--------------- FCopy ---------------
c:\windows\system32\dllcache\beep.sys --> c:\windows\System32\drivers\beep.sys
c:\windows\ServicePackFiles\i386\explorer.exe --> c:\windows\Explorer.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_8ff0f6eb
-------\Service_ethpqnon
((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 )))))))))))))))))))))))))))))))
.
2009-10-13 19:33 . 2008-04-14 00:12 1033728 ----a-w- c:\windows\system32\dllcache\explorer.exe
2009-10-13 19:33 . 2008-04-14 00:12 1033728 ----a-w- c:\windows\Explorer.exe
2009-10-13 19:33 . 2004-08-10 10:00 4224 ----a-w- c:\windows\system32\drivers\beep.sys
2009-10-13 19:33 . 2004-08-10 10:00 4224 ----a-w- c:\windows\system32\dllcache\beep.sys
2009-10-13 02:48 . 2009-10-13 02:48 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2009-10-13 02:16 . 2009-10-13 02:16 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-12 23:31 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-12 23:31 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-10-12 04:47 . 2009-10-12 04:47 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-10-10 05:33 . 2009-10-10 05:34 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-10-10 00:53 . 2009-10-10 00:56 -------- d-----w- c:\documents and settings\Administrator\Tracing
2009-10-09 14:07 . 2009-10-09 14:07 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-10-09 14:07 . 2009-10-09 14:07 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-09-23 00:58 . 2009-10-03 06:54 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-23 00:14 . 2009-09-23 00:14 -------- d-----r- C:\MSOCache
2009-09-22 16:49 . 2009-09-23 01:16 -------- d-----w- c:\program files\a-squared Free
2009-09-22 16:48 . 2000-07-15 04:00 101888 ----a-w- c:\windows\system32\VB6STKIT.DLL
2009-09-22 16:48 . 1998-06-18 04:00 89360 ----a-w- c:\windows\system32\VB5DB.DLL
2009-09-22 16:48 . 2009-09-22 16:48 -------- d-----w- c:\program files\MCS Studios
2009-09-22 15:57 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-22 15:57 . 2009-10-03 04:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-22 15:57 . 2009-09-22 15:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-22 15:57 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-22 15:22 . 2009-09-22 15:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-09-22 15:21 . 2009-09-22 15:24 -------- d-----w- c:\program files\Sagasoft
2009-09-22 03:17 . 2009-09-22 03:17 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-09-17 04:45 . 2009-09-17 04:47 -------- d-----w- c:\windows\SxsCaPendDel
2009-09-17 04:45 . 2009-09-17 04:45 -------- d-----w- c:\program files\Microsoft
2009-09-17 04:44 . 2009-09-17 04:44 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-17 04:44 . 2009-09-17 04:45 -------- d-----w- c:\program files\Windows Live
2009-09-17 04:42 . 2009-09-17 04:42 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 19:40 . 2005-07-27 23:06 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
2009-10-13 19:40 . 2005-07-27 23:06 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
2009-10-11 21:19 . 2009-07-11 21:19 1011451 --sha-w- c:\windows\system32\rimuwuka.exe
2009-10-10 05:30 . 2009-07-10 05:30 1011570 --sha-w- c:\windows\system32\sedutodo.exe
2009-10-01 22:49 . 2009-07-01 22:49 50176 --sha-w- c:\windows\system32\tojowebo.dll
2009-09-30 21:19 . 2009-06-30 21:19 50688 --sha-w- c:\windows\system32\yinazeku.dll
2009-09-22 15:01 . 2008-10-14 02:52 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-22 03:22 . 2009-06-22 03:22 180224 --sha-w- c:\windows\system32\wimesabi.exe
2009-09-22 03:22 . 2009-06-22 03:22 44970 --sha-w- c:\windows\system32\pidokobo.exe
2009-09-09 10:50 . 2008-10-16 19:47 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-29 01:41 . 2005-12-13 16:56 -------- d-----w- c:\program files\DL_cats
2009-08-07 00:08 . 2009-08-07 00:09 67424 ----a-w- c:\windows\system32\drivers\CDAVFS.sys
2009-08-05 09:01 . 2004-08-19 20:49 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-26 20:44 . 2009-07-26 20:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 19:01 . 2004-08-19 20:49 58880 ----a-w- c:\windows\system32\atl.dll
2009-06-22 03:16 . 2009-06-22 03:16 49152 --sha-w- c:\windows\system32\zabufaki.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\System32\spool\DRIVERS\W32X86\3 ----
2005-12-21 04:17 . 2007-09-28 01:08 50908 -c-ha-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxma.GID
2005-12-13 16:59 . 2008-10-14 04:05 15856 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\lxWF2000.BUD
