ComboFix 09-12-06.09 - Greg Anderson 12/07/2009 17:58.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.63 [GMT -6:00]
Running from: c:\documents and settings\Greg Anderson\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Greg Anderson\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\windows\system32\DA.tmp"
"c:\windows\system32\dmintf32.dll"
"c:\windows\system32\fxsxp3232.dll"
"c:\windows\system32\gdi3232.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000012_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\_000014_.tmp.dll
c:\windows\system32\_000015_.tmp.dll
c:\windows\system32\DA.tmp
c:\windows\system32\dmintf32.dll
c:\windows\system32\fxsxp3232.dll
c:\windows\system32\gdi3232.dll
Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\ndis.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MDXGTHKN
-------\Service_mdxgthkn
((((((((((((((((((((((((( Files Created from 2009-11-08 to 2009-12-08 )))))))))))))))))))))))))))))))
.
2009-12-07 06:06 . 2009-12-07 06:06 -------- d-----w- c:\windows\ServicePackFiles
2009-12-07 06:04 . 2009-12-07 06:04 -------- d-----w- c:\program files\MSXML 4.0
2009-12-07 04:14 . 2009-08-29 08:08 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-07 04:14 . 2009-08-29 08:08 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-07 04:14 . 2009-08-29 08:08 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-12-07 04:14 . 2009-08-29 08:08 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2009-12-07 04:14 . 2009-08-29 08:08 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-07 04:13 . 2009-08-29 08:08 11069440 ------w- c:\windows\system32\dllcache\ieframe.dll
2009-12-07 04:08 . 2009-03-06 14:44 283648 ------w- c:\windows\system32\dllcache\pdh.dll
2009-12-07 04:08 . 2009-02-06 16:54 35328 ------w- c:\windows\system32\dllcache\sc.exe
2009-12-07 04:08 . 2005-07-26 04:39 60416 ------w- c:\windows\system32\dllcache\colbact.dll
2009-12-07 04:08 . 2009-02-09 10:20 399360 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-12-07 04:08 . 2009-02-09 10:20 473088 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-12-07 04:08 . 2009-02-06 17:14 110592 ------w- c:\windows\system32\dllcache\services.exe
2009-12-07 04:08 . 2009-02-06 16:39 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-12-07 04:08 . 2009-02-09 10:20 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-12-07 04:08 . 2009-02-09 10:20 616960 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-12-07 04:08 . 2009-02-09 10:20 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-12-07 04:07 . 2009-06-21 22:04 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-12-07 03:59 . 2009-06-05 07:42 655872 ------w- c:\windows\system32\dllcache\mstscax.dll
2009-12-07 03:56 . 2008-04-21 10:02 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-12-04 23:38 . 2009-12-04 23:38 862040 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-04 23:38 . 2009-12-04 23:38 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-12-04 23:38 . 2009-12-04 23:38 206944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-04 23:38 . 2009-12-04 23:38 390288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-04 23:38 . 2009-12-04 23:38 537576 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-04 23:38 . 2009-12-04 23:38 370744 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-04 23:38 . 2009-12-04 23:38 163728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-12-04 23:38 . 2009-12-04 23:38 194104 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-04 23:37 . 2009-12-04 23:37 5908024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-04 23:37 . 2009-12-04 23:37 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-12-04 23:37 . 