DDS:DDS (Ver_09-05-14.01) - NTFSx86
Run by Administrator at 14:53:25.17 on Fri 07/03/2009
Internet Explorer: 6.0.2800.1106
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1023.699 [GMT -5:00]
============== Running Processes ===============
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\ATKKBService.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINNT\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\WINNT\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\Virus\dds.scr
============== Pseudo HJT Report ===============
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\system32\blank.htm
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [WrtMon.exe] c:\winnt\system32\spool\drivers\w32x86\3\WrtMon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {0000000A-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/8/B/E/8BE028EC-F134-4AA0-84AB-64F76D6B9842/wmsp9dmo.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153420015171
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
============= SERVICES / DRIVERS ===============
R3 openhci;Microsoft USB Open Host Controller Driver;c:\winnt\system32\drivers\openhci.sys [1999-12-7 24784]
=============== Created Last 30 ================
2009-07-03 14:50 <DIR> -cd----- c:\winnt\system32\dllcache\cache
2009-07-03 14:46 161,792 a------- c:\winnt\SWREG.exe
2009-07-03 14:46 155,136 a------- c:\winnt\PEV.exe
2009-07-03 14:46 98,816 a------- c:\winnt\sed.exe
2009-07-03 14:46 <DIR> --ds---- C:\ComboFix
2009-07-03 14:42 16,384 a------t c:\winnt\system32\Perflib_Perfdata_514.dat
2009-07-03 14:41 16,384 a------t c:\winnt\system32\Perflib_Perfdata_300.dat
2009-07-03 14:41 16,384 a------t c:\winnt\system32\Perflib_Perfdata_234.dat
2009-07-02 11:26 16,384 a------t c:\winnt\system32\Perflib_Perfdata_89c.dat
2009-07-02 08:52 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6b0.dat
2009-07-02 08:52 16,384 a------t c:\winnt\system32\Perflib_Perfdata_418.dat
2009-06-29 12:42 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6a0.dat
2009-06-29 08:44 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6bc.dat
2009-06-29 08:44 16,384 a------t c:\winnt\system32\Perflib_Perfdata_320.dat
2009-06-28 08:36 16,384 a------t c:\winnt\system32\Perflib_Perfdata_694.dat
2009-06-28 08:36 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5c8.dat
2009-06-28 08:35 16,384 a------t c:\winnt\system32\Perflib_Perfdata_240.dat
2009-06-28 08:26 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6ac.dat
2009-06-28 08:26 16,384 a------t c:\winnt\system32\Perflib_Perfdata_608.dat
2009-06-28 07:45 16,384 a------t c:\winnt\system32\Perflib_Perfdata_700.dat
2009-06-27 07:40 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6d8.dat
2009-06-27 07:40 16,384 a------t c:\winnt\system32\Perflib_Perfdata_4dc.dat
2009-06-26 09:59 16,384 a------t c:\winnt\system32\Perflib_Perfdata_754.dat
2009-06-26 07:52 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6b4.dat
2009-06-26 07:43 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5b4.dat
2009-06-25 12:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_4c0.dat
2009-06-25 12:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_61c.dat
2009-06-25 12:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_318.dat
2009-06-25 11:57 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5d8.dat
2009-06-25 11:56 16,384 a------t c:\winnt\system32\Perflib_Perfdata_328.dat
2009-06-25 08:32 16,384 a------t c:\winnt\system32\Perflib_Perfdata_1c8.dat
2009-06-25 08:17 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5e0.dat
2009-06-25 07:23 16,384 a------t c:\winnt\system32\Perflib_Perfdata_4d4.dat
2009-06-25 07:23 16,384 a------t c:\winnt\system32\Perflib_Perfdata_334.dat
2009-06-24 12:59 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6c8.dat
2009-06-24 12:59 16,384 a------t c:\winnt\system32\Perflib_Perfdata_628.dat
2009-06-24 10:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_720.dat
2009-06-23 07:35 16,384 a------t c:\winnt\system32\Perflib_Perfdata_704.dat
2009-06-23 07:34 16,384 a------t c:\winnt\system32\Perflib_Perfdata_330.dat
2009-06-22 17:19 <DIR> --d----- c:\program files\Lavasoft
2009-06-22 17:19 <DIR> --d----- c:\winnt\winsxs
2009-06-20 07:36 16,384 a------t c:\winnt\system32\Perflib_Perfdata_654.dat
