FindAWF Report:
Find AWF report by noahdfear ©2006
Version 1.40
The current date is: Fri 10/26/2007
The current time is: 21:45:04.96
bak folders found
~~~~~~~~~~~
Directory of C:\PROGRA~1\QUICKT~1\BAK
03/18/2006 07:04 PM 98,304 qttask.exe
1 File(s) 98,304 bytes
Directory of C:\PROGRA~1\SYMANT~1\BAK
11/15/2005 01:28 PM 85,744 VPTray.exe
1 File(s) 85,744 bytes
Directory of C:\WINDOWS\EHOME\BAK
08/10/2004 05:04 AM 59,392 ehtray.exe
1 File(s) 59,392 bytes
Directory of C:\WINDOWS\SYSTEM32\BAK
08/10/2004 07:00 AM 15,360 ctfmon.exe
1 File(s) 15,360 bytes
Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK
10/04/2005 12:42 PM 48,752 ccApp.exe
1 File(s) 48,752 bytes
Directory of C:\PROGRA~1\MICROS~2\KEYBOARD\BAK
03/21/2002 11:41 PM 94,208 type32.exe
1 File(s) 94,208 bytes
Directory of C:\PROGRA~1\SCANSOFT\OMNIPA~1.0\BAK
05/08/2003 11:00 AM 49,152 OpwareSE2.exe
1 File(s) 49,152 bytes
Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
05/11/2007 03:06 AM 40,048 Reader_sl.exe
1 File(s) 40,048 bytes
Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK
03/10/2007 02:27 PM 185,896 realsched.exe
1 File(s) 185,896 bytes
Directory of C:\PROGRA~1\ROXIO\EASYME~1\DRAGTO~1\BAK
09/25/2004 02:37 AM 1,691,648 DrgToDsc.exe
1 File(s) 1,691,648 bytes
Directory of C:\PROGRA~1\ADOBE\PHOTOS~1\3.2\APPS\BAK
03/09/2007 11:09 AM 63,712 apdproxy.exe
1 File(s) 63,712 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
98304 Mar 18 2006 "C:\Program Files\QuickTime\qttask.exe"
98304 Mar 18 2006 "C:\Program Files\QuickTime\bak\qttask.exe"
85744 Nov 15 2005 "C:\Program Files\Symantec AntiVirus\VPTray.exe"
85744 Nov 15 2005 "C:\Program Files\Symantec AntiVirus\bak\VPTray.exe"
59392 Aug 10 2004 "C:\WINDOWS\ehome\ehtray.exe"
59392 Aug 10 2004 "C:\WINDOWS\ehome\bak\ehtray.exe"
15360 Aug 10 2004 "C:\WINDOWS\system32\ctfmon.exe"
15360 Aug 10 2004 "C:\WINDOWS\system32\bak\ctfmon.exe"
48752 Oct 4 2005 "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
48752 Oct 4 2005 "C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe"
94208 Mar 21 2002 "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
94208 Mar 21 2002 "C:\Program Files\Microsoft Hardware\Keyboard\bak\type32.exe"
49152 May 8 2003 "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
49152 May 8 2003 "C:\Program Files\ScanSoft\OmniPageSE2.0\bak\OpwareSE2.exe"
40048 May 11 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
40048 May 11 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
28672 May 24 2004 "C:\Program Files\Autodesk\Inventor Professional 9\Stress Analysis\AISOL\CAD Integration\ReaderHostU.exe"
185896 Mar 10 2007 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
185896 Mar 10 2007 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
1691648 Sep 25 2004 "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
1691648 Sep 25 2004 "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\bak\DrgToDsc.exe"
63712 Mar 9 2007 "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
63712 Mar 9 2007 "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak\apdproxy.exe"
end of report
****ComboFix Report****
ComboFix 07-10-26.4 - Ben Murphy 2007-10-26 21:41:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.693 [GMT -5:00]
Running from: C:\Documents and Settings\Ben Murphy\My Documents\Downloaded Setups\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\matrix.dat
.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.
