.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-08 16:23 --------- d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2007-10-08 05:26 6692 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-08 05:26 4412 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-07 14:38 --------- d-------- C:\Program Files\McAfee
2007-10-07 11:17 --------- d-------- C:\Program Files\FinePixViewer
2007-10-06 11:27 --------- d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2007-10-05 11:10 --------- d-------- C:\Program Files\Viewpoint
2007-10-05 11:10 --------- d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-03 16:41 --------- d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-03 16:36 --------- d-------- C:\Program Files\DoctorCleaner
2007-09-30 12:53 --------- d-------- C:\Program Files\Common Files\Ahead
2007-09-30 12:15 --------- d-------- C:\Documents and Settings\Zach\Application Data\Ahead
2007-09-30 09:24 --------- d-------- C:\Program Files\OneStepSearch
2007-09-30 09:23 --------- d-------- C:\Program Files\LimeWire
2007-09-30 09:21 --------- d-------- C:\Program Files\foobar2000
2007-09-30 09:10 --------- d-------- C:\Program Files\AC3Filter
2007-09-23 15:33 --------- d-------- C:\Program Files\Bonjour
2007-09-22 14:46 --------- d-------- C:\Program Files\Xvid
2007-09-22 14:46 --------- d-------- C:\Program Files\Hardwood Euchre
2007-09-22 14:46 --------- d-------- C:\Program Files\AudioRetoucher
2007-09-22 14:46 --------- d-------- C:\Program Files\Audacity
2007-09-16 20:01 --------- d-------- C:\Documents and Settings\Zach\Application Data\foobar2000
2007-08-14 20:40 --------- d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-08-13 17:13 --------- d-------- C:\Program Files\Google
2007-08-13 14:16 --------- d-------- C:\Program Files\RegistryCleanerXP
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2DC7C70A-B95D-4E0F-B49D-1C5D618D936C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72BDBFC0-3394-4944-BE07-BC05CF5049BE}]
2004-08-04 03:56 107409 --a------ C:\WINDOWS\system32\dmscrip.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FA1E1D-29FD-4E81-9690-C75B4E3108A0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DF50F976-592A-47a4-81C7-AD34D5A3A947}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1140116236\ee\AOLSoftware.exe" [2006-05-09 20:24]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 08:39 C:\WINDOWS\SOUNDMAN.EXE]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-07 12:57]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 23:32]
"NWEReboot"="" []
"ezShieldProtector for Px"="C:\WINDOWS\system32\ezSP_Px.exe" [2002-08-20 11:29]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 02:33]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 13:59]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-10-05 16:04]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26]
[email protected] - C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe [2007-03-21 17:48:41]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-08-13 17:13:16]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 05:01:04]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2006-02-18 13:04:30]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R0 rlgujhvq;rlgujhvq;C:\WINDOWS\system32\drivers\ctnluuwh.dat
R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys
R1 df401e41.sys;df401e41.sys;\??\C:\WINDOWS\system32\drivers\df401e41.sys
R2 DVDAccss;DVDAccss;C:\WINDOWS\system32\drivers\DVDAccss.sys
S4 OneStep Search Service;OneStep Search Service;"C:\Program Files\OneStepSearch\onestep.exe" "C:\Program Files\OneStepSearch\onestep.dll" Service
.
Contents of the 'Scheduled Tasks' folder
"2007-10-08 01:46:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-15 05:34:29 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-10-01 05:01:22 C:\WINDOWS\Tasks\McQcTask.job"
"2007-10-08 20:47:12 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-08 16:45:24
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-08 16:50:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-10-08 16:50
.
--- E O F ---
On start up, I still get the Nero NMBg Error, the McAfee LogOnHook error, a Zone Alarm trial, and a lot of crap relating to the "MG Secure Module." There is an automatic attempted installation that takes place while the computer is loading, and no matter how many times you click "finish" it keeps restarting itself.