2009-06-19 07:33 16,384 a------t c:\winnt\system32\Perflib_Perfdata_618.dat
2009-06-17 11:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5a8.dat
2009-06-16 09:58 16,384 a------t c:\winnt\system32\Perflib_Perfdata_520.dat
2009-06-12 09:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_2e8.dat
2009-06-08 15:11 554,306 ----h--- c:\winnt\ShellIconCache
2009-06-07 01:24 <DIR> --d----- c:\program files\Sun
2009-06-07 01:24 410,984 a------- c:\winnt\system32\deploytk.dll
2009-06-07 01:24 73,728 a------- c:\winnt\system32\javacpl.cpl
2009-06-07 01:18 16,384 a------t c:\winnt\system32\Perflib_Perfdata_678.dat
2009-06-07 01:11 <DIR> --d----- c:\documents and settings\administrator\.SunDownloadManager
2009-06-07 01:03 <DIR> --d----- c:\program files\Trend Micro
2009-06-07 00:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5a0.dat
2009-06-06 23:51 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-06-06 23:51 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-06 23:42 <DIR> --d----- c:\docume~1\admini~1\applic~1\Safer Networking
2009-06-06 23:42 <DIR> --d----- c:\program files\Safer Networking
==================== Find3M ====================
2009-05-31 21:43 16,384 a------t c:\winnt\system32\Perflib_Perfdata_578.dat
2009-05-31 21:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_584.dat
2009-05-31 21:14 16,384 a------t c:\winnt\system32\Perflib_Perfdata_7fc.dat
2009-05-31 15:26 16,384 a------t c:\winnt\system32\Perflib_Perfdata_424.dat
2009-05-30 15:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_374.dat
2009-05-30 15:28 16,384 a------t c:\winnt\system32\Perflib_Perfdata_670.dat
2009-05-30 15:25 16,384 a------t c:\winnt\system32\Perflib_Perfdata_484.dat
2009-05-30 15:25 16,384 a------t c:\winnt\system32\Perflib_Perfdata_590.dat
2009-05-30 14:55 16,384 a------t c:\winnt\system32\Perflib_Perfdata_574.dat
2009-05-30 13:20 16,384 a------t c:\winnt\system32\Perflib_Perfdata_728.dat
2009-05-30 12:46 16,384 a------t c:\winnt\system32\Perflib_Perfdata_64c.dat
2009-05-30 12:42 16,384 a------t c:\winnt\system32\Perflib_Perfdata_8d8.dat
2009-05-30 09:24 16,384 a------t c:\winnt\system32\Perflib_Perfdata_2a4.dat
2009-05-27 08:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_57c.dat
2009-05-25 16:55 16,384 a------t c:\winnt\system32\Perflib_Perfdata_534.dat
2009-05-23 16:41 16,384 a------t c:\winnt\system32\Perflib_Perfdata_570.dat
2009-05-23 16:29 16,384 a------t c:\winnt\system32\Perflib_Perfdata_308.dat
2009-05-23 16:22 16,384 a------t c:\winnt\system32\Perflib_Perfdata_644.dat
2009-05-23 16:17 16,384 a------t c:\winnt\system32\Perflib_Perfdata_660.dat
2009-05-23 13:53 16,384 a------t c:\winnt\system32\Perflib_Perfdata_630.dat
2009-05-23 10:44 16,384 a------t c:\winnt\system32\Perflib_Perfdata_650.dat
2009-05-14 09:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_524.dat
2009-05-09 09:41 16,384 a------t c:\winnt\system32\Perflib_Perfdata_65c.dat
2009-05-07 01:41 263,440 a------- c:\winnt\system32\LOCALSPL.DLL
2009-04-24 04:54 95,504 a------- c:\winnt\system32\WIN32SPL.DLL
2009-04-22 08:38 437,008 a------- c:\winnt\system32\rpcrt4.dll
2009-04-21 15:15 576,512 a------- c:\winnt\system32\WININET.DLL
2009-04-17 00:04 1,645,072 a------- c:\winnt\system32\WIN32K.SYS
2006-07-29 17:57 12,888 a------- c:\docume~1\admini~1\applic~1\GDIPFONTCACHEV1.DAT
2006-07-20 05:16 21,952 ----h--- c:\program files\folder.htt
2006-07-20 05:16 271 ----h--- c:\program files\desktop.ini
1999-12-07 07:00 32,528 a------- c:\winnt\inf\wbfirdma.sys
============= FINISH: 14:53:36.03 ===============
COMBO FIX:ComboFix 09-07-02.03 - Administrator 07/03/2009 14:47.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1023.721 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\arcldr.exe
C:\arcsetup.exe
c:\winnt\system32\404Fix.exe
c:\winnt\system32\Agent.OMZ.Fix.exe
c:\winnt\system32\dumphive.exe
c:\winnt\system32\IEDFix.C.exe
c:\winnt\system32\IEDFix.exe
c:\winnt\system32\mww29911.dll
c:\winnt\system32\o4Patch.exe
c:\winnt\system32\Process.exe
c:\winnt\system32\SrchSTS.exe
c:\winnt\system32\tmp.reg
c:\winnt\system32\VCCLSID.exe
c:\winnt\system32\WS2Fix.exe
c:\winnt\system32\ww29911.dll
c:\winnt\Web\default.htt
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2009-06-03 to 2009-07-03 )))))))))))))))))))))))))))))))
.
