codeman0013
Active Member
Hey guys... I have a pc for a good friend who had a daughter who decided to start using morpheus and downloaded a lot of viruses so i have done a lot but it appears to still be replicating please help...
ComboFix 07-12-22.1 - Owner 2007-12-22 9:30:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.74 [GMT -6:00]
Running from: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\J5R69IKQ\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\appatc~1
C:\Program Files\appatc~1\A?pPatch\
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\matrix.dat
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\knnmp.ini
C:\WINDOWS\system32\knnmp.ini2
C:\WINDOWS\system32\ljjhghe.dll
C:\WINDOWS\system32\winrnt32.dll
C:\WINDOWS\system32\ybeeg.ini
C:\WINDOWS\system32\ybeeg.ini2
.
((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 )))))))))))))))))))))))))))))))
.
2007-12-20 23:09 . 2007-12-20 23:09 <DIR> d-------- C:\Program Files\MSBuild
2007-12-20 22:57 . 2007-12-21 17:39 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-12-20 22:51 . 2007-12-20 22:51 <DIR> d-------- C:\Program Files\Reference Assemblies
2007-12-20 22:13 . 2001-08-17 13:28 771,581 --a--c--- C:\WINDOWS\system32\dllcache\winacisa.sys
2007-12-20 22:12 . 2001-08-17 13:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2007-12-20 22:11 . 2001-08-17 12:18 285,760 --a--c--- C:\WINDOWS\system32\dllcache\stlnata.sys
2007-12-20 22:10 . 2001-08-17 22:36 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll
2007-12-20 22:09 . 2001-08-17 13:28 899,146 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2007-12-20 22:08 . 2001-08-17 14:05 351,616 --a--c--- C:\WINDOWS\system32\dllcache\ovcodek2.sys
2007-12-20 22:07 . 2001-08-17 12:50 320,384 --a--c--- C:\WINDOWS\system32\dllcache\mgaum.sys
2007-12-20 22:06 . 2001-08-17 13:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2007-12-20 22:05 . 2004-08-04 00:56 152,576 --a--c--- C:\WINDOWS\system32\dllcache\irftp.exe
2007-12-20 22:04 . 2004-08-04 00:56 702,845 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2007-12-20 22:03 . 2001-08-17 14:56 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2007-12-20 22:02 . 2001-08-17 13:28 634,134 --a--c--- C:\WINDOWS\system32\dllcache\el656ct5.sys
2007-12-20 22:01 . 2001-08-17 12:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
2007-12-20 22:00 . 2001-08-17 12:13 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2007-12-20 21:59 . 2001-08-17 13:28 714,698 --a--c--- C:\WINDOWS\system32\dllcache\cbmdmkxx.sys
2007-12-20 21:58 . 2001-08-17 14:56 342,336 --a--c--- C:\WINDOWS\system32\dllcache\banshee.dll
2007-12-20 21:57 . 2001-08-17 14:55 382,592 --a--c--- C:\WINDOWS\system32\dllcache\atidrab.dll
2007-12-20 21:56 . 2001-08-17 14:07 56,960 --a--c--- C:\WINDOWS\system32\dllcache\aic78xx.sys
2007-12-20 21:56 . 2001-08-17 14:07 55,168 --a--c--- C:\WINDOWS\system32\dllcache\aic78u2.sys
2007-12-20 21:56 . 2004-08-03 22:31 36,224 --a--c--- C:\WINDOWS\system32\dllcache\an983.sys
2007-12-20 21:56 . 2001-08-17 12:11 27,678 --a--c--- C:\WINDOWS\system32\dllcache\ali5261.sys
2007-12-20 21:56 . 2001-08-17 13:49 26,624 --a--c--- C:\WINDOWS\system32\dllcache\alifir.sys
2007-12-20 21:56 . 2001-08-17 22:37 24,576 --a--c--- C:\WINDOWS\system32\dllcache\agcgauge.ax
2007-12-20 21:56 . 2001-08-17 12:11 16,969 --a--c--- C:\WINDOWS\system32\dllcache\amb8002.sys
2007-12-20 21:56 . 2001-08-17 13:52 12,800 --a--c--- C:\WINDOWS\system32\dllcache\aha154x.sys
2007-12-20 21:56 . 2001-08-17 13:52 12,032 --a--c--- C:\WINDOWS\system32\dllcache\amsint.sys
2007-12-20 21:56 . 2001-08-17 13:47 6,272 --a--c--- C:\WINDOWS\system32\dllcache\apmbatt.sys
2007-12-20 21:56 . 2001-08-17 13:51 5,248 --a--c--- C:\WINDOWS\system32\dllcache\aliide.sys
2007-12-20 21:53 . 2001-08-17 14:56 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2007-12-20 21:46 . 2007-12-20 21:46 <DIR> d-------- C:\VundoFix Backups
2007-12-20 12:25 . 2003-11-18 00:09 155,648 --a------ C:\WINDOWS\system32\igfxres.dll
