ComboFix 08-10-22.02 - Kevin 2008-10-22 22:58:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2531 [GMT -4:00]
Running from: C:\Documents and Settings\Kevin\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-23 to 2008-10-23 )))))))))))))))))))))))))))))))
.
2008-10-22 20:58 . 2008-10-22 20:58 <DIR> d-------- C:\Program Files\Avira
2008-10-22 20:58 . 2008-10-22 20:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-20 21:54 . 2008-10-20 21:54 <DIR> d-------- C:\Program Files\MSECache
2008-10-17 07:03 . 2008-10-17 07:03 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-17 07:03 . 2008-10-19 23:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-16 16:19 . 2008-10-16 16:19 <DIR> d-------- C:\Program Files\gnzwuze
2008-10-16 16:19 . 2008-10-21 03:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\vghunqry
2008-10-15 20:12 . 2008-08-14 06:11 2,189,184 --------- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 20:12 . 2008-08-14 06:09 2,145,280 --------- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 20:12 . 2008-08-14 05:33 2,066,048 --------- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 20:12 . 2008-08-14 05:33 2,023,936 --------- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 20:12 . 2008-09-15 08:12 1,846,400 --------- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 20:12 . 2008-09-08 06:41 333,824 --------- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 22:13 . 2008-10-14 22:13 262,144 --a------ C:\ntuser.dat
2008-10-12 22:39 . 2008-10-12 22:40 <DIR> d-------- C:\Documents and Settings\Kevin\Application Data\vlc
2008-10-12 22:38 . 2008-10-12 22:38 <DIR> d-------- C:\Program Files\VideoLAN
2008-09-30 15:49 . 2008-09-30 15:49 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-30 15:49 . 2008-09-30 15:49 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-09-30 15:45 . 2008-09-30 15:45 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-09-30 15:45 . 2006-11-13 14:45 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-09-30 15:45 . 2007-02-27 14:31 21,504 --a------ C:\WINDOWS\system32\drivers\motmodem.sys
2008-09-30 15:44 . 2008-09-30 15:44 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared
2008-09-30 15:41 . 2008-09-30 15:42 <DIR> d-------- C:\Program Files\Avanquest update
2008-09-30 15:41 . 2008-04-13 14:45 26,112 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-09-30 15:41 . 2008-04-13 14:45 26,112 --a------ C:\WINDOWS\system32\dllcache\usbser.sys
2008-09-30 15:40 . 2008-09-30 15:45 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-09-30 15:40 . 2008-09-30 15:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-09-30 15:40 . 2008-09-30 15:40 92,064 --a------ C:\Documents and Settings\Kevin\mqdmmdm.sys
2008-09-30 15:40 . 2008-09-30 15:40 79,328 --a------ C:\Documents and Settings\Kevin\mqdmserd.sys
2008-09-30 15:40 . 2008-09-30 15:40 66,656 --a------ C:\Documents and Settings\Kevin\mqdmbus.sys
2008-09-30 15:40 . 2008-09-30 15:40 25,600 --a------ C:\Documents and Settings\Kevin\usbsermptxp.sys
2008-09-30 15:40 . 2008-09-30 15:40 22,768 --a------ C:\Documents and Settings\Kevin\usbsermpt.sys
2008-09-30 15:40 . 2008-09-30 15:40 9,232 --a------ C:\Documents and Settings\Kevin\mqdmmdfl.sys
2008-09-30 15:40 . 2008-09-30 15:40 6,208 --a------ C:\Documents and Settings\Kevin\mqdmcmnt.sys
2008-09-30 15:40 . 2008-09-30 15:40 5,936 --a------ C:\Documents and Settings\Kevin\mqdmwhnt.sys
2008-09-30 15:40 . 2008-09-30 15:40 4,048 --a------ C:\Documents and Settings\Kevin\mqdmcr.sys
2008-09-30 10:20 . 2008-09-30 10:20 60,968 --a------ C:\Documents and Settings\Kevin\GoToAssistDownloadHelper.exe
2008-09-29 21:45 . 2008-10-15 17:14 <DIR> d-------- C:\Program Files\Swarm Gold
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-22 23:39 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-10-22 18:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-21 13:04 --------- d-----w C:\Documents and Settings\Kevin\Application Data\U3
2008-10-17 01:55 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-10-16 20:18 507,904 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-10-16 20:18 295,424 ----a-w C:\WINDOWS\system32\termsrv.dll
2008-10-15 13:09 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Yahoo!
