Thanks Gecko, Hope everything turns okey for you.
ComboFix 09-04-28.02 - RC 04/28/2009 15:32.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.956 [GMT -7:00]
Running from: c:\documents and settings\RC\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\RC\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
AV: Norton Internet Security *On-access scanning enabled* (Outdated)
FW: Norton Internet Security *disabled*
* Created a new restore point
FILE ::
c:\docume~1\RC\LOCALS~1\Temp\4677BA9B840C3280\4677BA9B840C3280
c:\windows\system32\24.tmp
c:\windows\TEMP\TMP0000002E13CA0AC35F6DED75
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-28 )))))))))))))))))))))))))))))))
.
2009-04-27 07:06 . 2009-04-27 07:06 -------- d-----w c:\documents and settings\RC\.gimp-2.6
2009-04-27 07:06 . 2009-04-27 07:06 -------- d-----w c:\documents and settings\RC\.gegl-0.0
2009-04-27 07:03 . 2009-04-27 07:03 -------- d-----w c:\program files\GIMP-2.0
2009-04-14 21:28 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-14 21:28 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-14 21:28 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-14 21:28 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-14 21:28 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 21:28 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 21:28 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-14 21:28 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-14 21:28 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 21:28 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-14 21:28 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-13 19:16 . 2009-04-13 19:18 -------- d--h--w C:\$AVG8.VAULT$
2009-04-13 10:53 . 2009-04-13 10:53 -------- d-----w c:\program files\iPod
2009-04-13 10:53 . 2009-04-13 10:53 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-13 10:53 . 2009-04-13 10:53 -------- d-----w c:\program files\iTunes
2009-04-13 10:51 . 2009-04-13 10:51 -------- d-----w c:\program files\Bonjour
2009-04-08 10:51 . 2009-04-08 18:40 -------- d-----w c:\windows\SxsCaPendDel
2009-04-08 09:39 . 2009-04-08 09:24 1340961 ----a-w C:\MGtools.exe
2009-04-08 09:11 . 2009-04-08 09:11 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-07 22:55 . 2009-04-07 22:55 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-07 22:55 . 2009-04-07 22:55 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-07 22:55 . 2009-04-07 22:55 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-07 22:54 . 2009-04-28 21:49 -------- d-----w c:\windows\system32\drivers\Avg
2009-04-07 22:54 . 2009-04-07 22:54 -------- d-----w c:\program files\AVG
2009-04-07 10:01 . 2009-04-07 10:01 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-04-07 10:00 . 2009-04-07 10:01 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-07 10:00 . 2009-04-07 10:00 -------- d-----w c:\documents and settings\RC\Application Data\SUPERAntiSpyware.com
2009-04-07 08:26 . 2009-04-07 22:54 -------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-04-07 05:48 . 2009-04-07 05:55 -------- d-----w C:\Mus27
2009-04-06 05:35 . 2009-04-06 05:35 -------- d-----w c:\program files\Remove Empty Directories
2009-04-06 04:59 . 2009-04-06 04:59 -------- d-----w c:\program files\Duplicate Music Files Finder
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 09:20 . 2005-07-27 01:13 -------- d-----w c:\program files\Warcraft III
2009-04-14 01:26 . 2005-08-25 18:16 -------- d-----w c:\program files\Free Download Manager
2009-04-13 10:53 . 2007-09-04 02:31 -------- d-----w c:\program files\Common Files\Apple
2009-04-13 10:51 . 2007-02-26 15:08 -------- d-----w c:\program files\QuickTime Alternative
2009-04-12 03:49 . 2005-07-28 09:46 96048 -c--a-w c:\documents and settings\RC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-08 09:57 . 2007-04-19 22:14 -------- d-----w c:\program files\SpywareBlaster
2009-04-08 09:56 . 2009-03-09 22:20 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-08 09:11 . 2005-07-21 03:16 -------- d-----w c:\program files\Java
2009-04-08 02:08 . 2006-08-01 20:59 -------- d-----w c:\program files\HJT
2009-04-08 01:56 . 2005-12-02 02:40 -------- d-----w c:\program files\Symantec
2009-04-08 01:12 . 2006-08-23 12:17 -------- d-----w c:\program files\PokerRoom Home Game Organizer
2009-04-08 01:12 . 2005-08-08 09:17 -------- d-----w c:\program files\DivX
2009-04-08 01:11 . 2006-01-23 14:54 -------- d-----w c:\program files\SlySoft
2009-04-08 01:10 . 2005-07-21 03:25 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-08 01:09 . 2006-03-13 05:38 -------- d-----w c:\program files\Free Audio Pack
2009-04-08 00:48 . 2005-07-21 03:19 -------- d-----w c:\program files\MUSICMATCH
2009-04-08 00:46 . 2005-08-02 00:22 -------- d-----w c:\program files\Creative
2009-04-08 00:44 . 2006-08-07 02:56 -------- d-----w c:\program files\WinISD
2009-04-08 00:43 . 2008-01-28 01:41 -------- d-----w c:\program files\WC3Banlist
2009-04-07 22:42 . 2005-12-02 02:40 -------- d-----w c:\program files\Symantec AntiVirus
2009-04-07 18:59 . 2007-04-22 05:19 -------- d-----w c:\program files\Bulent's Screen Recorder
2009-04-07 18:58 . 2005-10-23 12:59 -------- d-----w c:\program files\Full Tilt Poker
2009-04-07 18:05 . 2005-07-21 03:21 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-07 17:53 . 2007-10-30 00:38 -------- d-----w c:\program files\BitComet
2009-04-07 17:52 . 2005-07-28 04:39 -------- d-----w c:\program files\Winamp
2009-04-07 17:47 . 2005-07-21 03:20 -------- d-----w c:\program files\Jasc Software Inc
2009-04-07 17:43 . 2007-11-12 08:28 -------- d-----w c:\program files\AIM
