2008-04-17 08:41 . 2008-04-17 21:50 <DIR> d-------- C:\Program Files\Easy Avi Divx Xvid to DVD Burner
2008-04-17 08:41 . 2008-04-17 22:42 67 --a------ C:\WINDOWS\Easy Avi Divx Xvid to DVD Burner.INI
2008-04-17 08:35 . 2008-04-17 21:35 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\DVD Flick
2008-04-17 08:24 . 2000-05-19 17:56 81,920 --a------ C:\WINDOWS\system32\mbmouse.ocx
2008-04-17 08:24 . 2000-11-05 15:27 36,864 --a------ C:\WINDOWS\system32\trayicon.ocx
2008-04-17 00:58 . 2008-04-19 09:39 <DIR> dr-h----- C:\$VAULT$.AVG
2008-04-16 23:06 . 2008-04-17 20:28 <DIR> d-------- C:\Program Files\Any Video Converter
2008-04-16 23:06 . 2008-04-18 00:06 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Any Video Converter
2008-04-16 22:33 . 2008-04-16 22:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-04-16 20:49 . 2008-04-16 20:49 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-04-16 20:49 . 2008-04-17 21:33 47,360 --a------ C:\Documents and Settings\Mike\Application Data\pcouffin.sys
2008-04-15 23:25 . 2008-04-15 23:29 256 --a------ C:\WINDOWS\onlineeye.INI
2008-04-13 09:02 . 2008-04-13 09:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PCPitstop
2008-04-13 09:01 . 2008-04-14 15:21 <DIR> d-------- C:\Program Files\PCPitstop
2008-04-10 13:05 . 2008-04-14 19:49 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Web Page Maker V2
2008-04-10 09:00 . 2008-04-20 18:08 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-04-10 09:00 . 2008-04-20 18:14 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Spyware Terminator
2008-04-10 09:00 . 2008-04-20 12:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-04-10 09:00 . 2008-04-10 09:00 138,752 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-04-09 18:30 . 2008-04-09 18:30 0 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT_TU_31280.LOG
2008-04-09 18:30 . 2008-04-09 18:30 0 --ah----- C:\Documents and Settings\Mike\ntuser.dat_TU_90818.LOG
2008-04-09 18:30 . 2008-04-09 18:30 0 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT_TU_25715.LOG
2008-04-09 18:06 . 2008-04-09 18:06 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\TuneUp Software
2008-04-07 08:16 . 2008-04-07 08:16 <DIR> d-------- C:\Program Files\DeskSweeper
2008-04-06 11:58 . 2008-04-06 12:42 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\U3
2008-04-05 12:50 . 2008-04-05 13:06 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-04 17:41 . 2008-04-09 18:30 6,553,600 --a------ C:\Documents and Settings\Mike\ntuser.dat_BAK_90818
2008-04-03 19:49 . 2008-04-03 19:49 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Grisoft
2008-04-03 19:49 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-03 19:04 . 2008-04-20 17:21 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\AVG7
2008-04-03 19:03 . 2008-04-03 19:03 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-03 19:03 . 2008-04-03 20:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-03 18:26 . 2008-04-03 18:26 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\AVGTOOLBAR
2008-04-03 18:25 . 2008-04-03 18:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-01 20:15 . 2008-04-01 20:15 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\{A25FEDC1-F6D7-440C-BCE2-B71F595F6646}
2008-03-31 23:56 . 2008-04-01 00:03 <DIR> d-------- C:\Program Files\Veoh Networks
2008-03-31 22:11 . 2008-03-31 22:35 <DIR> d-------- C:\Program Files\Bestel Software
2008-03-31 20:25 . 2008-03-31 20:25 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-31 20:06 . 2008-03-31 20:06 <DIR> d-------- C:\!KillBox
2008-03-25 21:28 . 2008-04-10 22:06 <DIR> d-------- C:\Program Files\Wise Registry Cleaner 3
2008-03-24 17:16 . 2008-04-20 18:27 74,139,680 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-24 17:16 . 2008-04-20 18:27 824,108 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-24 17:13 . 2008-03-14 00:11 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-03-24 16:59 . 2008-03-24 16:59 <DIR> d-------- C:\Program Files\ZyXEL
2008-03-24 16:59 . 2006-04-14 16:35 31,744 --a------ C:\WINDOWS\system32\drivers\ZDPSp50a64.sys