2008-10-03 17:41 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-10-02 17:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\PCPitstop
2008-09-30 19:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-20 15:08 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Tunebite
2008-09-20 01:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\RapidSolution
2008-09-20 01:07 --------- d-----w C:\Program Files\PixiePack Codec Pack
2008-09-20 01:06 --------- d-----w C:\Program Files\RapidSolution
2008-09-15 12:12 1,846,400 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-14 19:28 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Flood Light Games
2008-09-14 19:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Flood Light Games
2008-09-09 23:53 --------- d-----w C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-06 03:30 241,704 ------w C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-06 03:29 917,032 ------w C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-09-05 22:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2008-09-05 22:36 --------- d-----w C:\Program Files\Safari Island Deluxe
2008-09-05 22:06 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Ludia
2008-09-05 22:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ludia
2008-09-05 22:05 --------- d-----w C:\Program Files\The Price Is Right
2008-09-05 16:37 --------- d-----w C:\Documents and Settings\Kevin\Application Data\ForgottenRiddles
2008-09-04 17:43 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Ahead
2008-09-04 16:46 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Ahead
2008-09-04 16:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-09-04 16:00 --------- d-----w C:\Program Files\Common Files\Ahead
2008-09-04 15:59 --------- d-----w C:\Program Files\Nero
2008-09-04 13:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-09-04 02:43 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Roxio
2008-09-04 02:21 --------- d-----w C:\Program Files\DVD Shrink
2008-09-04 02:03 7,040 ----a-w C:\WINDOWS\system32\drivers\FNETURPX.SYS
2008-09-04 02:03 17,792 ----a-w C:\WINDOWS\system32\drivers\FNETTBOH.SYS
2008-09-04 02:03 --------- d-----w C:\Program Files\TurboHddUsb
2008-09-04 02:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\FNET
2008-09-03 14:05 --------- d-----w C:\Program Files\Ice Cream Dee Lites
2008-09-03 13:59 --------- d-----w C:\Program Files\eGames
2008-09-02 16:41 --------- d-----w C:\Program Files\LeeGTs Games
2008-09-01 14:39 --------- d-----w C:\Documents and Settings\Kevin\Application Data\iWin
2008-09-01 03:18 --------- d-----w C:\Program Files\Pirateville
2008-08-31 20:44 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Legends of pirates
2008-08-31 01:34 --------- d-----w C:\Program Files\Forgotten Riddles - The Mayan Princess
2008-08-29 23:26 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 08:24 3,593,216 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-25 08:38 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-25 08:37 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-23 05:56 635,848 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-14 10:09 2,145,280 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 10:04 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-08-14 09:33 2,023,936 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-06-10 00:36 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008060920080610\index.dat
.
------- Sigcheck -------
2004-08-04 06:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 20:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-10-16 16:18 507904 3969440ba384d35317dbbdeeaae641ce C:\WINDOWS\system32\winlogon.exe
2004-08-04 06:00 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2008-04-13 20:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-10-16 16:18 295424 63999d0abd8dabfd76a9c07f6e104868 C:\WINDOWS\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 700416]
"Pando"="C:\Program Files\Pando Networks\Pando\Pando.exe" [2008-07-25 6591816]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]
"Search Protection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-27 8429568]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 16384]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 842584]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2006-10-03 221184]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 385024]
"TurboHddUsb"="C:\Program Files\TurboHddUsb\TurboHddUsb.exe" [2008-09-03 3327488]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-10-16 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"MntWin"= {6280B887-A416-F4C4-5581-0BA044BAC6EA} - C:\Program Files\gnzwuze\MntWin.dll [2008-10-16 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-10-16 21:55 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"57885:TCP"= 57885:TCP:Pando P2P TCP Listening Port
"57885:UDP"= 57885:UDP:Pando P2P UDP Listening Port
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 28184]
R1 FNETURPX;FNETURPX;C:\WINDOWS\system32\drivers\FNETURPX.SYS [2008-09-03 7040]
R3 FNETTBOH;FNETTBOH;C:\WINDOWS\system32\drivers\FNETTBOH.SYS [2008-09-03 17792]
S2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\X]
\Shell\AutoRun\command - X:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6a675f8-790d-11dd-a2e9-001aa09fb8d6}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
*Newly Created Service* - CATCHME
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\opw5ts4p.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-22 22:58:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-22 22:59:45
ComboFix-quarantined-files.txt 2008-10-23 02:59:41
ComboFix2.txt 2008-10-23 02:52:08
Pre-Run: 95,662,518,272 bytes free
Post-Run: 95,647,424,512 bytes free
209 --- E O F --- 2008-10-22 03:21:53
ComboFix 08-10-22.02 - Kevin 2008-10-22 22:44:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2529 [GMT -4:00]
Running from: C:\Documents and Settings\Kevin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kevin\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PACKET
-------\Service_Packet
((((((((((((((((((((((((( Files Created from 2008-09-23 to 2008-10-23 )))))))))))))))))))))))))))))))
.
