l3x
Task To Run: C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe update all silent
———————–
ComboFix 09-12-28.06 - alex 12/29/2009 10:10:26.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2574 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\alex\Desktop\cfscript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.
2009-12-23 22:08 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-23 17:44 . 2009-12-23 17:44 ——– d—–w- c:\program files\Smart Projects
2009-12-22 21:53 . 2009-12-22 21:53 454656 —-a-w- C:\putty.exe
2009-12-22 21:11 . 2001-08-17 21:53 4992 -c–a-w- c:\windows\system32\dllcache\loop.sys
2009-12-22 21:11 . 2001-08-17 21:53 4992 —-a-w- c:\windows\system32\drivers\loop.sys
2009-12-22 19:47 . 2009-12-23 22:08 ——– d—–w- C:\DynaWorkDir
2009-12-22 19:46 . 2009-12-23 22:07 ——– d—–w- C:\projectGNS3
2009-12-22 19:41 . 2009-12-22 19:41 ——– d—–w- c:\program files\WinPcap
2009-12-22 19:41 . 2009-12-22 21:17 ——– d—–w- c:\program files\GNS3
2009-12-22 19:11 . 2009-12-22 19:11 ——– d—–w- c:\program files\Cisco Systems
2009-12-22 19:11 . 1997-12-18 02:33 304128 —-a-w- c:\windows\IsUninst.exe
2009-12-22 19:11 . 2009-12-22 19:11 ——– d—–w- c:\documents and settings\alex\WINDOWS
2009-12-22 18:28 . 2009-12-11 17:06 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-22 18:28 . 2009-12-11 17:06 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-22 18:28 . 2009-12-18 19:38 294656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-18 19:47 . 2009-12-04 00:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-18 19:47 . 2009-12-18 19:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 19:47 . 2009-12-04 00:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 06:17 . 2009-12-17 06:17 1956528 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-12-16 20:18 . 2009-12-16 20:18 ——– d—–w- c:\program files\MSXML 4.0
2009-12-16 20:07 . 2009-12-16 20:07 12568 —-a-w- c:\windows\system32\drivers\PROCEXP111.SYS
2009-12-16 02:18 . 2009-12-16 02:18 ——– d—–w- c:\program files\ERUNT
2009-12-16 01:47 . 2009-12-16 01:47 56532 —ha-w- c:\windows\system32\mlfcache.dat
2009-12-16 01:47 . 2009-12-16 01:47 ——– d—–w- c:\program files\Safari
2009-12-16 00:03 . 2009-12-16 01:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-15 22:59 . 2009-12-15 22:59 ——– d—–w- c:\program files\Trend Micro
2009-12-15 22:25 . 2009-12-15 22:25 ——– d—–w- c:\program files\MSSOAP
2009-12-15 22:25 . 2009-12-15 22:25 ——– d—–w- c:\program files\Webroot
2009-12-15 22:24 . 2009-12-15 22:24 164 —-a-w- c:\windows\install.dat
2009-12-15 22:01 . 2009-12-15 22:01 ——– d—–w- c:\documents and settings\alex\Local Settings\Application Data\Threat Expert
2009-12-15 21:44 . 2009-10-30 19:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-15 21:43 . 2009-11-09 19:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-15 21:43 . 2009-10-07 00:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-15 21:43 . 2009-09-03 17:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-15 21:43 . 2009-12-15 21:49 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-15 21:43 . 2009-12-16 02:24 ——– d—–w- c:\program files\Spyware Doctor
2009-12-15 21:43 . 2009-12-15 21:43 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-15 21:43 . 2009-12-15 21:43 ——– d—–w- c:\documents and settings\alex\Application Data\PC Tools
2009-12-15 21:42 . 2009-12-19 16:42 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-14 18:52 . 2009-12-16 18:54 ——– d—–w- c:\documents and settings\alex\Packet Tracer 5.2
2009-12-12 21:02 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2009-12-12 21:02 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-12-12 21:02 . 2001-08-17 21:48 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2009-12-12 21:02 . 2001-08-17 21:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-12-12 21:02 . 2008-04-13 18:39 14592 -c–a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-12-12 21:02 . 2008-04-13 18:39 14592 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2009-12-12 21:02 . 2008-04-13 18:45 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2009-12-12 21:02 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-12-12 19:47 . 2009-12-12 19:47 ——– d—–w- c:\documents and settings\alex\Application Data\Malwarebytes
