|
|
|||||||
|
"Graham" - 2008-02-20 7:26:20 - ComboFix 07-07-14.6 - Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2008-01-20 to 2008-02-20 ))))))))))))))))))))))))))))))) 2008-02-15 10:35 <DIR> d-------- C:\Perl 2008-02-06 07:21 <DIR> d-------- C:\DOCUME~1\Rachel\APPLIC~1\Sereniti 2008-02-04 18:10 <DIR> d-------- C:\DOCUME~1\CATHER~1\WINDOWS 2008-02-01 07:41 <DIR> d-------- C:\DOCUME~1\CATHER~1\APPLIC~1\Sereniti 2008-01-31 16:09 <DIR> d-------- C:\DOCUME~1\Annette\APPLIC~1\Sereniti 2008-01-31 15:52 <DIR> d-------- C:\DOCUME~1\Graham\APPLIC~1\Sereniti 2008-01-31 15:38 <DIR> d-------- C:\DOCUME~1\Graham\APPLIC~1\WeatherWatcher 2008-01-29 20:23 <DIR> d-------- C:\Program Files\iPod 2008-01-29 20:22 <DIR> d-------- C:\Program Files\QuickTime 2008-01-29 19:37 86,016 --a------ C:\WINDOWS\Dit.exe 2008-01-29 19:37 61,440 --a------ C:\WINDOWS\DitExp.exe 2008-01-29 19:37 266,240 -r------- C:\WINDOWS\Dit.DLL 2008-01-29 19:37 24,576 --a------ C:\WINDOWS\CICache.exe 2008-01-29 19:37 13,568 --a------ C:\WINDOWS\system32\drivers\USBCRFT.SYS 2008-01-28 17:49 <DIR> d-------- C:\DOCUME~1\Graham\.freeguide 2008-01-27 20:54 123,664 --a------ C:\WINDOWS\system32\MSJInt35.dll 2008-01-27 20:53 24,848 --a------ C:\WINDOWS\system32\MSJtEr35.dll 2008-01-27 20:52 71,680 --a------ C:\WINDOWS\ST5UNST.EXE 2008-01-27 20:52 29,696 --a------ C:\WINDOWS\system32\VB5StKit.dll 2008-01-27 11:00 <DIR> d-------- C:\Program Files\DupKiller 2008-01-27 10:40 <DIR> d-------- C:\Program Files\Desktop Graffitist 2008-01-27 10:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Earthsim 2008-01-27 10:28 <DIR> d-------- C:\Program Files\CachemanXP 2008-01-26 09:30 <DIR> d-------- C:\Bourne 3 2008-01-25 17:01 <DIR> d-------- C:\Program Files\Microsoft IntelliPoint 2008-01-25 16:50 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS 2008-01-25 16:33 <DIR> d-------- C:\Program Files\Microsoft Silverlight 2008-01-20 23:15 <DIR> d-------- C:\SKILLB (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2008-02-20 07:27:29 32,071,712 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-02-20 07:24:21 -------- d-----w C:\Program Files\Firefly Media Server 2008-02-19 23:43:06 376,640 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-02-19 20:03:31 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\LimeWire 2008-02-17 16:50:42 -------- d-----w C:\Program Files\SpywareBlaster 2008-02-16 09:50:47 -------- d-----w C:\Program Files\LimeWire 2008-02-08 18:15:50 -------- d-----w C:\Program Files\DivX 2008-01-31 15:38:20 -------- d-----w C:\Program Files\Weather Watcher 2008-01-29 20:23:47 -------- d-----w C:\Program Files\iTunes 2008-01-29 19:37:37 -------- d--h--w C:\Program Files\InstallShield Installation Information 2008-01-28 07:28:02 -------- d-----w C:\Program Files\VideoLAN 2008-01-25 17:01:46 -------- d-----w C:\Program Files\Microsoft Hardware 2008-01-24 05:43:56 -------- d-----w C:\Program Files\Family Tree Maker 2005 2008-01-21 07:11:43 -------- d-----w C:\Program Files\Common Files\AOL 2008-01-18 22:18:27 -------- d-----w C:\Program Files\MFInstall 2008-01-18 14:43:49 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe 2008-01-10 05:22:54 -------- d-----w C:\Program Files\MusicBrainz Picard 2008-01-09 07:28:03 -------- d-----w C:\Program Files\RokuNSE 2008-01-06 10:51:27 -------- d-----w C:\Program Files\Lavalys 2008-01-06 10:37:16 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE 2008-01-06 10:33:35 -------- d-----w C:\Program Files\Realtek AC97 2008-01-04 21:59:04 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2008-01-04 21:58:50 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll 2008-01-04 21:58:42 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll 2008-01-04 21:58:42 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll 2008-01-04 21:57:22 81,920 -c--a-w C:\WINDOWS\system32\dpl100.dll 2008-01-04 21:57:22 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll 2008-01-04 21:57:16 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll 2008-01-04 21:57:14 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll 2008-01-04 21:57:14 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll 2008-01-04 21:57:14 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll 2008-01-04 