Sorry for delay. There is the combo fix log file.
ComboFix 10-10-09.06 - Rob 10/10/2010 19:50:12.5.1 - x86
Running from: c:\documents and settings\Rob\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\41K62.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\8bk4bb.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\aNn4k78a7.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\xy1KjBxyy.jpg
c:\documents and settings\All Users\Application Data\32Y1167.exe
c:\documents and settings\All Users\Application Data\4J05NMf8.exe
c:\documents and settings\All Users\Documents\Server\admin.txt
c:\documents and settings\All Users\Documents\Server\server.dat
c:\documents and settings\LocalService\Local Settings\Application Data\32Y1167.exe
c:\documents and settings\NetworkService\Application Data\Microsoft\stor.cfg
c:\documents and settings\NetworkService\Application Data\Microsoft\svchost .exe
c:\documents and settings\NetworkService\Application Data\Microsoft\svchost.exe
c:\documents and settings\NetworkService\Local Settings\Application Data\32Y1167.exe
c:\documents and settings\Rob\.COMMgr
c:\documents and settings\Rob\.COMMgr\complmgr .exe
c:\documents and settings\Rob\.COMMgr\complmgr.exe
c:\documents and settings\Rob\.COMMgr\complmgrSrv.exe
c:\documents and settings\Rob\Application Data\Bifygy\zoorw.exe
c:\documents and settings\Rob\Application Data\Bowyy
c:\documents and settings\Rob\Application Data\Bowyy\olvy.exe
c:\documents and settings\Rob\Application Data\Buicuk
c:\documents and settings\Rob\Application Data\Buicuk\abmo.tmp
c:\documents and settings\Rob\Application Data\Hyro
c:\documents and settings\Rob\Application Data\Hyro\isyqd.nes
c:\documents and settings\Rob\Application Data\Hyro\isyqd.tmp
c:\documents and settings\Rob\Application Data\Irokge
c:\documents and settings\Rob\Application Data\Irokge\paozu.tmp
c:\documents and settings\Rob\Application Data\Luol
c:\documents and settings\Rob\Application Data\Luol\cacu.exe
c:\documents and settings\Rob\Application Data\Microsoft\stor.cfg
c:\documents and settings\Rob\Application Data\Microsoft\svchost .exe
c:\documents and settings\Rob\Application Data\Microsoft\svchost.exe
c:\documents and settings\Rob\Application Data\Microsoft\svchostSrv.exe
c:\documents and settings\Rob\Application Data\Microsoft\Windows\shell.exe
c:\documents and settings\Rob\Application Data\Nekev
c:\documents and settings\Rob\Application Data\Nekev\zauz.tmp
c:\documents and settings\Rob\Application Data\Nekev\zauz.upy
c:\documents and settings\Rob\Application Data\Opuqc\nexek.exe
c:\documents and settings\Rob\Application Data\Tydi
c:\documents and settings\Rob\Application Data\Tydi\ydfi.exe
c:\documents and settings\Rob\Application Data\Uragl
c:\documents and settings\Rob\Application Data\Uragl\nace.tmp
c:\documents and settings\Rob\Application Data\Wyudu
c:\documents and settings\Rob\Application Data\Wyudu\osdo.afe
c:\documents and settings\Rob\Application Data\Wyudu\osdo.tmp
c:\documents and settings\Rob\Application Data\Xaaxy
c:\documents and settings\Rob\Application Data\Xaaxy\axih.exe
c:\documents and settings\Rob\Application Data\Yfni
c:\documents and settings\Rob\Application Data\Yfni\ovnaa.tmp
c:\documents and settings\Rob\Application Data\Yhwa\uneni.exe
c:\documents and settings\Rob\Application Data\Ylyhob
c:\documents and settings\Rob\Application Data\Ylyhob\peah.tmp
c:\documents and settings\Rob\Local Settings\Application Data\cjivwkphx\ikmlxmuuqiw.exe
c:\documents and settings\Rob\Local Settings\Application Data\ljcvwrpou\ichnraluqiw.exe
c:\documents and settings\Rob\Local Settings\Application Data\nbjdawicy\lkasifuuqiw.exe
C:\Microsoft
c:\progra~1\mcafee.com\agent\McUpdate .exe
c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe
c:\program files\DivX\DivX Update\DivXUpdate.exe
c:\program files\DNA\btdna .exe
c:\program files\DNA\btdna .exe
c:\program files\DNA\btdna .exe
c:\program files\DNA\btdna .exe
c:\program files\DNA\btdna .exe
c:\program files\DNA\btdna .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\ew1\setup .exe
c:\program files\Internet Explorer\complete.dat
c:\program files\Internet Explorer\dmlconf.dat
c:\program files\Internet Explorer\svchost.exe
c:\program files\iTunes\iTunesHelper.exe
c:\program files\McAfee.com\Personal Firewall\MpfTray.exe