2008-10-22 20:58 . 2008-10-22 20:58 <DIR> d-------- C:\Program Files\Avira
2008-10-22 20:58 . 2008-10-22 20:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-20 21:54 . 2008-10-20 21:54 <DIR> d-------- C:\Program Files\MSECache
2008-10-17 07:03 . 2008-10-17 07:03 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-17 07:03 . 2008-10-19 23:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-16 16:19 . 2008-10-16 16:19 <DIR> d-------- C:\Program Files\gnzwuze
2008-10-16 16:19 . 2008-10-21 03:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\vghunqry
2008-10-15 20:12 . 2008-08-14 06:11 2,189,184 --------- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 20:12 . 2008-08-14 06:09 2,145,280 --------- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 20:12 . 2008-08-14 05:33 2,066,048 --------- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 20:12 . 2008-08-14 05:33 2,023,936 --------- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 20:12 . 2008-09-15 08:12 1,846,400 --------- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 20:12 . 2008-09-08 06:41 333,824 --------- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 22:13 . 2008-10-14 22:13 262,144 --a------ C:\ntuser.dat
2008-10-12 22:39 . 2008-10-12 22:40 <DIR> d-------- C:\Documents and Settings\Kevin\Application Data\vlc
2008-10-12 22:38 . 2008-10-12 22:38 <DIR> d-------- C:\Program Files\VideoLAN
2008-09-30 15:49 . 2008-09-30 15:49 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-30 15:49 . 2008-09-30 15:49 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-09-30 15:45 . 2008-09-30 15:45 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-09-30 15:45 . 2006-11-13 14:45 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-09-30 15:45 . 2007-02-27 14:31 21,504 --a------ C:\WINDOWS\system32\drivers\motmodem.sys
2008-09-30 15:44 . 2008-09-30 15:44 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared
2008-09-30 15:41 . 2008-09-30 15:42 <DIR> d-------- C:\Program Files\Avanquest update
2008-09-30 15:41 . 2008-04-13 14:45 26,112 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-09-30 15:41 . 2008-04-13 14:45 26,112 --a------ C:\WINDOWS\system32\dllcache\usbser.sys
2008-09-30 15:40 . 2008-09-30 15:45 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-09-30 15:40 . 2008-09-30 15:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-09-30 15:40 . 2008-09-30 15:40 92,064 --a------ C:\Documents and Settings\Kevin\mqdmmdm.sys
2008-09-30 15:40 . 2008-09-30 15:40 79,328 --a------ C:\Documents and Settings\Kevin\mqdmserd.sys
2008-09-30 15:40 . 2008-09-30 15:40 66,656 --a------ C:\Documents and Settings\Kevin\mqdmbus.sys
2008-09-30 15:40 . 2008-09-30 15:40 25,600 --a------ C:\Documents and Settings\Kevin\usbsermptxp.sys
2008-09-30 15:40 . 2008-09-30 15:40 22,768 --a------ C:\Documents and Settings\Kevin\usbsermpt.sys
2008-09-30 15:40 . 2008-09-30 15:40 9,232 --a------ C:\Documents and Settings\Kevin\mqdmmdfl.sys
2008-09-30 15:40 . 2008-09-30 15:40 6,208 --a------ C:\Documents and Settings\Kevin\mqdmcmnt.sys
2008-09-30 15:40 . 2008-09-30 15:40 5,936 --a------ C:\Documents and Settings\Kevin\mqdmwhnt.sys
2008-09-30 15:40 . 2008-09-30 15:40 4,048 --a------ C:\Documents and Settings\Kevin\mqdmcr.sys
2008-09-30 10:20 . 2008-09-30 10:20 60,968 --a------ C:\Documents and Settings\Kevin\GoToAssistDownloadHelper.exe
2008-09-29 21:45 . 2008-10-15 17:14 <DIR> d-------- C:\Program Files\Swarm Gold
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-22 23:39 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-10-22 18:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-21 13:04 --------- d-----w C:\Documents and Settings\Kevin\Application Data\U3
2008-10-17 01:55 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-10-16 20:18 507,904 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-10-16 20:18 295,424 ----a-w C:\WINDOWS\system32\termsrv.dll
2008-10-15 13:09 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Yahoo!