2009-12-04 23:37 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-12-04 23:37 . 2009-12-04 23:37 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-04 23:37 . 2009-12-04 23:37 641632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-12-04 23:36 . 2009-12-04 23:36 816272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-04 23:36 . 2009-12-04 23:36 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-04 23:36 . 2009-12-04 23:36 1638640 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-04 23:36 . 2009-12-04 23:36 788880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-04 23:36 . 2009-12-04 23:36 1184912 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-04 01:53 . 2009-12-04 01:53 -------- d-----w- c:\program files\Trend Micro
2009-12-03 19:00 . 2009-07-28 21:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-03 19:00 . 2009-03-30 15:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-12-03 19:00 . 2009-02-13 17:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-12-03 19:00 . 2009-02-13 17:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-12-03 19:00 . 2009-12-03 19:00 -------- d-----w- c:\program files\Avira
2009-12-03 19:00 . 2009-12-03 19:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-12-03 13:41 . 2009-12-03 13:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG8
2009-12-03 13:37 . 2009-12-03 13:37 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2009-12-02 02:12 . 2009-09-03 09:17 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-12-01 23:32 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-12-01 23:29 . 2009-12-01 23:29 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-12-01 23:29 . 2009-10-03 08:15 2924848 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-12-01 23:25 . 2009-12-01 23:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-01 22:59 . 2009-12-01 22:59 -------- d-----w- c:\documents and settings\Greg Anderson\Application Data\Malwarebytes
2009-12-01 22:41 . 2009-12-01 22:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-12-01 22:41 . 2009-12-03 22:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-01 22:41 . 2009-12-04 01:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-01 22:41 . 2009-12-03 22:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-01 22:41 . 2009-12-01 22:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-01 22:39 . 2009-12-01 22:39 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-12-01 21:55 . 2009-12-01 21:55 -------- d--h--w- c:\windows\PIF
2009-12-01 21:50 . 2009-12-01 21:50 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-12-01 21:49 . 2009-12-01 21:49 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-12-01 21:40 . 2009-12-01 21:40 -------- d-----w- c:\program files\Alwil Software
2009-12-01 21:34 . 2009-12-01 21:34 -------- d-----w- c:\documents and settings\Greg Anderson\Application Data\AVG8
2009-12-01 19:14 . 2009-12-01 19:15 -------- d-sh--w- c:\windows\system32\SysWoW32
2009-11-27 01:37 . 2009-11-29 21:21 -------- d-----w- c:\program files\GamersFirst
1601-01-01 00:00 . 1601-01-01 00:00 -------- d-----w- c:\windows\LastGood.Tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 01:30 . 2009-09-03 01:39 69 ----a-w- c:\documents and settings\Greg Anderson\jagex_runescape_preferences2.dat
2009-12-07 01:30 . 2009-09-03 01:38 39 ----a-w- c:\documents and settings\Greg Anderson\jagex_runescape_preferences.dat
2009-12-03 20:17 . 2008-10-27 21:36 -------- d-----w- c:\program files\EA GAMES
2009-12-03 20:01 . 2005-07-20 06:47 -------- d-----w- c:\program files\Common Files\AOL
2009-12-01 23:25 . 2006-05-08 00:16 -------- d-----w- c:\program files\Lavasoft
