continuation
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-08 02:12:46 -------- d--h--w C:\Program Files\WindowsUpdate
2007-06-06 21:22:02 -------- d-----w C:\DOCUME~1\ROSAAL~1.COQ\APPLIC~1\ComcastToolbar
2007-05-15 22:38:49 -------- d-----w C:\Program Files\Yahoo!
2007-05-15 20:23:40 -------- d-----w C:\Program Files\RamBooster 2.0
2007-05-09 21:05:02 -------- d-----w C:\DOCUME~1\ROSAAL~1.COQ\APPLIC~1\Yahoo!
2007-05-09 18:57:40 -------- d-----w C:\Program Files\The Rise Of Atlantis
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-18 12:35:55 -------- d-----w C:\Program Files\ComcastToolbar
2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 03:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 03:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-10 13:27:32 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-04-10 13:27:13 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-04-10 13:10:54 -------- d-----w C:\Program Files\iWin Games
2007-04-09 15:52:50 -------- d-----w C:\Program Files\iWin.com
2007-04-09 13:26:11 -------- d-----w C:\Program Files\Oberon Media
2007-04-08 22:03:48 -------- d-----w C:\Program Files\BFG
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 10:28]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-05-14 23:47]
{08C134D3-087C-4139-A98C-3A078358DFDE}=C:\WINDOWS\system32\byxurrr.dll [2007-06-06 16:28]
{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29}=C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-07 14:21]
{58CAD45F-1435-432C-3ABC-6E148B3BE658}=C:\Program Files\Windows Media Player\lavufaw.dll []
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}=C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-01-06 11:52]
{6F282B65-56BF-4BD1-A8B2-A4449A05863D}=C:\Program Files\GamesBar\oberontb.dll [2006-07-06 14:54]
{7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED}=C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll [2006-01-19 18:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 20:33]
{B12B391A-A0A7-FB27-D97F-89ADA897299D}=C:\WINDOWS\system32\dakv.dll []
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll [2006-01-17 15:04]
{E12BFF69-38A7-406e-A8EF-2738107A7831}=C:\WINDOWS\system32\xanjvlym.dll [2007-06-07 16:46]
{F1CEB0E0-FB0E-4F79-8019-3031A22FCF7D}=C:\Program Files\WindowsUpdate\hokel.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-01-15 12:28]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-06-21 11:50]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{08C134D3-087C-4139-A98C-3A078358DFDE}"="C:\WINDOWS\system32\byxurrr.dll" [2007-06-06 16:28]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxurrr]
byxurrr.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AOL"=C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe /d locale=en-US ee://aol/browserapp
"Crao"="C:\WINDOWS\system32\CROSOF~1.NET\dexplore.exe" -vt yazb
"ccleaner"="C:\Program Files\CCleaner\ccleaner.exe" /AUTO
"msnmsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
"YSearchProtection"=C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HostManager"=C:\Program Files\Common Files\AOL\1152373256\ee\AOLSoftware.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"tgcmd"=C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"runner1"=C:\WINDOWS\retadpu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
"VTPreset"=VTPreset.exe
"Configuration Manager"=C:\WINDOWS\cfg32.exe
"oaftrobA"=C:\WINDOWS\oaftrobA.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
UxTuneUp
Contents of the 'Scheduled Tasks' folder
2007-06-08 22:15:00 C:\WINDOWS\tasks\1-Click Maintenance.job
**************************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-06-08 19:47:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-08 19:48:50 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-08 19:48
--- E O F ---