ComboFix 09-11-01.04 - Administrator 11/02/2009 20:29.26.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.541 [GMT -5:00]
Running from: c:\documents and settings\Administrator\My Documents\commy.exe
Command switches used :: c:\documents and settings\Administrator\My Documents\CFScript.txt
FILE ::
"c:\documents and settings\ADMINISTRATOR\LOCAL SETTINGS\Temp\aswArKrn.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\msdownld.tmp
.
((((((((((((((((((((((((( Files Created from 2009-10-03 to 2009-11-03 )))))))))))))))))))))))))))))))
.
2009-11-02 08:02 . 2009-11-02 08:04 -------- d-----w- c:\windows\system32\Adobe
2009-11-02 05:53 . 2005-04-25 18:28 871040 ----a-w- c:\windows\system32\drivers\iastor.sys
2009-11-02 05:53 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-11-02 05:53 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-01 07:46 . 2009-11-01 07:46 102032 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-01 07:19 . 2009-11-01 07:19 -------- d-----w- c:\program files\Microsoft IntelliPoint
2009-11-01 01:37 . 2009-11-01 07:46 -------- d-----w- c:\windows\system32\XPSViewer
2009-11-01 01:37 . 2009-11-01 01:37 -------- d-----w- c:\program files\MSBuild
2009-11-01 01:37 . 2009-11-01 01:37 -------- d-----w- c:\program files\Reference Assemblies
2009-10-30 09:46 . 2008-04-15 15:17 295424 ------w- c:\windows\system32\dllcache\termsrv.dll
2009-10-30 06:38 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-10-30 06:38 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-10-30 06:38 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-10-30 06:38 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-10-30 06:38 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-10-30 06:38 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-10-30 06:38 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-10-29 22:01 . 2009-10-29 22:01 -------- dc-h--w- c:\windows\ie8
2009-10-29 21:39 . 2009-10-29 21:39 -------- d-----w- c:\windows\Logs
2009-10-29 07:27 . 2009-10-29 07:27 -------- d-----w- c:\program files\Disney
2009-10-29 04:26 . 2009-10-29 04:26 -------- d-----w- c:\program files\MSXML 6.0
2009-10-29 01:24 . 2009-10-29 01:24 -------- d-----w- c:\program files\Alwil Software
2009-10-28 19:57 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-28 19:57 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-10-28 03:37 . 2009-10-28 03:37 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Navnet_Solutions
2009-10-28 03:17 . 2009-10-28 03:44 -------- d-----w- c:\program files\NavNet
2009-10-27 22:42 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-27 22:42 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-27 19:11 . 2009-10-27 19:11 0 ----a-r- c:\windows\win32k.sys
2009-10-22 10:39 . 2009-10-22 10:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\Viewpoint
2009-10-19 17:06 . 2009-10-19 17:06 223232 ------w- c:\windows\system32\wksprt.exe
2009-10-19 17:06 . 2009-10-19 17:06 223232 ------w- c:\windows\system32\dllcache\wksprt.exe
2009-10-19 17:06 . 2009-10-19 17:06 46080 ------w- c:\windows\system32\TSWbPrxy.exe
2009-10-19 17:06 . 2009-10-19 17:06 46080 ------w- c:\windows\system32\dllcache\TSWbPrxy.exe
2009-10-19 17:06 . 2009-10-19 17:06 36864 ------w- c:\windows\system32\dllcache\tsgQec.dll
2009-10-19 17:06 . 2009-10-19 17:06 12800 ------w- c:\windows\system32\wksprtPS.dll
2009-10-19 17:06 . 2009-10-19 17:06 12800 ------w- c:\windows\system32\dllcache\wksprtPS.dll
2009-10-19 17:06 . 2009-10-19 17:06 1033728 ------w- c:\windows\system32\dllcache\mstsc.exe
2009-10-19 17:06 . 2009-10-19 17:06 44544 ------w- c:\windows\system32\MsRdpWebAccess.dll
2009-10-19 17:06 . 2009-10-19 17:06 44544 ------w- c:\windows\system32\dllcache\MsRdpWebAccess.dll
2009-10-19 17:06 . 2009-10-19 17:06 130560 ------w- c:\windows\system32\dllcache\aaclient.dll
2009-10-16 00:13 . 2009-10-16 00:13 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Help
2009-10-15 23:59 . 2009-10-15 23:59 -------- d-----w- c:\documents and settings\Administrator\Application Data\Leadertech
2009-10-15 01:05 . 2009-10-15 02:07 -------- d-----w- c:\program files\Softick
2009-10-13 23:13 . 2009-11-01 22:43 35904 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-13 19:46 . 2009-10-13 19:46 -------- d--h--w- c:\documents and settings\All Users\Application Data\GTek