2009-07-03 19:42 . 2009-07-03 19:42 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_514.dat
2009-07-03 19:41 . 2009-07-03 19:41 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_300.dat
2009-07-03 19:41 . 2009-07-03 19:41 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_234.dat
2009-07-02 16:26 . 2009-07-02 16:26 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_89c.dat
2009-07-02 13:52 . 2009-07-02 13:52 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6b0.dat
2009-07-02 13:52 . 2009-07-02 13:52 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_418.dat
2009-06-29 17:42 . 2009-06-29 17:42 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6a0.dat
2009-06-29 13:44 . 2009-06-29 13:44 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6bc.dat
2009-06-29 13:44 . 2009-06-29 13:44 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_320.dat
2009-06-28 13:36 . 2009-06-28 13:36 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_694.dat
2009-06-28 13:36 . 2009-06-28 13:36 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5c8.dat
2009-06-28 13:35 . 2009-06-28 13:35 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_240.dat
2009-06-28 13:26 . 2009-06-28 13:26 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6ac.dat
2009-06-28 13:26 . 2009-06-28 13:26 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_608.dat
2009-06-28 12:45 . 2009-06-28 12:45 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_700.dat
2009-06-27 12:40 . 2009-06-27 12:40 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6d8.dat
2009-06-27 12:40 . 2009-06-27 12:40 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_4dc.dat
2009-06-26 14:59 . 2009-06-26 14:59 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_754.dat
2009-06-26 12:52 . 2009-06-26 12:52 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6b4.dat
2009-06-26 12:43 . 2009-06-26 12:43 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5b4.dat
2009-06-25 17:08 . 2009-06-25 17:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_4c0.dat
2009-06-25 17:08 . 2009-06-25 17:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_61c.dat
2009-06-25 17:08 . 2009-06-25 17:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_318.dat
2009-06-25 16:57 . 2009-06-25 16:57 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5d8.dat
2009-06-25 16:56 . 2009-06-25 16:56 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_328.dat
2009-06-25 13:32 . 2009-06-25 13:32 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_1c8.dat
2009-06-25 13:17 . 2009-06-25 13:17 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5e0.dat
2009-06-25 12:23 . 2009-06-25 12:23 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_4d4.dat
2009-06-25 12:23 . 2009-06-25 12:23 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_334.dat
2009-06-24 17:59 . 2009-06-24 17:59 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6c8.dat
2009-06-24 17:59 . 2009-06-24 17:59 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_628.dat
2009-06-24 15:30 . 2009-06-24 15:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_720.dat
2009-06-23 12:35 . 2009-06-23 12:35 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_704.dat
2009-06-23 12:34 . 2009-06-23 12:34 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_330.dat
2009-06-22 22:22 . 2009-07-03 19:39 -------- dc----w- c:\winnt\system32\DRVSTORE
2009-06-22 22:19 . 2009-07-03 19:39 -------- d-----w- c:\program files\Lavasoft
2009-06-22 22:19 . 2009-06-22 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-22 22:19 . 2009-06-22 22:19 -------- d-----w- c:\winnt\winsxs
2009-06-20 12:36 . 2009-06-20 12:36 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_654.dat
2009-06-19 12:33 . 2009-06-19 12:33 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_618.dat
2009-06-17 16:30 . 2009-06-17 16:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5a8.dat
2009-06-16 14:58 . 2009-06-16 14:58 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_520.dat
2009-06-12 14:08 . 2009-06-12 14:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_2e8.dat
2009-06-07 06:24 . 2009-06-07 06:24 -------- d-----w- c:\program files\Sun
2009-06-07 06:24 . 2009-06-07 06:24 410984 ----a-w- c:\winnt\system32\deploytk.dll
2009-06-07 06:18 . 2009-06-07 06:18 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_678.dat
2009-06-07 06:11 . 2009-06-07 06:15 -------- d-----w- c:\documents and settings\Administrator\.SunDownloadManager
2009-06-07 06:03 . 2009-06-07 06:03 -------- d-----w- c:\program files\Trend Micro