2007-12-20 12:15 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-12-20 12:15 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2007-12-20 12:13 . 2007-12-20 12:13 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\TeamViewer
2007-12-20 03:31 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2007-12-20 03:18 . 2007-12-20 03:18 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-12-20 03:10 . 2007-12-20 03:10 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2007-12-20 03:10 . 2007-12-20 03:10 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2007-12-20 02:57 . 2007-12-20 02:57 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-12-20 02:09 . 2007-12-20 12:33 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-12-20 02:09 . 2007-12-20 02:29 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-12-19 22:19 . 2007-12-19 23:03 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2007-12-19 22:13 . 2006-11-13 00:02 288,768 --a------ C:\WINDOWS\system32\rhttpaa.dll
2007-12-19 22:13 . 2006-11-13 00:02 116,736 --a------ C:\WINDOWS\system32\aaclient.dll
2007-12-19 22:13 . 2006-11-13 00:02 36,352 --a------ C:\WINDOWS\system32\tsgqec.dll
2007-12-19 19:49 . 2007-12-19 19:49 <DIR> d-------- C:\Program Files\CCleaner
2007-12-19 19:23 . 2007-12-22 08:00 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVG7
2007-12-19 19:23 . 2007-12-19 19:23 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-19 19:22 . 2007-12-19 19:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-19 19:22 . 2007-12-19 19:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-12-19 18:54 . 2007-12-20 12:13 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-12-19 18:43 . 2007-12-19 18:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\TeamViewer
2007-12-19 18:42 . 2007-12-19 18:43 <DIR> d-------- C:\Program Files\TeamViewer3
2007-12-19 18:41 . 2007-12-19 18:41 <DIR> d-------- C:\Documents and Settings\Owner\temp
2007-12-19 17:40 . 2007-12-20 18:18 <DIR> d-------- C:\WINDOWS\system32\njprckha
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\VirDefs
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\Support
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\SevInst
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\LiveUpdt
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\Data
2007-12-14 22:25 . 2007-12-19 18:20 1,246,773 --a------ C:\Data1.cab
2007-12-14 22:25 . 2007-12-19 18:20 1,663 --a------ C:\Setup.wis
2007-12-14 22:19 . 2007-12-19 12:46 <DIR> d-------- C:\WINDOWS\system32\juvprpba
2007-12-14 22:18 . 2007-12-19 22:29 <DIR> d-------- C:\Program Files\Bqscjpok
2007-12-14 22:18 . 2007-12-19 22:29 <DIR> d-------- C:\Program Files\aryvobmf
2007-12-13 14:48 . 2007-12-13 14:48 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-13 02:54 . 2007-12-13 02:54 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\TransRender
2007-12-13 02:54 . 2007-12-13 02:54 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Temporary
2007-12-13 02:54 . 2007-12-13 02:54 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Samsung
2007-12-13 02:53 . 2007-12-13 02:53 <DIR> d-------- C:\Program Files\Samsung
2007-12-10 00:57 . 2007-12-10 00:58 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Move Networks
2007-12-04 13:55 . 2007-12-14 20:30 <DIR> d-------- C:\Program Files\Eypekskp
2007-12-03 21:45 . 2007-12-14 20:38 <DIR> d-------- C:\Program Files\Zcmvyoll
2007-12-03 00:58 . 2007-12-14 20:37 <DIR> d-------- C:\Program Files\Pqdoufwx
2007-12-03 00:58 . 2007-12-14 22:16 <DIR> d-------- C:\Program Files\lshklgle
2007-12-03 00:21 . 2007-12-03 00:21 <DIR> d-------- C:\Program Files\Drug Lord 2
2007-11-26 06:19 . 2007-11-26 06:19 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Viewpoint
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-22 03:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-21 23:31 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-20 23:46 --------- d-----w C:\Program Files\Morpheus