2009-12-12 19:47 . 2009-12-12 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-12 19:38 . 2009-12-12 20:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-12 19:38 . 2009-12-12 19:38 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-12 18:27 . 2009-12-13 03:34 ——– d—–w- c:\program files\Visual CertExam Suite
2009-12-12 16:42 . 2003-06-23 10:44 1415680 —-a-w- c:\windows\system32\WMV9VCM.DLL
2009-12-12 16:42 . 1999-12-16 08:01 49152 —-a-w- c:\windows\system32\TSCCVID.DLL
2009-12-12 16:41 . 2009-12-12 17:26 ——– d—–w- c:\program files\TESTOUT
2009-12-11 17:06 . 2009-12-11 17:05 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-09 19:32 . 2009-12-09 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Boson Software
2009-12-08 03:46 . 2009-12-08 03:46 ——– d—–w- c:\program files\gs
2009-12-08 03:45 . 2009-12-08 03:45 ——– d—–w- c:\program files\PlotSoft
2009-12-08 03:45 . 2009-12-08 03:45 ——– d—–w- c:\documents and settings\All Users\Application Data\PlotSoft
2009-12-07 17:51 . 2009-12-07 17:51 ——– d—–w- c:\documents and settings\alex\Application Data\Foxit Software
2009-12-02 00:33 . 2009-12-23 17:09 ——– d—–w- c:\documents and settings\alex\Application Data\dvdcss
2009-11-30 18:42 . 2009-11-30 19:46 ——– d—–w- c:\documents and settings\alex\Application Data\TeamViewer
2009-11-30 18:42 . 2009-11-30 18:42 ——– d—–w- c:\program files\TeamViewer
2009-11-30 18:41 . 2009-11-30 18:41 ——– d—–w- c:\documents and settings\alex\temp
2009-11-29 21:36 . 2009-11-29 21:36 ——– d—–w- c:\documents and settings\alex\Application Data\UltraVNC
2009-11-29 21:33 . 2009-11-29 21:33 20672 —-a-w- c:\windows\system32\mv2.dll
2009-11-29 21:33 . 2009-11-29 21:33 10688 —-a-w- c:\windows\system32\drivers\mv2.sys
2009-11-29 21:33 . 2009-11-30 18:38 ——– d—–w- c:\program files\UltraVNC
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 01:05 . 2009-11-20 21:51 39 —-a-w- c:\documents and settings\alex\jagex_runescape_preferences.dat
2009-12-29 01:03 . 2009-11-20 21:52 69 —-a-w- c:\documents and settings\alex\jagex_runescape_preferences2.dat
2009-12-26 19:24 . 2009-11-20 19:40 ——– d—–w- c:\documents and settings\alex\Application Data\Skype
2009-12-26 19:13 . 2009-11-20 19:41 ——– d—–w- c:\documents and settings\alex\Application Data\skypePM
2009-12-24 05:59 . 2009-11-20 21:54 ——– d—–w- c:\documents and settings\alex\Application Data\vlc
2009-12-24 00:01 . 2009-11-20 19:48 ——– d—–w- c:\documents and settings\alex\Application Data\uTorrent
2009-12-23 22:09 . 2009-12-23 22:09 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-23 22:09 . 2009-12-23 22:09 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-17 06:22 . 2009-11-20 19:42 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-16 01:47 . 2009-11-24 04:23 ——– d—–w- c:\documents and settings\alex\Application Data\Apple Computer
2009-12-16 01:46 . 2009-11-24 04:21 ——– d—–w- c:\program files\Common Files\Apple
2009-12-15 01:08 . 2009-11-20 20:10 ——– d—–w- c:\program files\age
2009-12-12 18:27 . 2009-11-20 17:56 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-11 19:59 . 2009-11-20 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-11 17:05 . 2009-11-22 17:44 3967256 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-28 19:22 . 2009-11-28 19:22 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-11-28 19:21 . 2009-11-28 19:21 ——– d—–w- c:\program files\Microsoft
2009-11-28 19:21 . 2009-11-28 19:22 ——– d—–w- c:\program files\Windows Live
2009-11-28 19:19 . 2009-11-28 19:19 ——– d—–w- c:\program files\Common Files\Windows Live
2009-11-24 19:16 . 2009-11-24 19:15 ——– d—–w- c:\program files\Packet Tracer 5.2
2009-11-24 19:06 . 2009-11-20 18:06 69232 —-a-w- c:\documents and settings\alex\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-24 19:04 . 2009-11-24 19:04 ——– d—–w- c:\program files\Reference Assemblies
2009-11-24 18:53 . 2009-11-24 18:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Boson
2009-11-24 18:52 . 2009-11-24 18:52 127 —-a-w- c:\documents and settings\alex\Local Settings\Application Data\fusioncache.dat
2009-11-24 18:51 . 2009-11-24 18:51 69632 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\NewShortcut2_12F69331DCBB46D5B4756BFD0F9048B3.exe