2009-04-07 10:00 . 2008-12-20 04:13 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-06 22:32 . 2009-03-09 22:21 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 22:32 . 2009-03-09 22:21 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-01 02:35 . 2006-07-31 12:19 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-20 23:20 . 2005-07-28 05:38 78441 -c--a-w c:\windows\War3Unin.dat
2009-03-19 23:32 . 2006-09-19 23:44 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-06 14:22 . 2004-08-10 17:51 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-10 17:51 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-21 07:38 . 2007-04-22 05:19 2048 -c--a-w c:\windows\system32\Tr_sttool.dat
2009-02-20 18:09 . 2004-08-10 17:51 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2004-08-10 17:51 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-10 17:51 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2004-08-10 17:51 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-10 17:50 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2004-08-10 17:51 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2004-08-10 17:51 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2004-08-10 17:51 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-10 17:51 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-04 03:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2004-08-10 17:51 56832 ----a-w c:\windows\system32\secur32.dll
2009-01-30 09:54 . 2004-08-10 18:03 77423 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-01-13 03:27 . 2009-01-13 03:27 27976 ----a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-01-13 03:27 . 2009-01-13 03:27 126360 ----a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2009-02-26 04:28 . 2009-01-13 03:27 98712 ----a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
2008-02-04 10:07 . 2008-02-04 10:06 24 --sh--w c:\windows\SF234F3B6.tmp
2005-12-05 00:47 . 2005-08-31 04:48 56 --sh--r c:\windows\system32\21A3B98AC5.sys
2005-12-05 00:47 . 2005-08-31 04:48 1682 -csha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-04-13_18.40.55.85 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-28 21:46 . 2009-04-28 21:46 16384 c:\windows\Temp\Perflib_Perfdata_8e4.dat
+ 2005-07-27 00:33 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2005-07-27 00:33 . 2007-11-30 11:18 26488 c:\windows\system32\spupdsvc.exe
+ 2004-08-10 17:51 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-10 17:51 . 2009-04-18 00:10 72576 c:\windows\system32\perfc009.dat
- 2004-08-10 17:51 . 2009-04-11 22:14 72576 c:\windows\system32\perfc009.dat
+ 2004-08-10 18:01 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
- 2004-08-10 18:01 . 2008-04-14 00:12 91648 c:\windows\system32\mtxoci.dll
+ 2004-08-10 17:51 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2004-08-10 17:51 . 2008-04-14 00:12 66560 c:\windows\system32\mtxclu.dll
+ 2006-10-17 20:33 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
- 2006-10-17 20:33 . 2008-12-20 23:15 52224 c:\windows\system32\msfeedsbs.dll
- 2004-08-10 18:01 . 2008-04-14 00:11 58880 c:\windows\system32\msdtclog.dll
+ 2004-08-10 18:01 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
+ 2004-08-10 18:01 . 2004-08-04 10:00 19429 c:\windows\system32\MsDtc\Trace\msdtcvtr.bat
+ 2004-08-10 17:51 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 27648 c:\windows\system32\jsproxy.dll
- 2006-08-23 07:13 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
+ 2006-08-23 07:13 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
- 2004-08-10 17:51 . 2008-12-20 23:15 44544 c:\windows\system32\iernonce.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2004-08-10 17:51 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2004-08-10 17:51 . 2008-12-19 09:10 70656 c:\windows\system32\ie4uinit.exe
+ 2006-10-17 19:58 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
- 2006-10-17 19:58 . 2008-12-20 23:15 63488 c:\windows\system32\icardie.dll
+ 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll
+ 2004-08-10 17:51 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
+ 2006-05-10 05:25 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2007-05-12 08:24 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-05-12 08:24 . 2008-12-20 23:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-05-12 08:24 . 2008-12-19 09:10 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-05-12 08:24 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2004-08-10 17:51 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2006-10-17 20:00 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2006-10-17 20:00 . 2008-12-19 09:10 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2007-08-20 10:04 . 2008-12-20 23:15 63488 c:\windows\system32\dllcache\icardie.dll
+ 2007-08-20 10:04 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2009-01-30 07:16 . 2009-04-08 10:41 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-04-07 09:43 . 2009-04-07 09:43 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-04-17 09:22 . 2009-04-17 09:22 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-04-17 09:29 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-17 09:29 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-17 09:29 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-17 09:29 . 2008-04-14 00:11 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-17 09:29 . 2008-12-19 09:10 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-17 09:29 . 2008-12-20 23:15 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2008-12-05 10:28 . 2008-01-18 15:13 2247 c:\windows\ServicePackFiles\i386\tscdsbl.bat
