((((((((((((((((((((((((( Files Created from 2007-10-25 to 2007-11-25 )))))))))))))))))))))))))))))))
.
2007-11-24 14:31 1,308,216 --a------ C:\Program Files\HiJackThis_v2.exe
2007-11-07 19:56 532,480 --a------ C:\Program Files\cwshredder.exe
2007-11-07 19:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-07 19:00 7,467,056 --a------ C:\Program Files\spybotsd15.exe
2007-11-07 18:49 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-11-07 18:49 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2007-11-07 18:48 2,566,736 --a------ C:\Program Files\spywareblastersetup351.exe
2007-11-07 18:35 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-07 18:32 <DIR> d-------- C:\WINDOWS\system32\DRVSTORE
2007-11-07 18:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-11-07 18:25 <DIR> d-------- C:\WINDOWS\LastGood(2)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-25 19:34 295,096 ----a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2007-11-25 19:34 295,096 ----a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT
2007-11-25 19:34 1,204 ----a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2007-11-25 19:34 1,204 ----a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG
2007-11-25 19:34 --------- d-----w C:\Documents and Settings\Heather\Application Data\OpenOffice.org2
2007-11-24 19:35 10,479 ----a-w C:\Program Files\hijackthis.log
2007-11-21 17:28 --------- d-----w C:\Program Files\Juno
2007-11-18 21:00 --------- d-----w C:\Program Files\Trillian
2007-11-07 23:37 --------- d-----w C:\Program Files\Ad-Aware 2007
2007-11-07 23:35 --------- d-----w C:\Program Files\Games
2007-11-07 23:35 --------- d-----w C:\Program Files\Forgotten Riddles - The Mayan Princess
2007-11-07 23:35 --------- d-----w C:\Program Files\Dream Day Honeymoon
2007-11-07 23:35 --------- d-----w C:\Program Files\bfgclient
2007-11-07 23:35 --------- d-----w C:\Documents and Settings\Heather\Application Data\HouseCall 6.6
2007-11-07 23:34 --------- d-----w C:\Program Files\FastStone Image Viewer
2007-11-07 23:34 --------- d-----w C:\Program Files\Common Files\Panda Software
2007-11-07 23:33 --------- d-----w C:\Program Files\QuickTime
2007-11-07 23:33 --------- d-----w C:\Program Files\iTunes
2007-11-07 23:33 --------- d-----w C:\Program Files\iPod
2007-11-07 23:27 --------- d-----w C:\Program Files\LexmarkX84-X85
2007-10-26 03:36 8,454,656 ------w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-23 14:44 --------- d-----w C:\Program Files\Java
2007-10-10 02:55 --------- d-----w C:\Documents and Settings\Heather\Application Data\ForgottenRiddles
2007-10-03 22:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2007-09-19 02:49 3,605,992 ----a-w C:\Program Files\FSViewerSetup32.exe
2007-09-07 12:11 63,024 ----a-w C:\WINDOWS\system32\pavipc.dll
2007-09-07 12:11 292,400 ----a-w C:\WINDOWS\system32\PavSHook.dll
2007-09-07 12:11 161,328 ----a-w C:\WINDOWS\system32\TpUtil.dll
2007-07-25 02:27 9,679,815 ----a-w C:\Program Files\vlc-0.8.6c-win32.exe
2007-07-18 01:44 20,256,064 ----a-w C:\Program Files\QuickTimeInstaller.exe
2007-06-30 23:11 17,896,352 ----a-w C:\Program Files\aaw2007.exe
2007-03-10 01:51 24,187,080 ----a-w C:\Program Files\T07nt.exe
2007-03-06 17:30 37,844,544 ----a-w C:\Program Files\iTunesSetup.exe
2007-02-25 15:35 98,554,909 ----a-w C:\Program Files\OOo_2.1.0_Win32Intel_install_en-US.exe
2007-02-24 22:46 6,006,304 ----a-w C:\Program Files\Firefox Setup 2.0.0.2.exe