21:57:14 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll 2008-01-04 21:57:14 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll 2008-01-04 21:57:12 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll 2008-01-04 21:57:10 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll 2008-01-04 21:57:10 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll 2008-01-04 21:57:10 682,496 ----a-w C:\WINDOWS\system32\DivX.dll 2008-01-04 21:56:48 156,992 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2008-01-04 21:56:24 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll 2008-01-04 15:05:15 -------- d-----w C:\Program Files\Kontiki 2008-01-01 23:47:19 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\TwonkyMedia 2008-01-01 16:12:21 -------- d-----w C:\Program Files\tl-it.de 2008-01-01 13:43:13 -------- d-----w C:\Program Files\BitComet 2008-01-01 13:41:34 -------- d-----w C:\Program Files\Roku Radio Snooper 2008-01-01 13:39:58 46 ----a-w C:\WINDOWS\system32\DonationCoder_rokusnooper_InstallInfo.dat 2008-01-01 13:39:46 -------- d-----w C:\Program Files\WinPcap 2008-01-01 12:31:14 -------- d-----w C:\Program Files\Musicmatch 2008-01-01 12:31:02 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\Musicmatch 2007-12-31 12:57:36 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\AutoTransfer 2007-12-25 08:58:13 -------- d-----w C:\Program Files\Diskeeper Corporation 2007-12-25 08:04:23 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\dvdcss 2007-12-25 07:41:26 -------- d-----w C:\Program Files\Elaborate Bytes 2007-12-23 23:21:55 -------- d-----w C:\Program Files\EsetOnlineScanner 2007-12-23 21:26:49 -------- d-----w C:\Program Files\RogueRemover FREE 2007-12-23 13:03:31 2,560 -c--a-w C:\WINDOWS\system32\bitcometres.dll 2007-12-23 12:59:38 -------- d-----w C:\Program Files\WordBiz 2007-12-23 12:58:53 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-12-14 20:39:02 4,212 -c-h--w C:\WINDOWS\system32\zllictbl.dat 2007-12-13 12:05:48 531,248 ----a-w C:\WINDOWS\system32\es.scr 2007-12-07 15:30:30 103,776 -c--a-w C:\WINDOWS\system32\AOLDial.dll 2007-12-04 18:38:13 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll 2007-12-04 13:04:28 837,496 -c--a-w C:\WINDOWS\system32\aswBoot.exe 2007-12-04 12:54:04 95,608 -c--a-w C:\WINDOWS\system32\AvastSS.scr ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2006-10-22 22:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}] 2007-09-28 13:30 521528 --a------ C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}] 2007-12-17 11:12 56360 --a------ C:\Program Files\Windows Live\Family Safety\fssbho.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] 2008-01-04 17:21 1548624 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] 2007-09-25 00:11 501136 --a--c--- C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] 2007-09-20 10:30 328752 --a------ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}] 2006-08-20 18:55 81920 --a--c--- C:\Program Files\Free Download Manager\iefdmcks.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 13:00] "HostManager"="C:\Program Files\Common Files\AOL\1179865871\ee\AOLSoftware.exe" [2006-11-17 13:21] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11] "IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-22 04:41] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25] "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05] "IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 15:52] "CICache"="CICache.exe" [2002-09-05 14:21 C:\WINDOWS\CICache.exe] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "LinkResolveIgnoreLinkInfo"=0 (0x0) "NoResolveSearch"=1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "LinkResolveIgnoreLinkInfo"=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 12:29] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages :\WINDOWS\syste [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard] Contents of the 'Scheduled Tasks' folder 2008-02-19 20:07:02 C:\WINDOWS\tasks\AppleSoftwareUpdate.job ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-20 07:27:48 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2008-02-20 7:28:35 C:\ComboFix2.txt ... 2008-02-20 07:25 C:\ComboFix3.txt ... 2008-02-19 21:01 --- E O F --- |