+ 2004-08-04 08:00:00 61,440 -c----w c:\windows\ie8\admparse.dll
+ 2004-08-04 08:00:00 99,840 -c----w c:\windows\ie8\advpack.dll
+ 2006-01-09 18:08:38 1,022,976 -c----w c:\windows\ie8\browseui.dll
+ 2004-08-04 08:00:00 35,328 -c----w c:\windows\ie8\corpol.dll
+ 2004-08-04 08:00:00 357,888 -c----w c:\windows\ie8\dxtmsft.dll
+ 2006-01-09 18:08:38 205,312 -c----w c:\windows\ie8\dxtrans.dll
+ 2004-08-04 08:00:00 38,912 -c----w c:\windows\ie8\hmmapi.dll
+ 2004-08-04 08:00:00 34,304 -c----w c:\windows\ie8\ie4uinit.exe
+ 2004-08-04 08:00:00 139,264 -c----w c:\windows\ie8\ieakeng.dll
+ 2004-08-04 08:00:00 216,576 -c----w c:\windows\ie8\ieaksie.dll
+ 2004-08-04 08:00:00 221,184 -c----w c:\windows\ie8\ieakui.dll
+ 2004-08-04 08:00:00 323,584 -c----w c:\windows\ie8\iedkcs32.dll
+ 2004-08-04 08:00:00 81,920 -c----w c:\windows\ie8\ieencode.dll
+ 2006-01-09 18:08:38 251,392 -c----w c:\windows\ie8\iepeers.dll
+ 2007-08-13 22:54:10 287,744 -c----w c:\windows\ie8\ieproxy.dll
+ 2004-08-04 08:00:00 48,640 -c----w c:\windows\ie8\iernonce.dll
+ 2004-08-04 08:00:00 62,976 -c----w c:\windows\ie8\iesetup.dll
+ 2004-08-04 08:00:00 93,184 -c----w c:\windows\ie8\iexplore.exe
+ 2004-08-04 08:00:00 35,840 -c----w c:\windows\ie8\imgutil.dll
+ 2006-01-09 18:08:38 96,256 -c----w c:\windows\ie8\inseng.dll
+ 2004-08-04 08:00:00 450,560 -c----w c:\windows\ie8\jscript.dll
+ 2004-08-04 08:00:00 15,872 -c----w c:\windows\ie8\jsproxy.dll
+ 2004-08-04 08:00:00 22,016 -c----w c:\windows\ie8\licmgr10.dll
+ 2004-08-04 08:00:00 29,184 -c----w c:\windows\ie8\mshta.exe
+ 2006-02-01 01:59:04 3,070,464 -c----w c:\windows\ie8\mshtml.dll
+ 2006-01-09 18:08:40 448,512 -c----w c:\windows\ie8\mshtmled.dll
+ 2004-08-04 08:00:00 56,832 -c----w c:\windows\ie8\mshtmler.dll
+ 2004-08-04 08:00:00 146,432 -c----w c:\windows\ie8\msls31.dll
+ 2006-01-09 18:08:40 146,432 -c----w c:\windows\ie8\msrating.dll
+ 2006-01-09 18:08:40 530,944 -c----w c:\windows\ie8\mstime.dll
+ 2004-08-04 08:00:00 96,256 -c----w c:\windows\ie8\occache.dll
+ 2006-01-09 18:08:40 39,424 -c----w c:\windows\ie8\pngfilt.dll
+ 2006-01-09 18:08:41 1,492,480 -c----w c:\windows\ie8\shdocvw.dll
+ 2006-01-09 18:08:41 474,112 -c----w c:\windows\ie8\shlwapi.dll
+ 2006-09-06 21:43:16 213,216 -c----w c:\windows\ie8\spuninst.exe
+ 2009-03-08 19:23:50 58,464 -c----w c:\windows\ie8\spuninst\iecustom.dll
+ 2009-01-07 23:20:58 231,456 -c----w c:\windows\ie8\spuninst\spuninst.exe
+ 2009-01-07 23:21:02 382,496 -c----w c:\windows\ie8\spuninst\updspapi.dll
+ 2004-08-04 08:00:00 37,888 -c----w c:\windows\ie8\url.dll
+ 2006-01-09 18:08:41 612,352 -c----w c:\windows\ie8\urlmon.dll
+ 2004-08-04 08:00:00 417,792 -c----w c:\windows\ie8\vbscript.dll
+ 2004-08-04 08:00:00 848,384 -c----w c:\windows\ie8\vgx.dll
+ 2004-08-04 08:00:00 276,480 -c----w c:\windows\ie8\webcheck.dll
+ 2006-01-09 18:08:41 658,432 -c----w c:\windows\ie8\wininet.dll
+ 2009-04-04 03:39:20 80,395 ----a-r c:\windows\Installer\{0AAA9C97-74D4-47CE-B089-0B147EF3553C}\MsblIco.Exe
+ 2009-04-04 03:38:27 62,304 ----a-r c:\windows\Installer\{F6BD194C-4190-4D73-B1B1-C48C99921BFE}\IconWlc.exe
- 2005-09-09 21:21:51 466,944 ----a-w c:\windows\system32\capicom.dll
+ 2006-07-25 23:03:42 466,944 ----a-w c:\windows\system32\capicom.dll
- 2004-08-11 08:45:04 28,672 ----a-w c:\windows\system32\dllcache\custsat.dll
+ 2006-06-03 11:40:49 33,792 ----a-w c:\windows\system32\dllcache\custsat.dll
+ 2008-10-16 19:08:58 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
- 2005-09-20 01:23:26 12,944 ----a-w c:\windows\system32\drivers\symdns.sys
+ 2007-10-01 19:48:56 12,680 ----a-w c:\windows\system32\drivers\symdns.sys
- 2005-09-20 01:23:32 109,200 ----a-w c:\windows\system32\drivers\symfw.sys
+ 2007-10-01 19:49:04 98,184 ----a-w c:\windows\system32\drivers\symfw.sys
- 2005-09-20 01:23:40 31,888 ----a-w c:\windows\system32\drivers\symids.sys
+ 2007-10-01 19:49:16 31,624 ----a-w c:\windows\system32\drivers\symids.sys
- 2005-09-20 01:23:36 27,792 ----a-w c:\windows\system32\drivers\symndis.sys
