Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:31:47 PM, on 7/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Windows SteadyState\SCTSvc.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Common Files\LightScribe\LSSrvc.exe
E:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
e:\program files\common files\mcafee\mna\mcnasvc.exe
e:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
E:\Program Files\McAfee\VirusScan\McShield.exe
E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
E:\Program Files\McAfee\MPF\MPFSrv.exe
E:\Program Files\McAfee\MSK\MskSrver.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\Program Files\Spyware Doctor\pctsAuxs.exe
E:\Program Files\Spyware Doctor\pctsSvc.exe
E:\Program Files\SiteAdvisor\6261\SAService.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\SearchIndexer.exe
E:\WINDOWS\system32\svchost.exe
e:\PROGRA~1\mcafee.com\agent\mcagent.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Canon\CAL\CALMAIN.exe
E:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\Spyware Doctor\pctsTray.exe
E:\Program Files\SiteAdvisor\6261\SiteAdv.exe
E:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\iTunesHelper.exe
E:\Program Files\Windows SteadyState\Bubble.exe
E:\Program Files\PeerGuardian2\pg2.exe
E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Microsoft ActiveSync\Wcescomm.exe
E:\WINDOWS\system32\wbem\unsecapp.exe
E:\PROGRA~1\MI3AA1~1\rapimgr.exe
E:\Program Files\uTorrent\uTorrent.exe
E:\Program Files\Windows Desktop Search\WindowsSearch.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\WINDOWS\System32\alg.exe
E:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
E:\Program Files\Mozilla Firefox\firefox.exe
E:\Program Files\Trend Micro\HijackThis\HijackThis.exe
E:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - E:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - E:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RCAutoLiveUpdate] E:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe -AUTO
O4 - HKLM\..\Run: [RCSystemTray] E:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISTray] "E:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [mcagent_exe] E:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "E:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [McENUI] E:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RCAutoScan] "E:\Program Files\Max Registry Cleaner\MaxRegistryCleaner.exe" -AUTOSCAN
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunesHelper.exe"
O4 - HKLM\..\Run: [amd_dc_opt] E:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Bubble] E:\Program Files\Windows SteadyState\Bubble.exe
O4 - HKLM\..\Run: [Logoff] E:\Program Files\Windows SteadyState\SCTUINotify.exe
O4 - HKCU\..\Run: [PeerGuardian] E:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [swg] E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "E:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [uTorrent] "E:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-21-117609710-1767777339-682003330-500\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = E:\Program Files\Microsoft Office\OFFICE12\ONENOTEM.EXE
O4 - Global Startup: Windows Desktop Search.lnk = E:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search -
res://E:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxO8 - Extra context menu item: E&xport to Microsoft Excel -
res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: McAfee Application Installer Cleanup (0166251215818400) (0166251215818400mcinstcleanup) - Unknown owner - E:\WINDOWS\TEMP\016625~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - E:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - E:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - E:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - e:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - E:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - e:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - E:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - E:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - E:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - E:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - E:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - E:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - E:\Program Files\SiteAdvisor\6261\SAService.exe
--
End of file - 10388 bytes
ComboFix 08-07-07.3 - Alan 2008-07-12 19:43:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1352 [GMT -7:00]
Running from: E:\Documents and Settings\Alan\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\WINDOWS\pskt.ini
E:\WINDOWS\system32\dqvdcvpm.ini
E:\WINDOWS\system32\mhbuysci.ini
E:\WINDOWS\system32\nrilbsgi.ini
E:\WINDOWS\system32\ttrwembn.ini
E:\WINDOWS\system32\uokqjsrm.ini
E:\WINDOWS\system32\VyJiQXbc.ini
E:\WINDOWS\system32\VyJiQXbc.ini2
.
((((((((((((((((((((((((( Files Created from 2008-06-13 to 2008-07-13 )))))))))))))))))))))))))))))))
.