2009-06-07 05:30 . 2009-06-07 05:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5a0.dat
2009-06-07 04:51 . 2009-06-07 04:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-07 04:51 . 2009-06-07 04:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-07 04:42 . 2009-06-07 04:42 -------- d-----w- c:\documents and settings\Administrator\Application Data\Safer Networking
2009-06-07 04:42 . 2009-06-07 04:43 -------- d-----w- c:\program files\Safer Networking
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-03 19:40 . 2008-08-30 05:11 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-03 19:39 . 2008-08-30 05:11 -------- d---a-w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-15 18:46 . 2006-08-19 19:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-06-07 06:24 . 2009-05-30 19:06 -------- d-----w- c:\program files\Java
2009-06-01 02:43 . 2009-06-01 02:43 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_578.dat
2009-06-01 02:30 . 2009-06-01 02:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_584.dat
2009-06-01 02:14 . 2009-06-01 02:14 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_7fc.dat
2009-05-31 20:26 . 2009-05-31 20:26 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_424.dat
2009-05-30 20:30 . 2009-05-30 20:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_374.dat
2009-05-30 20:28 . 2009-05-30 20:28 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_670.dat
2009-05-30 20:25 . 2009-05-30 20:25 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_484.dat
2009-05-30 20:25 . 2009-05-30 20:25 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_590.dat
2009-05-30 19:55 . 2009-05-30 19:55 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_574.dat
2009-05-30 19:05 . 2009-05-30 19:05 -------- d-----w- c:\program files\Common Files\Java
2009-05-30 18:20 . 2009-05-30 18:20 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_728.dat
2009-05-30 17:46 . 2009-05-30 17:46 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_64c.dat
2009-05-30 17:42 . 2009-05-30 17:42 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_8d8.dat
2009-05-30 14:24 . 2009-05-30 14:24 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_2a4.dat
2009-05-27 13:30 . 2009-05-27 13:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_57c.dat
2009-05-25 21:55 . 2009-05-25 21:55 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_534.dat
2009-05-23 21:41 . 2009-05-23 21:41 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_570.dat
2009-05-23 21:29 . 2009-05-23 21:29 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_308.dat
2009-05-23 21:22 . 2009-05-23 21:22 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_644.dat
2009-05-23 21:17 . 2009-05-23 21:17 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_660.dat
2009-05-23 18:53 . 2009-05-23 18:53 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_630.dat
2009-05-23 15:44 . 2009-05-23 15:44 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_650.dat
2009-05-14 14:08 . 2009-05-14 14:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_524.dat
2009-05-09 14:41 . 2009-05-09 14:41 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_65c.dat
2009-05-07 06:41 . 1999-12-07 12:00 263440 ----a-w- c:\winnt\system32\LOCALSPL.DLL
2009-04-24 09:54 . 1999-12-07 12:00 95504 ----a-w- c:\winnt\system32\WIN32SPL.DLL
2009-04-22 13:38 . 2009-04-22 13:38 437008 ----a-w- c:\winnt\system32\rpcrt4.dll
2009-04-21 20:15 . 2009-04-21 20:15 576512 ----a-w- c:\winnt\system32\WININET.DLL
2009-04-17 05:04 . 1999-12-07 12:00 1645072 ----a-w- c:\winnt\system32\WIN32K.SYS
2006-07-20 10:16 . 2006-07-20 10:16 21952 ---h--w- c:\program files\folder.htt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"WrtMon.exe"="c:\winnt\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-07 148888]
"Synchronization Manager"="mobsync.exe" - c:\winnt\system32\mobsync.exe [2003-06-19 111376]
"SoundMan"="SOUNDMAN.EXE" - c:\winnt\SOUNDMAN.EXE [2005-04-15 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 186640]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-7-20 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iexplore.exe]
"Debugger"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
R3 openhci;Microsoft USB Open Host Controller Driver;c:\winnt\system32\drivers\openhci.sys [12/7/1999 7:00 AM 24784]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://dyroom.cn/
mLocal Page = c:\windows\system32\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-03 14:50