c:\program files\McAfee.com\VSO\mcvsshld.exe
c:\program files\McAfee.com\VSO\oasclnt.exe
c:\program files\Microsoft\DesktopLayer.exe
c:\program files\Microsoft\DesktopLayerSrv.exe
c:\program files\Steam\steam.exe
c:\windows\ExplorerSrv.exe
c:\windows\Fonts\32Y1167.com
c:\windows\system32\config\systemprofile\32Y1167.com
c:\windows\system32\regsvr32Srv.exe
c:\windows\Tasks\At1.job
Code:
<pre>
c:\documents and settings\Rob\Application Data\Bifygy\zoorw .exe ---^> c:\documents and settings\Rob\Application Data\Bifygy\zoorw.exe
c:\documents and settings\Rob\Application Data\Opuqc\nexek .exe ---^> c:\documents and settings\Rob\Application Data\Opuqc\nexek.exe
c:\documents and settings\Rob\Application Data\Yhwa\uneni .exe ---^> c:\documents and settings\Rob\Application Data\Yhwa\uneni.exe
c:\documents and settings\Rob\Local Settings\Application Data\cjivwkphx\ikmlxmuuqiw .exe ---^> c:\documents and settings\Rob\Local Settings\Application Data\cjivwkphx\ikmlxmuuqiw.exe
c:\documents and settings\Rob\Local Settings\Application Data\ljcvwrpou\ichnraluqiw .exe ---^> c:\documents and settings\Rob\Local Settings\Application Data\ljcvwrpou\ichnraluqiw.exe
c:\documents and settings\Rob\Local Settings\Application Data\nbjdawicy\lkasifuuqiw .exe ---^> c:\documents and settings\Rob\Local Settings\Application Data\nbjdawicy\lkasifuuqiw.exe
</pre>
.
Infected copy of c:\windows\system32\drivers\ftdisk.sys was found and disinfected
Restored copy from - Kitty had a snack :p
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\winlogon.exe
Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\explorer.exe
.
((((((((((((((((((((((((( Files Created from 2010-09-10 to 2010-10-10 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Code:
<pre>
c:\program files\ATI Technologies\ATI.ACE\cli .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\aw1\setup .exe
c:\program files\Common Files\Ahead\Lib\NeroCheck .exe
c:\program files\Common Files\Ahead\Lib\NMBgMonitor .exe
c:\program files\Common Files\AOL\ACS\AOLDial .exe
c:\program files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler .exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier .exe
c:\program files\Common Files\InstallShield\UpdateService\issch .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Dell\Media Experience\DMXLauncher .exe
c:\program files\Dell Support\DSAgnt .exe
c:\program files\DivX\DivX Update\DivXUpdate .exe
c:\program files\DNA\btdna .exe
c:\program files\ew1\setup .exe
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
c:\program files\Internet Explorer\svchost .exe
c:\program files\iTunes\iTunesHelper .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\McAfee\SpamKiller\MSKAGE~1 .exe
c:\program files\McAfee.com\Agent\mcagent .exe
c:\program files\McAfee.com\Agent\MCUPDA~1 .exe
c:\program files\McAfee.com\Personal Firewall\MpfTray .exe
c:\program files\McAfee.com\VSO\mcmnhdlr .exe
c:\program files\McAfee.com\VSO\mcvsshld .exe
c:\program files\McAfee.com\VSO\oasclnt .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\QuickTime\QTTask .exe
c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher .exe
c:\program files\Steam\steam .exe
c:\program files\sys5\sol .exe
c:\program files\sys5\sol .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
c:\program files\Windows Live\Messenger\MsnMsgr .exe
</pre>
(((((((((((((((((((((((((((((
SnapShot@2010-08-08_15.59.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-01 16:34 . 2010-09-30 16:06 16384 c:\windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-10-10 18:48 . 2010-10-10 18:48 16384 c:\windows\temp\Perflib_Perfdata_750.dat
+ 2010-09-29 09:44 . 2010-09-29 09:44 56320 c:\windows\system32\WgaTraySrv.exe
+ 2010-09-25 18:22 . 2010-09-29 10:26 56320 c:\windows\system32\dwwinSrv.exe
+ 2010-09-25 18:23 . 2010-09-30 15:58 56320 c:\windows\system32\DLA\DLACTRLWSrv.exe
+ 2010-09-23 16:35 . 2010-09-23 16:35 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-09-29 17:03 . 2010-08-08 13:43 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-09-29 17:03 . 2010-09-23 16:35 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-09-23 16:35 . 2010-09-23 16:35 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-09-14 04:45 . 2010-10-06 00:08 35336 c:\windows\system32\32Y1167.com