2008-07-09 02:27 . 2008-07-09 02:27 0 --ah----- E:\WINDOWS\system32\drivers\Msft_Kernel_VCFFltr_01005.Wdf
2008-07-09 01:39 . 2008-07-09 01:46 <DIR> d-------- E:\Documents and Settings\Alan\.housecall6.6
2008-07-08 12:58 . 2008-07-08 12:58 <DIR> d-------- E:\VundoFix Backups
2008-07-08 12:54 . 2008-07-08 12:54 <DIR> d-------- E:\Program Files\Trend Micro
2008-07-08 12:53 . 2008-07-08 12:53 <DIR> d-------- E:\Documents and Settings\Administrator\Application Data\U3
2008-07-08 12:39 . 2008-07-08 12:39 <DIR> d-------- E:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
2008-07-08 12:39 . 2008-07-08 14:28 <DIR> d-------- E:\Documents and Settings\Administrator\Application Data\SiteAdvisor
2008-07-08 12:37 . 2008-07-08 14:47 <DIR> d-------- E:\Documents and Settings\Administrator
2008-07-08 01:58 . 2008-07-08 01:58 <DIR> d-------- E:\Documents and Settings\Bob
2008-07-08 01:50 . 2008-07-08 01:50 <DIR> d-------- E:\WINDOWS\Downloaded Installations
2008-07-08 01:50 . 2008-07-08 01:50 <DIR> d-------- E:\Program Files\Polar
2008-07-08 01:43 . 2008-07-08 01:43 <DIR> d-------- E:\Program Files\Windows Live Favorites
2008-07-08 01:42 . 2008-07-08 01:43 <DIR> d-------- E:\Program Files\Windows Live Toolbar
2008-07-08 01:42 . 2008-07-08 01:42 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-07-08 01:41 . 2008-07-08 01:41 <DIR> d-------- E:\Program Files\Windows SteadyState
2008-07-07 14:40 . 2008-07-12 14:41 110,419 --a------ E:\WINDOWS\BM87cae103.xml
2008-07-02 01:55 . 2008-07-02 01:55 <DIR> d-------- E:\Program Files\PowerISO
2008-07-01 00:13 . 2008-07-01 00:13 <DIR> d-------- E:\Program Files\Apple Software Update
2008-06-30 12:21 . 2008-06-30 12:25 <DIR> d-------- E:\Torrent files
2008-06-27 14:37 . 2006-11-13 14:45 1,419,232 --a------ E:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-06-27 14:37 . 2007-06-18 14:18 23,680 --a------ E:\WINDOWS\system32\drivers\motmodem.sys
2008-06-27 12:53 . 2008-06-27 12:54 <DIR> d-------- E:\Program Files\Motorola Phone Tools
2008-06-22 19:02 . 2008-06-22 19:02 <DIR> d-------- E:\Program Files\THQ
2008-06-22 18:56 . 2008-06-22 18:57 <DIR> d-------- E:\Program Files\MagicISO
2008-06-22 18:39 . 2008-06-22 18:39 <DIR> d-------- E:\Program Files\AMD
2008-06-22 18:39 . 2007-06-29 14:47 34,304 --a------ E:\WINDOWS\system32\drivers\AmdLLD.sys
2008-06-20 10:46 . 2008-06-20 10:46 245,248 -----c--- E:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 10:46 . 2008-06-20 10:46 147,968 -----c--- E:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 04:51 . 2008-06-20 04:51 361,600 -----c--- E:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 04:40 . 2008-06-20 04:40 138,496 -----c--- E:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 04:08 . 2008-06-20 04:08 225,856 -----c--- E:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-19 16:19 . 2008-06-19 16:19 <DIR> d-------- E:\Program Files\iPod
2008-06-19 16:19 . 2008-06-19 16:19 <DIR> d-------- E:\Program Files\Bonjour
2008-06-19 16:19 . 2008-06-19 16:19 <DIR> d-------- E:\Documents and Settings\Alan\Application Data\Apple Computer
2008-06-19 16:18 . 2008-06-19 16:19 <DIR> d-------- E:\Program Files\QuickTime
2008-06-19 16:18 . 2008-06-19 16:19 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-19 16:17 . 2008-06-19 16:17 <DIR> d-------- E:\Program Files\Common Files\Apple
2008-06-19 16:17 . 2008-06-19 16:17 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Apple
2008-06-18 12:58 . 2008-06-18 13:36 <DIR> d-------- E:\Program Files\Guitar Pro 5
2008-06-17 00:28 . 2008-06-17 00:28 <DIR> d--h----- E:\WINDOWS\PIF
2008-06-16 22:41 . 2008-06-18 14:05 <DIR> d-------- E:\Documents and Settings\Alan\Application Data\ZoomBrowser EX
