETWORK_MONITOR
-------\Legacy_WINDOWS_OVERLAY_COMPONENTS
((((((((((((((((((((((((( Files Created from 2008-04-24 to 2008-05-24 )))))))))))))))))))))))))))))))
.
2008-05-23 18:30 . 2008-05-23 18:30 <DIR> d-------- C:\Deckard
2008-05-14 20:00 . 2008-05-14 20:00 <DIR> d-------- C:\CB_3075
2008-05-14 19:57 . 2008-05-14 19:57 <DIR> d-------- C:\WINDOWS\A5W_DATA
2008-05-14 19:57 . 2008-05-14 19:57 28,042 --a------ C:\WINDOWS\Run32A50.mch
2008-05-14 19:57 . 2008-05-14 19:57 35 --a------ C:\WINDOWS\A5W.INI
2008-05-14 19:56 . 2008-05-14 19:56 <DIR> d-------- C:\CB_3058
2008-05-14 19:50 . 2008-05-14 19:50 <DIR> d-------- C:\Program Files\EpiCalc 2000
2008-05-14 19:50 . 2008-05-21 12:34 4,840 --a------ C:\WINDOWS\EpiCalc.ini
2008-05-14 19:49 . 1996-11-05 16:13 299,008 --a------ C:\WINDOWS\uninst.exe
2008-05-13 07:27 . 2008-05-13 07:27 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-13 07:27 . 2008-05-13 07:27 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-02 00:05 . 2008-05-02 00:05 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-05-01 23:53 . 2008-05-01 23:54 <DIR> d-------- C:\Program Files\Ruckus Player
2008-05-01 23:53 . 2008-05-01 23:55 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-05-01 23:53 . 2008-05-01 23:53 <DIR> d-------- C:\Documents and Settings\Scott\.realobjects
2008-04-30 19:01 . 2008-04-30 19:01 <DIR> d-------- C:\Program Files\ESET
2008-04-30 19:01 . 2008-04-30 19:01 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\Uniblue
2008-04-30 19:01 . 2008-04-30 19:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-04-27 11:57 . 2008-04-27 11:58 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-26 19:47 . 2008-05-01 23:55 <DIR> d-------- C:\Program Files\Spyware Doctor
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-24 02:16 --------- d-----w C:\Documents and Settings\Scott\Application Data\AVG7
2008-05-20 22:26 --------- d-----w C:\Documents and Settings\Brooke\Application Data\AVG7
2008-05-14 00:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-02 04:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-02 04:04 --------- d--h--w C:\Documents and Settings\Scott\Application Data\Move Networks
2008-05-02 04:04 --------- d-----w C:\Program Files\McAfee.com
2008-05-02 04:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-05-02 03:55 --------- d-----w C:\Program Files\WAV to MP3 Encoder
2008-05-02 03:55 --------- d-----w C:\Program Files\MP3 to WAV Decoder
2008-05-02 03:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-02 03:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-02 02:16 --------- d-----w C:\Program Files\Winamp
2008-05-02 02:15 --------- d-----w C:\Program Files\BitLord
2008-04-27 13:36 --------- d-----w C:\Program Files\ewido anti-malware
2008-04-02 10:02 --------- d-----w C:\Program Files\NetRatingsNetSight
2008-03-30 02:11 --------- d-----w C:\Documents and Settings\Scott\Application Data\Viewpoint
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2006-01-07 05:16 120 -c--a-w C:\Documents and Settings\Scott\Application Data\wklnhst.dat
2005-07-29 21:24 472 -csha-r C:\WINDOWS\U2NvdHQg\oZhSxJk0.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 03:32 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"Microsoft Location Finder"="C:\Program Files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 18:25 101080]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 20:04 139264]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-01 21:03 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-01 20:59 126976]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 19:17 88358 C:\WINDOWS\agrsmmsg.exe]
"NDSTray.exe"="NDSTray.exe" []
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2005-04-20 23:38 28672]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-25 18:59 65536]
"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2005-02-22 16:51 24576]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-04-28 23:08 675840]
"TPSMain"="TPSMain.exe" [2004-12-28 19:02 270336 C:\WINDOWS\system32\TPSMain.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 17:03 1077301]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-15 19:51 122880]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-30 00:06 53248]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-04-05 19:25 73728]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 19:37 151552]
"ACU"="C:\Program Files\Atheros\ACU.exe" [2005-03-28 17:28 290816]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"ZoomingHook"="ZoomingHook.exe" [2004-05-01 02:03 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 18:22 35328]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-04 12:43 185896]
"TFncKy"="TFncKy.exe" []
"TCtryIOHook"="TCtrlIOHook.exe" [2004-05-01 17:03 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-05-23 17:49 98304]
"Notebook Maximizer"="C:\Program Files\Notebook Maximizer\maximizer_startup.exe" [2004-05-25 17:35 28672]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 12:05 212992]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29 303104]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2004-03-24 01:40 196608]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-27 15:06 579584]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-13 18:04 219136]
C:\Documents and Settings\Scott\Start Menu\Programs\Startup\
Microsoft Office Groove.lnk - C:\Program Files\Microsoft Office\Office12\GROOVE.EXE [2006-10-27 16:37:44 338216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-05-23 16:39:01 155648]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\MSN Gaming Zone\profsyvyra.html
FriendlyName=
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B9E618A2-A4FE-11D4-83C2-005004636C96}"= C:\Program Files\Metamail Inc\Metamail Reader\OESHook.dll [2005-04-26 18:26 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-02 19:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2005-09-19 16:25:53 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-23 22:13:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\WINDOWS\explorer.exe [1408] 0x81D983E8
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\acs.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDANTSRV.EXE
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\PROGRA~1\McAfee.com\Agent\McTskshd.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
C:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Apoint2K\ApntEx.exe
.
**************************************************************************
.
Completion time: 2008-05-23 22:22:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-24 02:22:09
Pre-Run: 34,318,012,416 bytes free
Post-Run: 34,549,694,464 bytes free
263 --- E O F --- 2008-05-14 00:04:39