2009-10-29 20:04 . 2006-07-09 01:36 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-10-29 18:54 . 2009-10-15 22:01 -------- d-----w- c:\program files\Cricket Broadband Connect
2009-10-29 18:54 . 2005-10-11 03:09 -------- d-----w- c:\program files\BFG
2009-10-29 18:54 . 2005-07-22 05:21 -------- d-----w- c:\program files\AIM
2009-10-17 06:34 . 2009-10-15 22:01 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-10-15 22:38 . 2009-10-13 23:11 -------- d-----w- c:\program files\SwiftKit
2009-10-15 22:03 . 2009-10-15 22:03 -------- d-----w- c:\program files\PANTECH
2009-10-15 22:01 . 2009-10-15 22:01 -------- d-----w- c:\program files\Common Files\Avanquest software Shared
2009-10-15 22:01 . 2005-07-20 06:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-13 23:11 . 2009-10-13 23:11 -------- d-----w- c:\documents and settings\All Users\Application Data\SwiftKit
2009-10-13 22:52 . 2005-07-20 06:41 -------- d-----w- c:\program files\Java
2009-10-13 22:49 . 2009-10-13 22:49 152576 ----a-w- c:\documents and settings\Greg Anderson\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-09-11 14:33 . 2004-08-10 17:51 133632 ----a-w- c:\windows\system32\msv1_0.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-12-07_03.29.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-29 05:42 . 2009-06-29 05:42 91656 c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2009-12-08 00:22 . 2009-12-08 00:22 16384 c:\windows\temp\Perflib_Perfdata_18c.dat
+ 2005-05-26 09:16 . 2009-08-07 01:24 44768 c:\windows\system32\wups2.dll
+ 2004-08-10 18:02 . 2009-08-07 01:24 35552 c:\windows\system32\wups.dll
+ 2004-08-10 17:51 . 2009-06-25 08:44 59392 c:\windows\system32\wdigest.dll
+ 2007-01-29 08:58 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
+ 2004-08-10 17:51 . 2009-06-12 11:50 76288 c:\windows\system32\telnet.exe
+ 2004-08-10 17:51 . 2009-06-25 08:44 56320 c:\windows\system32\secur32.dll
+ 2004-08-10 17:51 . 2009-02-06 16:54 35328 c:\windows\system32\sc.exe
- 2004-08-10 17:51 . 2009-12-07 03:32 53436 c:\windows\system32\perfc009.dat
+ 2004-08-10 17:51 . 2009-12-08 00:30 53436 c:\windows\system32\perfc009.dat
+ 2004-08-10 18:01 . 2008-06-12 14:16 91648 c:\windows\system32\mtxoci.dll
+ 2004-08-10 17:51 . 2008-06-12 14:16 66560 c:\windows\system32\mtxclu.dll
- 2004-08-10 17:51 . 2006-03-01 19:42 66560 c:\windows\system32\mtxclu.dll
+ 2009-03-08 09:31 . 2009-08-29 08:08 55296 c:\windows\system32\msfeedsbs.dll
- 2009-03-08 09:31 . 2009-03-08 09:31 55296 c:\windows\system32\msfeedsbs.dll
+ 2004-08-10 18:01 . 2008-06-12 14:16 58880 c:\windows\system32\msdtclog.dll
- 2004-08-10 18:01 . 2004-08-04 10:00 58880 c:\windows\system32\msdtclog.dll
+ 2004-08-10 17:51 . 2009-09-04 20:45 58880 c:\windows\system32\msasn1.dll
- 2004-08-10 17:51 . 2009-03-08 09:33 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-10 17:51 . 2009-08-29 08:08 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-10 17:51 . 2009-07-29 04:53 82432 c:\windows\system32\fontsub.dll
+ 2004-08-10 17:51 . 2009-06-22 11:34 92544 c:\windows\system32\drivers\ksecdd.sys
+ 2004-08-10 18:02 . 2009-08-07 01:24 35552 c:\windows\system32\dllcache\wups.dll
+ 2009-06-25 08:44 . 2009-06-25 08:44 59392 c:\windows\system32\dllcache\wdigest.dll
+ 2009-06-12 11:50 . 2009-06-12 11:50 76288 c:\windows\system32\dllcache\telnet.exe
+ 2009-06-25 08:44 . 2009-06-25 08:44 56320 c:\windows\system32\dllcache\secur32.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2009-09-04 20:45 . 2009-09-04 20:45 58880 c:\windows\system32\dllcache\msasn1.dll
+ 2009-06-22 11:34 . 2009-06-22 11:34 92544 c:\windows\system32\dllcache\ksecdd.sys