2007-12-20 18:13 --------- d-----w C:\Program Files\Google
2007-12-20 00:54 --------- d-----w C:\Program Files\Windows Defender
2007-12-20 00:53 --------- d-----w C:\Program Files\Symantec
2007-12-20 00:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-20 00:51 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-15 04:18 --------- d-----w C:\Program Files\Finale NotePad 2007
2007-12-13 08:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-16 04:14 --------- d-----w C:\Program Files\Trillian
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-23 00:52 --------- d-----w C:\Program Files\QuickTime
1998-12-09 02:53 99,840 ----a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 ----a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 ----a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 ----a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 ----a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 ----a-w C:\Program Files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 675,840 2006-02-07 19:36:23 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\bak\DirectCD.exe
----a-w 180,269 2006-08-22 13:45:17 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 155,648 2006-02-07 21:03:41 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 1,415,824 2005-05-31 07:04:00 C:\Program Files\Spybot - Search & Destroy\bak\TeaTimer.exe
----a-w 1,460,560 2007-08-31 22:46:28 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
----a-w 77,824 2002-07-30 17:35:04 C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\bak\vptray.exe
----a-w 777,424 2006-04-03 23:12:24 C:\Program Files\Windows Defender\bak\MSASCui.exe
----a-w 15,360 2004-08-04 06:56:50 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-04 06:56:50 C:\WINDOWS\system32\ctfmon.exe
----a-w 106,496 2002-03-27 01:20:52 C:\WINDOWS\system32\bak\hkcmd.exe
----a-w 118,784 2003-11-18 06:11:00 C:\WINDOWS\system32\hkcmd.exe
----a-w 155,648 2002-03-27 01:28:56 C:\WINDOWS\system32\bak\igfxtray.exe
----a-w 155,648 2003-11-18 06:24:00 C:\WINDOWS\system32\igfxtray.exe
----a-w 196,608 2001-10-15 08:42:45 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb04.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7555906D-70F1-4FD6-8250-4FBE75252F58}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 08:15]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-11-18 00:24]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-11-18 00:11]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-19 19:22]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhghe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Last.fm Helper.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Last.fm Helper.lnk
backup=C:\WINDOWS\pss\Last.fm Helper.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
backup=C:\WINDOWS\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 00:56 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fypsbqpy]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\fypsbqpy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GWMDMMSG]
GWMDMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\odmtypcj]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\odmtypcj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\bak\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tkdglqlq]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\tkdglqlq.dll
S3 Dptiiserwia;Dptiiserwia;C:\WINDOWS\system32\drivers\bthpan.sys [2004-08-03 22:58]
S3 iscFlash;iscFlash;C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys []
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 12:24]
S3 sscdmdfl;SAMSUNG CDMA Modem Filter;C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 12:24]
S3 sscdmdm;SAMSUNG CDMA Modem Drivers;C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 12:24]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 09:46:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-22 9:48:54 - machine was rebooted
.