2009-11-24 18:51 . 2009-11-24 18:51 69632 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\NewShortcut1_12F69331DCBB46D5B4756BFD0F9048B3.exe
2009-11-24 18:51 . 2009-11-24 18:51 26694 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\ARPPRODUCTICON.exe
2009-11-24 18:51 . 2009-11-24 18:51 ——– d—–w- c:\program files\Boson Software
2009-11-24 06:26 . 2009-11-24 06:26 0 —-a-w- c:\windows\nsreg.dat
2009-11-24 04:28 . 2009-11-24 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\iTunes
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\iPod
2009-11-24 04:23 . 2009-11-24 04:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\Bonjour
2009-11-24 04:22 . 2009-11-24 04:22 ——– d—–w- c:\program files\QuickTime
2009-11-24 04:22 . 2009-11-24 04:22 ——– d—–w- c:\program files\Apple Software Update
2009-11-23 21:39 . 2009-11-23 21:39 8854 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\readme_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2009-11-23 21:39 . 2009-11-23 21:39 40960 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\NewShortcut1_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2009-11-23 21:39 . 2009-11-23 21:39 1078 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\ARPPRODUCTICON.exe
2009-11-23 21:39 . 2009-11-23 21:39 ——– d—–w- c:\program files\Hewlett-Packard
2009-11-21 22:24 . 2009-11-21 18:29 ——– d—–w- c:\program files\DVDFab 6
2009-11-21 22:11 . 2009-11-21 22:11 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2009-11-21 18:29 . 2009-11-21 18:29 ——– d—–w- c:\documents and settings\alex\Application Data\Vso
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\documents and settings\alex\Application Data\pcouffin.sys
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\documents and settings\alex\Application Data\pcouffin.sys
2009-11-21 17:57 . 2009-11-21 17:56 ——– d—–w- c:\program files\Ahead
2009-11-21 17:57 . 2009-11-21 17:57 ——– d—–w- c:\program files\Common Files\Ahead
2009-11-21 02:22 . 2009-11-21 02:22 ——– d—–w- c:\program files\CDisplay
2009-11-21 00:51 . 2009-11-21 00:51 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-20 21:53 . 2009-11-20 21:53 ——– d—–w- c:\program files\VideoLAN
2009-11-20 21:30 . 2009-11-20 21:30 ——– d—–w- c:\program files\Bitcricket
2009-11-20 21:07 . 2009-11-20 21:07 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-20 21:07 . 2009-11-20 21:07 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-20 21:07 . 2009-11-20 21:07 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-20 21:07 . 2009-11-20 21:07 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-20 21:07 . 2009-11-20 21:07 ——– d—–w- c:\program files\AVG
2009-11-20 21:07 . 2009-11-20 21:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2009-11-20 20:31 . 2009-11-20 20:11 ——– d—–w- c:\program files\Microsoft Works
2009-11-20 20:24 . 2009-11-20 20:24 ——– d—–w- c:\program files\TTERMPRO
2009-11-20 20:14 . 2009-11-20 20:14 ——– d—–w- c:\program files\MSECache
2009-11-20 20:10 . 2009-11-20 20:10 ——– d—–w- c:\program files\MSBuild
2009-11-20 19:48 . 2009-11-20 19:48 ——– d—–w- c:\program files\uTorrent
2009-11-20 19:46 . 2009-11-20 19:46 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-20 19:46 . 2009-11-20 19:46 ——– d—–w- c:\program files\Java
2009-11-20 19:45 . 2009-11-20 19:45 152576 —-a-w- c:\documents and settings\alex\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-20 19:44 . 2009-11-20 19:44 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-20 19:43 . 2009-11-20 19:43 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-11-20 19:42 . 2009-11-20 19:42 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-20 19:41 . 2009-11-20 19:41 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-11-20 19:40 . 2009-11-20 19:39 ——– d—–r- c:\program files\Skype
2009-11-20 19:39 . 2009-11-20 19:39 ——– d—–w- c:\program files\Common Files\Skype
2009-11-20 19:39 . 2009-11-20 19:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-11-20 19:36 . 2009-11-20 19:36 ——– d—–w- c:\program files\PowerISO
2009-11-20 19:10 . 2009-11-20 17:43 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-20 18:10 . 2009-11-20 18:10 ——– d—–w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-11-20 18:03 . 2009-11-20 18:03 ——– d—–w- c:\program files\Wireless LAN