2006-12-07 03:04 2,599,088 ----a-w C:\Program Files\Shockwave_Installer_Slim.exe
2006-11-30 15:14 56,558,505 ----a-w C:\Program Files\openofficeorg3.cab
2006-11-30 15:14 3,293,185 ----a-w C:\Program Files\openofficeorg4.cab
2006-11-30 15:08 15,519,065 ----a-w C:\Program Files\openofficeorg2.cab
2006-11-30 15:07 18,169,081 ----a-w C:\Program Files\openofficeorg1.cab
2006-11-30 15:05 5,294,592 ----a-w C:\Program Files\openofficeorg21.msi
2006-11-30 15:05 217 ----a-w C:\Program Files\setup.ini
2006-11-13 16:31 315,392 ----a-w C:\Program Files\setup.exe
2006-01-18 18:00 6,974,864 ----a-w C:\Program Files\serif_ph55preloader.exe
2006-01-05 21:18 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2005-12-17 20:10 36,081,152 ----a-w C:\Program Files\titan6shuk.exe
2002-03-11 09:06 1,822,520 ----a-w C:\Program Files\instmsiw.exe
2002-03-11 08:45 1,708,856 ----a-w C:\Program Files\instmsia.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-03 12:12]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 19:42]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 01:02]
"Lexmark X84-X85 Button Monitor"="C:\PROGRA~1\LEXMAR~1\ACMonitor_X84-X85.exe" [2002-08-01 14:20]
"Lexmark X84-X85 Button Manager"="C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X84-X85.exe" [2002-09-04 10:36]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-09-18 22:52]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 04:33]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe" [2005-10-31 06:20]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-09 13:03]
"APVXDWIN"="C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.exe" [2007-03-30 14:52]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 17:44]
"PPFW"="c:\program files\panda software\panda antivirus + firewall 2007\firewall\PPFW.exe" [2007-04-02 17:52]
C:\Documents and Settings\Heather\Start Menu\Programs\Startup\
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 16:45:48]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Microsoft Office.lnk - C:\Program Files\Word\Office\OSA9.EXE [1999-02-17 15:05:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 18:02 50736 C:\WINDOWS\system32\avldr.dll
R1 APPFLT;App Filter Plugin;\??\C:\WINDOWS\system32\Drivers\APPFLT.SYS
R1 DSAFLT;DSA Filter Plugin;\??\C:\WINDOWS\system32\Drivers\DSAFLT.SYS
R1 FNETMON;NetMon Filter Plugin;\??\C:\WINDOWS\system32\Drivers\fnetmon.SYS
R1 IDSFLT;Ids Filter Plugin;\??\C:\WINDOWS\system32\Drivers\IDSFLT.SYS
R1 NETFLTDI;Panda Net Driver [TDI Layer];\??\C:\WINDOWS\system32\Drivers\NETFLTDI.SYS
R1 ShldDrv;Panda File Shield Driver;\??\C:\WINDOWS\system32\DRIVERS\ShlDrv51.sys
R1 SMSFLT;SMS Filter Plugin;\??\C:\WINDOWS\system32\Drivers\SMSFLT.SYS
R1 WNMFLT;Wifi Monitor Filter Plugin;\??\C:\WINDOWS\system32\Drivers\WNMFLT.SYS
R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\Drivers\cpoint.sys
R2 PavProc;Panda Process Protection Driver;\??\C:\WINDOWS\system32\DRIVERS\PavProc.sys
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys
R3 NETIMFLT;PANDA NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\netimflt.sys
R3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\system32\PavSRK.sys
R3 PavTPK.sys;PavTPK.sys;\??\C:\WINDOWS\system32\PavTPK.sys
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-08-11 12:19:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-09-19 21:15:10 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-25 15:17:43
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-25 15:19:30
.
--- E O F ---