2007-12-20 23:44:33 --- E O F ---
ComboFix 07-12-22.1 - Owner 2007-12-22 9:30:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.74 [GMT -6:00]
Running from: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\J5R69IKQ\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\appatc~1
C:\Program Files\appatc~1\A?pPatch\
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\matrix.dat
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\knnmp.ini
C:\WINDOWS\system32\knnmp.ini2
C:\WINDOWS\system32\ljjhghe.dll
C:\WINDOWS\system32\winrnt32.dll
C:\WINDOWS\system32\ybeeg.ini
C:\WINDOWS\system32\ybeeg.ini2
.
((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 )))))))))))))))))))))))))))))))
.
2007-12-20 23:09 . 2007-12-20 23:09 <DIR> d-------- C:\Program Files\MSBuild
2007-12-20 22:57 . 2007-12-21 17:39 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-12-20 22:51 . 2007-12-20 22:51 <DIR> d-------- C:\Program Files\Reference Assemblies
2007-12-20 22:13 . 2001-08-17 13:28 771,581 --a--c--- C:\WINDOWS\system32\dllcache\winacisa.sys
2007-12-20 22:12 . 2001-08-17 13:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2007-12-20 22:11 . 2001-08-17 12:18 285,760 --a--c--- C:\WINDOWS\system32\dllcache\stlnata.sys
2007-12-20 22:10 . 2001-08-17 22:36 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll
2007-12-20 22:09 . 2001-08-17 13:28 899,146 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2007-12-20 22:08 . 2001-08-17 14:05 351,616 --a--c--- C:\WINDOWS\system32\dllcache\ovcodek2.sys
2007-12-20 22:07 . 2001-08-17 12:50 320,384 --a--c--- C:\WINDOWS\system32\dllcache\mgaum.sys
2007-12-20 22:06 . 2001-08-17 13:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2007-12-20 22:05 . 2004-08-04 00:56 152,576 --a--c--- C:\WINDOWS\system32\dllcache\irftp.exe
2007-12-20 22:04 . 2004-08-04 00:56 702,845 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2007-12-20 22:03 . 2001-08-17 14:56 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2007-12-20 22:02 . 2001-08-17 13:28 634,134 --a--c--- C:\WINDOWS\system32\dllcache\el656ct5.sys
2007-12-20 22:01 . 2001-08-17 12:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
2007-12-20 22:00 . 2001-08-17 12:13 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2007-12-20 21:59 . 2001-08-17 13:28 714,698 --a--c--- C:\WINDOWS\system32\dllcache\cbmdmkxx.sys
2007-12-20 21:58 . 2001-08-17 14:56 342,336 --a--c--- C:\WINDOWS\system32\dllcache\banshee.dll
2007-12-20 21:57 . 2001-08-17 14:55 382,592 --a--c--- C:\WINDOWS\system32\dllcache\atidrab.dll
2007-12-20 21:56 . 2001-08-17 14:07 56,960 --a--c--- C:\WINDOWS\system32\dllcache\aic78xx.sys
2007-12-20 21:56 . 2001-08-17 14:07 55,168 --a--c--- C:\WINDOWS\system32\dllcache\aic78u2.sys
2007-12-20 21:56 . 2004-08-03 22:31 36,224 --a--c--- C:\WINDOWS\system32\dllcache\an983.sys
2007-12-20 21:56 . 2001-08-17 12:11 27,678 --a--c--- C:\WINDOWS\system32\dllcache\ali5261.sys
2007-12-20 21:56 . 2001-08-17 13:49 26,624 --a--c--- C:\WINDOWS\system32\dllcache\alifir.sys
2007-12-20 21:56 . 2001-08-17 22:37 24,576 --a--c--- C:\WINDOWS\system32\dllcache\agcgauge.ax
2007-12-20 21:56 . 2001-08-17 12:11 16,969 --a--c--- C:\WINDOWS\system32\dllcache\amb8002.sys
2007-12-20 21:56 . 2001-08-17 13:52 12,800 --a--c--- C:\WINDOWS\system32\dllcache\aha154x.sys
2007-12-20 21:56 . 2001-08-17 13:52 12,032 --a--c--- C:\WINDOWS\system32\dllcache\amsint.sys
2007-12-20 21:56 . 2001-08-17 13:47 6,272 --a--c--- C:\WINDOWS\system32\dllcache\apmbatt.sys
2007-12-20 21:56 . 2001-08-17 13:51 5,248 --a--c--- C:\WINDOWS\system32\dllcache\aliide.sys
2007-12-20 21:53 . 2001-08-17 14:56 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2007-12-20 21:46 . 2007-12-20 21:46 <DIR> d-------- C:\VundoFix Backups
2007-12-20 12:25 . 2003-11-18 00:09 155,648 --a------ C:\WINDOWS\system32\igfxres.dll
2007-12-20 12:15 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-12-20 12:15 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2007-12-20 12:13 . 2007-12-20 12:13 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\TeamViewer