2009-10-13 19:45 . 2009-10-13 19:45 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AOL
2009-10-13 19:33 . 2008-04-14 00:12 1033728 ----a-w- c:\windows\system32\dllcache\explorer.exe
2009-10-13 19:33 . 2008-04-14 00:12 1033728 ------w- c:\windows\Explorer.exe
2009-10-13 19:33 . 2004-08-10 10:00 4224 ----a-w- c:\windows\system32\dllcache\beep.sys
2009-10-13 19:33 . 2004-08-10 10:00 4224 ------w- c:\windows\system32\drivers\beep.sys
2009-10-13 02:48 . 2009-10-13 02:48 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2009-10-13 02:16 . 2009-10-13 02:16 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-12 04:47 . 2009-10-12 04:47 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-10-10 05:33 . 2009-10-15 23:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-10-10 00:53 . 2009-11-03 01:23 -------- d-----w- c:\documents and settings\Administrator\Tracing
2009-10-09 14:07 . 2009-10-09 14:07 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-10-09 14:07 . 2009-10-09 14:07 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-03 00:38 . 2005-07-27 23:06 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
2009-11-03 00:38 . 2005-07-27 23:06 384 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
2009-10-29 07:24 . 2004-08-19 21:20 -------- d-----w- c:\program files\RGB
2009-10-27 22:42 . 2009-09-22 15:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-19 17:06 . 2008-10-14 03:14 36864 ------w- c:\windows\system32\tsgQec.dll
2009-10-19 17:06 . 2004-08-19 21:01 1033728 ----a-w- c:\windows\system32\mstsc.exe
2009-10-19 17:06 . 2004-08-19 21:01 2689024 ----a-w- c:\windows\system32\mstscax.dll
2009-10-19 17:06 . 2008-10-14 03:10 130560 ------w- c:\windows\system32\aaclient.dll
2009-10-16 00:15 . 2005-12-13 16:56 -------- d-----w- c:\program files\DL_cats
2009-10-13 21:39 . 2005-07-27 23:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\Jasc Software Inc
2009-10-03 06:54 . 2009-09-23 00:58 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-22 16:48 . 2009-09-22 16:48 -------- d-----w- c:\program files\MCS Studios
2009-09-22 15:57 . 2009-09-22 15:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-22 15:24 . 2009-09-22 15:21 -------- d-----w- c:\program files\Sagasoft
2009-09-22 15:01 . 2008-10-14 02:52 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-17 04:45 . 2009-09-17 04:45 -------- d-----w- c:\program files\Microsoft
2009-09-17 04:45 . 2009-09-17 04:44 -------- d-----w- c:\program files\Windows Live
2009-09-17 04:44 . 2009-09-17 04:44 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-17 04:42 . 2009-09-17 04:42 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-11 14:18 . 2004-08-19 20:49 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 10:50 . 2008-10-16 19:47 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-04 21:44 . 2009-10-29 21:41 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-09-04 21:44 . 2009-10-29 21:41 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-09-04 21:44 . 2009-10-29 21:41 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 21:29 . 2009-10-29 21:41 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-09-04 21:29 . 2009-10-29 21:41 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-09-04 21:29 . 2009-10-29 21:41 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 21:29 . 2009-10-29 21:41 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 21:29 . 2009-10-29 21:41 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-09-04 21:03 . 2004-08-19 20:49 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-19 20:49 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-19 20:50 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-07 00:08 . 2009-08-07 00:09 67424 ----a-w- c:\windows\system32\drivers\CDAVFS.sys
2009-08-06 23:24 . 2004-08-19 21:04 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2004-08-19 21:04 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2005-05-26 10:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2004-08-19 21:04 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2004-08-19 21:04 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2004-08-19 20:49 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2004-08-19 21:04 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2005-12-11 04:44 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 23:23 . 2005-12-11 04:44 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 23:23 . 2004-08-19 21:04 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-19 20:49 204800 ----a-w- c:\windows\system32\mswebdvd.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-11-02_06.01.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-07-27 23:06 . 2007-04-09 17:21 22528 c:\windows\system32\sfman32.dll
