cation Data\Thunderbird
2007-12-24 04:29 --------- d-----w C:\Program Files\Alwil Software
2007-12-23 22:42 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-12-23 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-23 22:41 --------- d-----w C:\Program Files\SiteAdvisor
2007-12-23 22:38 --------- d–h–r C:\Documents and Settings\Student\Application Data\yahoo!
2007-12-23 04:12 --------- d-----w C:\Program Files\Trend Micro
2007-12-22 21:01 --------- d-----w C:\Program Files\CCleaner
2007-12-21 17:59 --------- d-----w C:\Program Files\File Shredder
2007-12-21 16:41 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-21 15:57 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2007-12-21 15:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-21 00:44 --------- d-----w C:\Program Files\MSN Messenger
2007-12-21 00:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-21 00:36 --------- d-----w C:\Documents and Settings\Student\Application Data\acccore
2007-12-21 00:19 --------- d-----w C:\Program Files\AOL Search
2007-12-21 00:19 --------- d-----w C:\Program Files\AIM6
2007-12-21 00:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-12-21 00:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-21 00:18 --------- d-----w C:\Program Files\Common Files\AOL
.
<pre>
----a-w 524,288 2007-06-19 13:24:53 C:\Program Files\Thoosje Sidebar V2.0\Thoosje Sidebar .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-03 23:56 15360]
“Aim6”=“”
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2006-10-18 20:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“TrackPointSrv”=“tp4mon.exe” [2004-08-03 19:56 82432 C:\WINDOWS\system32\tp4mon.exe]
“AGRSMMSG”=“AGRSMMSG.exe” [2003-06-27 07:53 88363 C:\WINDOWS\AGRSMMSG.exe]
“vptray”=“C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe” [2003-05-21 00:21 90112]
“NWTRAY”=“NWTRAY.EXE” [2002-03-12 09:37 28672 C:\WINDOWS\system32\nwtray.exe]
“TPHOTKEY”=“C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe” [2006-05-10 14:03 94208]
“Airlink101 WLAN Monitor”=“C:\Program Files\Airlink101\Airlink101 WLAN Monitor\WLANmon.exe” [2006-10-12 18:38 958464]
“ANIWZCS2Service”=“C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe” [2006-06-29 16:34 49152]
“SiteAdvisor”=“C:\Program Files\SiteAdvisor\6253\SiteAdv.exe” [2007-12-04 16:03 36640]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 08:00 79224]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11 132496]
C:\Documents and Settings\Student\Start Menu\Programs\Startup
Thoosje Sidebar .lnk - C:\Program Files\Thoosje Sidebar V2.0\Thoosje Sidebar .exe [2007-06-19 08:24:52 524288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“CompatibleRUPSecurity”= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoWelcomeScreen”= 1 (0x1)
“NoSMMyPictures”= 1 (0x1)
“NoStartMenuMyMusic”= 1 (0x1)
“NoSMConfigurePrograms”= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
notifyf2.dll 2005-07-05 22:45 28672 C:\WINDOWS\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 2005-11-30 19:16 24576 C:\WINDOWS\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
R1 nipplpt;Novell iCapture Lpt Redirector;C:\WINDOWS\system32\drivers\nipplpt.sys [2003-02-24 16:10]
R3 AEIWL;IBM High Rate Wireless LAN MiniPCI Combo Card Driver;C:\WINDOWS\system32\DRIVERS\AEIWLNDS.sys [2002-09-23 18:16]
S3 CWEN5;Xircom Wireless Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\CWEN5.sys [2001-01-26 05:34]
S3 LucentSoftModem;Lucent Technologies Soft Modem;C:\WINDOWS\system32\DRIVERS\LTSM.sys [2001-08-17 08:28]
S3 N5SG;Airlink101 SuperG Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\N5SG.sys [2006-11-03 14:30]
S3 PCX500;Cisco Wireless LAN Adapters Driver;C:\WINDOWS\system32\DRIVERS\pcx500.sys [2004-08-03 21:06]
S3 rtl8180;Realtek RTL8180 Wireless LAN (Mini-)PCI NIC NT Driver;C:\WINDOWS\system32\DRIVERS\RTL8180.SYS [2004-04-29 00:45]
.
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-11 19:43:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
→ C:\WINDOWS\system32\tphklock.dll
→ C:\WINDOWS\system32\NavLogon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ibmpmsvc.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
.
.
Completion time: 2008-02-11 19:47:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-12 00:46:42