+ 2010-09-25 18:23 . 2010-09-30 15:58 56320 c:\windows\stsystraSrv.exe
+ 2010-09-21 01:26 . 2010-09-21 01:26 25214 c:\windows\Installer\{171E6C1E-B5FC-11DF-B115-005056C00008}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2010-09-21 01:26 . 2010-09-21 01:26 25214 c:\windows\Installer\{171E6C1E-B5FC-11DF-B115-005056C00008}\ARPPRODUCTICON.exe
+ 2006-09-27 13:39 . 2010-10-04 21:10 10240 c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB.exe
- 2006-09-27 13:39 . 2007-06-12 18:05 10240 c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 69120 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\xlicons.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 69120 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\xlicons.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 35328 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\wordicon.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 35328 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\wordicon.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 30208 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\pptico.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 30208 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\pptico.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 11264 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\PEicons.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 11264 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\PEicons.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 28160 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\misc.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 28160 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\misc.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 73216 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\fpicon.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 73216 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\fpicon.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 22528 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\bindico.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 22528 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\bindico.exe
+ 2004-08-10 12:03 . 2010-08-15 10:33 4056 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2007-02-13 02:13 . 2010-10-04 21:10 7168 c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB5.exe
- 2007-02-13 02:13 . 2007-06-12 18:05 7168 c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB5.exe
- 2006-09-27 13:39 . 2007-06-12 18:05 7168 c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe
+ 2006-09-27 13:39 . 2010-10-04 21:10 7168 c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe
+ 2010-09-29 10:20 . 2010-09-29 10:22 563520 c:\windows\system32\Restore\rstrlog.dat
+ 2010-09-21 01:26 . 2010-09-21 01:26 874496 c:\windows\Installer\20bff595.msi
- 2009-08-11 23:22 . 2009-08-11 23:22 102400 c:\windows\Installer\{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}\iTunesIco.exe
+ 2009-08-11 23:22 . 2010-08-18 03:09 102400 c:\windows\Installer\{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}\iTunesIco.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 104960 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\outicon.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 104960 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\outicon.exe
- 2006-09-29 18:41 . 2006-09-29 18:41 155136 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\accicons.exe
+ 2006-09-29 18:41 . 2010-10-10 18:12 155136 c:\windows\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\accicons.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-17 39408]
"Steam"="c:\program files\steam\steam.exe" [N/A]
"{7AD1994C-E6B6-D453-2621-DFA5E501A564}"="c:\documents and settings\Rob\Application Data\Opuqc\nexek.exe" [2007-08-18 114176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe -startup" [X]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [N/A]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [N/A]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [N/A]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [N/A]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [N/A]
"VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [N/A]