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\winnt\system32\Perflib_Perfdata_6c0.dat 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(200)
c:\winnt\system32\Ati2evxx.dll
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Completion time: 2009-07-03 14:51
ComboFix-quarantined-files.txt 2009-07-03 19:51
Pre-Run: 127,574,392,832 bytes free
Post-Run: 127,689,740,288 bytes free
180 --- E O F --- 2009-06-15 23:01
DDS:DDS (Ver_09-05-14.01) - NTFSx86
Run by Administrator at 14:53:25.17 on Fri 07/03/2009
Internet Explorer: 6.0.2800.1106
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1023.699 [GMT -5:00]
============== Running Processes ===============
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\ATKKBService.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINNT\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\WINNT\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\Virus\dds.scr
============== Pseudo HJT Report ===============
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\system32\blank.htm
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [WrtMon.exe] c:\winnt\system32\spool\drivers\w32x86\3\WrtMon.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {0000000A-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/8/B/E/8BE028EC-F134-4AA0-84AB-64F76D6B9842/wmsp9dmo.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153420015171
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
============= SERVICES / DRIVERS ===============
R3 openhci;Microsoft USB Open Host Controller Driver;c:\winnt\system32\drivers\openhci.sys [1999-12-7 24784]
=============== Created Last 30 ================
2009-07-03 14:50 <DIR> -cd----- c:\winnt\system32\dllcache\cache
2009-07-03 14:46 161,792 a------- c:\winnt\SWREG.exe
2009-07-03 14:46 155,136 a------- c:\winnt\PEV.exe
2009-07-03 14:46 98,816 a------- c:\winnt\sed.exe
2009-07-03 14:46 <DIR> --ds---- C:\ComboFix
2009-07-03 14:42 16,384 a------t c:\winnt\system32\Perflib_Perfdata_514.dat
2009-07-03 14:41 16,384 a------t c:\winnt\system32\Perflib_Perfdata_300.dat
2009-07-03 14:41 16,384 a------t c:\winnt\system32\Perflib_Perfdata_234.dat
2009-07-02 11:26 16,384 a------t c:\winnt\system32\Perflib_Perfdata_89c.dat
2009-07-02 08:52 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6b0.dat
2009-07-02 08:52 16,384 a------t c:\winnt\system32\Perflib_Perfdata_418.dat
2009-06-29 12:42 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6a0.dat
2009-06-29 08:44 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6bc.dat
2009-06-29 08:44 16,384 a------t c:\winnt\system32\Perflib_Perfdata_320.dat
2009-06-28 08:36 16,384 a------t c:\winnt\system32\Perflib_Perfdata_694.dat
2009-06-28 08:36 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5c8.dat
2009-06-28 08:35 16,384 a------t c:\winnt\system32\Perflib_Perfdata_240.dat
2009-06-28 08:26 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6ac.dat
2009-06-28 08:26 16,384 a------t c:\winnt\system32\Perflib_Perfdata_608.dat
2009-06-28 07:45 16,384 a------t c:\winnt\system32\Perflib_Perfdata_700.dat
2009-06-27 07:40 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6d8.dat
2009-06-27 07:40 16,384 a------t c:\winnt\system32\Perflib_Perfdata_4dc.dat
2009-06-26 09:59 16,384 a------t c:\winnt\system32\Perflib_Perfdata_754.dat
2009-06-26 07:52 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6b4.dat
2009-06-26 07:43 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5b4.dat
2009-06-25 12:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_4c0.dat
2009-06-25 12:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_61c.dat
2009-06-25 12:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_318.dat
2009-06-25 11:57 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5d8.dat
2009-06-25 11:56 16,384 a------t c:\winnt\system32\Perflib_Perfdata_328.dat
2009-06-25 08:32 16,384 a------t c:\winnt\system32\Perflib_Perfdata_1c8.dat
2009-06-25 08:17 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5e0.dat
2009-06-25 07:23 16,384 a------t c:\winnt\system32\Perflib_Perfdata_4d4.dat
2009-06-25 07:23 16,384 a------t c:\winnt\system32\Perflib_Perfdata_334.dat
2009-06-24 12:59 16,384 a------t c:\winnt\system32\Perflib_Perfdata_6c8.dat
2009-06-24 12:59 16,384 a------t c:\winnt\system32\Perflib_Perfdata_628.dat
2009-06-24 10:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_720.dat
2009-06-23 07:35 16,384 a------t c:\winnt\system32\Perflib_Perfdata_704.dat