2008-06-16 22:37 . 2008-06-16 23:00 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-06-16 22:36 . 2008-06-16 22:38 <DIR> d-------- E:\Program Files\Canon
2008-06-16 22:35 . 2008-06-16 22:35 <DIR> d-------- E:\Program Files\Common Files\Canon
2008-06-15 13:48 . 2008-06-15 13:48 <DIR> d-------- E:\Documents and Settings\Alan\Application Data\Windows Desktop Search
2008-06-15 13:45 . 2008-06-15 13:45 <DIR> d-------- E:\Program Files\Windows Desktop Search
2008-06-15 13:42 . 2008-06-20 01:55 151 --a------ E:\WINDOWS\PhotoSnapViewer.INI
2008-06-14 19:05 . 2007-07-30 19:19 271,224 --a------ E:\WINDOWS\system32\mucltui.dll
2008-06-14 19:05 . 2007-07-30 19:19 207,736 --a------ E:\WINDOWS\system32\muweb.dll
2008-06-14 19:05 . 2007-07-30 19:19 30,072 --a------ E:\WINDOWS\system32\mucltui.dll.mui
2008-06-14 18:29 . 2006-10-26 19:56 32,592 --a------ E:\WINDOWS\system32\msonpmon.dll
2008-06-14 18:26 . 2008-06-14 18:26 <DIR> d-------- E:\Program Files\Microsoft Works
2008-06-14 18:25 . 2008-06-14 18:25 <DIR> d-------- E:\Program Files\Microsoft.NET
2008-06-14 18:23 . 2008-06-14 18:23 <DIR> d-------- E:\Program Files\Microsoft Visual Studio 8
2008-06-14 18:23 . 2008-06-14 18:23 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\TomTom
2008-06-14 18:22 . 2008-06-14 18:23 <DIR> d-------- E:\WINDOWS\SHELLNEW
2008-06-14 18:21 . 2008-06-14 18:21 <DIR> dr-h----- E:\MSOCache
2008-06-14 18:09 . 2008-06-14 19:31 <DIR> d-------- E:\Program Files\TomTom HOME
2008-06-14 17:39 . 2008-06-14 17:39 <DIR> d-------- E:\Program Files\Microsoft ActiveSync
2008-06-14 17:08 . 2006-11-06 18:04 28,672 --a------ E:\WINDOWS\system32\drivers\wceusbsh.sys
2008-06-14 17:08 . 2006-11-06 18:04 28,672 --a--c--- E:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-06-14 16:54 . 2008-06-14 16:54 0 --ah----- E:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-14 16:54 . 2008-06-14 16:54 0 --ah----- E:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-06-14 16:36 . 2008-06-14 16:37 <DIR> d-------- E:\Program Files\Avanquest update
2008-06-14 16:34 . 2008-06-27 14:37 <DIR> d----c--- E:\WINDOWS\system32\DRVSTORE
2008-06-14 16:34 . 2008-06-14 16:34 <DIR> d-------- E:\Program Files\Common Files\Motorola Shared
2008-06-14 16:34 . 2008-06-14 16:54 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\BVRP Software
2008-06-14 15:59 . 2008-06-14 15:59 <DIR> d-------- E:\Program Files\DVD Shrink
2008-06-14 15:59 . 2008-06-14 16:00 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-06-14 03:07 . 2005-10-29 05:12 29,384 --a------ E:\WINDOWS\system32\mdimon.dll
2008-06-14 03:02 . 2008-07-09 03:01 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-14 03:02 . 2008-06-14 03:03 376 --a------ E:\WINDOWS\ODBC.INI
2008-06-14 02:25 . 2008-06-14 02:25 <DIR> d-------- E:\Program Files\DVD Decrypter
2008-06-13 15:43 . 2008-06-16 11:50 <DIR> d-------- E:\Documents and Settings\Alan\Application Data\dvdcss
2008-06-13 12:13 . 2008-04-13 17:12 221,184 --a------ E:\WINDOWS\system32\wmpns.dll
2008-06-13 09:30 . 2008-07-08 14:19 <DIR> d-------- E:\Documents and Settings\Alan\Application Data\U3
2008-06-13 01:43 . 2008-06-13 01:43 <DIR> d-------- E:\WINDOWS\Sun
2008-06-13 01:32 . 2008-06-13 01:32 <DIR> d-------- E:\Program Files\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-13 02:45 --------- d-----w E:\Program Files\PeerGuardian2
2008-07-13 02:40 --------- d-----w E:\Documents and Settings\Alan\Application Data\uTorrent
2008-07-13 02:37 --------- d---a-w E:\Documents and Settings\All Users\Application Data\TEMP
2008-07-13 02:37 --------- d-----w E:\Program Files\Spyware Doctor
2008-07-10 22:53 --------- d-----w E:\Program Files\McAfee
2008-07-08 23:02 --------- d-----w E:\WINDOWS\system32\config\systemprofile\Application Data\SiteAdvisor