2009-11-20 18:02 . 2009-11-20 18:02 ——– d—–w- c:\program files\Apoint2K
2009-11-20 18:02 . 2009-11-20 17:52 ——– d—–w- c:\program files\Common Files\InstallShield
2009-11-20 18:02 . 2009-11-20 18:02 ——– d—–w- c:\program files\Power Manager
2009-11-20 18:01 . 2009-11-20 18:01 ——– d—–w- c:\program files\DIFX
2009-11-20 18:01 . 2009-11-20 18:01 ——– d—–w- c:\program files\CONEXANT
2009-11-20 18:00 . 2009-11-20 18:00 ——– d—–w- c:\program files\Hotkey Management
2009-11-20 17:56 . 2009-11-20 17:56 ——– d—–w- c:\program files\Realtek
2009-11-20 17:44 . 2009-11-20 17:44 ——– d—–w- c:\program files\microsoft frontpage
2009-11-20 17:39 . 2009-11-20 17:39 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-11-09 03:21 . 2009-11-09 03:21 59388 —-a-w- c:\windows\system32\drivers\scdemu.sys
2009-11-06 05:16 . 2009-11-06 05:16 73728 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-10-29 07:45 . 2004-08-04 07:56 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 07:56 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 07:56 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 07:56 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-10 07:07 . 2009-11-28 19:28 38208 —-a-w- c:\documents and settings\HelpAssistant\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-10 07:07 . 2009-11-20 19:43 38208 —-a-w- c:\documents and settings\alex\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-10 07:07 . 2009-11-20 19:43 38208 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-13 16264192]
"FuncKey"="c:\program files\Hotkey Management\FuncKey.exe" [2006-10-09 139264]
"PowerManager"="c:\program files\Power Manager\PM.exe" [2006-10-09 151552]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-10-02 151552]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-20 149280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-11 2033432]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
c:\documents and settings\alex\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-20 21:07 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2009-11-18 20:47 1243088 —-a-w- c:\program files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-08-16 18:42 7585792 —-a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-08-16 18:42 1617920 —-a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-17 02:04 2879488 —-a-w- c:\windows\SkyTel.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\TESTOUT\\Cmi\\Navigator.exe"=
"c:\\Documents and Settings\\alex\\Desktop\\age\\MYTH-age2_x1.exe"=
"c:\\Documents and Settings\\alex\\Desktop\\age\\Age2_x1\\age2_x1.exe"=
"c:\\Program Files\\Packet Tracer 5.2\\bin\\PacketTracer5.exe"=
"c:\\Program Files\\age\\Age2_x1\\age2_x1.exe"=
"c:\\Program Files\\age\\MYTH-age2_x1.exe"=
"c:\\Program Files\\Cisco Systems\\Cisco TFTP Server\\TFTPServer.exe"=
"c:\\Program Files\\GNS3\\Dynamips\\dynamips-wxp.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/15/2009 1:43 PM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/20/2009 1:07 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/20/2009 1:07 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/20/2009 1:07 PM 285392]
S3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [11/29/2009 1:33 PM 10688]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 12:22 PM 34064]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/15/2009 1:43 PM 359624]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\alex\Application Data\Mozilla\Firefox\Profiles\8smgit17.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-SpySweeper - c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-29 10:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(624)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-12-29 10:19:21
ComboFix-quarantined-files.txt 2009-12-29 18:19
Pre-Run: 3,746,861,056 bytes free
Post-Run: 3,937,693,696 bytes free
- - End Of File - - DDA64117AB3BE5045DA9C5B8677EFDCC
———————–
ComboFix 09-12-28.06 - alex 12/29/2009 10:10:26.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2574 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\alex\Desktop\cfscript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.