2009-06-23 07:34 16,384 a------t c:\winnt\system32\Perflib_Perfdata_330.dat
2009-06-22 17:19 <DIR> --d----- c:\program files\Lavasoft
2009-06-22 17:19 <DIR> --d----- c:\winnt\winsxs
2009-06-20 07:36 16,384 a------t c:\winnt\system32\Perflib_Perfdata_654.dat
2009-06-19 07:33 16,384 a------t c:\winnt\system32\Perflib_Perfdata_618.dat
2009-06-17 11:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5a8.dat
2009-06-16 09:58 16,384 a------t c:\winnt\system32\Perflib_Perfdata_520.dat
2009-06-12 09:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_2e8.dat
2009-06-08 15:11 554,306 ----h--- c:\winnt\ShellIconCache
2009-06-07 01:24 <DIR> --d----- c:\program files\Sun
2009-06-07 01:24 410,984 a------- c:\winnt\system32\deploytk.dll
2009-06-07 01:24 73,728 a------- c:\winnt\system32\javacpl.cpl
2009-06-07 01:18 16,384 a------t c:\winnt\system32\Perflib_Perfdata_678.dat
2009-06-07 01:11 <DIR> --d----- c:\documents and settings\administrator\.SunDownloadManager
2009-06-07 01:03 <DIR> --d----- c:\program files\Trend Micro
2009-06-07 00:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_5a0.dat
2009-06-06 23:51 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-06-06 23:51 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-06 23:42 <DIR> --d----- c:\docume~1\admini~1\applic~1\Safer Networking
2009-06-06 23:42 <DIR> --d----- c:\program files\Safer Networking
==================== Find3M ====================
2009-05-31 21:43 16,384 a------t c:\winnt\system32\Perflib_Perfdata_578.dat
2009-05-31 21:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_584.dat
2009-05-31 21:14 16,384 a------t c:\winnt\system32\Perflib_Perfdata_7fc.dat
2009-05-31 15:26 16,384 a------t c:\winnt\system32\Perflib_Perfdata_424.dat
2009-05-30 15:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_374.dat
2009-05-30 15:28 16,384 a------t c:\winnt\system32\Perflib_Perfdata_670.dat
2009-05-30 15:25 16,384 a------t c:\winnt\system32\Perflib_Perfdata_484.dat
2009-05-30 15:25 16,384 a------t c:\winnt\system32\Perflib_Perfdata_590.dat
2009-05-30 14:55 16,384 a------t c:\winnt\system32\Perflib_Perfdata_574.dat
2009-05-30 13:20 16,384 a------t c:\winnt\system32\Perflib_Perfdata_728.dat
2009-05-30 12:46 16,384 a------t c:\winnt\system32\Perflib_Perfdata_64c.dat
2009-05-30 12:42 16,384 a------t c:\winnt\system32\Perflib_Perfdata_8d8.dat
2009-05-30 09:24 16,384 a------t c:\winnt\system32\Perflib_Perfdata_2a4.dat
2009-05-27 08:30 16,384 a------t c:\winnt\system32\Perflib_Perfdata_57c.dat
2009-05-25 16:55 16,384 a------t c:\winnt\system32\Perflib_Perfdata_534.dat
2009-05-23 16:41 16,384 a------t c:\winnt\system32\Perflib_Perfdata_570.dat
2009-05-23 16:29 16,384 a------t c:\winnt\system32\Perflib_Perfdata_308.dat
2009-05-23 16:22 16,384 a------t c:\winnt\system32\Perflib_Perfdata_644.dat
2009-05-23 16:17 16,384 a------t c:\winnt\system32\Perflib_Perfdata_660.dat
2009-05-23 13:53 16,384 a------t c:\winnt\system32\Perflib_Perfdata_630.dat
2009-05-23 10:44 16,384 a------t c:\winnt\system32\Perflib_Perfdata_650.dat
2009-05-14 09:08 16,384 a------t c:\winnt\system32\Perflib_Perfdata_524.dat
2009-05-09 09:41 16,384 a------t c:\winnt\system32\Perflib_Perfdata_65c.dat
2009-05-07 01:41 263,440 a------- c:\winnt\system32\LOCALSPL.DLL
2009-04-24 04:54 95,504 a------- c:\winnt\system32\WIN32SPL.DLL
2009-04-22 08:38 437,008 a------- c:\winnt\system32\rpcrt4.dll
2009-04-21 15:15 576,512 a------- c:\winnt\system32\WININET.DLL
2009-04-17 00:04 1,645,072 a------- c:\winnt\system32\WIN32K.SYS
2006-07-29 17:57 12,888 a------- c:\docume~1\admini~1\applic~1\GDIPFONTCACHEV1.DAT
2006-07-20 05:16 21,952 ----h--- c:\program files\folder.htt
2006-07-20 05:16 271 ----h--- c:\program files\desktop.ini
1999-12-07 07:00 32,528 a------- c:\winnt\inf\wbfirdma.sys
============= FINISH: 14:53:36.03 ===============
COMBO FIX:ComboFix 09-07-02.03 - Administrator 07/03/2009 14:47.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1023.721 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\arcldr.exe
C:\arcsetup.exe
c:\winnt\system32\404Fix.exe
c:\winnt\system32\Agent.OMZ.Fix.exe
c:\winnt\system32\dumphive.exe
c:\winnt\system32\IEDFix.C.exe
c:\winnt\system32\IEDFix.exe
c:\winnt\system32\mww29911.dll
c:\winnt\system32\o4Patch.exe
c:\winnt\system32\Process.exe
c:\winnt\system32\SrchSTS.exe
c:\winnt\system32\tmp.reg
c:\winnt\system32\VCCLSID.exe
c:\winnt\system32\WS2Fix.exe
c:\winnt\system32\ww29911.dll
c:\winnt\Web\default.htt
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2009-06-03 to 2009-07-03 )))))))))))))))))))))))))))))))
.