2008-07-07 21:48 --------- d-----w E:\Program Files\Max Registry Cleaner
2008-06-27 19:53 --------- d--h--w E:\Program Files\InstallShield Installation Information
2008-06-20 17:46 245,248 ----a-w E:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w E:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w E:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w E:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-15 01:08 --------- d-----w E:\Program Files\MSBuild
2008-06-14 07:55 --------- d-----w E:\Program Files\uTorrent
2008-06-13 11:05 272,128 ------w E:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 06:58 --------- d-----w E:\Program Files\Common Files\Adobe
2008-06-12 21:34 --------- d-----w E:\Program Files\Ahead
2008-06-12 21:34 --------- d-----w E:\Documents and Settings\All Users\Application Data\Ahead
2008-06-12 21:18 --------- d-----w E:\Program Files\Common Files\Nero
2008-06-12 21:18 --------- d-----w E:\Program Files\Common Files\LightScribe
2008-06-12 21:16 --------- d-----w E:\Program Files\Common Files\Ahead
2008-06-12 07:35 --------- d-----w E:\Program Files\Reference Assemblies
2008-06-12 07:20 499,712 ----a-w E:\WINDOWS\system32\msvcp71.dll
2008-06-12 07:20 348,160 ----a-w E:\WINDOWS\system32\msvcr71.dll
2008-06-12 07:20 --------- d-----w E:\Program Files\Common Files\xing shared
2008-06-12 07:20 --------- d-----w E:\Program Files\Common Files\Real
2008-06-11 08:15 108,144 ----a-w E:\WINDOWS\system32\CmdLineExt.dll
2008-06-11 08:05 60,416 ----a-w E:\WINDOWS\ALCFDRTM.EXE
2008-06-11 01:57 --------- d-----w E:\Documents and Settings\Alan\Application Data\vlc
2008-06-10 21:50 --------- d-----w E:\Program Files\2K Games
2008-06-10 21:49 --------- d-----w E:\Documents and Settings\Alan\Application Data\InstallShield
2008-06-10 20:59 --------- d-----w E:\Documents and Settings\Alan\Application Data\SiteAdvisor
2008-06-10 20:58 159,880 ----a-w E:\WINDOWS\system32\drivers\pctfw2.sys
2008-06-10 20:58 --------- d-----w E:\Program Files\Common Files\PC Tools
2008-06-10 20:58 --------- d-----w E:\Documents and Settings\All Users\Application Data\PC Tools
2008-06-10 20:51 --------- d-----w E:\Program Files\SiteAdvisor
2008-06-10 20:49 --------- d-----w E:\Program Files\Realtek Sound Manager
2008-06-10 20:49 --------- d-----w E:\Program Files\Realtek AC97
2008-06-10 20:49 --------- d-----w E:\Program Files\AvRack
2008-06-10 20:46 --------- d-----w E:\Program Files\Common Files\McAfee
2008-06-10 20:46 --------- d-----w E:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-06-10 20:43 --------- d-----w E:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-06-10 20:43 --------- d-----w E:\Documents and Settings\All Users\Application Data\McAfee
2008-06-10 20:29 --------- d-----w E:\Program Files\VideoLAN
2008-06-10 20:29 --------- d-----w E:\Program Files\Google
2008-06-10 20:29 --------- d-----w E:\Documents and Settings\Alan\Application Data\PC Tools
2008-06-10 20:08 --------- d-----w E:\Program Files\Common Files\InstallShield
2008-06-10 20:02 --------- d-----w E:\Program Files\McAfee.com
2008-06-10 19:47 --------- d-----w E:\Program Files\microsoft frontpage
2008-05-30 21:41 223,760 ----a-w E:\WINDOWS\system32\WSSCredentialProvider.dll
2008-05-30 21:41 20,496 ----a-w E:\WINDOWS\system32\WSSCPFilter.dll
2008-05-09 10:53 90,112 ----a-w E:\WINDOWS\system32\wshext.dll
2008-05-09 10:53 430,080 ----a-w E:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53 180,224 ----a-w E:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53 172,032 ----a-w E:\WINDOWS\system32\scrrun.dll
2008-05-08 11:24 155,648 ----a-w E:\WINDOWS\system32\wscript.exe
2008-05-07 09:07 135,168 ----a-w E:\WINDOWS\system32\cscript.exe
2008-05-07 05:12 1,288,192 ----a-w E:\WINDOWS\system32\quartz.dll