"OASClnt"="c:\program files\McAfee.com\VSO\oasclnt.exe" [N/A]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [N/A]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [N/A]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 1121280]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"VirusScan Online"="c:\program files\McAfee.com\VSO\mcvsshld.exe" [N/A]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [N/A]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
acwe.exe [2010-9-22 107008]
dihuh.exe [2010-9-23 116224]
opela.exe [2010-10-4 114176]
oxmi.exe [2010-9-30 113664]
rogua.exe [2010-10-6 114176]
vewipi.exe [2010-9-23 116224]
vyyb.exe [2010-9-29 134144]
wiytca.exe [2010-9-23 116224]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
aqxaux.exe [2010-9-23 116224]
azxayq.exe [2010-9-23 116224]
ebaxx.exe [2010-9-22 107008]
epxeo.exe [2010-9-23 116224]
icqufi.exe [2010-10-4 114176]
laafu.exe [2010-9-23 116224]
moaqzi.exe [2010-9-29 134144]
pyabdi.exe [2010-9-30 113664]
wylyi.exe [2010-10-6 114176]
c:\documents and settings\Rob\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2010-1-6 3450608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-9-27 7168]
NETGEAR WPN111 Smart Wizard.lnk - c:\program files\NETGEAR\WPN111\wpn111.exe [2007-4-12 884838]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2009-11-1 119296]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,,c:\program files\mcafee.com\agent\mcdetectsrv.exe"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
c:\program files\QuickTime\QTTask .exe -atboottime [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
c:\program files\DNA\btdna .exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
c:\program files\DAEMON Tools Pro\DTProAgent.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
2005-07-22 23:25 28160 ----a-w- c:\windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MP4 Player]
c:\program files\MP4 Player\mp4Player.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
c:\program files\McAfee.com\Personal Firewall\MPFTray.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
c:\program files\Common Files\Ahead\Lib\NeroCheck.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ouccrasi]
2010-09-22 01:05 305664 ----a-w- c:\documents and settings\Rob\Local Settings\Application Data\nbjdawicy\lkasifuuqiw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qlwmxytv]
2010-09-22 00:38 305664 ----a-w- c:\documents and settings\Rob\Local Settings\Application Data\ljcvwrpou\ichnraluqiw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]
c:\program files\Rainlendar2\Rainlendar2.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2010-09-25 14:06 83968 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wscjiwos]
2010-09-22 00:26 305664 ----a-w- c:\documents and settings\Rob\Local Settings\Application Data\cjivwkphx\ikmlxmuuqiw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{6BCAE218-C949-5DD7-B5AA-C06EA2EC20F8}]
c:\documents and settings\Rob\Application Data\Azubep\ybro.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{7AD1994C-E6B6-D453-2621-DFA5E501A564}]
2007-04-18 08:27 116224 ----a-w- c:\documents and settings\Rob\Application Data\Yhwa\uneni.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{B2234604-1D67-796D-989D-7551FA679455}]
2007-01-04 10:04 125440 ----a-w- c:\documents and settings\Rob\Application Data\Bifygy\zoorw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Steam\\steamapps\\rob399\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\VentSrv\\ventrilo_srv.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Tortun\\gui.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Rob\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\peggle deluxe\\Peggle.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Age Of Empires 2 & The Conquerors Expansion - Full Game\\age2_x1.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\Rob\\My Documents\\utorrent.exe"=
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-07-08 721904]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 135664]
R2 RPCER;Remote Procedure Call (HNM);c:\program files\NetMeeting\comp.exe [x]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.SYS [2003-07-24 17149]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\DRIVERS\WPN111.sys [2005-09-26 362944]
.