2009-07-03 19:42 . 2009-07-03 19:42 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_514.dat
2009-07-03 19:41 . 2009-07-03 19:41 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_300.dat
2009-07-03 19:41 . 2009-07-03 19:41 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_234.dat
2009-07-02 16:26 . 2009-07-02 16:26 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_89c.dat
2009-07-02 13:52 . 2009-07-02 13:52 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6b0.dat
2009-07-02 13:52 . 2009-07-02 13:52 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_418.dat
2009-06-29 17:42 . 2009-06-29 17:42 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6a0.dat
2009-06-29 13:44 . 2009-06-29 13:44 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6bc.dat
2009-06-29 13:44 . 2009-06-29 13:44 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_320.dat
2009-06-28 13:36 . 2009-06-28 13:36 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_694.dat
2009-06-28 13:36 . 2009-06-28 13:36 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5c8.dat
2009-06-28 13:35 . 2009-06-28 13:35 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_240.dat
2009-06-28 13:26 . 2009-06-28 13:26 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6ac.dat
2009-06-28 13:26 . 2009-06-28 13:26 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_608.dat
2009-06-28 12:45 . 2009-06-28 12:45 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_700.dat
2009-06-27 12:40 . 2009-06-27 12:40 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6d8.dat
2009-06-27 12:40 . 2009-06-27 12:40 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_4dc.dat
2009-06-26 14:59 . 2009-06-26 14:59 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_754.dat
2009-06-26 12:52 . 2009-06-26 12:52 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6b4.dat
2009-06-26 12:43 . 2009-06-26 12:43 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5b4.dat
2009-06-25 17:08 . 2009-06-25 17:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_4c0.dat
2009-06-25 17:08 . 2009-06-25 17:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_61c.dat
2009-06-25 17:08 . 2009-06-25 17:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_318.dat
2009-06-25 16:57 . 2009-06-25 16:57 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5d8.dat
2009-06-25 16:56 . 2009-06-25 16:56 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_328.dat
2009-06-25 13:32 . 2009-06-25 13:32 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_1c8.dat
2009-06-25 13:17 . 2009-06-25 13:17 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5e0.dat
2009-06-25 12:23 . 2009-06-25 12:23 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_4d4.dat
2009-06-25 12:23 . 2009-06-25 12:23 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_334.dat
2009-06-24 17:59 . 2009-06-24 17:59 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_6c8.dat
2009-06-24 17:59 . 2009-06-24 17:59 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_628.dat
2009-06-24 15:30 . 2009-06-24 15:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_720.dat
2009-06-23 12:35 . 2009-06-23 12:35 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_704.dat
2009-06-23 12:34 . 2009-06-23 12:34 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_330.dat
2009-06-22 22:22 . 2009-07-03 19:39 -------- dc----w- c:\winnt\system32\DRVSTORE
2009-06-22 22:19 . 2009-07-03 19:39 -------- d-----w- c:\program files\Lavasoft
2009-06-22 22:19 . 2009-06-22 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-22 22:19 . 2009-06-22 22:19 -------- d-----w- c:\winnt\winsxs
2009-06-20 12:36 . 2009-06-20 12:36 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_654.dat
2009-06-19 12:33 . 2009-06-19 12:33 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_618.dat
2009-06-17 16:30 . 2009-06-17 16:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5a8.dat
2009-06-16 14:58 . 2009-06-16 14:58 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_520.dat
2009-06-12 14:08 . 2009-06-12 14:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_2e8.dat
2009-06-07 06:24 . 2009-06-07 06:24 -------- d-----w- c:\program files\Sun
2009-06-07 06:24 . 2009-06-07 06:24 410984 ----a-w- c:\winnt\system32\deploytk.dll
2009-06-07 06:18 . 2009-06-07 06:18 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_678.dat
2009-06-07 06:11 . 2009-06-07 06:15 -------- d-----w- c:\documents and settings\Administrator\.SunDownloadManager
2009-06-07 06:03 . 2009-06-07 06:03 -------- d-----w- c:\program files\Trend Micro
2009-06-07 05:30 . 2009-06-07 05:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_5a0.dat