2009-12-23 22:08 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-23 17:44 . 2009-12-23 17:44 ——– d—–w- c:\program files\Smart Projects
2009-12-22 21:53 . 2009-12-22 21:53 454656 —-a-w- C:\putty.exe
2009-12-22 21:11 . 2001-08-17 21:53 4992 -c–a-w- c:\windows\system32\dllcache\loop.sys
2009-12-22 21:11 . 2001-08-17 21:53 4992 —-a-w- c:\windows\system32\drivers\loop.sys
2009-12-22 19:47 . 2009-12-23 22:08 ——– d—–w- C:\DynaWorkDir
2009-12-22 19:46 . 2009-12-23 22:07 ——– d—–w- C:\projectGNS3
2009-12-22 19:41 . 2009-12-22 19:41 ——– d—–w- c:\program files\WinPcap
2009-12-22 19:41 . 2009-12-22 21:17 ——– d—–w- c:\program files\GNS3
2009-12-22 19:11 . 2009-12-22 19:11 ——– d—–w- c:\program files\Cisco Systems
2009-12-22 19:11 . 1997-12-18 02:33 304128 —-a-w- c:\windows\IsUninst.exe
2009-12-22 19:11 . 2009-12-22 19:11 ——– d—–w- c:\documents and settings\alex\WINDOWS
2009-12-22 18:28 . 2009-12-11 17:06 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-22 18:28 . 2009-12-11 17:06 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-22 18:28 . 2009-12-18 19:38 294656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-18 19:47 . 2009-12-04 00:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-18 19:47 . 2009-12-18 19:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 19:47 . 2009-12-04 00:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 06:17 . 2009-12-17 06:17 1956528 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-12-16 20:18 . 2009-12-16 20:18 ——– d—–w- c:\program files\MSXML 4.0
2009-12-16 20:07 . 2009-12-16 20:07 12568 —-a-w- c:\windows\system32\drivers\PROCEXP111.SYS
2009-12-16 02:18 . 2009-12-16 02:18 ——– d—–w- c:\program files\ERUNT
2009-12-16 01:47 . 2009-12-16 01:47 56532 —ha-w- c:\windows\system32\mlfcache.dat
2009-12-16 01:47 . 2009-12-16 01:47 ——– d—–w- c:\program files\Safari
2009-12-16 00:03 . 2009-12-16 01:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-15 22:59 . 2009-12-15 22:59 ——– d—–w- c:\program files\Trend Micro
2009-12-15 22:25 . 2009-12-15 22:25 ——– d—–w- c:\program files\MSSOAP
2009-12-15 22:25 . 2009-12-15 22:25 ——– d—–w- c:\program files\Webroot
2009-12-15 22:24 . 2009-12-15 22:24 164 —-a-w- c:\windows\install.dat
2009-12-15 22:01 . 2009-12-15 22:01 ——– d—–w- c:\documents and settings\alex\Local Settings\Application Data\Threat Expert
2009-12-15 21:44 . 2009-10-30 19:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-15 21:43 . 2009-11-09 19:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-15 21:43 . 2009-10-07 00:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-15 21:43 . 2009-09-03 17:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-15 21:43 . 2009-12-15 21:49 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-15 21:43 . 2009-12-16 02:24 ——– d—–w- c:\program files\Spyware Doctor
2009-12-15 21:43 . 2009-12-15 21:43 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-15 21:43 . 2009-12-15 21:43 ——– d—–w- c:\documents and settings\alex\Application Data\PC Tools
2009-12-15 21:42 . 2009-12-19 16:42 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-14 18:52 . 2009-12-16 18:54 ——– d—–w- c:\documents and settings\alex\Packet Tracer 5.2
2009-12-12 21:02 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2009-12-12 21:02 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-12-12 21:02 . 2001-08-17 21:48 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2009-12-12 21:02 . 2001-08-17 21:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-12-12 21:02 . 2008-04-13 18:39 14592 -c–a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-12-12 21:02 . 2008-04-13 18:39 14592 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2009-12-12 21:02 . 2008-04-13 18:45 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2009-12-12 21:02 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-12-12 19:47 . 2009-12-12 19:47 ——– d—–w- c:\documents and settings\alex\Application Data\Malwarebytes