+ 2009-11-03 00:35 . 2004-08-04 02:54 53932 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctdaught.dat
+ 2009-11-03 00:35 . 2008-04-14 00:12 23552 c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\wdmaud.drv
+ 2009-11-03 00:35 . 2008-04-13 18:45 49408 c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\stream.sys
+ 2009-11-03 00:35 . 2008-04-13 18:45 60160 c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\drmk.sys
+ 2009-11-03 00:35 . 2001-08-18 00:35 36864 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Common\sfman32.dll
+ 2009-11-03 00:35 . 2003-11-14 04:54 65536 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Common\a3d.dll
+ 2005-07-27 23:06 . 2007-04-09 17:21 48128 c:\windows\system32\regplib.exe
+ 2007-04-09 17:32 . 2007-04-09 17:32 38400 c:\windows\system32\readreg.exe
+ 2007-04-09 17:32 . 2007-04-09 17:32 37888 c:\windows\system32\psconv.exe
+ 2005-07-27 23:06 . 2007-04-09 17:21 81920 c:\windows\system32\piaproxy.dll
+ 2009-07-16 11:00 . 2009-07-16 11:00 98304 c:\windows\system32\Macromed\Shockwave 10\SwOnce.dll
+ 2009-07-16 11:00 . 2009-07-16 11:00 86016 c:\windows\system32\Macromed\Shockwave 10\SwMenuX.dll
+ 2009-07-16 11:00 . 2009-07-16 11:00 77824 c:\windows\system32\Macromed\Shockwave 10\SwInit.exe
+ 2009-07-16 11:00 . 2009-07-16 11:00 24576 c:\windows\system32\Macromed\Shockwave 10\DynaPlayer.dll
+ 2009-03-16 08:59 . 2009-03-16 08:59 53248 c:\windows\system32\Macromed\Common\SwSupport.dll
+ 2005-07-27 23:06 . 2007-04-09 17:19 10240 c:\windows\system32\killapps.exe
+ 2007-04-09 17:33 . 2007-04-09 17:33 11776 c:\windows\system32\inres.dll
- 2005-07-27 23:06 . 2001-07-11 20:51 77824 c:\windows\system32\EAXAC3.DLL
+ 2005-07-27 23:06 . 2001-07-11 07:51 77824 c:\windows\system32\eaxac3.dll
- 2004-08-04 04:08 . 2008-04-13 18:45 49408 c:\windows\system32\drivers\stream.sys
+ 2004-08-04 04:08 . 2008-04-13 19:45 49408 c:\windows\system32\drivers\stream.sys
+ 2005-07-27 23:06 . 2007-04-10 09:32 16168 c:\windows\system32\drivers\pfmodnt.sys
+ 2005-07-27 23:06 . 2007-04-10 09:28 92968 c:\windows\system32\drivers\emupia2k.sys
- 2005-07-27 22:49 . 2008-04-13 18:45 60160 c:\windows\system32\drivers\drmk.sys
+ 2005-07-27 22:49 . 2008-04-13 19:45 60160 c:\windows\system32\drivers\drmk.sys
+ 2005-07-27 23:06 . 2007-04-10 09:25 14632 c:\windows\system32\drivers\ctprxy2k.sys
+ 2004-08-04 04:08 . 2008-04-13 19:45 49408 c:\windows\system32\dllcache\stream.sys
+ 2005-07-27 22:49 . 2008-04-13 19:45 60160 c:\windows\system32\dllcache\drmk.sys
+ 2005-07-27 23:06 . 2007-04-09 17:32 34816 c:\windows\system32\dllcache\a3d.dll
+ 2007-04-09 17:19 . 2007-04-09 17:19 48640 c:\windows\system32\devreg.dll
+ 2007-04-09 17:19 . 2007-04-09 17:19 26783 c:\windows\system32\Data\ctd20x.dat
+ 2007-04-09 17:32 . 2007-04-09 17:32 46592 c:\windows\system32\CTxfiSpk.dll
+ 2007-04-09 17:29 . 2007-04-09 17:29 43520 c:\windows\system32\Ctxfireg.exe
+ 2007-04-09 17:32 . 2007-04-09 17:32 19968 c:\windows\system32\Ctxfihlp.exe
+ 2007-04-09 17:32 . 2007-04-09 17:32 35840 c:\windows\system32\CTxfiBtn.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 69632 c:\windows\system32\ctthxcal.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 45568 c:\windows\system32\ctspkhlp.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 78336 c:\windows\system32\ctscal.dll
+ 2006-11-14 14:01 . 2006-11-14 14:01 58104 c:\windows\system32\ctpxinst.exe
+ 2007-04-09 16:25 . 2007-04-09 16:25 45568 c:\windows\system32\ctppld.dll
+ 2007-04-09 17:32 . 2007-04-09 17:32 56832 c:\windows\system32\CTpcmcia.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 12800 c:\windows\system32\ctmmep.dll
+ 2005-06-16 15:17 . 2005-06-16 15:17 71680 c:\windows\system32\ctmmactl.dll
+ 2007-04-12 13:10 . 2007-04-12 13:10 66816 c:\windows\system32\CTHWIUT.DLL
+ 2005-07-27 23:06 . 2007-04-09 17:32 19456 c:\windows\system32\CtHelper.exe
+ 2007-04-12 13:10 . 2007-04-12 13:10 94976 c:\windows\system32\CTERFXFX.DLL
+ 2007-04-09 17:22 . 2007-04-09 17:22 50176 c:\windows\system32\ctedasio.dll