+ 2008-12-05 10:28 . 2008-01-18 15:13 2247 c:\windows\Installer\tsclientmsitrans\tscdsbl.bat
+ 2004-08-10 17:51 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
- 2004-08-10 17:51 . 2008-04-14 00:12 354304 c:\windows\system32\winhttp.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 233472 c:\windows\system32\webcheck.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2004-08-10 18:01 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2004-08-10 18:01 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-08-10 18:01 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 105984 c:\windows\system32\url.dll
- 2004-08-10 17:51 . 2009-04-11 22:14 445370 c:\windows\system32\perfh009.dat
+ 2004-08-10 17:51 . 2009-04-18 00:10 445370 c:\windows\system32\perfh009.dat
+ 2004-08-10 17:51 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 102912 c:\windows\system32\occache.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 671232 c:\windows\system32\mstime.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 193024 c:\windows\system32\msrating.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 477696 c:\windows\system32\mshtmled.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
- 2006-10-17 20:33 . 2008-12-20 23:15 459264 c:\windows\system32\msfeeds.dll
+ 2006-10-17 20:33 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
- 2004-08-10 18:01 . 2008-04-14 00:11 161792 c:\windows\system32\msdtcuiu.dll
+ 2004-08-10 18:01 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
- 2004-08-10 18:01 . 2008-04-14 00:11 956928 c:\windows\system32\msdtctm.dll
+ 2004-08-10 18:01 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
+ 2004-08-10 18:01 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
+ 2004-08-10 17:51 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
- 2004-08-10 17:51 . 2008-04-14 00:11 989696 c:\windows\system32\kernel32.dll
+ 2006-10-17 19:57 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
- 2006-10-17 19:27 . 2008-12-20 23:15 383488 c:\windows\system32\ieapfltr.dll
+ 2006-10-17 19:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
- 2004-08-10 17:51 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
+ 2004-08-10 17:51 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 133120 c:\windows\system32\extmgr.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 826368 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-10 17:51 . 2009-03-03 00:18 826368 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
+ 2006-10-17 20:33 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
- 2006-10-17 20:33 . 2008-12-20 23:15 233472 c:\windows\system32\dllcache\webcheck.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2006-10-17 20:04 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
- 2006-10-17 20:04 . 2008-12-20 23:15 102912 c:\windows\system32\dllcache\occache.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 671232 c:\windows\system32\dllcache\mstime.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 193024 c:\windows\system32\dllcache\msrating.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-05-12 08:24 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2007-05-12 08:24 . 2008-12-20 23:15 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2006-10-17 20:04 . 2009-02-28 04:54 636072 c:\windows\system32\dllcache\iexplore.exe
+ 2007-05-12 08:24 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2006-10-17 20:01 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-05-12 08:24 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2007-05-12 08:24 . 2008-12-20 23:15 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2004-08-10 17:51 . 2008-12-19 05:23 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-10 17:51 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2004-08-10 17:50 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
- 2004-08-10 17:50 . 2008-12-20 23:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-10 17:50 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2004-08-10 17:50 . 2008-12-20 23:15 124928 c:\windows\system32\advpack.dll
- 2009-01-30 07:16 . 2009-04-08 10:41 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-04-17 09:29 . 2008-12-20 23:15 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-17 09:29 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-17 09:29 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-17 09:29 . 2008-12-20 23:15 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-17 09:29 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-17 09:29 . 2008-12-20 23:15 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-17 09:29 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 1160192 c:\windows\system32\urlmon.dll
+ 2004-08-10 17:51 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
- 2004-08-10 17:51 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2004-08-10 17:51 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2006-10-17 20:33 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
- 2006-09-06 07:01 . 2007-04-17 09:28 2455488 c:\windows\system32\ieapfltr.dat
+ 2006-09-06 07:01 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
+ 2004-08-10 17:51 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2004-08-10 17:51 . 2008-12-20 23:15 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-12-05 10:02 . 2009-02-06 11:08 2189056 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-12-05 10:02 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