2009-12-12 19:47 . 2009-12-12 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-12 19:38 . 2009-12-12 20:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-12 19:38 . 2009-12-12 19:38 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-12 18:27 . 2009-12-13 03:34 ——– d—–w- c:\program files\Visual CertExam Suite
2009-12-12 16:42 . 2003-06-23 10:44 1415680 —-a-w- c:\windows\system32\WMV9VCM.DLL
2009-12-12 16:42 . 1999-12-16 08:01 49152 —-a-w- c:\windows\system32\TSCCVID.DLL
2009-12-12 16:41 . 2009-12-12 17:26 ——– d—–w- c:\program files\TESTOUT
2009-12-11 17:06 . 2009-12-11 17:05 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-09 19:32 . 2009-12-09 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Boson Software
2009-12-08 03:46 . 2009-12-08 03:46 ——– d—–w- c:\program files\gs
2009-12-08 03:45 . 2009-12-08 03:45 ——– d—–w- c:\program files\PlotSoft
2009-12-08 03:45 . 2009-12-08 03:45 ——– d—–w- c:\documents and settings\All Users\Application Data\PlotSoft
2009-12-07 17:51 . 2009-12-07 17:51 ——– d—–w- c:\documents and settings\alex\Application Data\Foxit Software
2009-12-02 00:33 . 2009-12-23 17:09 ——– d—–w- c:\documents and settings\alex\Application Data\dvdcss
2009-11-30 18:42 . 2009-11-30 19:46 ——– d—–w- c:\documents and settings\alex\Application Data\TeamViewer
2009-11-30 18:42 . 2009-11-30 18:42 ——– d—–w- c:\program files\TeamViewer
2009-11-30 18:41 . 2009-11-30 18:41 ——– d—–w- c:\documents and settings\alex\temp
2009-11-29 21:36 . 2009-11-29 21:36 ——– d—–w- c:\documents and settings\alex\Application Data\UltraVNC
2009-11-29 21:33 . 2009-11-29 21:33 20672 —-a-w- c:\windows\system32\mv2.dll
2009-11-29 21:33 . 2009-11-29 21:33 10688 —-a-w- c:\windows\system32\drivers\mv2.sys
2009-11-29 21:33 . 2009-11-30 18:38 ——– d—–w- c:\program files\UltraVNC
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 01:05 . 2009-11-20 21:51 39 —-a-w- c:\documents and settings\alex\jagex_runescape_preferences.dat
2009-12-29 01:03 . 2009-11-20 21:52 69 —-a-w- c:\documents and settings\alex\jagex_runescape_preferences2.dat
2009-12-26 19:24 . 2009-11-20 19:40 ——– d—–w- c:\documents and settings\alex\Application Data\Skype
2009-12-26 19:13 . 2009-11-20 19:41 ——– d—–w- c:\documents and settings\alex\Application Data\skypePM
2009-12-24 05:59 . 2009-11-20 21:54 ——– d—–w- c:\documents and settings\alex\Application Data\vlc
2009-12-24 00:01 . 2009-11-20 19:48 ——– d—–w- c:\documents and settings\alex\Application Data\uTorrent
2009-12-23 22:09 . 2009-12-23 22:09 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-23 22:09 . 2009-12-23 22:09 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-17 06:22 . 2009-11-20 19:42 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-16 01:47 . 2009-11-24 04:23 ——– d—–w- c:\documents and settings\alex\Application Data\Apple Computer
2009-12-16 01:46 . 2009-11-24 04:21 ——– d—–w- c:\program files\Common Files\Apple
2009-12-15 01:08 . 2009-11-20 20:10 ——– d—–w- c:\program files\age
2009-12-12 18:27 . 2009-11-20 17:56 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-11 19:59 . 2009-11-20 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-11 17:05 . 2009-11-22 17:44 3967256 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-28 19:22 . 2009-11-28 19:22 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-11-28 19:21 . 2009-11-28 19:21 ——– d—–w- c:\program files\Microsoft
2009-11-28 19:21 . 2009-11-28 19:22 ——– d—–w- c:\program files\Windows Live
2009-11-28 19:19 . 2009-11-28 19:19 ——– d—–w- c:\program files\Common Files\Windows Live
2009-11-24 19:16 . 2009-11-24 19:15 ——– d—–w- c:\program files\Packet Tracer 5.2
2009-11-24 19:06 . 2009-11-20 18:06 69232 —-a-w- c:\documents and settings\alex\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-24 19:04 . 2009-11-24 19:04 ——– d—–w- c:\program files\Reference Assemblies
2009-11-24 18:53 . 2009-11-24 18:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Boson
2009-11-24 18:52 . 2009-11-24 18:52 127 —-a-w- c:\documents and settings\alex\Local Settings\Application Data\fusioncache.dat
2009-11-24 18:51 . 2009-11-24 18:51 69632 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\NewShortcut2_12F69331DCBB46D5B4756BFD0F9048B3.exe
