(continued)
((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.
2008-01-25 04:16 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-24 20:39 . 2008-01-24 21:31 <DIR> d-------- C:\Program Files\a-squared Free
2008-01-24 20:22 . 2008-01-25 04:24 1,740,832 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-24 20:22 . 2008-01-25 04:22 21,404 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-24 20:17 . 2007-09-06 16:14 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-01-24 20:16 . 2007-09-06 16:14 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-01-24 20:16 . 2008-01-25 04:23 353,247 --a------ C:\WINDOWS\system32\vsconfig.xml
2008-01-24 19:43 . 2008-01-24 20:17 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-01-24 19:43 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-01-24 19:43 . 2008-01-24 20:19 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-01-24 19:42 . 2008-01-24 20:35 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-01-24 13:16 . 2008-01-24 13:16 <DIR> d-------- C:\Program Files\XoftSpySE
2008-01-24 11:32 . 2007-12-04 07:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-01-24 11:32 . 2004-01-09 03:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-01-24 11:32 . 2007-12-04 06:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-01-24 11:32 . 2007-12-04 08:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-24 11:32 . 2007-12-04 08:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-24 11:32 . 2007-12-04 08:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-24 11:32 . 2007-12-04 08:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-24 11:32 . 2007-12-04 08:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-22 19:39 . 2008-01-22 19:39 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-22 19:29 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-22 15:01 . 2008-01-22 15:01 120,576 --a------ C:\WINDOWS\system32\ecccigpx.dat
2008-01-22 14:50 . 2008-01-22 14:50 <DIR> d-------- C:\WINDOWS\system32\AppCert
2008-01-22 14:50 . 2004-09-15 12:27 16,384 --a------ C:\WINDOWS\system32\u4hgogewh.exe
2008-01-22 14:49 . 2008-01-22 14:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-22 14:49 . 2008-01-22 14:49 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-14 11:17 . 2008-01-14 11:17 <DIR> d-------- C:\Program Files\Axis Communications
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 01:32 --------- d-----w C:\Program Files\Google
2008-01-23 02:04 --------- d-----w C:\Program Files\dl_cats
2008-01-22 20:54 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2007-12-20 22:46 1,482,579 ----a-w C:\Program Files\AlphaChessHistory.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE4F4014-3BF4-4CEB-B46C-3730A2340C4E}]
2007-08-07 08:30 798720 --a------ C:\Program Files\100% Free Chess Toolbar\v3.2.0.0\100%_Free_Chess_Toolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA466D75-93CC-4B04-9048-691B9206C4B6}]
C:\WINDOWS\system32\dlcxcomml.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{6F4F95AF-1647-4B72-A632-055405455423}
[HKEY_CLASSES_ROOT\clsid\{6f4f95af-1647-4b72-a632-055405455423}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{6F4F95AF-1647-4B72-A632-055405455423}"= C:\Program Files\100% Free Chess Toolbar\v3.2.0.0\100%_Free_Chess_Toolbar.dll [2007-08-07 08:30 798720]
[HKEY_CLASSES_ROOT\clsid\{6f4f95af-1647-4b72-a632-055405455423}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 02:24 20480]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 21:57 395776]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 18:48 761947]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 09:28 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 09:28 602182]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 23:30 282624 C:\WINDOWS\stsystra.exe]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-08-03 18:51 1032192]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44 81920]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2006-08-22 15:32 184320]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 06:51 286720]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 05:34 299008]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2006-06-15 04:03 307200]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 11:06 106496]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00 79224]
"DLCXCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 10:17 106496]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-11-10 11:52 34832]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 18:28:28 622653]
Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-12-12 04:52:29 7168]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-12 04:48:16 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-06-11 03:25 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-12-12 05:00 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\u4hgogewh]
--a------ 2004-09-15 12:27 16384 C:\WINDOWS\system32\u4hgogewh.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\sessionmanager\appcertdlls]
appsecdll REG_EXPAND_SZ C:\WINDOWS\system32\AppCert\wsil32.dll
R3 dlcx_device;dlcx_device;C:\WINDOWS\system32\dlcxcoms.exe [2006-05-18 14:36]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 02:34:10 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-25 10:23:31 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-01-24 19:30:52 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-25 04:24:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-25 4:26:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-25 10:26:36
.
2008-01-18 22:52:57 --- E O F ---