+ 2005-07-27 23:06 . 2007-04-09 17:22 76800 c:\windows\system32\ctdproxy.dll
+ 2007-04-09 17:24 . 2007-04-09 17:24 46273 c:\windows\system32\ctdnlstr.dat
+ 2007-04-09 17:32 . 2007-04-09 17:32 10240 c:\windows\system32\ctdcres.dll
+ 2005-07-27 23:06 . 2007-04-09 17:19 53932 c:\windows\system32\ctdaught.dat
- 2005-07-27 23:06 . 2004-08-04 02:54 53932 c:\windows\system32\ctdaught.dat
+ 2007-04-09 17:33 . 2007-04-09 17:33 86016 c:\windows\system32\ctcoinst.dll
+ 2007-04-09 17:33 . 2007-04-09 17:33 43520 c:\windows\system32\CTBurst.dll
+ 2005-07-27 23:06 . 2007-04-09 17:22 79872 c:\windows\system32\ctasio.dll
+ 2007-04-09 17:29 . 2007-04-09 17:29 10752 c:\windows\system32\Ct20xspi.dll
+ 2005-07-27 23:06 . 2007-04-18 13:59 98600 c:\windows\system32\COMMONFX.DLL
+ 2009-11-02 08:03 . 2009-11-02 08:03 87618 c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
+ 2009-07-31 13:26 . 2009-07-31 13:26 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2009-07-31 12:54 . 2009-07-31 12:54 79488 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2009-07-31 13:42 . 2009-07-31 13:42 67000 c:\windows\system32\Adobe\Director\SWDNLD.EXE
+ 2007-04-09 16:25 . 2007-04-09 16:25 48400 c:\windows\system32\AddCat.exe
+ 2005-07-27 23:06 . 2007-04-09 17:32 27648 c:\windows\system32\ac3api.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 34816 c:\windows\system32\a3d.dll
+ 2009-11-03 00:35 . 2004-08-07 03:29 6656 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\pfmodnt.sys
+ 2009-11-03 00:35 . 2004-07-13 20:11 6096 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctprxy2k.sys
+ 2009-11-03 00:35 . 2008-04-14 00:11 4096 c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\ksuser.dll
+ 2007-04-09 17:19 . 2007-04-09 17:19 5120 c:\windows\system32\enlocstr.exe
+ 2007-04-09 17:19 . 2007-04-09 17:19 2091 c:\windows\system32\Data\cts20x.dat
+ 2007-04-09 17:32 . 2007-04-09 17:32 9216 c:\windows\system32\ctpres.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 8704 c:\windows\system32\ctagent.dll
+ 2009-07-31 13:28 . 2009-07-31 13:28 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2005-07-27 23:06 . 2007-04-09 17:21 130048 c:\windows\system32\sfms32.dll
+ 2009-11-03 00:35 . 2004-07-13 20:15 148432 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\haP16v2k.sys
+ 2009-11-03 00:35 . 2004-08-13 01:40 904752 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ha10kx2k.sys
+ 2009-11-03 00:35 . 2004-07-13 20:13 145488 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\emupia2k.sys
+ 2009-11-03 00:35 . 2004-07-13 20:12 130288 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctsfm2k.sys
+ 2009-11-03 00:35 . 2004-08-13 01:52 264466 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctsbas2w.dat
+ 2009-11-03 00:35 . 2004-07-13 20:11 178672 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctoss2k.sys
+ 2009-11-03 00:35 . 2003-11-13 07:11 333600 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctdvda2k.sys
+ 2009-11-03 00:35 . 2003-11-26 23:29 127226 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctdlang.dat
+ 2009-11-03 00:35 . 2004-08-13 01:52 140643 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctbas2w.dat
+ 2009-11-03 00:35 . 2004-08-06 20:43 366384 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctaud2k.sys
+ 2009-11-03 00:35 . 2004-07-13 20:09 645360 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Win2K_XP\ctac32k.sys
+ 2009-11-03 00:35 . 2008-04-13 19:19 146048 c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\portcls.sys
+ 2009-11-03 00:35 . 2008-04-13 19:16 141056 c:\windows\system32\ReinstallBackups\0018\DriverFiles\i386\ks.sys
+ 2009-11-03 00:35 . 2003-11-14 05:04 606208 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Common\ctsblfx.dll
+ 2009-11-03 00:35 . 2004-07-13 19:53 585728 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Common\ctaudfx.dll
+ 2009-11-03 00:35 . 2003-11-14 05:02 114688 c:\windows\system32\ReinstallBackups\0018\DriverFiles\Common\commonfx.dll
+ 2006-11-23 05:55 . 2006-11-23 05:55 782336 c:\windows\system32\OALInst.exe
+ 2009-07-16 11:00 . 2009-07-16 11:00 180224 c:\windows\system32\Macromed\Shockwave 10\Proj.dll
+ 2009-07-16 11:00 . 2009-07-16 11:00 475136 c:\windows\system32\Macromed\Shockwave 10\PluginPing.dll
+ 2009-07-16 11:00 . 2009-07-16 11:00 339968 c:\windows\system32\Macromed\Shockwave 10\Plugin.dll