2008-10-03 17:41 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-10-02 17:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\PCPitstop
2008-09-30 19:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-20 15:08 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Tunebite
2008-09-20 01:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\RapidSolution
2008-09-20 01:07 --------- d-----w C:\Program Files\PixiePack Codec Pack
2008-09-20 01:06 --------- d-----w C:\Program Files\RapidSolution
2008-09-15 12:12 1,846,400 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-14 19:28 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Flood Light Games
2008-09-14 19:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Flood Light Games
2008-09-09 23:53 --------- d-----w C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-06 03:30 241,704 ------w C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-06 03:29 917,032 ------w C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-09-05 22:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2008-09-05 22:36 --------- d-----w C:\Program Files\Safari Island Deluxe
2008-09-05 22:06 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Ludia
2008-09-05 22:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ludia
2008-09-05 22:05 --------- d-----w C:\Program Files\The Price Is Right
2008-09-05 16:37 --------- d-----w C:\Documents and Settings\Kevin\Application Data\ForgottenRiddles
2008-09-04 17:43 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Ahead
2008-09-04 16:46 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Ahead
2008-09-04 16:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-09-04 16:00 --------- d-----w C:\Program Files\Common Files\Ahead
2008-09-04 15:59 --------- d-----w C:\Program Files\Nero
2008-09-04 13:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-09-04 02:43 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Roxio
2008-09-04 02:21 --------- d-----w C:\Program Files\DVD Shrink
2008-09-04 02:03 7,040 ----a-w C:\WINDOWS\system32\drivers\FNETURPX.SYS
2008-09-04 02:03 17,792 ----a-w C:\WINDOWS\system32\drivers\FNETTBOH.SYS
2008-09-04 02:03 --------- d-----w C:\Program Files\TurboHddUsb
2008-09-04 02:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\FNET
2008-09-03 14:05 --------- d-----w C:\Program Files\Ice Cream Dee Lites
2008-09-03 13:59 --------- d-----w C:\Program Files\eGames
2008-09-02 16:41 --------- d-----w C:\Program Files\LeeGTs Games
2008-09-01 14:39 --------- d-----w C:\Documents and Settings\Kevin\Application Data\iWin
2008-09-01 03:18 --------- d-----w C:\Program Files\Pirateville
2008-08-31 20:44 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Legends of pirates
2008-08-31 01:34 --------- d-----w C:\Program Files\Forgotten Riddles - The Mayan Princess
2008-08-29 23:26 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 08:24 3,593,216 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-25 08:38 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-25 08:37 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-23 05:56 635,848 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-14 10:09 2,145,280 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 10:04 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-08-14 09:33 2,023,936 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-06-10 00:36 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008060920080610\index.dat
.
------- Sigcheck -------
2004-08-04 06:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 20:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-10-16 16:18 507904 3969440ba384d35317dbbdeeaae641ce C:\WINDOWS\system32\winlogon.exe
2004-08-04 06:00 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2008-04-13 20:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-10-16 16:18 295424 63999d0abd8dabfd76a9c07f6e104868 C:\WINDOWS\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 700416]
"Pando"="C:\Program Files\Pando Networks\Pando\Pando.exe" [2008-07-25 6591816]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]
"Search Protection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-27 8429568]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 16384]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 842584]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2006-10-03 221184]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 385024]
"TurboHddUsb"="C:\Program Files\TurboHddUsb\TurboHddUsb.exe" [2008-09-03 3327488]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-10-16 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"MntWin"= {6280B887-A416-F4C4-5581-0BA044BAC6EA} - C:\Program Files\gnzwuze\MntWin.dll [2008-10-16 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-10-16 21:55 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"57885:TCP"= 57885:TCP:Pando P2P TCP Listening Port
"57885:UDP"= 57885:UDP:Pando P2P UDP Listening Port
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 28184]
R1 FNETURPX;FNETURPX;C:\WINDOWS\system32\drivers\FNETURPX.SYS [2008-09-03 7040]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R3 FNETTBOH;FNETTBOH;C:\WINDOWS\system32\drivers\FNETTBOH.SYS [2008-09-03 17792]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\X]
\Shell\AutoRun\command - X:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6a675f8-790d-11dd-a2e9-001aa09fb8d6}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-updateMgr - C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-webact - C:\WINDOWS\system32\hsdebwto.exe
ShellExecuteHooks-{5BACC17E-BDF7-405B-BC68-ECB506395118} - (no file)
MSConfigStartUp-Google Desktop Search - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\opw5ts4p.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-22 22:47:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-10-22 22:52:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-23 02:52:02
Pre-Run: 95,067,357,184 bytes free
Post-Run: 95,682,617,344 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
245 --- E O F --- 2008-10-22 03:21:53