HeComboFix 07-06-11.3 - C:\Documents and Settings\Marcia\My Documents\ComboFix.exe
"Marcia" - 2007-06-11 17:49:41 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
((((((((((((((((((((((((( Files Created from 2007-05-11 to 2007-06-11 )))))))))))))))))))))))))))))))
2007-06-11 17:41 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-11 10:01 <DIR> d-------- C:\Program Files\CCleaner
2007-06-08 15:10 <DIR> d-------- C:\DOCUME~1\Marcia\APPLIC~1\Sammsoft
2007-06-08 15:09 <DIR> d-------- C:\Program Files\Advanced Registry Optimizer
2007-06-08 11:01 <DIR> d-------- C:\Program Files\RegCure
2007-06-08 09:28 <DIR> d-------- C:\Program Files\SpywareBot
2007-06-08 09:28 <DIR> d-------- C:\DOCUME~1\Marcia\APPLIC~1\SpywareBot
2007-06-07 14:58 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-06-06 17:17 <DIR> d-------- C:\Program Files\Okidata
2007-06-06 13:38 <DIR> d-------- C:\spoolerlogs
2007-06-06 12:45 94,208 --a------ C:\WINDOWS\SYSTEM32\OPDMN024.DLL
2007-06-06 12:45 94,208 --a------ C:\WINDOWS\SYSTEM32\OPDMN024(2).DLL
2007-06-06 12:45 81,920 --a------ C:\WINDOWS\SYSTEM32\OPM02LOC.DLL
2007-06-06 12:45 81,920 --a------ C:\WINDOWS\SYSTEM32\OPM02LOC(2).DLL
2007-06-06 12:45 65,536 -ra------ C:\WINDOWS\SYSTEM32\OPUSB020.DLL
2007-06-06 12:45 57,344 --a------ C:\WINDOWS\SYSTEM32\OPSLD020.DLL
2007-06-06 12:45 57,344 --a------ C:\WINDOWS\SYSTEM32\OPSLD020(2).DLL
2007-06-06 12:45 45,056 --a------ C:\WINDOWS\SYSTEM32\OPCLB020.DLL
2007-06-06 12:45 45,056 --a------ C:\WINDOWS\SYSTEM32\OPCLB020(2).DLL
2007-06-06 12:45 40,960 --a------ C:\WINDOWS\SYSTEM32\OPDVA022.DLL
2007-06-06 12:45 40,960 --a------ C:\WINDOWS\SYSTEM32\OPDVA022(2).DLL
2007-06-05 14:09 <DIR> d-------- C:\Program Files\Starfield
2007-06-05 14:00 <DIR> d-------- C:\892afa20402f92deb408
2007-06-04 08:00 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-06-04 07:50 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\UMDF
2007-06-01 11:49 4,980,736 --a------ C:\DOCUME~1\Marcia\ntuser.dat
2007-05-29 11:07 <DIR> d-------- C:\Program Files\AdwareAlert
2007-05-29 11:07 <DIR> d-------- C:\DOCUME~1\Marcia\APPLIC~1\AdwareAlert
2007-05-18 10:25 83,536 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2007-05-18 10:25 59,984 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2007-05-18 10:25 52,304 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2007-05-18 10:25 39,248 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikfileflt.sys
2007-05-18 10:25 26,064 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2007-05-18 10:25 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-05-18 10:25 <DIR> d-------- C:\DOCUME~1\Marcia\APPLIC~1\PC Tools
2007-05-18 10:24 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
2007-06-08 17:50:48 -------- d-----w C:\Program Files\Online Services
2007-06-06 21:17:22 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-06 15:03:21 -------- d-----w C:\Program Files\VCPERS
2007-05-09 21:37:09 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-04 17:54:45 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-05-04 17:54:44 88 --sh--r C:\WINDOWS\system32\FCD902E9B3.sys
2007-04-29 20:01:02 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-04-29 20:00:49 -------- d-----w C:\Program Files\Symantec
2007-04-25 16:28:51 -------- d-----w C:\Program Files\Citrix
2007-04-23 18:04:35 -------- d-----w C:\Program Files\Intel
2007-04-23 15:35:01 -------- d-----w C:\Program Files\123R5MM
2007-04-19 19:03:54 14 ----a-w C:\AUTOEXEC.BAT
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-14 01:59:11 -------- d-----w C:\Program Files\Microsoft SQL Server
2007-04-14 01:58:44 -------- d-----w C:\Program Files\MSXML 6.0
2007-04-14 00:25:35 -------- d-----w C:\DOCUME~1\Marcia\APPLIC~1\MSN6
2007-04-06 19:03:15 617,561 ----a-w C:\F5D7230-4_US_8.01.21.bin
2007-04-05 20:23:05 65 ----a-w C:\WINDOWS\system32\BD7820N.dat
2007-04-05 19:27:36 148,466,610 ----a-w C:\7820instb.EXE
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2005-08-11 20:45]
{D5233FCD-D258-4903-89B8-FB1568E7413D}=mscoree.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"PCTVOICE"="pctspk.exe" [2001-12-11 05:09 C:\WINDOWS\SYSTEM32\pctspk.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2001-10-26 02:08]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2001-10-26 02:07]
"Act.Outlook.Service"="C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe" [2006-10-25 08:57]
"Act! Preloader"="C:\Program Files\ACT\ACT for Windows\ActSage.exe" [2006-10-25 08:52]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 17:14]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2005-01-07 17:30]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-05-18 10:35]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-09-22 11:27]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" [2007-05-10 13:16]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" [2007-06-04 10:05]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" [2007-05-10 13:16]
"wben"="C:\Program Files\Starfield\Desktop Notifier\wben.exe" [2007-05-31 10:59]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" [2007-06-04 10:05]
"AROReminder"="C:\Program Files\Advanced Registry Optimizer\ARO.exe" [2007-03-23 11:45]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\safeboot\minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\safeboot\minimal\sdcoreservice]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Camio Viewer 2000.lnk]
backup=C:\WINDOWS\pss\Camio Viewer 2000.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu.lnk]
backup=C:\WINDOWS\pss\eFax Tray Menu.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Live Menu.lnk]
backup=C:\WINDOWS\pss\Live Menu.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkvMon.exe.lnk]
backup=C:\WINDOWS\pss\NkvMon.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RitzPix E-Z Print & Share.lnk]
backup=C:\WINDOWS\pss\RitzPix E-Z Print & Share.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless-B Notebook Adapter Utility.lnk]
backup=C:\WINDOWS\pss\Wireless-B Notebook Adapter Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DadApp]
C:\Program Files\DELL\AccessDirect\dadapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon03]
C:\WINDOWS\System32\hphmon03.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeScape Media Detector]
C:\Program Files\Picasa\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\Money Express.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
Contents of the 'Scheduled Tasks' folder
2007-06-11 22:02:13 C:\WINDOWS\tasks\AdwareAlert Scheduled Scan.job
2002-04-11 01:29:30 C:\WINDOWS\tasks\ISP signup reminder 1.job
2002-04-11 01:29:31 C:\WINDOWS\tasks\ISP signup reminder 2.job
2002-04-11 01:29:31 C:\WINDOWS\tasks\ISP signup reminder 3.job
2007-06-11 22:01:32 C:\WINDOWS\tasks\RegCure Program Check.job
2007-06-08 15:01:49 C:\WINDOWS\tasks\RegCure.job
2007-06-11 22:02:13 C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
************************************************** ************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-11 18:01:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
************************************************** ************************
Completion time: 2007-06-11 18:08:01 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-11 18:07
--- E O F ---
re is the results of the COMBOFIX scan...