+ 2009-07-16 11:00 . 2009-07-16 11:00 606208 c:\windows\system32\Macromed\Shockwave 10\iml32X.dll
+ 2009-07-16 11:00 . 2009-07-16 11:00 581632 c:\windows\system32\Macromed\Shockwave 10\Control.dll
- 2005-07-27 22:49 . 2008-04-13 19:19 146048 c:\windows\system32\drivers\portcls.sys
+ 2005-07-27 22:49 . 2008-04-13 20:19 146048 c:\windows\system32\drivers\portcls.sys
+ 2004-08-04 04:15 . 2008-04-13 20:16 141056 c:\windows\system32\drivers\ks.sys
- 2004-08-04 04:15 . 2008-04-13 19:16 141056 c:\windows\system32\drivers\ks.sys
+ 2007-04-10 09:32 . 2007-04-10 09:32 189736 c:\windows\system32\drivers\haP17v2k.sys
+ 2005-07-27 23:06 . 2007-04-10 09:31 163112 c:\windows\system32\drivers\haP16v2k.sys
+ 2005-07-27 23:06 . 2007-04-10 09:29 797992 c:\windows\system32\drivers\ha10kx2k.sys
+ 2005-07-27 23:06 . 2007-04-10 11:00 157480 c:\windows\system32\drivers\ctsfm2k.sys
+ 2005-07-27 23:06 . 2007-04-10 10:59 126760 c:\windows\system32\drivers\ctoss2k.sys
+ 2005-07-27 23:06 . 2007-04-10 09:21 347128 c:\windows\system32\drivers\ctdvda2k.sys
+ 2005-07-27 23:06 . 2007-04-10 09:20 520488 c:\windows\system32\drivers\ctaud2k.sys
+ 2005-07-27 23:06 . 2007-04-10 09:19 511272 c:\windows\system32\drivers\ctac32k.sys
+ 2005-07-27 22:49 . 2008-04-13 20:19 146048 c:\windows\system32\dllcache\portcls.sys
+ 2004-08-04 04:15 . 2008-04-13 20:16 141056 c:\windows\system32\dllcache\ks.sys
+ 2007-04-09 17:19 . 2007-04-09 17:19 233684 c:\windows\system32\Data\CTPM002W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTPDXW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 232158 c:\windows\system32\Data\CTP4893W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 232158 c:\windows\system32\Data\CTP4891W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 232158 c:\windows\system32\Data\CTP4890W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4875W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4872W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4871W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4870W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4850W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 232158 c:\windows\system32\Data\CTP4840W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4832W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4831W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4830W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 267599 c:\windows\system32\Data\CTP4820W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 232158 c:\windows\system32\Data\CTP4790W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4780W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4760W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4670W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233024 c:\windows\system32\Data\CTP4620W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 233684 c:\windows\system32\Data\CTP1140W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 268778 c:\windows\system32\Data\CTP0930W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 269402 c:\windows\system32\Data\CTP0773W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 263543 c:\windows\system32\Data\CTP0760W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 265966 c:\windows\system32\Data\CTP073AW.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 265966 c:\windows\system32\Data\CTP0730W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 345761 c:\windows\system32\Data\CTP0679W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 345761 c:\windows\system32\Data\CTP0678W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 319757 c:\windows\system32\Data\CTP0669W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 319757 c:\windows\system32\Data\CTP0610W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 319757 c:\windows\system32\Data\CTP0600W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264060 c:\windows\system32\Data\CTP055AW.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264388 c:\windows\system32\Data\CTP0550W.DAT
+ 2007-04-09 17:20 . 2007-04-09 17:20 321377 c:\windows\system32\Data\CTP0531W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 232116 c:\windows\system32\Data\CTP0531L.DAT
+ 2007-04-09 17:20 . 2007-04-09 17:20 321377 c:\windows\system32\Data\CTP0530W.DAT