2005-12-13 16:59 . 2003-02-06 17:09 3460 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\lxWF2000.GPD
2005-12-13 16:59 . 2002-03-11 23:32 2560 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\LXWF2000.DLL
2005-12-13 16:57 . 2004-06-01 17:50 2038 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxsccp.cnT
2005-12-13 16:57 . 2004-11-01 20:03 248294 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxsccp.hlP
2005-12-13 16:56 . 2005-01-07 18:14 2041158 -c--a-r- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxuser.chm
2005-12-13 16:56 . 2005-01-04 16:25 4243 -c--a-r- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxtele.ini
2005-12-13 16:56 . 2004-11-09 19:27 65536 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxcfg.dll
2005-12-13 16:56 . 2005-01-10 14:56 180224 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxunst.exe
2005-12-13 16:56 . 2005-01-13 10:29 27 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxprod.ver
2005-12-13 16:56 . 2004-08-27 19:35 1748 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxprod.ini
2005-12-13 16:56 . 2005-01-20 14:46 1442 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbx.loc
2005-12-13 16:55 . 2004-12-07 21:45 53248 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxupld.exe
2005-12-13 16:55 . 2004-12-07 21:44 53248 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxtime.exe
2005-12-13 16:55 . 2004-12-07 21:43 69632 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxtime.dll
2005-12-13 16:55 . 2004-12-07 21:44 57344 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxserv.exe
2005-12-13 16:55 . 2004-12-07 21:44 53248 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxview.exe
2005-12-13 16:55 . 2004-12-07 21:44 294912 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxuldr.dll
2005-12-13 16:55 . 2004-12-07 21:43 278528 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxretv.dll
2005-12-13 16:55 . 2004-12-02 19:55 176128 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxtsfw.dll
2005-12-13 16:55 . 2004-12-03 14:16 110592 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxdrec.dll
2005-12-13 16:55 . 2004-12-07 18:51 83852 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxdpp.hlp
2005-12-13 16:55 . 2004-09-29 20:37 22444 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxceip.hlp
2005-12-13 16:55 . 2004-07-01 20:16 1643218 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxphcl.out
2005-12-13 16:55 . 2004-08-10 19:12 1959746 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxphau.out
2005-12-13 16:55 . 2004-08-06 17:16 57344 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxppx.dll
2005-12-13 16:55 . 2004-12-16 15:36 630784 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxpmui.dll
2005-12-13 16:55 . 2004-08-21 16:15 368640 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxcomx.dll
2005-12-13 16:55 . 2005-01-20 09:56 98304 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxinsr.dll
2005-12-13 16:55 . 2005-01-20 09:54 139264 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxins.dll
2005-12-13 16:55 . 2004-03-30 21:45 40960 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxvs.dll
2005-12-13 16:55 . 2004-12-16 15:29 356352 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxih.exe
2005-12-13 16:55 . 2004-12-16 15:33 368640 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxcfg.exe
2005-12-13 16:55 . 2004-12-16 15:27 114688 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxpplc.dll
2005-12-13 16:55 . 2004-12-16 15:33 401408 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxcomm.dll
2005-12-13 16:55 . 2004-12-16 15:33 483328 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxlmpm.dll
2005-12-13 16:55 . 2004-12-16 15:32 1085440 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxusb1.dll
2005-12-13 16:55 . 2004-12-16 15:33 741376 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxhbn3.dll
2005-12-13 16:55 . 2004-12-16 15:27 507904 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxhbn1.dll
2005-12-13 16:55 . 2004-12-16 15:26 462848 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxcoms.exe
2005-12-13 16:55 . 2004-12-16 15:26 139264 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxprox.dll
2005-12-13 16:55 . 2004-12-16 15:33 663552 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxcomc.dll
2005-12-13 16:55 . 2004-12-16 15:36 1146880 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxserv.dll
