.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-18 09:36 . 2009-05-04 19:19 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2009-06-17 16:56 . 2009-05-04 16:59 13120 ----a-w- d:\documents and settings\srdjan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-17 09:27 . 2009-05-04 19:19 38160 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2009-05-04 19:20 19096 ----a-w- d:\windows\system32\drivers\mbam.sys
2009-06-04 09:22 . 2009-06-04 09:18 -------- d-----w- d:\documents and settings\srdjan\Application Data\Winamp
2009-06-04 09:22 . 2009-06-04 09:18 -------- d-----w- d:\program files\Winamp
2009-05-05 20:36 . 2009-05-05 20:36 -------- d-----w- d:\documents and settings\srdjan\Application Data\XRay Engine
2009-05-05 20:14 . 2009-05-05 20:14 304528 ----a-w- d:\windows\system32\appdrvrem01.exe
2009-05-05 20:14 . 2009-05-05 20:14 2915944 ----a-w- d:\windows\system32\drivers\appdrv01.sys
2009-05-05 18:19 . 2009-05-05 18:19 -------- d-----w- d:\program files\DAEMON Tools Toolbar
2009-05-05 18:19 . 2009-05-05 18:19 -------- d-----w- d:\program files\DAEMON Tools Lite
2009-05-05 18:13 . 2009-05-05 18:13 717296 ----a-w- d:\windows\system32\drivers\sptd.sys
2009-05-05 18:13 . 2009-05-05 18:13 -------- d-----w- d:\documents and settings\srdjan\Application Data\DAEMON Tools
2009-05-04 19:22 . 2009-05-04 19:22 -------- d-----w- d:\program files\Deep Silver
2009-05-04 19:20 . 2009-05-04 19:20 -------- d-----w- d:\documents and settings\srdjan\Application Data\Malwarebytes
2009-05-04 19:19 . 2009-05-04 19:19 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-04 19:06 . 2009-05-03 22:16 86327 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-04 18:57 . 2009-05-04 18:07 -------- d-----w- d:\program files\VIA
2009-05-04 18:33 . 2009-05-04 18:33 0 ----a-w- d:\windows\ativpsrm.bin
2009-05-04 18:27 . 2009-05-04 18:26 -------- d-----w- d:\program files\Microsoft IntelliPoint
2009-05-04 18:24 . 2009-05-04 18:24 -------- d-----w- d:\program files\MSXML 6.0
2009-05-04 18:21 . 2009-05-04 18:20 -------- d-----w- d:\program files\ATI
2009-05-04 18:20 . 2009-05-04 18:18 -------- d-----w- d:\program files\ATI Technologies
2009-05-04 18:19 . 2009-05-04 18:18 -------- d--h--w- d:\program files\InstallShield Installation Information
2009-05-04 18:19 . 2009-05-04 18:07 -------- d-----w- d:\program files\Common Files\InstallShield
2009-05-04 18:16 . 2009-05-04 18:16 36391320 ----a-w- d:\documents and settings\srdjan\Application Data\Uniblue\DriverScanner\Download\pci_ven_1002_dev_41528_552_0_0000.exe
2009-05-04 18:14 . 2009-05-04 18:14 15743560 ----a-w- d:\documents and settings\srdjan\Application Data\Uniblue\DriverScanner\Download\acpi_pnp0f036_30_189_0.exe
2009-05-04 18:12 . 2009-05-04 18:12 4505261 ----a-w- d:\documents and settings\srdjan\Application Data\Uniblue\DriverScanner\Download\display_ntativmd316_14_10_6240.exe
2009-05-04 17:52 . 2009-05-04 17:51 -------- d-----w- d:\documents and settings\All Users\Application Data\DriverScanner
2009-05-04 17:51 . 2009-05-04 17:43 -------- dc-h--w- d:\documents and settings\All Users\Application Data\{148D8B8A-8F96-4822-81EC-D510B626B7D5}
2009-05-04 17:51 . 2009-05-04 17:51 -------- d-----w- d:\program files\Uniblue
2009-05-04 17:51 . 2009-05-04 17:51 -------- d-----w- d:\documents and settings\srdjan\Application Data\Uniblue
2009-05-03 23:19 . 2009-05-03 23:17 -------- d-----w- d:\program files\Spybot - Search & Destroy
2009-05-03 23:19 . 2009-05-03 23:17 -------- d-----w- d:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-03 22:20 . 2009-05-03 22:20 -------- d-----w- d:\program files\microsoft frontpage
2009-05-03 22:11 . 2009-05-03 22:11 21640 ----a-w- d:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="d:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"SpybotSD TeaTimer"="d:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"BitTorrent DNA"="d:\program files\DNA\btdna.exe" [2009-06-05 321344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"ATICustomerCare"="d:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2007-10-04 307200]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2009-04-22 37888]
d:\documents and settings\srdjan\Start Menu\Programs\Startup\
taksman.exe [2009-6-17 1206552]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe"=
"d:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe"=
"d:\\Program Files\\DNA\\btdna.exe"=
"d:\\Program Files\\BitTorrent\\bittorrent.exe"=
"d:\\Documents and Settings\\srdjan\\Desktop\\New Folder (3)\\bfvietnam.exe"=
R1 appdrv01;Application Driver (01);d:\windows\system32\drivers\appdrv01.sys [5/5/2009 10:14 PM 2915944]
R2 VRAID Log Service;VRAID Log Service;d:\program files\VIA\RAID\vialogsv.exe [5/4/2009 8:57 PM 52888]
S2 appdrvrem01;Application Driver Auto Removal Service (01);d:\windows\System32\appdrvrem01.exe svc --> d:\windows\System32\appdrvrem01.exe svc [?]
S3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;d:\windows\system32\drivers\fetnd6v.sys [9/22/2008 11:20 AM 43520]
.
Contents of the 'Scheduled Tasks' folder
2009-06-19 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-1677128483-725345543-1003.job
- d:\documents and settings\srdjan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-04 17:25]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SystemManger - d:\program files\Internet Explorer\iexplorer.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath -
---- FIREFOX POLICIES ----
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.enforce_same_site_origin", false);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.cache_size", 51200);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.ogg.enabled", true);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.wave.enabled", true);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("media.autoplay.enabled", true);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("dom.storage.default_quota", 5120);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
d:\program files\Mozilla Firefox 3.5 Beta 4\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
d:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
d:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
d:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
d:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
d:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
d:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
d:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
d:\program files\Mozilla Firefox 3.5 Beta 4\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-20 13:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(668)
d:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-06-20 13:13
ComboFix-quarantined-files.txt 2009-06-20 11:13
Pre-Run: 46,279,081,984 bytes free
Post-Run: 46,386,245,632 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
188
.