PART 4.........
C:\WINNT\Install.txt
C:\WINNT\SNMPAPI.DLL
C:\WINNT\system32\atsxyzd.sys
C:\WINNT\system32\comsa32.sys
C:\WINNT\system32\KBPK080812.log
C:\WINNT\system32\roxtctm.exe
C:\WINNT\system32\rtl60.bpl
C:\WINNT\system32\sotpeca.exe
C:\WINNT\system32\syspilog.pil
C:\WINNT\system32\tmp0_239842534757.bk
C:\WINNT\system32\tmp0_298631483972.bk
C:\WINNT\system32\tmp0_362277416365.bk
C:\WINNT\system32\tmp0_483464206746.bk
C:\WINNT\system32\tmp0_752986259741.bk
C:\WINNT\system32\tmp1_2683186973.bk
C:\WINNT\system32\tmp1_279757721191.bk
C:\WINNT\system32\tmp1_280093609914.bk
C:\WINNT\system32\tmp1_348577106913.bk
C:\WINNT\system32\tmp1_85396553527.bk
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AFISICX
-------\Legacy_MACIDWE
-------\Legacy_NOXTCYR
-------\Legacy_ROXTCTM
-------\Legacy_SEUICTOL
-------\Legacy_SOBICYT
-------\Legacy_SOTPECA
-------\Legacy_TDXDOWKC
-------\Legacy_WSLDOEKD
-------\Service_seuictol
-------\Service_sotpeca
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-29 )))))))))))))))))))))))))))))))
.
2008-08-24 14:33 . 2008-08-24 14:33 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-08-19 02:00 . 2008-08-28 08:46 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-19 01:58 . 2008-08-19 02:00 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-08-19 01:52 . 2008-08-29 01:14 <DIR> d-------- C:\WINNT\system32\drivers\Avg
2008-08-19 01:52 . 2008-08-19 01:56 <DIR> d-------- C:\Documents and Settings\test\Application Data\AVGTOOLBAR
2008-08-19 01:52 . 2008-08-29 01:11 97,928 --a------ C:\WINNT\system32\drivers\avgldx86.sys
2008-08-19 01:52 . 2008-08-19 01:52 76,040 --a------ C:\WINNT\system32\drivers\avgtdix.sys
2008-08-19 01:52 . 2008-08-19 01:52 10,520 --a------ C:\WINNT\system32\avgrsstx.dll
2008-08-19 01:51 . 2008-08-19 01:51 <DIR> d-------- C:\Program Files\AVG
2008-08-19 01:41 . 2008-08-19 01:41 <DIR> d---s---- C:\Documents and Settings\test\UserData
2008-08-19 00:32 . 2008-08-19 00:32 0 --a------ C:\WINNT\system32\Je5qtC11.exe.a_a
2008-08-17 22:26 . 2008-06-19 17:24 28,544 --a------ C:\WINNT\system32\drivers\pavboot.sys
2008-08-17 12:29 . 2008-08-17 12:29 <DIR> d---s---- C:\Documents and Settings\LocalService\UserData
2008-08-17 11:49 . 2008-08-17 11:49 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-08-16 21:30 . 2003-08-02 12:52 <DIR> d-------- C:\Documents and Settings\test\Application Data\Symantec
2008-08-16 21:30 . 2003-08-02 12:50 <DIR> d-------- C:\Documents and Settings\test\Application Data\InterTrust
2008-08-16 21:30 . 2008-08-19 01:41 <DIR> d-------- C:\Documents and Settings\test
2008-08-16 19:13 . 2008-08-19 01:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-08-16 16:05 . 2008-05-01 10:30 331,776 --------- C:\WINNT\system32\dllcache\msadce.dll
2008-08-13 13:39 . 2008-08-13 13:39 <DIR> d-------- C:\windows
2008-08-06 17:38 . 2008-08-06 17:38 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\UNOUndercover
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 05:08 --------- d-----w C:\Documents and Settings\Owner\Application Data\WeatherBug
2008-08-28 23:53 --------- d-----w C:\Program Files\Java
2008-08-28 06:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-19 06:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-19 05:47 --------- d-----w C:\Program Files\SpywareBlaster
2008-08-17 01:30 --------- d-----w C:\Program Files\Web Publish
2008-08-16 00:54 --------- d-----w C:\Program Files\Google
2008-08-09 17:47 --------- d-----w C:\Program Files\IncrediMail
2008-08-06 21:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-08-04 19:32 --------- d-----w C:\Documents and Settings\Owner\Application Data\Sheeplings
2008-07-26 19:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-07-07 20:32 253,952 ----a-w C:\WINNT\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINNT\system32\dllcache\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINNT\system32\mscms.dll
2008-06-24 16:23 74,240 ------w C:\WINNT\system32\dllcache\mscms.dll
2008-06-23 09:49 18,432 ------w C:\WINNT\system32\dllcache\iedw.exe
2008-06-20 17:41 245,248 ----a-w C:\WINNT\system32\mswsock.dll
2008-06-20 17:41 245,248 ----a-w C:\WINNT\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINNT\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINNT\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINNT\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINNT\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINNT\system32\dllcache\bthport.sys