2005-12-13 16:55 . 2003-10-01 18:34 245760 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxsk2.dll
2005-12-13 16:55 . 2003-10-01 18:34 204800 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxsk1.dll
2005-12-13 16:55 . 2004-05-13 16:14 229376 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxsk0.dll
2005-12-13 16:55 . 2004-03-24 21:45 983101 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxGF.DLL
2005-12-13 16:55 . 2002-12-19 14:19 6841 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxeula.txt
2005-12-13 16:55 . 2004-08-10 19:12 1578218 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxaual.out
2005-12-13 16:55 . 2004-07-01 20:16 1896052 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxCLN.OUT
2005-12-13 16:55 . 2004-12-16 15:15 4096 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPCFG.DLL
2005-12-13 16:55 . 2004-12-16 15:15 73728 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPP5C.DLL
2005-12-13 16:55 . 2005-01-20 09:55 32768 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxCUR.DLL
2005-12-13 16:55 . 2005-01-20 09:53 69632 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxCU.DLL
2005-12-13 16:55 . 2005-01-20 09:56 90112 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxUPDR.DLL
2005-12-13 16:55 . 2005-01-20 09:53 73728 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxUPD.DLL
2005-12-13 16:55 . 2005-01-20 09:46 397312 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxUTIL.DLL
2005-12-13 16:55 . 2005-01-20 09:55 86016 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPSWR.DLL
2005-12-13 16:55 . 2005-01-20 09:51 368640 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPSW.DLL
2005-12-13 16:55 . 2005-01-20 09:55 122880 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxUPDB.DLL
2005-12-13 16:55 . 2005-01-20 09:55 757760 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPSWB.DLL
2005-12-13 16:55 . 2005-01-20 09:55 1990656 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPRPB.DLL
2005-12-13 16:55 . 2005-01-20 09:54 5480448 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxLPAB.DLL
2005-12-13 16:55 . 2005-01-20 09:54 471040 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxJSWB.DLL
2005-12-13 16:55 . 2005-01-20 09:54 176128 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxINSB.DLL
2005-12-13 16:55 . 2005-01-20 09:54 77824 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxCUB.DLL
2005-12-13 16:55 . 2005-01-20 09:55 90112 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPRPR.DLL
2005-12-13 16:55 . 2005-01-20 09:53 561152 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPRP.DLL
2005-12-13 16:55 . 2005-01-20 09:55 204800 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxLPAR.DLL
2005-12-13 16:55 . 2005-01-20 09:50 995328 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxLPA.DLL
2005-12-13 16:55 . 2005-01-20 09:55 135168 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxJSWR.DLL
2005-12-13 16:55 . 2005-01-20 09:47 139264 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxJSW.DLL
2005-12-13 16:55 . 2004-12-15 18:46 188416 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxPSWX.EXE
2005-12-13 16:55 . 2004-06-09 21:15 77824 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxJSWX.EXE
2005-12-13 16:55 . 2004-06-16 20:59 300 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxMA.CNT
2005-12-13 16:55 . 2004-05-28 18:48 5871 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxLPA.CNT
2005-12-13 16:55 . 2004-06-01 22:20 1593 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxDRV.CNT
2005-12-13 16:55 . 2004-05-18 20:57 7434 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxNOTE.HLP
2005-12-13 16:55 . 2005-01-07 22:05 986320 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxLPA.HLP
2005-12-13 16:55 . 2004-11-01 20:11 496313 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxDRV.HLP
2005-12-13 16:55 . 2004-12-16 15:24 295936 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxSTRN.DLL
2005-12-13 16:55 . 2004-12-16 15:14 56832 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxUI5C.DLL
2005-12-13 16:55 . 2004-10-20 13:37 114688 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxFLIB.DLL
2005-12-13 16:55 . 2004-10-20 13:37 704512 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxHPEH.DLL
2005-12-13 16:55 . 2004-10-20 13:37 147456 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxHPEP.DLL