+ 2006-05-10 05:22 . 2009-08-29 08:08 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2006-05-10 05:22 . 2009-03-08 09:33 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-07-29 04:53 . 2009-07-29 04:53 82432 c:\windows\system32\dllcache\fontsub.dll
+ 2009-06-10 14:21 . 2009-06-10 14:21 84992 c:\windows\system32\dllcache\avifil32.dll
+ 2009-07-17 18:55 . 2009-07-17 18:55 58880 c:\windows\system32\dllcache\atl.dll
+ 2004-08-10 17:50 . 2009-06-10 14:21 84992 c:\windows\system32\avifil32.dll
- 2004-08-10 17:50 . 2004-08-04 10:00 84992 c:\windows\system32\avifil32.dll
+ 2004-08-10 17:50 . 2009-07-17 18:55 58880 c:\windows\system32\atl.dll
- 2004-08-10 17:50 . 2004-08-04 10:00 58880 c:\windows\system32\atl.dll
+ 2009-06-25 01:56 . 2009-06-25 01:56 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
+ 2008-05-28 06:49 . 2008-05-28 06:49 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2007-04-14 01:58 . 2007-04-14 01:58 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2008-05-28 06:49 . 2008-05-28 06:49 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2007-04-14 01:57 . 2007-04-14 01:57 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2007-04-14 01:57 . 2007-04-14 01:57 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2008-05-28 06:49 . 2008-05-28 06:49 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2008-05-28 07:30 . 2008-05-28 07:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2007-04-14 02:30 . 2007-04-14 02:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2009-12-07 06:04 . 2009-12-07 06:04 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
+ 2009-12-07 06:19 . 2009-03-08 09:33 12288 c:\windows\ie8updates\KB974455-IE8\xpshims.dll
+ 2009-12-07 06:19 . 2009-03-08 09:31 55296 c:\windows\ie8updates\KB974455-IE8\msfeedsbs.dll
+ 2009-12-07 06:19 . 2009-03-08 09:33 25600 c:\windows\ie8updates\KB974455-IE8\jsproxy.dll
+ 2009-12-07 06:10 . 2009-12-07 06:10 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_047f93ee\System.Drawing.Design.dll
+ 2009-12-07 06:10 . 2009-12-07 06:10 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_4373b1ae\CustomMarshalers.dll
+ 2005-05-17 00:25 . 2009-04-15 09:24 351744 c:\windows\system32\xpsp3res.dll
+ 2004-08-10 17:51 . 2009-04-10 07:01 530280 c:\windows\system32\wmspdmod.dll
+ 2004-08-10 17:51 . 2009-07-13 16:08 286720 c:\windows\system32\wmpdxm.dll
+ 2004-08-10 17:51 . 2009-06-10 06:32 132096 c:\windows\system32\wkssvc.dll
- 2004-08-10 17:51 . 2006-08-17 12:28 132096 c:\windows\system32\wkssvc.dll
+ 2004-08-10 17:51 . 2009-08-29 08:08 916480 c:\windows\system32\wininet.dll
- 2004-08-10 17:51 . 2004-08-04 10:00 351232 c:\windows\system32\winhttp.dll
+ 2004-08-10 17:51 . 2008-12-16 12:47 351232 c:\windows\system32\winhttp.dll
+ 2004-08-10 18:01 . 2009-02-06 16:39 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2004-08-10 18:01 . 2009-02-09 10:20 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-08-10 18:01 . 2009-02-09 10:20 473088 c:\windows\system32\wbem\fastprox.dll
+ 2004-08-10 17:51 . 2009-07-29 04:53 119808 c:\windows\system32\t2embed.dll
+ 2004-08-10 17:51 . 2009-08-26 08:16 247326 c:\windows\system32\strmdll.dll
- 2004-08-10 17:51 . 2008-10-03 10:15 247326 c:\windows\system32\strmdll.dll
+ 2004-08-10 17:51 . 2009-02-06 17:14 110592 c:\windows\system32\services.exe
+ 2004-08-10 17:51 . 2009-06-25 08:44 168448 c:\windows\system32\schannel.dll
+ 2004-08-10 17:51 . 2009-02-09 10:20 399360 c:\windows\system32\rpcss.dll
+ 2004-08-10 17:51 . 2009-04-15 15:11 584192 c:\windows\system32\rpcrt4.dll
- 2004-08-10 17:51 . 2007-07-09 13:09 584192 c:\windows\system32\rpcrt4.dll
- 2004-08-10 17:51 . 2009-12-07 03:32 381692 c:\windows\system32\perfh009.dat
+ 2004-08-10 17:51 . 2009-12-08 00:30 381692 c:\windows\system32\perfh009.dat