+ 2007-04-09 17:20 . 2007-04-09 17:20 232116 c:\windows\system32\Data\CTP0530L.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 263802 c:\windows\system32\Data\CTP046CW.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 263802 c:\windows\system32\Data\CTP046BW.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 263802 c:\windows\system32\Data\CTP046AW.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264130 c:\windows\system32\Data\CTP0469W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264130 c:\windows\system32\Data\CTP0468W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264130 c:\windows\system32\Data\CTP0466W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264130 c:\windows\system32\Data\CTP0465W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264130 c:\windows\system32\Data\CTP0464W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264060 c:\windows\system32\Data\CTP0463W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264130 c:\windows\system32\Data\CTP0462W.DAT
+ 2007-04-09 17:21 . 2007-04-09 17:21 264130 c:\windows\system32\Data\CTP0460W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 319757 c:\windows\system32\Data\CTP0400W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 320076 c:\windows\system32\Data\CTP0380W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 320076 c:\windows\system32\Data\CTP0360W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 320622 c:\windows\system32\Data\CTP0359W.DAT
+ 2005-07-27 23:06 . 2007-04-09 17:19 321552 c:\windows\system32\Data\CTP0358W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 322194 c:\windows\system32\Data\CTP0355W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 321529 c:\windows\system32\Data\CTP0352W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 323640 c:\windows\system32\Data\CTP0350W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 318254 c:\windows\system32\Data\CTP0320W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 318254 c:\windows\system32\Data\CTP0280W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 318341 c:\windows\system32\Data\CTP0249W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 319730 c:\windows\system32\Data\CTP0246W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 318254 c:\windows\system32\Data\CTP0245W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 319730 c:\windows\system32\Data\CTP0244W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 318800 c:\windows\system32\Data\CTP0243W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 319730 c:\windows\system32\Data\CTP0242W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 319070 c:\windows\system32\Data\CTP0240W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 275517 c:\windows\system32\Data\CTP0238W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 277159 c:\windows\system32\Data\CTP0232W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 275816 c:\windows\system32\Data\CTP0231W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 277159 c:\windows\system32\Data\CTP0230W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 236189 c:\windows\system32\Data\CTP0222W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 236189 c:\windows\system32\Data\CTP0221W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 276738 c:\windows\system32\Data\CTP0192W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 275169 c:\windows\system32\Data\CTP0191W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTP017HW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTP017GW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTP017FW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTP017EW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTP017DW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTP017CW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTP017BW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CTP017AW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235259 c:\windows\system32\Data\CTP0170W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 276738 c:\windows\system32\Data\CTP0162W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 275427 c:\windows\system32\Data\CTP0161W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 232158 c:\windows\system32\Data\CTP0150W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235259 