+ 2007-10-01 19:49:10 28,040 ----a-w c:\windows\system32\drivers\symndis.sys
- 2005-09-20 01:23:48 24,720 ----a-w c:\windows\system32\drivers\symredrv.sys
+ 2007-10-01 19:49:20 23,944 ----a-w c:\windows\system32\drivers\symredrv.sys
- 2005-09-20 01:23:52 196,240 ----a-w c:\windows\system32\drivers\symtdi.sys
+ 2007-10-01 19:49:26 189,320 ----a-w c:\windows\system32\drivers\symtdi.sys
- 2009-04-03 18:32:35 242,328 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-04-04 04:22:18 245,512 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-08 09:32:52 36,864 ----a-w c:\windows\system32\ieudinit.exe
+ 2009-02-03 02:07:18 240,544 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil10b.exe
+ 2009-04-04 03:51:56 89,102 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-02-25 17:55:00 24,768,960 ----a-w c:\windows\system32\MRT.exe
- 2009-04-03 18:37:49 53,684 ----a-w c:\windows\system32\perfc009.dat
+ 2009-04-04 22:47:56 57,310 ----a-w c:\windows\system32\perfc009.dat
- 2009-04-03 18:37:49 381,794 ----a-w c:\windows\system32\perfh009.dat
+ 2009-04-04 22:47:57 387,926 ----a-w c:\windows\system32\perfh009.dat
- 2005-10-12 23:12:25 14,048 ----a-w c:\windows\system32\spmsg.dll
+ 2009-01-07 23:20:58 16,928 ------w c:\windows\system32\spmsg.dll
- 2005-09-20 01:24:00 534,160 ----a-w c:\windows\system32\SymNeti.dll
+ 2007-10-01 19:49:38 542,088 ----a-w c:\windows\system32\SymNeti.dll
- 2005-09-20 01:23:58 161,424 ----a-w c:\windows\system32\SymRedir.dll
+ 2007-10-01 19:49:36 161,160 ----a-w c:\windows\system32\SymRedir.dll
- 2004-08-04 08:00:00 49,152 ----a-w c:\windows\system32\wdigest.dll
+ 2006-03-24 04:37:50 49,152 ----a-w c:\windows\system32\wdigest.dll
- 2004-08-04 08:00:00 36,864 ----a-w c:\windows\system32\wups.dll
+ 2008-10-16 19:08:58 34,328 ----a-w c:\windows\system32\wups.dll
+ 2009-01-07 23:21:04 121,856 ----a-w c:\windows\system32\xmllite.dll
- 2006-02-08 00:29:48 16,384 ----a-w c:\windows\system32\xpsp3res.dll
+ 2006-10-10 06:12:10 214,528 ----a-w c:\windows\system32\xpsp3res.dll
+ 2005-09-23 03:48:08 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-23 03:48:08 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 03:48:06 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2006-12-02 03:54:32 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-02 03:54:34 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-02 03:54:32 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2007-11-07 01:23:58 224,768 ----a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2007-11-07 06:19:34 568,832 ----a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2007-11-07 06:19:34 655,872 ----a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-31 50480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-09-17 52848]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 405504]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-29 113664]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 73728]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-10-15 66864]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-04-04 101936]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2005-08-22 231424]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2009-03-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-04-04 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Brandie.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2007-05-23 12:13]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=laptopuInternet Connection Wizard,ShellNext =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=laptop.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-04 18:16:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe??????????O????|?????? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-04-04 18:19:17
ComboFix-quarantined-files.txt 2009-04-04 23:19:14
ComboFix2.txt 2009-04-04 02:08:19
Pre-Run: 14,389,059,584 bytes free
Post-Run: 14,402,498,560 bytes free
327