2007-12-20 03:31 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2007-12-20 03:18 . 2007-12-20 03:18 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-12-20 03:10 . 2007-12-20 03:10 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2007-12-20 03:10 . 2007-12-20 03:10 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2007-12-20 02:57 . 2007-12-20 02:57 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-12-20 02:09 . 2007-12-20 12:33 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-12-20 02:09 . 2007-12-20 02:29 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-12-19 22:19 . 2007-12-19 23:03 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2007-12-19 22:13 . 2006-11-13 00:02 288,768 --a------ C:\WINDOWS\system32\rhttpaa.dll
2007-12-19 22:13 . 2006-11-13 00:02 116,736 --a------ C:\WINDOWS\system32\aaclient.dll
2007-12-19 22:13 . 2006-11-13 00:02 36,352 --a------ C:\WINDOWS\system32\tsgqec.dll
2007-12-19 19:49 . 2007-12-19 19:49 <DIR> d-------- C:\Program Files\CCleaner
2007-12-19 19:23 . 2007-12-22 08:00 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVG7
2007-12-19 19:23 . 2007-12-19 19:23 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-19 19:22 . 2007-12-19 19:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-19 19:22 . 2007-12-19 19:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-12-19 18:54 . 2007-12-20 12:13 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-12-19 18:43 . 2007-12-19 18:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\TeamViewer
2007-12-19 18:42 . 2007-12-19 18:43 <DIR> d-------- C:\Program Files\TeamViewer3
2007-12-19 18:41 . 2007-12-19 18:41 <DIR> d-------- C:\Documents and Settings\Owner\temp
2007-12-19 17:40 . 2007-12-20 18:18 <DIR> d-------- C:\WINDOWS\system32\njprckha
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\VirDefs
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\Support
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\SevInst
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\LiveUpdt
2007-12-14 22:25 . 2007-12-14 22:25 <DIR> d-------- C:\Data
2007-12-14 22:25 . 2007-12-19 18:20 1,246,773 --a------ C:\Data1.cab
2007-12-14 22:25 . 2007-12-19 18:20 1,663 --a------ C:\Setup.wis
2007-12-14 22:19 . 2007-12-19 12:46 <DIR> d-------- C:\WINDOWS\system32\juvprpba
2007-12-14 22:18 . 2007-12-19 22:29 <DIR> d-------- C:\Program Files\Bqscjpok
2007-12-14 22:18 . 2007-12-19 22:29 <DIR> d-------- C:\Program Files\aryvobmf
2007-12-13 14:48 . 2007-12-13 14:48 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-13 02:54 . 2007-12-13 02:54 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\TransRender
2007-12-13 02:54 . 2007-12-13 02:54 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Temporary
2007-12-13 02:54 . 2007-12-13 02:54 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Samsung
2007-12-13 02:53 . 2007-12-13 02:53 <DIR> d-------- C:\Program Files\Samsung
2007-12-10 00:57 . 2007-12-10 00:58 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Move Networks
2007-12-04 13:55 . 2007-12-14 20:30 <DIR> d-------- C:\Program Files\Eypekskp
2007-12-03 21:45 . 2007-12-14 20:38 <DIR> d-------- C:\Program Files\Zcmvyoll
2007-12-03 00:58 . 2007-12-14 20:37 <DIR> d-------- C:\Program Files\Pqdoufwx
2007-12-03 00:58 . 2007-12-14 22:16 <DIR> d-------- C:\Program Files\lshklgle
2007-12-03 00:21 . 2007-12-03 00:21 <DIR> d-------- C:\Program Files\Drug Lord 2
2007-11-26 06:19 . 2007-11-26 06:19 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Viewpoint
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-22 03:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-21 23:31 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-20 23:46 --------- d-----w C:\Program Files\Morpheus
2007-12-20 18:13 --------- d-----w C:\Program Files\Google
