ComboFix 08-02-24.2 - Paul McVicker 2008-02-23 13:53:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.507 [GMT -8:00]
Running from: C:\Documents and Settings\Paul McVicker\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\MabryObj.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-24 to 2008-02-24 )))))))))))))))))))))))))))))))
.
2008-02-23 12:00 . 2008-02-23 12:44 <DIR> d----c--- C:\fixwareout
2008-02-23 11:49 . 2008-02-23 11:49 <DIR> d-------- C:\Program Files\RegCure
2008-02-23 07:47 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-19 09:26 . 2008-02-19 09:29 <DIR> d-------- C:\Program Files\QuickTime
2008-02-19 09:26 . 2008-02-19 09:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-11 09:05 . 2008-02-22 18:23 1,262 --a------ C:\WINDOWS\AADOCK32.INI
2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-28 20:14 . 2008-01-28 20:14 <DIR> d-------- C:\Temp\tmp
2008-01-28 20:14 . 2008-01-28 20:14 <DIR> d-------- C:\Temp\pre
2008-01-28 20:14 . 2008-01-28 20:14 <DIR> d-------- C:\Temp\peak
2008-01-28 20:14 . 2008-01-28 20:14 <DIR> d-------- C:\Temp\img
2008-01-28 20:14 . 2008-01-28 20:14 <DIR> d-------- C:\Temp\Alternate
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 15:47 --------- d-----w C:\Program Files\Java
2008-02-23 11:27 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-23 20:59 256 ----a-w C:\Program Files\pool.bin
2008-01-23 12:37 --------- d-----w C:\Documents and Settings\Paul McVicker\Application Data\Apple Computer
2008-01-20 12:19 --------- d-----w C:\Program Files\BadgeHelp
2008-01-20 12:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\FSQAPCSKNG
2008-01-13 12:49 3,932 -c--a-w C:\Documents and Settings\Paul McVicker\Application Data\LMLayout.dat
2008-01-13 12:49 268 ----a-w C:\Documents and Settings\Paul McVicker\Application Data\LMCPaper.dat
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-10 08:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 08:26 --------- d-----w C:\Program Files\AnyTime Deluxe
2008-01-05 23:45 --------- d-----w C:\Program Files\Apple Software Update
2008-01-05 23:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-08 05:21 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-11-07 02:49 2,629 ----a-w C:\Program Files\upgrade.log
2007-09-30 14:42 2,788,912 ----a-w C:\Program Files\LimeWireWin.exe
2007-01-24 13:54 101 ----a-w C:\Program Files\iloptcfg.cfg
2007-01-19 00:03 958,591 ----a-w C:\Program Files\Synchronize.dll
2007-01-19 00:03 389,203 ----a-w C:\Program Files\CE.dll
2007-01-19 00:03 139,264 ----a-w C:\Program Files\WebLink.dll
2007-01-19 00:03 1,609,728 ----a-w C:\Program Files\SwitchMediaCardWizard.exe
2007-01-19 00:02 884,736 ----a-w C:\Program Files\LoaderLauncher.dll
2007-01-19 00:02 585,728 ----a-w C:\Program Files\MultimediaManager.dll
2007-01-19 00:02 2,142,208 ----a-w C:\Program Files\product.dll
2007-01-19 00:02 1,212,416 ----a-w C:\Program Files\DesktopMgr.exe
2007-01-19 00:01 774,144 ----a-w C:\Program Files\rim_media_manager.exe
2007-01-19 00:01 618,634 ----a-w C:\Program Files\rim_hh.dll
2007-01-19 00:01 462,848 ----a-w C:\Program Files\backuprestore.dll
2007-01-19 00:01 352,256 ----a-w C:\Program Files\DeviceOptions.dll
2007-01-19 00:01 348,299 ----a-w C:\Program Files\rim_asci.dll
2007-01-19 00:01 270,336 ----a-w C:\Program Files\DeviceSwitch.dll
2007-01-19 00:01 229,514 ----a-w C:\Program Files\RIMCXLServer.dll
2007-01-19 00:01 11,012 ----a-w C:\Program Files\desktopapi.tlb
2007-01-19 00:01 1,605,632 ----a-w C:\Program Files\RIMShellExt.dll
2006-11-10 19:06 70,312 ----a-w C:\Program Files\BlackBerry_Desktop_Software_Help.chm
2006-10-18 16:49 49,152 ----a-w C:\Program Files\Inetwh32.dll
2006-10-18 16:49 401,408 ----a-w C:\Program Files\toc_updt.exe