- 2004-08-10 17:51 . 2004-08-04 10:00 283648 c:\windows\system32\pdh.dll
+ 2004-08-10 17:51 . 2009-03-06 14:44 283648 c:\windows\system32\pdh.dll
+ 2004-08-10 17:51 . 2009-08-29 08:08 206848 c:\windows\system32\occache.dll
+ 2004-08-10 17:51 . 2009-02-09 10:20 714752 c:\windows\system32\ntdll.dll
+ 2004-08-10 17:51 . 2009-08-05 09:11 204800 c:\windows\system32\mswebdvd.dll
+ 2004-08-10 18:01 . 2009-06-05 07:42 655872 c:\windows\system32\mstscax.dll
- 2009-03-08 09:32 . 2009-03-08 09:32 594432 c:\windows\system32\msfeeds.dll
+ 2009-03-08 09:32 . 2009-08-29 08:08 594432 c:\windows\system32\msfeeds.dll
+ 2004-08-10 18:01 . 2008-06-12 14:16 161792 c:\windows\system32\msdtcuiu.dll
+ 2004-08-10 18:01 . 2008-06-12 14:16 956928 c:\windows\system32\msdtctm.dll
+ 2004-08-10 18:01 . 2008-06-12 14:16 428032 c:\windows\system32\msdtcprx.dll
+ 2004-08-10 17:51 . 2009-06-25 08:44 724480 c:\windows\system32\lsasrv.dll
+ 2004-08-10 17:51 . 2009-05-07 15:44 344064 c:\windows\system32\localspl.dll
+ 2004-08-10 17:51 . 2009-03-21 14:18 986112 c:\windows\system32\kernel32.dll
+ 2004-08-10 17:51 . 2009-06-25 08:44 298496 c:\windows\system32\kerberos.dll
+ 2004-08-10 17:51 . 2009-06-22 06:44 726528 c:\windows\system32\jscript.dll
- 2004-08-10 17:51 . 2009-03-08 09:33 726528 c:\windows\system32\jscript.dll
+ 2004-08-10 17:51 . 2009-08-29 08:08 184320 c:\windows\system32\iepeers.dll
+ 2004-08-10 17:51 . 2009-08-29 08:08 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-10 17:51 . 2009-03-08 09:32 173056 c:\windows\system32\ie4uinit.exe
+ 2004-08-10 17:51 . 2009-08-28 10:35 173056 c:\windows\system32\ie4uinit.exe
- 2004-08-10 17:57 . 2009-03-23 23:39 184224 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-10 17:57 . 2009-12-08 00:22 184224 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-10 17:51 . 2009-04-10 07:01 530280 c:\windows\system32\dllcache\wmspdmod.dll
+ 2004-08-10 17:51 . 2009-07-13 16:08 286720 c:\windows\system32\dllcache\wmpdxm.dll
+ 2006-08-17 12:28 . 2009-06-10 06:32 132096 c:\windows\system32\dllcache\wkssvc.dll
- 2006-08-17 12:28 . 2006-08-17 12:28 132096 c:\windows\system32\dllcache\wkssvc.dll
+ 2006-05-10 05:23 . 2009-08-29 08:08 916480 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:47 . 2008-12-16 12:47 351232 c:\windows\system32\dllcache\winhttp.dll
+ 2009-07-29 04:53 . 2009-07-29 04:53 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2006-08-21 15:52 . 2009-08-26 08:16 247326 c:\windows\system32\dllcache\strmdll.dll
- 2006-08-21 15:52 . 2008-10-03 10:15 247326 c:\windows\system32\dllcache\strmdll.dll
+ 2008-12-05 07:12 . 2009-06-25 08:44 168448 c:\windows\system32\dllcache\schannel.dll
- 2009-03-23 04:34 . 2007-07-09 13:09 584192 c:\windows\system32\dllcache\rpcrt4.dll
+ 2009-03-23 04:34 . 2009-04-15 15:11 584192 c:\windows\system32\dllcache\rpcrt4.dll
+ 2009-03-08 09:34 . 2009-08-29 08:08 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-08-05 09:11 . 2009-08-05 09:11 204800 c:\windows\system32\dllcache\mswebdvd.dll
+ 2009-06-25 08:44 . 2009-09-11 14:33 133632 c:\windows\system32\dllcache\msv1_0.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2006-08-17 12:28 . 2009-06-25 08:44 724480 c:\windows\system32\dllcache\lsasrv.dll
+ 2009-05-07 15:44 . 2009-05-07 15:44 344064 c:\windows\system32\dllcache\localspl.dll
+ 2006-07-05 10:55 . 2009-03-21 14:18 986112 c:\windows\system32\dllcache\kernel32.dll
+ 2009-06-25 08:44 . 2009-06-25 08:44 298496 c:\windows\system32\dllcache\kerberos.dll
- 2006-05-18 05:24 . 2009-03-08 09:33 726528 c:\windows\system32\dllcache\jscript.dll
+ 2006-05-18 05:24 . 2009-06-22 06:44 726528 c:\windows\system32\dllcache\jscript.dll
