ComboFix 08-12-02.02 - Teresa 2008-12-03 23:02:09.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1063 [GMT -6:00]
Running from: c:\users\Teresa\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.
2008-12-03 22:32 . 2008-12-03 22:32 <DIR> d-------- c:\windows\Sun
2008-12-02 19:23 . 2008-12-02 19:23 <DIR> d-------- c:\users\Teresa\AppData\Roaming\Malwarebytes
2008-12-02 19:23 . 2008-12-02 19:23 <DIR> d-------- c:\users\All Users\Malwarebytes
2008-12-02 19:23 . 2008-12-02 19:23 <DIR> d-------- c:\programdata\Malwarebytes
2008-12-02 19:23 . 2008-12-02 19:23 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-02 19:23 . 2008-10-22 16:10 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-12-02 19:23 . 2008-10-22 16:10 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-12-02 18:36 . 2008-12-02 18:36 <DIR> d-------- c:\program files\Trend Micro
2008-11-29 04:36 . 2008-11-29 04:36 <DIR> d-------- c:\users\All Users\Symantec
2008-11-29 04:36 . 2008-11-29 04:36 <DIR> d-------- c:\programdata\Symantec
2008-11-27 16:42 . 2008-11-27 16:42 <DIR> d-------- c:\users\Teresa\AppData\Roaming\CyberLink
2008-11-26 22:28 . 2008-10-21 21:43 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-26 22:28 . 2008-10-21 21:43 160,768 --a------ c:\windows\System32\PortableDeviceTypes.dll
2008-11-26 22:28 . 2008-10-21 21:43 95,232 --a------ c:\windows\System32\PortableDeviceClassExtension.dll
2008-11-26 22:27 . 2008-08-27 21:24 712,192 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-26 22:27 . 2008-08-27 21:24 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 22:27 . 2008-08-27 21:24 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-26 22:06 . 2008-10-20 23:16 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-23 23:32 . 2008-12-03 22:34 <DIR> d-------- c:\program files\Norton Security Scan
2008-11-23 23:32 . 2008-11-29 08:39 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2008-11-23 22:43 . 2008-12-01 21:02 <DIR> d-------- c:\users\All Users\Google Updater
2008-11-23 22:43 . 2008-12-01 21:02 <DIR> d-------- c:\programdata\Google Updater
2008-11-14 09:34 . 2008-10-16 15:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-14 09:34 . 2008-10-16 14:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-14 09:34 . 2008-10-16 15:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-14 09:34 . 2008-10-16 14:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-14 09:34 . 2008-10-16 15:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-14 09:34 . 2008-10-16 15:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-14 09:34 . 2008-10-16 15:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-14 09:33 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-14 09:33 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-13 19:54 . 2008-09-09 21:25 1,341,440 --a------ c:\windows\System32\msxml6.dll
2008-11-13 19:54 . 2008-09-09 21:21 2,048 --a------ c:\windows\System32\msxml6r.dll
2008-11-13 19:46 . 2008-08-25 19:11 211,456 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-13 19:41 . 2008-09-04 22:48 1,194,496 --a------ c:\windows\System32\msxml3.dll
2008-11-13 19:41 . 2008-09-04 22:45 2,048 --a------ c:\windows\System32\msxml3r.dll
2008-11-07 15:58 . 2008-08-05 21:19 1,244,672 --a------ c:\windows\System32\mcmde.dll
2008-11-07 15:58 . 2008-08-05 21:27 428,032 --a------ c:\windows\System32\EncDec.dll
2008-11-07 15:58 . 2008-08-05 21:21 292,352 --a------ c:\windows\System32\psisdecd.dll
2008-11-07 15:58 . 2008-08-05 21:21 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-11-07 15:58 . 2008-08-05 21:26 177,152 --a------ c:\windows\System32\mpg2splt.ax
2008-11-07 15:58 . 2008-08-05 21:20 80,896 --a------ c:\windows\System32\MSNP.ax
2008-11-07 15:58 . 2008-08-05 21:19 68,608 --a------ c:\windows\System32\Mpeg2Data.ax
2008-11-07 15:58 . 2008-08-05 21:19 57,856 --a------ c:\windows\System32\MSDvbNP.ax
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 04:35 --------- d-----w c:\users\Teresa\AppData\Roaming\LimeWire
2008-12-03 01:05 --------- d-----w c:\program files\LimeWire
2008-11-29 15:24 --------- d-----w c:\program files\Common Files\Adobe
2008-11-24 04:50 --------- d-----w c:\program files\Google
2008-11-24 02:56 --------- d-----w c:\programdata\McAfee
2008-11-24 02:56 --------- d-----w c:\program files\McAfee
2008-11-16 21:52 1,368 ----a-w c:\users\Teresa\AppData\Roaming\wklnhst.dat
2008-10-21 03:18 --------- d-----w c:\programdata\Dell
2008-10-20 15:12 --------- d-----w c:\program files\Windows Mail
2008-10-02 03:49 826,368 ----a-w c:\windows\System32\wininet.dll
2008-10-02 03:49 56,320 ----a-w c:\windows\System32\iesetup.dll
2008-10-02 03:49 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-10-02 03:48 26,624 ----a-w c:\windows\System32\ieUnatt.exe
2008-09-18 04:35 3,505,208 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 04:35 3,470,904 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:03 2,027,520 ----a-w c:\windows\System32\win32k.sys
2008-08-21 22:22 174 --sha-w c:\program files\desktop.ini
2008-07-15 14:16 76 --sh--r c:\windows\CT4CET.bin
2008-09-02 22:51 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-09-02 22:51 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-09-02 22:51 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-23 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-24 159744]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-12-02 36864]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-01-01 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-28 133656]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-19 3444736]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-15 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-07-15 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-02-22 1193240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-07-15 08:29 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{801B9625-A24B-45D4-8FBE-6420E1EAF859}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{00BCA362-2EB9-496E-8083-B3AEE8DCDC5F}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{42C42AD2-512B-493B-B732-C15ACB7E560E}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{A0C5762B-6DFB-429C-842D-028D124D4FF6}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{8B8C92C1-A8DD-4F82-A861-6F7EB28D0043}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{9EB28302-AE7A-4588-AD6A-5BF87ED34129}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{A3D04AF9-C798-4511-A5FC-DBCC9682FCC5}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{1C936232-0EEB-4ADA-9003-AF0B8F7AE7AB}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-10 124832]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2008-07-15 73728]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\DRIVERS\OEM02Dev.sys [2008-07-15 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\DRIVERS\OEM02Vfx.sys [2008-07-15 7424]
S3 GoToAssist;GoToAssist;"c:\program files\Citrix\GoToAssist\514\g2aservice.exe" Start=service [2008-07-15 16680]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-12-02 c:\windows\Tasks\Norton Security Scan for Teresa.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-03 23:04:09
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-03 23:04:58
ComboFix-quarantined-files.txt 2008-12-04 05:04:55
Pre-Run: 69,888,073,728 bytes free
Post-Run: 69,935,267,840 bytes free
154 --- E O F --- 2008-12-02 00:57:55