2006-10-18 16:49 4,178 ----a-w C:\Program Files\conn_install.cfg
2006-10-18 16:49 39,116 ----a-w C:\Program Files\ILSYNC.HLP
2006-10-18 16:49 28,887 ----a-w C:\Program Files\DESKTOP.HLP
2006-10-18 16:49 2,506 ----a-w C:\Program Files\ConnectorToXlatorMaps.txt
2006-10-18 16:49 10,871 ----a-w C:\Program Files\desktop.cnt
2006-10-18 16:49 1,743 ----a-w C:\Program Files\ilsync.cnt
2002-07-27 00:02 153,088 ----a-w C:\Program Files\UNWISE.EXE
2002-01-18 14:52 3,932 -c----w C:\Documents and Settings\LocalService\Application Data\LMLayout.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect0]
@={D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect1]
@={8A814C29-D3CD-4F9E-9770-DF8704503ACA}
[HKEY_CLASSES_ROOT\CLSID\{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}]
2006-12-20 14:23 57344 --a------ C:\Program Files\PC Beginner Windows Tools 2007\FolderProtectShellExtension.dll
[HKEY_CLASSES_ROOT\CLSID\{8A814C29-D3CD-4F9E-9770-DF8704503ACA}]
2006-12-20 14:23 57344 --a------ C:\Program Files\PC Beginner Windows Tools 2007\FolderProtectShellExtension.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SM_IAN"="C:\Program Files\AdvancedCleaner Free\ian_monitor.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 17:17 443968]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SetupComponent"= {66c03315-6d68-4e30-812d-461342def19b} - C:\WINDOWS\Installer\{66c03315-6d68-4e30-812d-461342def19b}\SetupComponent.dll [2008-02-22 18:48 17958]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
path=
backup=
[HKLM\~\startupfolder\C:^Documents and Settings^Paul McVicker^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\Paul McVicker\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Zinio DLM"=C:\Program Files\Zinio\ZinioReader.exe /autostart
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\LMpdpsrv.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Avant Browser\\avant.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\smf\\StubInstaller.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\PROGRA~1\\ExamSoft\\SofTest\\SoftLnch.exe"=
"C:\\PROGRA~1\\ExamSoft\\SofTest\\softest.exe"= C:\\PROGRA~1\\ExamSoft\\SofTest\\SofTest.exe
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"C:\\smf\\music\\LimeWire\\LimeWire.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7:TCP"= 7:TCP:Laptop
R2 FolderProtectService;FolderProtectService;C:\Program Files\PC Beginner Windows Tools 2007\FolderProtectService.exe [2006-12-16 13:18]
R3 CALIAUD;Conexant AMC 3D Environmental Audio;C:\WINDOWS\system32\drivers\caliaud.sys [2004-02-17 16:58]
R3 CALIHALA;CALIHALA;C:\WINDOWS\system32\drivers\calihal.sys [2004-02-17 16:59]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\system32\DRIVERS\DP83815.SYS [2004-07-15 17:31]
R3 FolderProtectDriver;FolderProtectDriver;C:\Program Files\PC Beginner Windows Tools 2007\FolderProtectDriver.sys [2006-12-12 15:25]
S3 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-07 14:13]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 17:19:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-23 20:41:47 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-02-14 11:00:00 C:\WINDOWS\Tasks\RegCure.job"
- C:\RegCure[1]\RegCure\RegCure.exe
"2008-02-24 21:56:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 13:59:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SM_IAN = C:\Program Files\AdvancedCleaner Free\ian_monitor.exe??|??????????@???@????????????????|??@?????????p???????? A?3??|???|??C???@???@???????C????????|??@?????????,?????@???@?d???u)?|??@??????????)?|???|??C???@?3??|??????C???@???@?????????? A????|??????@?d??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-02-24 14:01:10
ComboFix-quarantined-files.txt 2008-02-24 22:00:48
.
2008-02-13 11:06:11 --- E O F ---