+ 2006-05-10 05:22 . 2009-08-29 08:08 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2009-03-08 19:09 . 2009-08-29 08:08 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2009-03-08 09:32 . 2009-03-08 09:32 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-03-08 09:32 . 2009-08-28 10:35 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2004-08-10 17:50 . 2009-02-09 10:20 616960 c:\windows\system32\advapi32.dll
- 2004-08-10 17:50 . 2004-08-04 10:00 616960 c:\windows\system32\advapi32.dll
+ 2008-05-28 06:49 . 2008-05-28 06:49 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2007-04-14 01:58 . 2007-04-14 01:58 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2007-04-14 01:56 . 2007-04-14 01:56 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2008-05-28 06:48 . 2008-05-28 06:48 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2008-05-28 07:30 . 2008-05-28 07:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2007-04-14 02:30 . 2007-04-14 02:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2009-12-07 06:04 . 2009-12-07 06:04 429568 c:\windows\Installer\938f69.msi
+ 2009-12-07 06:19 . 2009-03-08 09:34 914944 c:\windows\ie8updates\KB974455-IE8\wininet.dll
+ 2009-12-07 06:19 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB974455-IE8\spuninst\updspapi.dll
+ 2009-12-07 06:19 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB974455-IE8\spuninst\spuninst.exe
+ 2009-12-07 06:19 . 2009-03-08 09:34 109568 c:\windows\ie8updates\KB974455-IE8\occache.dll
+ 2009-12-07 06:19 . 2009-03-08 09:32 594432 c:\windows\ie8updates\KB974455-IE8\msfeeds.dll
+ 2009-12-07 06:19 . 2009-03-08 09:33 246784 c:\windows\ie8updates\KB974455-IE8\ieproxy.dll
+ 2009-12-07 06:19 . 2009-03-08 09:31 183808 c:\windows\ie8updates\KB974455-IE8\iepeers.dll
+ 2009-12-07 06:19 . 2009-03-08 19:09 391536 c:\windows\ie8updates\KB974455-IE8\iedkcs32.dll
+ 2009-12-07 06:19 . 2009-03-08 09:32 173056 c:\windows\ie8updates\KB974455-IE8\ie4uinit.exe
+ 2009-12-07 06:05 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2009-12-07 06:05 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2009-12-07 06:05 . 2009-03-08 09:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2009-12-07 06:11 . 2009-12-07 06:11 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_bf1c7b8c\System.Drawing.dll
+ 2009-12-07 04:12 . 2009-08-13 13:55 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll
+ 2009-07-21 06:03 . 2009-07-21 06:03 1348432 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9876.0_x-ww_a621d1d5\msxml4.dll
+ 2004-08-10 17:51 . 2009-05-20 18:44 2355200 c:\windows\system32\WMVCore.dll
- 2004-08-10 17:51 . 2007-04-30 13:20 5537792 c:\windows\system32\wmp.dll
+ 2004-08-10 17:51 . 2009-07-13 16:08 5537792 c:\windows\system32\wmp.dll
+ 2004-08-10 17:51 . 2009-08-14 12:19 1850112 c:\windows\system32\win32k.sys
+ 2004-08-10 17:51 . 2009-08-29 08:08 1208832 c:\windows\system32\urlmon.dll
- 2004-08-10 17:51 . 2006-06-22 05:06 1435648 c:\windows\system32\query.dll
+ 2004-08-10 17:51 . 2009-07-17 16:27 1435648 c:\windows\system32\query.dll
+ 2004-08-10 17:51 . 2009-06-03 19:27 1290752 c:\windows\system32\quartz.dll
- 2004-08-10 17:51 . 2008-08-14 10:00 2180352 c:\windows\system32\ntoskrnl.exe
+ 2004-08-10 17:51 . 2009-08-04 14:00 2180352 c:\windows\system32\ntoskrnl.exe
+ 2004-08-04 03:59 . 2009-08-04 13:13 2057728 c:\windows\system32\ntkrnlpa.exe
- 2004-08-04 03:59 . 2008-08-14 09:22 2057728 c:\windows\system32\ntkrnlpa.exe
+ 2009-07-21 06:05 . 2009-07-21 06:05 1348432 c:\windows\system32\msxml4.dll
+ 2004-08-10 17:51 . 2009-07-31 04:57 1172480 c:\windows\system32\msxml3.dll
+ 2004-08-10 17:51 . 2009-08-29 08:08 5940224 c:\windows\system32\mshtml.dll