2007-12-20 00:54 --------- d-----w C:\Program Files\Windows Defender
2007-12-20 00:53 --------- d-----w C:\Program Files\Symantec
2007-12-20 00:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-20 00:51 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-15 04:18 --------- d-----w C:\Program Files\Finale NotePad 2007
2007-12-13 08:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-16 04:14 --------- d-----w C:\Program Files\Trillian
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-23 00:52 --------- d-----w C:\Program Files\QuickTime
1998-12-09 02:53 99,840 ----a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 ----a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 ----a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 ----a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 ----a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 ----a-w C:\Program Files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 675,840 2006-02-07 19:36:23 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\bak\DirectCD.exe
----a-w 180,269 2006-08-22 13:45:17 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 155,648 2006-02-07 21:03:41 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 1,415,824 2005-05-31 07:04:00 C:\Program Files\Spybot - Search & Destroy\bak\TeaTimer.exe
----a-w 1,460,560 2007-08-31 22:46:28 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
----a-w 77,824 2002-07-30 17:35:04 C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\bak\vptray.exe
----a-w 777,424 2006-04-03 23:12:24 C:\Program Files\Windows Defender\bak\MSASCui.exe
----a-w 15,360 2004-08-04 06:56:50 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-04 06:56:50 C:\WINDOWS\system32\ctfmon.exe
----a-w 106,496 2002-03-27 01:20:52 C:\WINDOWS\system32\bak\hkcmd.exe
----a-w 118,784 2003-11-18 06:11:00 C:\WINDOWS\system32\hkcmd.exe
----a-w 155,648 2002-03-27 01:28:56 C:\WINDOWS\system32\bak\igfxtray.exe
----a-w 155,648 2003-11-18 06:24:00 C:\WINDOWS\system32\igfxtray.exe
----a-w 196,608 2001-10-15 08:42:45 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpztsb04.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7555906D-70F1-4FD6-8250-4FBE75252F58}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 08:15]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-11-18 00:24]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-11-18 00:11]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-19 19:22]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhghe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Last.fm Helper.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Last.fm Helper.lnk
backup=C:\WINDOWS\pss\Last.fm Helper.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
backup=C:\WINDOWS\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 00:56 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fypsbqpy]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\fypsbqpy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GWMDMMSG]
GWMDMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\odmtypcj]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\odmtypcj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\bak\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tkdglqlq]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\tkdglqlq.dll
S3 Dptiiserwia;Dptiiserwia;C:\WINDOWS\system32\drivers\bthpan.sys [2004-08-03 22:58]
S3 iscFlash;iscFlash;C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys []
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 12:24]
S3 sscdmdfl;SAMSUNG CDMA Modem Filter;C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 12:24]
S3 sscdmdm;SAMSUNG CDMA Modem Drivers;C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 12:24]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 09:46:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-22 9:48:54 - machine was rebooted
.
2007-12-20 23:44:33 --- E O F ---