2005-12-13 16:55 . 2004-10-20 13:37 413696 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxHPEC.DLL
2005-12-13 16:55 . 2004-12-16 18:55 539843 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxCLR4.LUT
2005-12-13 16:55 . 2004-12-22 14:20 1005912 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxCLR3.LUT
2005-12-13 16:55 . 2004-12-22 14:20 987923 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxCLR2.LUT
2005-12-13 16:55 . 2004-12-22 14:20 987923 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxCLR1.LUT
2005-12-13 16:55 . 2004-03-30 21:45 152576 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\ptzipw32.dll
2005-12-13 16:55 . 2004-03-30 21:45 73856 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\hlp256.dll
2005-12-13 16:55 . 2004-03-30 21:45 24576 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\lexgo.EXE
2005-12-13 16:55 . 2003-08-19 15:01 430080 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\LEXEDF.DLL
2005-12-13 16:55 . 2004-12-16 15:14 116736 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\dlbxDR5C.DLL
2005-07-27 23:09 . 2007-04-09 17:24 758664 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\mdigraph.dll
2005-07-27 23:09 . 2007-04-09 17:23 46472 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\mdiui.dll
2004-08-04 06:56 . 2008-04-14 00:12 373248 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\unidrv.dll
2004-08-04 06:56 . 2008-04-14 00:12 744448 ----a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\unidrvui.dll
2004-08-04 06:56 . 2007-05-15 08:08 761344 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\unires.dll
2001-07-22 01:41 . 2001-07-22 01:41 14362 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\STDNAMES.GPD
2001-07-22 00:39 . 2001-07-22 00:39 21225 -c--a-w- c:\windows\System32\spool\DRIVERS\W32X86\3\UNIDRV.HLP
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2005-05-15 332800]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-04-25 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-15 344064]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"DLBXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll" [2004-12-07 69632]
"dlbxmon.exe"="c:\program files\Dell Photo AIO Printer 962\dlbxmon.exe" [2005-01-18 425984]
"HostManager"="c:\program files\Common Files\AOL\1134621263\ee\AOLSoftware.exe" [2007-10-08 41824]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 284184]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-7-27 24576]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1134621263\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1134621263\\ee\\aim6.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
S3 CDAVFS;CDAVFS;c:\windows\system32\drivers\CDAVFS.sys [8/6/2009 8:09 PM 67424]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]
.
.
------- Supplementary Scan -------
.
mStart Page =
hxxp://www.google.comIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-CyberDefender Early Detection Center - c:\program files\CyberDefender\AntiSpyware\cdas4.exe
AddRemove-{AA63780B-DDB7-417b-8A13-E5AFBE08E807} - c:\program files\CyberDefender\cdinstx.exe
AddRemove-{AC5352DA-F4F2-4A59-A1BF-41546342746B} - c:\program files\CyberDefender\cdinstx.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-13 15:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
c:\docume~1\ADMINI~1\LOCALS~1\Temp\~DF5E9A.tmp 16384 bytes
c:\docume~1\ADMINI~1\LOCALS~1\Temp\~DF5EB6.tmp 512 bytes
scan completed successfully
hȋdden files: 2
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,44,5c,8d,03,37,4c,d2,4d,aa,20,0e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,44,5c,8d,03,37,4c,d2,4d,aa,20,0e,\
[HKEY_USERS\S-1-5-21-3835334267-1934715317-2934981272-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a9,9c,5d,7b,36,8f,3b,41,b2,20,90,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a9,9c,5d,7b,36,8f,3b,41,b2,20,90,\
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4004)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\a-squared Free\a2service.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\wanmpsvc.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\dlbxcoms.exe
.
**************************************************************************
.
Completion time: 2009-10-13 15:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-13 19:48
ComboFix2.txt 2009-10-13 19:00
ComboFix3.txt 2009-10-13 03:51
Pre-Run: 217,656,991,744 bytes free
Post-Run: 217,556,037,632 bytes free
1546 --- E O F --- 2009-09-18 16:14