+ 2009-03-08 09:32 . 2009-08-29 08:08 1985536 c:\windows\system32\iertutil.dll
+ 2004-08-10 17:51 . 2009-05-20 18:44 2355200 c:\windows\system32\dllcache\WMVCore.dll
- 2004-08-10 17:51 . 2007-04-30 13:20 5537792 c:\windows\system32\dllcache\wmp.dll
+ 2004-08-10 17:51 . 2009-07-13 16:08 5537792 c:\windows\system32\dllcache\wmp.dll
+ 2007-03-08 13:47 . 2009-08-14 12:19 1850112 c:\windows\system32\dllcache\win32k.sys
+ 2006-05-10 05:23 . 2009-08-29 08:08 1208832 c:\windows\system32\dllcache\urlmon.dll
+ 2006-06-22 05:06 . 2009-07-17 16:27 1435648 c:\windows\system32\dllcache\query.dll
- 2006-06-22 05:06 . 2006-06-22 05:06 1435648 c:\windows\system32\dllcache\query.dll
+ 2008-05-07 05:18 . 2009-06-03 19:27 1290752 c:\windows\system32\dllcache\quartz.dll
+ 2009-03-23 04:19 . 2009-08-04 14:00 2180352 c:\windows\system32\dllcache\ntoskrnl.exe
- 2009-03-23 04:19 . 2008-08-14 10:00 2180352 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-03-23 04:19 . 2009-08-04 13:13 2015744 c:\windows\system32\dllcache\ntkrpamp.exe
- 2009-03-23 04:19 . 2008-08-14 09:22 2015744 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-03-23 04:19 . 2009-08-04 13:13 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-03-23 04:19 . 2008-08-14 09:22 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-03-23 04:19 . 2008-08-14 09:58 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-03-23 04:19 . 2009-08-04 13:58 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-09-13 05:01 . 2009-07-31 04:57 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2006-11-08 05:06 . 2009-07-10 13:42 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2006-05-19 15:08 . 2009-08-29 08:08 5940224 c:\windows\system32\dllcache\mshtml.dll
+ 2008-05-28 07:35 . 2008-05-28 07:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2007-04-14 02:35 . 2007-04-14 02:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2007-04-14 02:35 . 2007-04-14 02:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2008-05-28 07:35 . 2008-05-28 07:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2007-04-14 01:57 . 2007-04-14 01:57 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2008-05-28 06:48 . 2008-05-28 06:48 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2008-05-28 06:48 . 2008-05-28 06:48 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2007-04-14 01:57 . 2007-04-14 01:57 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2007-04-14 01:50 . 2007-04-14 01:50 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2008-05-28 06:43 . 2008-05-28 06:43 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2009-12-07 06:19 . 2009-03-08 09:34 1206784 c:\windows\ie8updates\KB974455-IE8\urlmon.dll
+ 2009-12-07 06:19 . 2009-03-08 09:41 5937152 c:\windows\ie8updates\KB974455-IE8\mshtml.dll
+ 2009-12-07 06:19 . 2009-03-08 09:32 1985024 c:\windows\ie8updates\KB974455-IE8\iertutil.dll
+ 2005-08-18 21:58 . 2009-08-04 14:00 2180352 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2005-08-18 21:58 . 2008-08-14 10:00 2180352 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2005-08-18 21:58 . 2009-08-04 13:13 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2005-08-18 21:58 . 2008-08-14 09:22 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2005-08-18 21:58 . 2008-08-14 09:22 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2005-08-18 21:58 . 2009-08-04 13:13 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2005-08-18 21:58 . 2008-08-14 09:58 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2005-08-18 21:58 . 2009-08-04 13:58 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-12-07 06:10 . 2009-12-07 06:10 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_8ecf189a\System.dll
