View Single Post
Old 06-26-2007, 11:21 AM   #8 (permalink)
anewton
Registered User
 
Join Date: Nov 2005
Posts: 36
OS: Windows XP


Re: Panda scan results

Combo-fix log:-

"Deb & Adam" - 2007-06-26 18:13:51 - ComboFix 07-06-26.10 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\Mark & Matt.HOME-NEWTON\Application Data\64WARNLOCKS
C:\Documents and Settings\Mark & Matt.HOME-NEWTON\Application Data\64WARNLOCKS\913A6767
C:\Documents and Settings\Mark & Matt.HOME-NEWTON\Application Data\64WARNLOCKS\FILEDARTPEAKAXIS.exe
C:\Documents and Settings\Mark & Matt.HOME-NEWTON\Application Data\64WARNLOCKS\onefastdate.exe
C:\Documents and Settings\Mark & Matt.HOME-NEWTON\Application Data\64WARNLOCKS\qcljksoe.exe
C:\Documents and Settings\Mark & Matt.HOME-NEWTON\Application Data\64WARNLOCKS\send comp bat.exe
C:\Documents and Settings\Mark & Matt.HOME-NEWTON\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\dsbr.jar-54fff5de-2309b2a3.zip
C:\WINDOWS\Tasks\A3C3CF0B91D0422F.job


((((((((((((((((((((((((( Files Created from 2007-05-26 to 2007-06-26 )))))))))))))))))))))))))))))))


2007-06-26 17:50 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-25 18:10 <DIR> d-------- C:\Deckard
2007-06-24 12:26 <DIR> d-------- C:\DOCUME~1\MARK&M~1.HOM\APPLIC~1\Comodo
2007-06-23 19:32 <DIR> d-------- C:\DOCUME~1\DEB&AD~1\APPLIC~1\Comodo
2007-06-23 19:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
2007-06-23 19:28 <DIR> d-------- C:\Program Files\Comodo
2007-06-22 21:38 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-06-22 21:08 <DIR> d-------- C:\Program Files\Lavasoft
2007-06-22 21:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-22 21:06 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-06-22 18:36 33,408 --a------ C:\WINDOWS\system32\drivers\freedom.sys
2007-06-22 18:35 <DIR> d-------- C:\Program Files\Common Files\PestPatrol
2007-06-22 18:35 <DIR> d-------- C:\Program Files\Common Files\Command Software
2007-06-22 18:13 <DIR> d-------- C:\Program Files\Virgin Broadband
2007-06-22 16:50 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-22 16:49 12,413,440 --a------ C:\avgas-setup-7.5.1.43.exe
2007-06-22 16:42 7,423,960 --a------ C:\Malicious software removal.exe
2007-06-08 21:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\fourdefydrivepart
2007-06-08 20:59 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2007-06-04 15:18 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-31 20:36 <DIR> d-------- C:\Program Files\Common Files\Nokia
2007-05-30 20:56 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-24 20:29:26 -------- d-----w C:\Program Files\Windows Defender
2007-06-24 20:10:40 -------- d-----w C:\Program Files\Messenger
2007-06-24 20:05:53 -------- d-----w C:\Program Files\iTunes
2007-06-22 19:43:22 -------- d-----w C:\Program Files\MSN Messenger
2007-06-22 17:42:17 -------- d-----w C:\DOCUME~1\DEB&AD~1\APPLIC~1\Virgin Broadband
2007-06-06 19:35:21 -------- d-----w C:\Program Files\Championship Manager 2007
2007-05-31 19:36:49 -------- d-----w C:\Program Files\Nokia
2007-05-24 13:30:49 -------- d-----w C:\Program Files\Wmf_mark
2007-05-18 19:52:14 -------- d-----w C:\Program Files\Google
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-27 18:07:48 79,384 ----a-r C:\WINDOWS\system32\avmontr.dll
2007-04-27 17:49:12 840,352 ----a-r C:\WINDOWS\system32\drivers\css-dvp.sys
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 21:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 21:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 21:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 21:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 21:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 21:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 21:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 21:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-13 14:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{3C060EA2-E6A9-4E49-A530-D4657B8C449A}=C:\Program Files\Virgin Broadband\PCguard\pkR.dll [2007-01-24 18:51]
{56071E0D-C61B-11D3-B41C-00E02927A304}=C:\Program Files\Virgin Broadband\PCguard\FBHR.dll [2007-01-24 18:51]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 04:23]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 20:33]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2001-09-04 16:31]
"Workflow"="D:\Workflow.exe" []
"Ulead Photo Express Calendar Checker"="C:\Program Files\calcheck.exe" [2004-01-12 21:40]
"Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-11-18 18:20]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-13 21:37]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-08 15:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 04:23]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Broadbandadvisor.exe"="C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-01-24 14:12]
"PCguard"="C:\Program Files\Virgin Broadband\PCguard\Rps.exe" [2007-01-24 18:53]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-06-23 19:28]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 08:56]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]


HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub

Contents of the 'Scheduled Tasks' folder
2007-06-26 16:40:52 C:\WINDOWS\tasks\MP Scheduled Scan.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-26 18:17:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-06-26 18:18:56
C:\ComboFix-quarantined-files.txt ... 2007-06-26 18:18

--- E O F ---

Can't get Kaspersky online scan to run at all.

Last edited by anewton; 06-26-2007 at 11:34 AM.
anewton is offline