2008-03-24 16:59 . 2006-04-14 16:35 17,151 --a------ C:\WINDOWS\system32\drivers\ZDPNDIS5.sys
2008-03-24 09:31 . 2008-03-24 09:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-03-23 23:21 . 2008-03-23 23:21 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-21 17:42 . 2008-03-23 20:59 805 --a------ C:\rollback.ini
2008-03-21 13:32 . 2008-03-21 13:32 <DIR> d-------- C:\Program Files\SonicWallES
2008-04-20 17:26 89,088 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-04-20 15:46 --------- d-----w C:\Documents and Settings\Mike\Application Data\SiteAdvisor
2008-04-20 06:40 --------- d-----w C:\Documents and Settings\Mike\Application Data\LimeWire
2008-04-20 00:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-04-19 21:57 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-04-19 20:57 63,488 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-04-19 20:50 --------- d-----w C:\Program Files\Lavasoft
2008-04-19 20:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-19 19:03 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-04-19 15:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\iolo
2008-04-19 13:52 --------- d-----w C:\Program Files\Java
2008-04-18 13:01 --------- d-----w C:\Documents and Settings\Mike\Application Data\Ahead
2008-04-18 12:52 --------- d-----w C:\Program Files\Ahead
2008-04-17 20:33 --------- d-----w C:\Program Files\VSO
2008-04-17 20:33 --------- d-----w C:\Documents and Settings\Mike\Application Data\Vso
2008-04-15 20:46 --------- d-----w C:\Documents and Settings\Mike\Application Data\Skype
2008-04-14 19:34 --------- d-----w C:\Program Files\MSECACHE
2008-04-10 21:07 --------- d-----w C:\Program Files\Wise Disk Cleaner
2008-04-10 20:55 --------- d-----w C:\Program Files\RogueRemover FREE
2008-04-10 20:49 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-10 20:49 --------- d-----w C:\Program Files\SpywareBlaster
2008-04-05 11:51 --------- d-----w C:\Program Files\FLV Player
2008-04-03 18:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-01 08:37 --------- d-----w C:\Program Files\DivX
2008-03-31 22:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-31 07:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\grey ante kind mess
2008-03-25 22:10 --------- d-----w C:\Program Files\Auslogics
2008-03-22 16:07 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-21 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 19:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\ExPLabs.com
2008-03-13 23:11 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-03-13 08:08 --------- d-----w C:\Program Files\Real
2008-03-13 08:08 --------- d-----w C:\Program Files\Common Files\Real
2008-03-12 23:35 --------- d-----w C:\Documents and Settings\NetworkService\Application Data\SiteAdvisor
2008-03-08 13:45 164 ----a-w C:\install.dat
2008-03-08 13:44 --------- d-----w C:\Documents and Settings\Mike\Application Data\GetRightToGo
2008-03-05 12:25 --------- d-----w C:\Program Files\Spyware Doctor
2008-03-03 19:53 --------- d-----w C:\Program Files\CyberLink
2008-03-03 19:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-03-03 17:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-03-01 15:46 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-01 13:58 --------- d-----w C:\Program Files\VS Revo Group
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-01 08:41 --------- d-----w C:\Program Files\PurgeIE
2008-02-29 08:45 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-02-28 20:21 --------- d-----w C:\Program Files\TVUPlayer
2008-02-27 18:58 --------- d--h--w C:\Documents and Settings\Mike\Application Data\GTek
2008-02-25 20:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Registry Helper
2008-02-24 20:14 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-02-24 20:14 --------- d-----w C:\Documents and Settings\Mike\Application Data\Malwarebytes
2008-02-24 20:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-24 10:43 --------- d-----w C:\Program Files\Enigma Software Group
2008-02-23 20:00 --------- d-----w C:\Program Files\SpywareGuard