2007-11-10 18:55 115,176 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2006-04-04 20:39 212 ----a-w C:\Program Files\regfix.reg
2006-04-01 20:10 220 ----a-w C:\Documents and Settings\Owner\n.bat
2006-03-30 07:46 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2003-03-04 13:14 45,568 ----a-w C:\Documents and Settings\Owner\onuninst.dll
1998-07-03 20:27 7,488 ----a-w C:\WINNT\inf\unregpn.exe
2007-08-02 07:55 80 --sh--r C:\WINNT\system32\C54E22B8EC.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 14:22 243072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GWMDMpi"="C:\WINNT\GWMDMpi.exe" [2002-08-06 15:24 53248]
"EPSON Stylus Photo RX600"="C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2M1.EXE" [2003-09-10 03:00 99840]
"IgfxTray"="C:\WINNT\system32\igfxtray.exe" [2005-06-21 17:48 155648]
"HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [2005-06-21 17:44 126976]
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"EPSON Stylus Photo RX600 (Copy 1)"="C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2M1.EXE" [2003-09-10 03:00 99840]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-23 09:48 282624]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 01:11 1235736]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 14:50 66048 C:\WINNT\system32\SK9910DM.EXE]
"Logitech Utility"="Logi_MwX.Exe" [2002-11-08 05:50 19968 C:\WINNT\LOGI_MWX.EXE]
"GWMDMMSG"="GWMDMMSG.exe" [2002-08-06 15:24 90112 C:\WINNT\GWMDMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 14:22 243072]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-24 13:06 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-27 18:21 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=AVGRSSTX.DLL,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINNT\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINNT\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINNT\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-07 00:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-05-23 09:48 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2005-01-12 04:01 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-03-27 16:22 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINNT\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\PopCap Games\\Zuma Deluxe\\Zuma.exe"=
"C:\\Program Files\\BearShare\\BearShare.exe"=
"C:\\Program Files\\Real\\RealOne Player\\realplay.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\Real\\RealOne Player\\trueplay.exe"=
"C:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"C:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"C:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\Zone.com Deluxe Games\\Wheel of Fortune Deluxe\\Wheel of Fortune Deluxe.exe"=
"C:\\Program Files\\Yahoo! Games\\JEOPARDY!\\JEOPARDY!.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImSc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh
R0 pavboot;pavboot;C:\WINNT\system32\drivers\pavboot.sys [2008-06-19 17:24]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINNT\system32\Drivers\avgldx86.sys [2008-08-29 01:11]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 15:46]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 01:11]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 01:11]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINNT\system32\Drivers\avgtdix.sys [2008-08-19 01:52]
S3 PCDRDRV;Pcdr Helper Driver;C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys []
S3 StreamSurge;StreamSurge Driver (miniport);C:\WINNT\system32\DRIVERS\ss.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\d2d5a19a-7530-43d2-baca-7a9ef323da99]
C:\WINNT\system32\wqxuxz.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-AOLDialer - C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
MSConfigStartUp-DAEMON Tools Lite - C:\Program Files\DAEMON Tools Lite\daemon.exe
MSConfigStartUp-WeatherDPA - C:\Program Files\Zango\bin\10.3.37.0\Weather.exe
MSConfigStartUp-ZangoSA - C:\Program Files\Zango\bin\10.3.37.0\ZangoSA.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-29 02:18:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-08-29 2:30:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-29 06:30:01
Pre-Run: 17,453,203,456 bytes free
Post-Run: 17,586,393,088 bytes free
506 --- E O F --- 2008-08-17 09:06:45