2009-11-24 18:51 . 2009-11-24 18:51 69632 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\NewShortcut1_12F69331DCBB46D5B4756BFD0F9048B3.exe
2009-11-24 18:51 . 2009-11-24 18:51 26694 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\ARPPRODUCTICON.exe
2009-11-24 18:51 . 2009-11-24 18:51 ——– d—–w- c:\program files\Boson Software
2009-11-24 06:26 . 2009-11-24 06:26 0 —-a-w- c:\windows\nsreg.dat
2009-11-24 04:28 . 2009-11-24 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\iTunes
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\iPod
2009-11-24 04:23 . 2009-11-24 04:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\Bonjour
2009-11-24 04:22 . 2009-11-24 04:22 ——– d—–w- c:\program files\QuickTime
2009-11-24 04:22 . 2009-11-24 04:22 ——– d—–w- c:\program files\Apple Software Update
2009-11-23 21:39 . 2009-11-23 21:39 8854 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\readme_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2009-11-23 21:39 . 2009-11-23 21:39 40960 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\NewShortcut1_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2009-11-23 21:39 . 2009-11-23 21:39 1078 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\ARPPRODUCTICON.exe
2009-11-23 21:39 . 2009-11-23 21:39 ——– d—–w- c:\program files\Hewlett-Packard
2009-11-21 22:24 . 2009-11-21 18:29 ——– d—–w- c:\program files\DVDFab 6
2009-11-21 22:11 . 2009-11-21 22:11 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2009-11-21 18:29 . 2009-11-21 18:29 ——– d—–w- c:\documents and settings\alex\Application Data\Vso
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\documents and settings\alex\Application Data\pcouffin.sys
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\documents and settings\alex\Application Data\pcouffin.sys
2009-11-21 17:57 . 2009-11-21 17:56 ——– d—–w- c:\program files\Ahead
2009-11-21 17:57 . 2009-11-21 17:57 ——– d—–w- c:\program files\Common Files\Ahead
2009-11-21 02:22 . 2009-11-21 02:22 ——– d—–w- c:\program files\CDisplay
2009-11-21 00:51 . 2009-11-21 00:51 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-20 21:53 . 2009-11-20 21:53 ——– d—–w- c:\program files\VideoLAN
2009-11-20 21:30 . 2009-11-20 21:30 ——– d—–w- c:\program files\Bitcricket
2009-11-20 21:07 . 2009-11-20 21:07 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-20 21:07 . 2009-11-20 21:07 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-20 21:07 . 2009-11-20 21:07 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-20 21:07 . 2009-11-20 21:07 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-20 21:07 . 2009-11-20 21:07 ——– d—–w- c:\program files\AVG
2009-11-20 21:07 . 2009-11-20 21:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2009-11-20 20:31 . 2009-11-20 20:11 ——– d—–w- c:\program files\Microsoft Works
2009-11-20 20:24 . 2009-11-20 20:24 ——– d—–w- c:\program files\TTERMPRO
2009-11-20 20:14 . 2009-11-20 20:14 ——– d—–w- c:\program files\MSECache
2009-11-20 20:10 . 2009-11-20 20:10 ——– d—–w- c:\program files\MSBuild
2009-11-20 19:48 . 2009-11-20 19:48 ——– d—–w- c:\program files\uTorrent
2009-11-20 19:46 . 2009-11-20 19:46 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-20 19:46 . 2009-11-20 19:46 ——– d—–w- c:\program files\Java
2009-11-20 19:45 . 2009-11-20 19:45 152576 —-a-w- c:\documents and settings\alex\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-20 19:44 . 2009-11-20 19:44 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-20 19:43 . 2009-11-20 19:43 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-11-20 19:42 . 2009-11-20 19:42 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-20 19:41 . 2009-11-20 19:41 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-11-20 19:40 . 2009-11-20 19:39 ——– d—–r- c:\program files\Skype
2009-11-20 19:39 . 2009-11-20 19:39 ——– d—–w- c:\program files\Common Files\Skype
2009-11-20 19:39 . 2009-11-20 19:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-11-20 19:36 . 2009-11-20 19:36 ——– d—–w- c:\program files\PowerISO