2008-05-01 00:27 442,368 ----a-w E:\WINDOWS\system32\NVUNINST.EXE
2008-04-23 04:16 826,368 ----a-w E:\WINDOWS\system32\wininet.dll
2008-04-14 12:42 985,088 ----a-w E:\WINDOWS\system32\setupapi.dll
2008-04-14 12:42 11,264 ----a-w E:\WINDOWS\system32\spnpinst.exe
2008-04-14 12:41 423,936 ----a-w E:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w E:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 ----a-w E:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w E:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w E:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 299,520 ----a-w E:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 12,168 ----a-w E:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 997,376 ----a-w E:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 ----a-w E:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w E:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w E:\WINDOWS\system32\msafd.dll
2008-04-13 19:30 1,845,632 ----a-w E:\WINDOWS\system32\win32k.sys
2008-04-13 19:24 2,145,280 ----a-w E:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 ----a-w E:\WINDOWS\system32\watchdog.sys
2008-04-13 18:43 9,728 ------w E:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 12,800 ----a-w E:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:31 7,424 ----a-w E:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,023,936 ----a-w E:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 ----a-w E:\WINDOWS\system32\msvcrt40.dll
2008-04-13 18:14 76,800 ------w E:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:39 438,784 ----a-w E:\WINDOWS\system32\xpob2res.dll
2008-04-13 17:39 2,897,920 ----a-w E:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 187,392 ----a-w E:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 ----a-w E:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w E:\WINDOWS\system32\dssenh.dll
2008-04-13 17:28 2,940,928 ----a-w E:\WINDOWS\system32\wmploc.dll
2008-04-13 17:27 79,872 ------w E:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 94,208 ----a-w E:\WINDOWS\system32\odbcint.dll
2008-04-13 17:26 12,288 ----a-w E:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w E:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:24 20,480 ----a-w E:\WINDOWS\system32\msorc32r.dll
2008-04-13 17:23 8,192 ----a-w E:\WINDOWS\system32\asferror.dll
2008-04-13 17:23 168,448 ----a-w E:\WINDOWS\system32\wmerror.dll
2008-04-13 17:21 733,696 ----a-w E:\WINDOWS\system32\qedwipes.dll
2008-04-13 17:09 4,096 ----a-w E:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:03 63,488 ----a-w E:\WINDOWS\system32\browselc.dll
2008-04-13 17:03 549,376 ----a-w E:\WINDOWS\system32\shdoclc.dll
2008-04-13 16:48 1,647,616 ----a-w E:\WINDOWS\system32\winbrand.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="E:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
"swg"="E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-09 14:59 68856]
"ctfmon.exe"="E:\WINDOWS\system32\ctfmon.exe" [2008-04-13 17:12 15360]
"H/PC Connection Agent"="E:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 13:39 1289000]
"uTorrent"="E:\Program Files\uTorrent\uTorrent.exe" [2008-06-10 14:56 219952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RCAutoLiveUpdate"="E:\Program Files\Max Registry Cleaner\MaxLiveUpdateRC.exe" [2008-05-30 15:49 865744]
"RCSystemTray"="E:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe" [2008-05-30 15:49 914896]
"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"NvMediaCenter"="E:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"ISTray"="E:\Program Files\Spyware Doctor\pctsTray.exe" [2008-04-10 15:14 1107848]