2008-02-23 19:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\BOC425
2008-02-23 16:21 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-23 15:30 812,344 ----a-w C:\sniper fix.exe
2008-02-22 18:44 86,016 -c--a-w C:\WINDOWS\system32\VACFix.exe
2008-02-22 10:29 --------- d-----w C:\Program Files\MSXML 4.0
2008-02-21 11:23 --------- d-----w C:\Documents and Settings\Mike\Application Data\TSO
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:03 156,992 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-11 08:39 253,952 -c--a-w C:\WINDOWS\system32\OnlineScannerDLLA.dll
2008-02-11 08:39 237,568 -c--a-w C:\WINDOWS\system32\OnlineScannerDLLW.dll
2008-02-08 12:53 110,592 -c--a-w C:\WINDOWS\system32\OnlineScannerLang.dll
2008-02-08 10:37 82,432 -c--a-w C:\WINDOWS\system32\IEDFix.exe
2008-02-06 22:36 30,615 -c--a-w C:\Documents and Settings\Mike\x.exe
2008-02-05 07:48 77,824 -c--a-w C:\WINDOWS\system32\OnlineScannerUninstaller.exe
2007-10-25 07:07 32,768 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012007102520071026\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 17:06 292152]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-08-13 19:05 36640]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-14 00:11 919016]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-15 08:57 579584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-04-10 09:00 2957824]
"QuickTime Task"="C:\WINDOWS\system32\qttask.exe" [2008-04-17 14:32 98304]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-03 19:03 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ZyXEL G-202 Wireless Adapter Utility.lnk - C:\Program Files\ZyXEL\ZyXEL G-202 Wireless Adapter Utility\ZyXEL G-202.exe [2008-03-24 16:59:11 10870784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 21:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 21:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PowerDVD"=C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe /autostart
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Mike\\My Documents\\My Music\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\PROGRAM FILES\\SKYPE\\PHONE\\SKYPE.EXE"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 18:31]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-04-10 09:00]
R2 adunidrv;UniDriver for OneCare;C:\WINDOWS\system32\DRIVERS\adunidrv.sys [2007-09-25 11:43]
R2 advproct;Microsoft Corporation Process Trigger Driver;C:\WINDOWS\system32\DRIVERS\advproct.sys [2007-09-25 13:49]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 18:35]
R2 palproct;Gteko ProcessTriggerDriver;C:\WINDOWS\system32\DRIVERS\palproct.sys [2007-04-11 17:55]
R2 palunidr;UniDriver for PCPal;C:\WINDOWS\system32\DRIVERS\palunidr.sys [2007-04-11 17:55]
R2 PCPalSrvHost;PCPalSrvHost;"C:\Program Files\PCPal\PCPalSrvHost.exe" [2007-10-24 18:43]
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2006-02-14 16:02]
R3 ZY202_XP;ZyXEL 802.11g XG202 1211 Driver;C:\WINDOWS\system32\DRIVERS\WlanUZXP.sys [2006-04-14 16:35]
R4 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver;C:\WINDOWS\ZDCNDIS5.sys [2006-04-14 16:35]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt [2005-08-18 08:00]
S3 MBAMCatchMe;MBAMCatchMe;C:\Program Files\Malwarebytes' Anti-Malware\catchme.sys [2008-04-07 20:17]
S3 W35UND;W89C35 802.11bg WLAN USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\W35UND.SYS [2006-01-12 16:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{83b933c2-03c5-11dd-8250-0013498da9f0}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-20 18:29:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\EverestDriver]
"ImagePath"="\??\C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6253\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Skype\Phone\Skype.exe
.
**************************************************************************
.
Completion time: 2008-04-20 18:33:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-20 17:33:15
Pre-Run: 26,350,305,280 bytes free
Post-Run: 26,740,350,976 bytes free
271 --- E O F --- 2008-04-17 13:00:54