2007-10-26 21:40 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-26 19:09 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-26 19:09 <DIR> d-------- C:\WINDOWS\LastGood
2007-10-26 19:09 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2007-10-25 20:49 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-10-25 20:47 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-10-25 19:56 <DIR> d-------- C:\Program Files\Windows Defender
2007-10-16 20:12 <DIR> d-------- C:\Documents and Settings\Ben Murphy\Application Data\PlayFirst
2007-10-03 21:34 <DIR> d-------- C:\WINDOWS\system32\bak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 02:38 --------- d-----w C:\Program Files\Symantec AntiVirus
2007-10-27 02:38 --------- d-----w C:\Program Files\QuickTime
2007-10-27 02:38 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-10-26 03:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-26 03:10 --------- d-----w C:\Program Files\Google
2007-10-26 02:13 49,152 ----a-w C:\WINDOWS\system32\niSvcLoc.exe
2007-10-04 22:47 --------- d-----w C:\Documents and Settings\Ben Murphy\Application Data\Canon
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-19 02:31 92,064 ----a-w C:\Documents and Settings\Ben Murphy\mqdmmdm.sys
2007-08-19 02:31 9,232 ----a-w C:\Documents and Settings\Ben Murphy\mqdmmdfl.sys
2007-08-19 02:31 79,328 ----a-w C:\Documents and Settings\Ben Murphy\mqdmserd.sys
2007-08-19 02:31 66,656 ----a-w C:\Documents and Settings\Ben Murphy\mqdmbus.sys
2007-08-19 02:31 6,208 ----a-w C:\Documents and Settings\Ben Murphy\mqdmcmnt.sys
2007-08-19 02:31 5,936 ----a-w C:\Documents and Settings\Ben Murphy\mqdmwhnt.sys
2007-08-19 02:31 4,048 ----a-w C:\Documents and Settings\Ben Murphy\mqdmcr.sys
2007-08-19 02:31 25,600 ----a-w C:\Documents and Settings\Ben Murphy\usbsermptxp.sys
2007-08-19 02:31 22,768 ----a-w C:\Documents and Settings\Ben Murphy\usbsermpt.sys
2007-07-31 00:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 00:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 00:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 00:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 00:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 00:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 00:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 00:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 63,712 2007-03-09 16:09:58 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\bak\apdproxy.exe
----a-w 63,712 2007-03-09 16:09:58 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
----a-w 40,048 2007-05-11 08:06:32 C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
----a-w 40,048 2007-05-11 08:06:32 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
----a-w 185,896 2007-03-10 19:27:08 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 185,896 2007-03-10 19:27:08 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
----a-w 48,752 2005-10-04 17:42:40 C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe
----a-w 48,752 2005-10-04 17:42:40 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
----a-w 94,208 2002-03-22 04:41:56 C:\Program Files\Microsoft Hardware\Keyboard\bak\type32.exe
----a-w 94,208 2002-03-22 04:41:56 C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
----a-w 98,304 2006-03-19 00:04:13 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 98,304 2006-03-19 00:04:13 C:\Program Files\QuickTime\qttask.exe
----a-w 1,691,648 2004-09-25 07:37:42 C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\bak\DrgToDsc.exe
----a-w 1,691,648 2004-09-25 07:37:42 C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
----a-w 49,152 2003-05-08 16:00:58 C:\Program Files\ScanSoft\OmniPageSE2.0\bak\OpwareSE2.exe
----a-w 49,152 2003-05-08 16:00:58 C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
----a-w 85,744 2005-11-15 18:28:04 C:\Program Files\Symantec AntiVirus\bak\VPTray.exe
----a-w 85,744 2005-11-15 18:28:04 C:\Program Files\Symantec AntiVirus\VPTray.exe
----a-w 59,392 2004-08-10 10:04:42 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 59,392 2004-08-10 10:04:42 C:\WINDOWS\ehome\ehtray.exe
----a-w 15,360 2004-08-10 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-10 12:00:00 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 05:04]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 02:47 C:\WINDOWS\SOUNDMAN.EXE]
"USRpdA"="C:\WINDOWS\SYSTEM32\USRmlnkA.exe" [2004-08-10 07:00]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"Shockwave Updater"=C:\WINDOWS\system32\Macromed\SHOCKW~1\SWHELP~1.EXE -Update -1020022 -iexplore.exe7.0
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys
R3 USRpdA;U.S. Robotics 56K PCI Faxmodem Driver;C:\WINDOWS\system32\DRIVERS\USRpdA.sys
S3 AC2003;AC2003;C:\WINDOWS\system32\Drivers\AC2003.sys
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 09:00:25 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-26 21:42:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-26 21:43:24
.
--- E O F ---
benbob