2009-06-07 04:51 . 2009-06-07 04:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-07 04:51 . 2009-06-07 04:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-07 04:42 . 2009-06-07 04:42 -------- d-----w- c:\documents and settings\Administrator\Application Data\Safer Networking
2009-06-07 04:42 . 2009-06-07 04:43 -------- d-----w- c:\program files\Safer Networking
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-03 19:40 . 2008-08-30 05:11 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-03 19:39 . 2008-08-30 05:11 -------- d---a-w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-15 18:46 . 2006-08-19 19:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-06-07 06:24 . 2009-05-30 19:06 -------- d-----w- c:\program files\Java
2009-06-01 02:43 . 2009-06-01 02:43 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_578.dat
2009-06-01 02:30 . 2009-06-01 02:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_584.dat
2009-06-01 02:14 . 2009-06-01 02:14 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_7fc.dat
2009-05-31 20:26 . 2009-05-31 20:26 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_424.dat
2009-05-30 20:30 . 2009-05-30 20:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_374.dat
2009-05-30 20:28 . 2009-05-30 20:28 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_670.dat
2009-05-30 20:25 . 2009-05-30 20:25 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_484.dat
2009-05-30 20:25 . 2009-05-30 20:25 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_590.dat
2009-05-30 19:55 . 2009-05-30 19:55 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_574.dat
2009-05-30 19:05 . 2009-05-30 19:05 -------- d-----w- c:\program files\Common Files\Java
2009-05-30 18:20 . 2009-05-30 18:20 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_728.dat
2009-05-30 17:46 . 2009-05-30 17:46 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_64c.dat
2009-05-30 17:42 . 2009-05-30 17:42 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_8d8.dat
2009-05-30 14:24 . 2009-05-30 14:24 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_2a4.dat
2009-05-27 13:30 . 2009-05-27 13:30 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_57c.dat
2009-05-25 21:55 . 2009-05-25 21:55 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_534.dat
2009-05-23 21:41 . 2009-05-23 21:41 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_570.dat
2009-05-23 21:29 . 2009-05-23 21:29 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_308.dat
2009-05-23 21:22 . 2009-05-23 21:22 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_644.dat
2009-05-23 21:17 . 2009-05-23 21:17 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_660.dat
2009-05-23 18:53 . 2009-05-23 18:53 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_630.dat
2009-05-23 15:44 . 2009-05-23 15:44 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_650.dat
2009-05-14 14:08 . 2009-05-14 14:08 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_524.dat
2009-05-09 14:41 . 2009-05-09 14:41 16384 ----atw- c:\winnt\system32\Perflib_Perfdata_65c.dat
2009-05-07 06:41 . 1999-12-07 12:00 263440 ----a-w- c:\winnt\system32\LOCALSPL.DLL
2009-04-24 09:54 . 1999-12-07 12:00 95504 ----a-w- c:\winnt\system32\WIN32SPL.DLL
2009-04-22 13:38 . 2009-04-22 13:38 437008 ----a-w- c:\winnt\system32\rpcrt4.dll
2009-04-21 20:15 . 2009-04-21 20:15 576512 ----a-w- c:\winnt\system32\WININET.DLL
2009-04-17 05:04 . 1999-12-07 12:00 1645072 ----a-w- c:\winnt\system32\WIN32K.SYS
2006-07-20 10:16 . 2006-07-20 10:16 21952 ---h--w- c:\program files\folder.htt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"WrtMon.exe"="c:\winnt\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-07 148888]
"Synchronization Manager"="mobsync.exe" - c:\winnt\system32\mobsync.exe [2003-06-19 111376]
"SoundMan"="SOUNDMAN.EXE" - c:\winnt\SOUNDMAN.EXE [2005-04-15 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-19 186640]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-7-20 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iexplore.exe]
"Debugger"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
R3 openhci;Microsoft USB Open Host Controller Driver;c:\winnt\system32\drivers\openhci.sys [12/7/1999 7:00 AM 24784]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://dyroom.cn/
mLocal Page = c:\windows\system32\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-03 14:50
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\winnt\system32\Perflib_Perfdata_6c0.dat 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(200)
c:\winnt\system32\Ati2evxx.dll
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
.
Completion time: 2009-07-03 14:51
ComboFix-quarantined-files.txt 2009-07-03 19:51
Pre-Run: 127,574,392,832 bytes free
Post-Run: 127,689,740,288 bytes free
180 --- E O F --- 2009-06-15 23:01