.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\svchost.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-13 to 2007-12-13 )))))))))))))))))))))))))))))))
.
2007-12-12 19:39 . 2007-12-12 19:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ashampoo
2007-12-12 19:36 . 2007-12-12 19:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ashampoo
2007-12-11 13:11 . 2007-12-11 13:11 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-11 11:03 . 2007-12-11 11:03 110,592 --a------ C:\WINDOWS\system32\avgfwafu.dll
2007-12-11 11:03 . 2007-12-11 11:03 9,216 --a------ C:\WINDOWS\system32\avgwlntf.dll
2007-12-11 00:16 . 2007-12-11 00:16 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-11 00:16 . 2007-12-13 00:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2007-12-11 00:15 . 2007-12-11 00:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-10 23:25 . 2007-12-11 11:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-09 15:34 . 2007-12-09 15:34 <DIR> d-------- C:\Program Files\DivX
2007-12-06 18:17 . 2007-12-06 18:17 <DIR> d-------- C:\Program Files\CCleaner
2007-12-05 23:43 . 2007-12-05 23:43 <DIR> d-------- C:\Program Files\Uniblue
2007-12-03 17:33 . 2007-12-03 17:33 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-12-03 17:33 . 2007-12-03 17:33 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-12-03 17:33 . 2007-12-03 17:33 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-12-03 17:33 . 2007-12-03 17:33 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2007-12-03 17:33 . 2007-12-03 17:33 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
2007-12-03 15:25 . 2007-12-03 16:13 <DIR> d-------- C:\Program Files\SpacialAudio
2007-12-01 18:11 . 2007-12-01 18:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
2007-12-01 18:11 . 2007-12-01 18:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Insight Software
2007-11-29 14:30 . 2007-11-29 14:30 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-11-29 14:30 . 2007-11-29 14:30 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-11-29 14:30 . 2007-11-29 14:30 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2007-11-29 14:28 . 2007-11-29 14:28 196,608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-11-29 14:28 . 2007-11-29 14:28 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2007-11-29 14:28 . 2007-11-29 14:28 416 --a------ C:\WINDOWS\system32\dtu100.dll.manifest
2007-11-29 14:28 . 2007-11-29 14:28 416 --a------ C:\WINDOWS\system32\dpl100.dll.manifest
2007-11-28 13:55 . 2007-11-28 13:55 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 13:53 . 2007-11-28 13:53 593,920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 13:53 . 2007-11-28 13:53 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
2007-11-28 13:53 . 2007-11-28 13:53 344,064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-11-28 13:53 . 2007-11-28 13:53 294,912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-11-28 13:53 . 2007-11-28 13:53 294,912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-11-28 13:53 . 2007-11-28 13:53 57,344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-11-28 13:53 . 2007-11-28 13:53 53,248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 13:52 . 2007-11-28 13:52 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-22 08:42 . 2007-11-24 13:51 <DIR> d-------- C:\Fraps
2007-11-22 08:42 . 2007-12-12 21:20 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-21 10:23 . 2007-11-21 10:23 81,920 --a------ C:\WINDOWS\system32\frapsvid.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-11 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-11 08:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-12-11 02:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-12-11 00:52 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Azureus
2007-12-08 00:08 --------- d-----w C:\Program Files\Azureus
2007-12-06 07:46 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-06 07:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Uniblue
2007-11-29 22:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-25 07:36 --------- d-----w C:\Documents and Settings\Administrator\Application Data\gtk-2.0
2007-11-13 10:25 20,480 ----a-r C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-13 06:38 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-13 06:33 --------- d-----w C:\Program Files\Windows Live
2007-11-13 06:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-05 03:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Uniblue
2007-11-05 00:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-05 00:03 --------- d-----w C:\Program Files\SlySoft
2007-11-05 00:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-11-04 22:02 0 ----a-w C:\$RJ$.DAT
2007-11-01 19:44 --------- d-----w C:\Program Files\Java
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 01:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-25 00:52 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-25 00:44 --------- d-----w C:\Program Files\Rockstar Games
2007-10-24 20:31 --------- d--h--w C:\Documents and Settings\Administrator\Application Data\ijjigame
2007-10-18 23:36 --------- d-----w C:\Program Files\TryMedia
2007-10-18 19:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-10-17 19:19 --------- d-----w C:\Program Files\CyberLink
2007-10-17 19:16 --------- d-----w C:\Documents and Settings\LocalService\Application Data\CyberLink
2007-10-17 19:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-10-17 19:14 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CyberLink
2007-10-17 19:07 4,184 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-10-14 18:13 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Pro
2007-10-14 18:10 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-10-14 06:15 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InfraRecorder
2007-10-13 18:59 --------- d-----w C:\Program Files\LimeWire
2007-10-13 05:26 --------- d-----w C:\Program Files\AC3Filter
2007-10-13 04:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\IGN_DLM
2007-09-23 18:50 77,824 ----a-w C:\WINDOWS\system32\ws232.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 17:07]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 17:07 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-06-28 23:43 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-03 17:07 C:\WINDOWS\system32\rundll32.exe]
"EnvyHFCPL"="C:\Program Files\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe" [2007-03-15 09:52]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-11 00:15]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-11 00:15]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-12-11 11:03 9216 C:\WINDOWS\system32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpyEraser]
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe -m
R2 Block Level Filtering Service;Block Level Filtering Service;C:\WINDOWS\svchost.exe
R3 Envy24HFS;ICE Envy24 Family Audio Controller WDM;C:\WINDOWS\system32\drivers\Envy24HF.sys
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-12-12 08:04:56 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-13 11:44:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
EnvyHFCPL = C:\Program Files\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe 1?????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-13 11:45:14
.
2007-12-11 19:07:41 --- E O F ---