c:\windows\system32\Data\CTP0105W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235259 c:\windows\system32\Data\CTP0103W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235259 c:\windows\system32\Data\CTP0102W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235259 c:\windows\system32\Data\CTP0101W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235259 c:\windows\system32\Data\CTP0100W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 274587 c:\windows\system32\Data\CTP0095W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 276738 c:\windows\system32\Data\CTP0092W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 275169 c:\windows\system32\Data\CTP0091W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 276738 c:\windows\system32\Data\CTP0090W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 289409 c:\windows\system32\Data\CTP0073W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 289409 c:\windows\system32\Data\CTP0070W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235259 c:\windows\system32\Data\CTP0061W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235259 c:\windows\system32\Data\CTP0060W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 374041 c:\windows\system32\Data\CTEDSPW.DAT
+ 2007-04-09 17:20 . 2007-04-09 17:20 270927 c:\windows\system32\Data\CTEDSPUW.DAT
+ 2007-04-09 17:20 . 2007-04-09 17:20 270927 c:\windows\system32\Data\CTEDSPTW.DAT
+ 2007-04-09 17:20 . 2007-04-09 17:20 330665 c:\windows\system32\Data\CTEDSPPW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 294775 c:\windows\system32\Data\CTEDSPLW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 294775 c:\windows\system32\Data\CTEDSPKW.DAT
+ 2007-04-09 17:20 . 2007-04-09 17:20 348425 c:\windows\system32\Data\CTEDSPHW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 374041 c:\windows\system32\Data\CTEDSP2W.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 201502 c:\windows\system32\Data\CTEAPSW.DAT
+ 2007-04-09 17:19 . 2007-04-09 17:19 235142 c:\windows\system32\Data\CT0060W.DAT
+ 2007-04-09 17:29 . 2007-04-09 17:29 934400 c:\windows\system32\CTxfispi.exe
+ 2007-04-09 17:19 . 2007-04-09 17:19 313207 c:\windows\system32\ctstatic.dat
+ 2005-06-30 12:24 . 2005-06-30 12:24 121856 c:\windows\system32\ctsfinst.dll
+ 2005-07-27 23:06 . 2007-04-12 13:10 560384 c:\windows\system32\CTSBLFX.DLL
+ 2005-07-27 22:43 . 2007-04-09 17:19 274587 c:\windows\system32\ctsbas2w.dat
+ 2005-07-27 23:06 . 2007-04-09 17:21 137728 c:\windows\system32\ctosuser.dll
+ 2005-07-27 23:06 . 2007-04-09 17:24 110080 c:\windows\system32\ctemupia.dll
+ 2007-04-12 13:10 . 2007-04-12 13:10 323328 c:\windows\system32\CTEDSPSY.DLL
+ 2007-04-12 13:10 . 2007-04-12 13:10 128768 c:\windows\system32\CTEDSPIO.DLL
+ 2007-04-12 13:10 . 2007-04-12 13:10 280320 c:\windows\system32\CTEDSPFX.DLL
+ 2007-04-12 13:10 . 2007-04-12 13:10 168192 c:\windows\system32\CTEAPSFX.DLL
+ 2007-04-09 17:33 . 2007-04-09 17:33 163328 c:\windows\system32\ctdvinst.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 131072 c:\windows\system32\ctdcifce.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 335872 c:\windows\system32\ctdc0001.dll
+ 2005-07-27 23:06 . 2007-04-09 17:32 227840 c:\windows\system32\ctdc0000.dll
+ 2005-07-27 22:43 . 2007-04-09 17:21 149838 c:\windows\system32\ctbas2w.dat
+ 2005-07-27 23:06 . 2007-04-12 13:10 546048 c:\windows\system32\CTAUDFX.DLL
+ 2007-04-09 16:25 . 2007-04-09 16:25 444928 c:\windows\system32\CTAPO32.dll
+ 2007-04-12 13:10 . 2007-04-12 13:10 164608 c:\windows\system32\CT20XUT.DLL
+ 2007-04-09 17:22 . 2007-04-09 17:22 205312 c:\windows\system32\ct_oal.dll
+ 2007-04-12 13:10 . 2007-04-12 13:10 105728 c:\windows\system32\APOMgrH.dll
+ 2009-07-31 12:54 . 2009-07-31 12:54 132472 c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 2009-07-31 13:26 . 2009-07-31 13:26 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2009-07-31 13:40 . 2009-07-31 13:40 468408 c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe
+ 2009-07-31 13:28 . 2009-07-31 13:28 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2009-07-31 13:26 . 2009-07-31 13:26 372736 c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2009-07-31 12:54 . 2009-07-31 12:54 714752 c:\windows\system32\Adobe\Shockwave 11\gi.dll
+ 2009-07-31 13:25 . 2009-07-31 13:25 614400 c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2009-07-31 13:41 . 2009-07-31 13:41 206264 c:\windows\system32\Adobe\Director\SwDir.dll
