((((((((((((((((((((((((( Files Created from 2007-09-23 to 2007-10-23 )))))))))))))))))))))))))))))))
.
2007-10-23 19:28 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-23 15:20 d-------- C:\Program Files\Bonjour
2007-10-23 15:10 d-------- C:\Program Files\Common Files\Macrovision Shared
2007-10-23 14:03 d-------- C:\Program Files\Trend Micro
2007-10-22 15:18 d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-22 10:20 d-------- C:\Documents and Settings\Srecica\Application Data\Grisoft
2007-10-22 10:19 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-21 21:47 d-------- C:\Program Files\Spyware Doctor
2007-10-21 18:55 525 --ahs---- C:\WINDOWS\system32\2961320727.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-23 13:20 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-23 13:05 --------- d–h–w C:\Program Files\InstallShield Installation Information
2007-10-23 13:05 --------- d-----w C:\Program Files\Macromedia
2007-10-23 13:05 --------- d-----w C:\Program Files\Common Files\Macromedia
2007-10-21 16:55 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
2007-09-18 18:31 --------- d-----w C:\Program Files\Common Files\Synacast
2007-09-18 18:31 --------- d-----w C:\Documents and Settings\Srecica\Application Data\PPMate
2007-09-18 18:01 --------- d-----w C:\Program Files\MSN Messenger
2007-09-18 16:35 32 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2007-09-18 16:34 --------- d-----w C:\Program Files\SAGEM
2007-09-18 16:34 --------- d-----w C:\Documents and Settings\Srecica\Application Data\InstallShield
2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-02 08:12 --------- d-----w C:\Program Files\Java
2007-09-02 07:47 --------- d-----w C:\Program Files\Common Files\Java
2006-11-23 11:41 0 —ha-w C:\Documents and Settings\Srecica\hpothb07.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NVMixerTray”=“C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe” [2004-06-03 20:51]
“ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2004-08-25 12:52]
“NeroCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50]
“NWEReboot”=“”
“Share-to-Web Namespace Daemon”=“C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe” [2002-04-17 10:42]
“mmtask”=“C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe” [2005-05-03 09:10]
“Logitech Hardware Abstraction Layer”=“KHALMNPR.EXE” [2005-05-20 14:46 C:\WINDOWS\KHALMNPR.Exe]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2006-12-20 16:24]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 12:06]
“Acrobat Assistant 7.0”=“C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe” [2004-12-14 02:12]
“SunJavaUpdateSched”=“C:\Program Files\Java\j2re1.4.2_15\bin\jusched.exe” [2007-05-22 17:39]
“RegistryMechanic”=“”
“!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 11:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 03:07]
“MsnMsgr”=“C:\Program Files\MSN Messenger\MsnMsgr.exe” [2007-01-19 12:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
“DisableRegistryTools”=0 (0x0)
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys
R1 UsbFltr;WayTechUSBFilterDriver;C:\WINDOWS\system32\drivers\UsbFltr.sys
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys
R3 SKYNET;B2C2 Broadband Receiver PCI Adapter;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS
S2 ClipSrvClipSrv;ClipBook ClipSrvClipSrv;C:\WINDOWS\system32\wupdsvc4.exe srv
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys
S3 AC2003;AC2003;C:\WINDOWS\system32\Drivers\AC2003.sys
S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;“C:\Program Files\MSN Messenger\usnsvc.exe”
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{5bc4da29-d530-11da-914b-806d6172696f}]
AutoRun\command - F:\Autorun.exe root.ini
.
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-23 19:35:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
.
Completion time: 2007-10-23 19:37:24 - machine was rebooted
.
— E O F —