Contents of the 'Scheduled Tasks' folder
2010-09-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 11:34]
2010-10-05 c:\windows\Tasks\At25.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At26.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At27.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At28.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At29.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At3.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At30.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At31.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-05 c:\windows\Tasks\At313.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At314.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At315.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At316.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At317.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At318.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At319.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At32.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At320.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At321.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At322.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-22 c:\windows\Tasks\At323.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-29 c:\windows\Tasks\At324.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-23 c:\windows\Tasks\At325.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-22 c:\windows\Tasks\At326.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-28 c:\windows\Tasks\At327.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-22 c:\windows\Tasks\At328.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-22 c:\windows\Tasks\At329.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At33.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-22 c:\windows\Tasks\At330.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-23 c:\windows\Tasks\At331.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At332.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-22 c:\windows\Tasks\At333.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-22 c:\windows\Tasks\At334.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-04 c:\windows\Tasks\At335.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-22 c:\windows\Tasks\At336.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At34.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-22 c:\windows\Tasks\At35.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-29 c:\windows\Tasks\At36.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-23 c:\windows\Tasks\At37.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-22 c:\windows\Tasks\At38.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-28 c:\windows\Tasks\At39.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At4.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-09-22 c:\windows\Tasks\At40.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-22 c:\windows\Tasks\At41.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-22 c:\windows\Tasks\At42.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-23 c:\windows\Tasks\At43.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-10 c:\windows\Tasks\At44.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-22 c:\windows\Tasks\At45.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-22 c:\windows\Tasks\At46.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-04 c:\windows\Tasks\At47.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-09-22 c:\windows\Tasks\At48.job
- c:\windows\system32\32Y1167.com [2010-09-14 00:08]
2010-10-06 c:\windows\Tasks\At5.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At6.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At7.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At769.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At770.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At771.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At772.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At773.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At774.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At775.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At776.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At777.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At778.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At779.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At780.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At781.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At782.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At783.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At784.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At785.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At786.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At787.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At788.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At789.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At790.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At791.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\At792.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At8.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-06 c:\windows\Tasks\At9.job
- c:\windows\Fonts\32Y1167.com [2010-10-10 00:08]
2010-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 03:53]
2010-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 03:53]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uSearch Page =
hxxp://www.google.comuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearch Bar =
hxxp://www.google.com/ieuInternet Settings,ProxyServer = http=127.0.0.1:50370
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Bejeweled 2 - c:\program files\Bejeweled 2\uninstall.exe
AddRemove-LimeWire - c:\program files\LimeWire\uninstall.exe
AddRemove-MP4 Player - c:\program files\MP4 Player\uninst.exe
AddRemove-Steam App 220 - c:\program files\Steam\steam.exe
AddRemove-Steam App 340 - c:\program files\Steam\steam.exe
AddRemove-Steam App 3482 - c:\program files\Steam\steam.exe
AddRemove-Steam App 3483 - c:\program files\Steam\steam.exe
AddRemove-Steam App 380 - c:\program files\Steam\steam.exe
AddRemove-Steam App 400 - c:\program files\Steam\steam.exe
AddRemove-Steam App 420 - c:\program files\Steam\steam.exe
AddRemove-Steam App 440 - c:\program files\Steam\steam.exe
AddRemove-BitTorrent DNA - c:\program files\DNA\btdna.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-147038334-2158946348-2334436982-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-147038334-2158946348-2334436982-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5e,3c,da,7b,39,6f,7f,b3,a4,e5,e1,c0,14,5f,93,01,18,dc,11,1c,85,19,a3,
ce,b2,85,42,49,fe,49,98,de,dd,51,fd,4c,11,2d,71,a6,f4,5e,f2,bf,ee,dd,ae,67,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
[HKEY_USERS\S-1-5-21-147038334-2158946348-2334436982-1006\Software\SecuROM\License information*]
"datasecu"=hex:e1,4d,2d,b6,16,e7,39,57,ab,55,5e,d8,87,ef,02,3e,9d,af,39,29,ab,
0d,62,cf,b5,b7,e4,f8,ee,43,8b,62,17,d2,54,64,dc,72,22,1b,6f,cd,0d,a6,72,62,\
"rkeysecu"=hex:5b,b1,f1,96,e6,e7,05,7e,0c,23,86,99,20,fc,03,4c
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3380)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\program files\Stardock\Fences\FencesMenu.dll
c:\program files\stardock\fences\DesktopDock.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\vso\mcshield.exe
c:\program files\Internet Explorer\iexplore.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\VentSrv\ventrilo_svc.exe
c:\program files\VentSrv\ventrilo_srv.exe
c:\windows\stsystra.exe
.
**************************************************************************
.
Completion time: 2010-10-10 20:11:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-10 19:11
ComboFix2.txt 2010-08-13 13:36
ComboFix3.txt 2010-08-09 21:02
ComboFix4.txt 2010-08-08 16:01
ComboFix5.txt 2010-10-10 18:37
Pre-Run: 1,374,904,320 bytes free
Post-Run: 1,268,649,984 bytes free
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 3375D342497B66F6FA27384177034414