"mcagent_exe"="E:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"SiteAdvisor"="E:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2006-07-24 13:28 35992]
"McENUI"="E:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 05:42 1164576]
"RCAutoScan"="E:\Program Files\Max Registry Cleaner\MaxRegistryCleaner.exe" [2008-07-03 11:59 5780944]
"TkBellExe"="E:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-12 00:20 185896]
"NeroFilterCheck"="E:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"Adobe Reader Speed Launcher"="E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"GrooveMonitor"="E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"QuickTime Task"="E:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="D:\Program Files\iTunesHelper.exe" [2008-06-02 11:13 267048]
"amd_dc_opt"="E:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 11:06 77824]
"Bubble"="E:\Program Files\Windows SteadyState\Bubble.exe" [2008-05-30 14:41 182288]
"Logoff"="E:\Program Files\Windows SteadyState\SCTUINotify.exe" [2008-05-30 14:40 163856]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 E:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-10-23 23:45 90112 E:\WINDOWS\soundman.exe]
E:\Documents and Settings\Alan\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - E:\Program Files\Microsoft Office\OFFICE12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]
E:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Windows Desktop Search.lnk - E:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 15:40:46 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "E:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 15:39 294400]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windows SteadyState]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"E:\\Program Files\\uTorrent\\uTorrent.exe"=
"E:\Program Files\Microsoft ActiveSync\rapimgr.exe"= E:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"E:\Program Files\Microsoft ActiveSync\wcescomm.exe"= E:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"E:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= E:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"E:\\Program Files\\Microsoft Office\\OFFICE12\\OUTLOOK.EXE"=
"E:\\Program Files\\Microsoft Office\\OFFICE12\\GROOVE.EXE"=
"E:\\Program Files\\Microsoft Office\\OFFICE12\\ONENOTE.EXE"=
"E:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\Program Files\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 pctfw2;pctfw2;E:\WINDOWS\system32\drivers\pctfw2.sys [2008-06-10 13:58]
R2 Windows SteadyState;Windows SteadyState Service;E:\Program Files\Windows SteadyState\SCTSvc.exe [2008-05-30 14:41]
S2 0166251215818400mcinstcleanup;McAfee Application Installer Cleanup (0166251215818400);E:\WINDOWS\TEMP\
016625~1.EXE E:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\setup.exe
*Newly Created Service* - 0166251215818400MCINSTCLEANUP
*Newly Created Service* - CATCHME
*Newly Created Service* - PGFILTER
.
Contents of the 'Scheduled Tasks' folder
"2008-07-09 21:32:03 E:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- E:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-13 02:15:00 E:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- E:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-06-15 08:19:43 E:\WINDOWS\Tasks\McDefragTask.job"
- E:\WINDOWS\system32\defrag.exe
"2008-07-01 08:00:26 E:\WINDOWS\Tasks\McQcTask.job"
- e:\program files\mcafee\mqc\QcConsol.exe.4158 0
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-12 19:45:58
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-12 19:46:55
ComboFix-quarantined-files.txt 2008-07-13 02:46:51
Pre-Run: 25,514,819,584 bytes free
Post-Run: 25,589,633,024 bytes free
301 --- E O F --- 2008-07-11 21:22:10
Thank You for your time!