+ 2009-12-07 06:11 . 2009-12-07 06:11 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_82eeb235\System.Xml.dll
+ 2009-12-07 06:11 . 2009-12-07 06:11 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_6cb3c053\System.Windows.Forms.dll
+ 2009-12-07 06:11 . 2009-12-07 06:11 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_5cb03e87\System.Design.dll
+ 2009-12-07 06:11 . 2009-12-07 06:11 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_98428a8d\mscorlib.dll
+ 2009-12-07 06:10 . 2009-12-07 06:10 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2009-03-23 05:23 . 2009-03-23 05:23 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2009-03-23 05:23 . 2009-03-23 05:23 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-12-07 06:10 . 2009-12-07 06:10 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-03-08 09:39 . 2009-08-29 08:08 11069440 c:\windows\system32\ieframe.dll
+ 2009-08-11 03:08 . 2009-08-11 03:08 11315712 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp
+ 2009-08-10 20:09 . 2009-08-10 20:09 17254912 c:\windows\Installer\938f7f.msp
+ 2009-12-07 06:19 . 2009-03-08 09:39 11063808 c:\windows\ie8updates\KB974455-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-07-20 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2003-09-29 81990]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-25 139320]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-03-12 11776]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-03-29 180269]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2008-03-10 17672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"{F9AA8FE2-E89A-E99B-E8b8-E9AE9B9ABA99}"="c:\program files\Cricket Broadband Connect\AvqAutoRun.exe" [2009-04-17 73728]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2005-12-5 1385400]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2005-8-18 315392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8081:TCP"= 8081:TCP:RESNET-EPO-8081-TCP
"8082:TCP"= 8082:TCP:RESNET-EPO-8082-TCP
"8444:TCP"= 8444:TCP:RESNET-EPO-8444-TCP
"8081:UDP"= 8081:UDP:RESNET-EPO-8081-UDP
"8082:UDP"= 8082:UDP:RESNET-EPO-8082-UDP
"8444:UDP"= 8444:UDP:RESNET-EPO-8444-UDP
"4500:UDP"= 4500:UDP:VPN-4500-UDP
"10000:UDP"= 10000:UDP:VPN-10000-UDP
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/1/2009 5:32 PM 64288]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [12/1/2009 4:41 PM 38224]
--- Other Services/Drivers In Memory ---
*Deregistered* - BMLoad
*Deregistered* - NaiAvFilter101
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.xbox.com/en-US/uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Greg Anderson\Application Data\Mozilla\Firefox\Profiles\2ik6svsx.default\
FF - prefs.js: browser.startup.homepage -
hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:officialFF - component: c:\program files\Cricket Broadband Connect\Bytemobile\addon\components\bmboc_addon3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-07 18:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4024)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\program files\Network Associates\VirusScan\vstskmgr.exe
c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\wbem\unsecapp.exe
c:\progra~1\MUSICM~1\MUSICM~3\MMDiag.exe
c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe
c:\program files\Network Associates\VirusScan\mcshield.exe
c:\program files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2009-12-07 19:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-08 01:21
ComboFix2.txt 2009-12-07 05:51
Pre-Run: 36,156,686,336 bytes free
Post-Run: 36,219,195,392 bytes free
- - End Of File - - 14A8F4F11DC15C4740AB1E42B7992A74