2009-11-20 19:10 . 2009-11-20 17:43 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-20 18:10 . 2009-11-20 18:10 ——– d—–w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-11-20 18:03 . 2009-11-20 18:03 ——– d—–w- c:\program files\Wireless LAN
2009-11-20 18:02 . 2009-11-20 18:02 ——– d—–w- c:\program files\Apoint2K
2009-11-20 18:02 . 2009-11-20 17:52 ——– d—–w- c:\program files\Common Files\InstallShield
2009-11-20 18:02 . 2009-11-20 18:02 ——– d—–w- c:\program files\Power Manager
2009-11-20 18:01 . 2009-11-20 18:01 ——– d—–w- c:\program files\DIFX
2009-11-20 18:01 . 2009-11-20 18:01 ——– d—–w- c:\program files\CONEXANT
2009-11-20 18:00 . 2009-11-20 18:00 ——– d—–w- c:\program files\Hotkey Management
2009-11-20 17:56 . 2009-11-20 17:56 ——– d—–w- c:\program files\Realtek
2009-11-20 17:44 . 2009-11-20 17:44 ——– d—–w- c:\program files\microsoft frontpage
2009-11-20 17:39 . 2009-11-20 17:39 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-11-09 03:21 . 2009-11-09 03:21 59388 —-a-w- c:\windows\system32\drivers\scdemu.sys
2009-11-06 05:16 . 2009-11-06 05:16 73728 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-10-29 07:45 . 2004-08-04 07:56 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 07:56 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 07:56 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 07:56 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-10 07:07 . 2009-11-28 19:28 38208 —-a-w- c:\documents and settings\HelpAssistant\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-10 07:07 . 2009-11-20 19:43 38208 —-a-w- c:\documents and settings\alex\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-10 07:07 . 2009-11-20 19:43 38208 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-13 16264192]
"FuncKey"="c:\program files\Hotkey Management\FuncKey.exe" [2006-10-09 139264]
"PowerManager"="c:\program files\Power Manager\PM.exe" [2006-10-09 151552]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-10-02 151552]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-20 149280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-11 2033432]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
c:\documents and settings\alex\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-20 21:07 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2009-11-18 20:47 1243088 —-a-w- c:\program files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-08-16 18:42 7585792 —-a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-08-16 18:42 1617920 —-a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-17 02:04 2879488 —-a-w- c:\windows\SkyTel.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\TESTOUT\\Cmi\\Navigator.exe"=
"c:\\Documents and Settings\\alex\\Desktop\\age\\MYTH-age2_x1.exe"=
"c:\\Documents and Settings\\alex\\Desktop\\age\\Age2_x1\\age2_x1.exe"=
"c:\\Program Files\\Packet Tracer 5.2\\bin\\PacketTracer5.exe"=
"c:\\Program Files\\age\\Age2_x1\\age2_x1.exe"=
"c:\\Program Files\\age\\MYTH-age2_x1.exe"=
"c:\\Program Files\\Cisco Systems\\Cisco TFTP Server\\TFTPServer.exe"=
"c:\\Program Files\\GNS3\\Dynamips\\dynamips-wxp.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/15/2009 1:43 PM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/20/2009 1:07 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/20/2009 1:07 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/20/2009 1:07 PM 285392]
S3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [11/29/2009 1:33 PM 10688]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 12:22 PM 34064]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/15/2009 1:43 PM 359624]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\alex\Application Data\Mozilla\Firefox\Profiles\8smgit17.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-SpySweeper - c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-29 10:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(624)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-12-29 10:19:21
ComboFix-quarantined-files.txt 2009-12-29 18:19
Pre-Run: 3,746,861,056 bytes free
Post-Run: 3,937,693,696 bytes free
- - End Of File - - DDA64117AB3BE5045DA9C5B8677EFDCC