+ 2009-07-31 13:27 . 2009-07-31 13:27 131072 c:\windows\system32\Adobe\Director\np32dsw.dll
+ 2009-07-16 11:00 . 2009-07-16 11:00 1490944 c:\windows\system32\Macromed\Shockwave 10\dirapiX.dll
+ 2007-04-10 11:03 . 2007-04-10 11:03 1164072 c:\windows\system32\drivers\ha20x2k.sys
+ 2007-04-12 13:10 . 2007-04-12 13:10 1317632 c:\windows\system32\CTEXFIFX.DLL
+ 2009-07-31 13:00 . 2009-07-31 13:00 1011712 c:\windows\system32\Adobe\Shockwave 11\iml32.dll
+ 2009-07-31 12:54 . 2009-07-31 12:54 1886320 c:\windows\system32\Adobe\Shockwave 11\gt.exe
+ 2009-07-31 13:04 . 2009-07-31 13:04 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2005-05-15 332800]
"WAB"="c:\documents and settings\Administrator\Application Data\Macromedia\Common\102d407419.exe" [2009-11-03 16384]
"rundll32.exe"="" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-04-25 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-15 344064]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"DLBXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll" [2004-12-07 69632]
"dlbxmon.exe"="c:\program files\Dell Photo AIO Printer 962\dlbxmon.exe" [2005-01-18 425984]
"HostManager"="c:\program files\Common Files\AOL\1134621263\ee\AOLSoftware.exe" [2007-10-08 41824]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 284184]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-06-01 1468296]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-7-27 24576]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\reset5c]
reset5c.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave1"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\102d40741.dll
"midi1"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\102d40741.dll
"mixer1"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\102d40741.dll
"wave2"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\102d40741.dll
"midi2"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\102d40741.dll
"mixer2"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\102d40741.dll
"aux1"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\102d40741.dll
"aux2"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\102d40741.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1134621263\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1134621263\\ee\\aim6.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"%windir%\\system32\\lsass.exe"=
"c:\\Program Files\\Disney\\Disney Online\\PiratesOnline\\Launcher1.exe"=
"c:\\Program Files\\Disney\\Disney Online\\PiratesOnline\\Pirates.exe"=
"c:\\Program Files\\Disney\\Disney Online\\PiratesOnline\\Pirates_Online.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
S3 aswArKrn;aswArKrn;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\aswArKrn.sys --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\aswArKrn.sys [?]
S3 CDAVFS;CDAVFS;c:\windows\system32\drivers\CDAVFS.sys [8/6/2009 7:09 PM 67424]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder
2009-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-02 20:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,44,5c,8d,03,37,4c,d2,4d,aa,20,0e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,44,5c,8d,03,37,4c,d2,4d,aa,20,0e,\
[HKEY_USERS\S-1-5-21-3835334267-1934715317-2934981272-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a9,9c,5d,7b,36,8f,3b,41,b2,20,90,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a9,9c,5d,7b,36,8f,3b,41,b2,20,90,\
[HKEY_USERS\S-1-5-21-3835334267-1934715317-2934981272-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8C1A580A-4BAD-8BC4-F5E5-BF4C87F6657D}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"pamofejndooopfiopnnejpgkhebaepfa"=hex:6b,61,68,6c,6a,6e,64,6c,66,6f,70,63,65,
6b,69,63,63,66,66,65,6b,69,00,00
"oacpjgecpodccglbknncijmgeniaed"=hex:6b,61,68,6c,6a,6e,64,6c,66,6f,70,63,65,6b,
69,63,63,66,66,65,6b,69,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\wininet.dll
- - - - - - - > 'explorer.exe'(3472)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-11-03 20:41
ComboFix-quarantined-files.txt 2009-11-03 01:41
ComboFix2.txt 2009-11-02 23:52
ComboFix3.txt 2009-11-02 06:03
ComboFix4.txt 2009-11-01 00:02
ComboFix5.txt 2009-11-03 01:08
Pre-Run: 213,154,615,296 bytes free
Post-Run: 213,219,586,048 bytes free
- - End Of File - - DC294981E78964688B83903049CA6542