- 2008-12-05 10:02 . 2008-08-14 09:33 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-12-05 10:02 . 2009-02-08 02:02 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-12-05 10:02 . 2008-08-14 09:33 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-12-05 10:02 . 2008-08-14 10:09 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-12-05 10:02 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-05-19 15:06 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2007-05-12 08:24 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2007-05-12 08:24 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
- 2007-05-12 08:24 . 2007-04-17 09:28 2455488 c:\windows\system32\dllcache\ieapfltr.dat
- 2009-01-30 07:16 . 2009-04-08 10:41 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-01-30 07:16 . 2009-04-17 09:23 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2009-01-30 07:16 . 2009-04-08 10:41 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-04-17 09:29 . 2008-12-20 23:15 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-17 09:29 . 2009-01-17 04:35 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-17 09:29 . 2008-12-20 23:15 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-17 09:29 . 2007-04-17 09:28 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2008-12-05 10:02 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-12-05 10:02 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-12-05 10:02 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-12-05 10:02 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-12-05 10:02 . 2009-02-08 02:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2008-12-05 10:02 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-12-05 10:02 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2005-07-27 00:45 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SansaDispatch"="c:\documents and settings\RC\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2008-11-15 79872]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-23 81920]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"FLMOFFICE4DMOUSE"="c:\program files\Browser Mouse\MOffice.exe" [2007-02-07 958464]
"VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"SmartDefrag"="c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2007-04-29 3996632]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-21 213936]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-07 1932568]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-08 148888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="c:\program files\QuickTime Alternative\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-12-05 1626112]
"WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2008-02-24 364544]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2006-1-12 315392]
MA111 Configuration Utility.lnk - c:\program files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe [2005-8-30 1158144]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-07 22:55 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\dlbccoms.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\xerox\\nwwia\\XrxFTPLt.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:War3
"6112:UDP"= 6112:UDP:War3a
"6346:TCP"= 6346:TCP:Limewire1
"6346:UDP"= 6346:UDP:Limewire2
"9090:TCP"= 9090:TCP:BitComet 9090 TCP
"9090:UDP"= 9090:UDP:BitComet 9090 UDP
"49152:TCP"= 49152:TCP:Bitcomet49152
"49152:UDP"= 49152:UDP:Bitcomet49152
"14226:TCP"= 14226:TCP:Emule TCP
"11223:UDP"= 11223:UDP:Emule UDP
"36877:UDP"= 36877:UDP:UTorrent36877
"36877:TCP"= 36877:TCP:UTorrent36877
R2 4677BA9B840C3280;4677BA9B840C3280; [x]
R3 MEMSWEEP2;MEMSWEEP2; [x]
R3 WlanUIB;NETGEAR 802.11b USB Driver;c:\windows\system32\DRIVERS\MA111nd5.sys [2004-09-29 666624]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-07 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-07 108552]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-07 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-07 298264]
S2 dlbc_device;dlbc_device;c:\windows\system32\dlbccoms.exe [2007-02-07 538096]
S2 GhostLpt;GhostLpt;c:\windows\system32\Drivers\GhostLpt.sys [2007-03-08 9344]
S2 LF30FS;LF30FS;c:\program files\Everstrike Software\Folder XP 3.5\LF30XP.sys [2004-11-20 101488]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e2c8002-e32b-11dc-a114-0013204dd06d}]
\Shell\AutoRun\command - h:\wd_windows_tools\WDEULA.exe
.
Contents of the 'Scheduled Tasks' folder
2009-04-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 20:34]
2009-04-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
2009-04-28 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\schedule.exe [2007-05-31 04:15]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = cdn;*.local
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uSearchURL,(Default) =
hxxp://www.google.com/keyword/%s
TCP: {D6EE5048-7244-4A3D-AF88-340C3F21B131} = 192.168.1.1
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\RC\Application Data\Mozilla\Firefox\Profiles\b0797rci.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfdm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin6.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin7.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-28 15:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(788)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(3020)
c:\windows\system32\nview.dll
c:\windows\system32\nvwddi.dll
c:\program files\Browser Mouse\MOUDL32A.DLL
.
Completion time: 2009-04-28 15:38
ComboFix-quarantined-files.txt 2009-04-28 22:38
ComboFix2.txt 2009-04-14 01:42
ComboFix3.txt 2009-04-12 04:13
Pre-Run: 12,618,797,056 bytes free
Post-Run: 12,615,712,768 bytes free
505 --- E O F --- 2009-04-28 09:29