NP
ComboFix 11-06-25.05 - XP PRO SP3 User 06/26/2011 9:31.2.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3327.2943 [GMT -4:00]
Running from: c:\documents and settings\XP PRO SP3 User\Desktop\commy.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\XP PRO SP3 User\Application Data\Mozilla\Firefox\Profiles\fmorhb5n.default\extensions\{938185b4-3363-46e6-8131-913c73cd9438}
c:\documents and settings\XP PRO SP3 User\Application Data\Mozilla\Firefox\Profiles\fmorhb5n.default\extensions\{938185b4-3363-46e6-8131-913c73cd9438}\chrome.manifest
c:\documents and settings\XP PRO SP3 User\Application Data\Mozilla\Firefox\Profiles\fmorhb5n.default\extensions\{938185b4-3363-46e6-8131-913c73cd9438}\chrome\xulcache.jar
c:\documents and settings\XP PRO SP3 User\Application Data\Mozilla\Firefox\Profiles\fmorhb5n.default\extensions\{938185b4-3363-46e6-8131-913c73cd9438}\defaults\preferences\xulcache.js
c:\documents and settings\XP PRO SP3 User\Application Data\Mozilla\Firefox\Profiles\fmorhb5n.default\extensions\{938185b4-3363-46e6-8131-913c73cd9438}\install.rdf
.
.
((((((((((((((((((((((((( Files Created from 2011-05-26 to 2011-06-26 )))))))))))))))))))))))))))))))
.
.
2011-06-26 13:29 . 2011-06-26 13:29 63115 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-06-26 13:29 . 2011-06-26 13:29 9310 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2011-06-26 13:29 . 2011-06-26 13:29 8646 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2011-06-26 13:29 . 2011-06-26 13:29 8613 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2011-06-26 13:29 . 2011-06-26 13:29 8288 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2011-06-26 13:29 . 2011-06-26 13:29 6910 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2011-06-26 13:29 . 2011-06-26 13:29 6429 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-06-26 13:29 . 2011-06-26 13:29 6208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2011-06-26 13:29 . 2011-06-26 13:29 5927 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2011-06-26 13:29 . 2011-06-26 13:29 4599 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-06-26 13:29 . 2011-06-26 13:29 18541 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2011-06-26 13:29 . 2011-06-26 13:29 1651 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2011-06-26 13:28 . 2011-06-26 13:28 8782 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2011-06-26 13:28 . 2011-06-26 13:28 7271 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2011-06-26 13:28 . 2011-06-26 13:28 51852 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2011-06-26 13:28 . 2011-06-26 13:28 23327 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2011-06-26 13:28 . 2011-06-26 13:28 20719 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2011-06-25 22:34 . 2011-05-29 13:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-25 22:34 . 2011-06-25 22:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-06-25 22:34 . 2011-05-29 13:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-23 00:26 . 2011-06-25 01:16 -------- d-----w- c:\program files\SBR Poker
2011-06-22 20:01 . 2011-04-30 08:50 766464 ------w- c:\windows\system32\dllcache\vgx.dll
2011-06-22 02:41 . 2011-06-22 03:20 -------- d-----w- C:\commy
2011-06-18 23:49 . 2011-06-18 23:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco
2011-06-18 23:49 . 2011-06-18 23:49 -------- d-----w- c:\program files\Raxco
2011-06-18 18:01 . 2011-06-18 18:01 -------- d-----w- c:\program files\DiskTrix
2011-06-18 14:44 . 2011-06-18 14:44 -------- d-----w- c:\documents and settings\XP PRO SP3 User\Application Data\IObit
2011-06-18 14:44 . 2011-06-18 14:44 -------- d-----w- c:\program files\IObit
2011-06-18 13:49 . 2011-06-18 13:49 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-06-16 20:26 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-12 14:58 . 2011-06-12 14:58 0 ---ha-w- c:\documents and settings\XP PRO SP3 User\nwfumzidgw.tmp
2011-06-12 03:36 . 2011-06-12 03:36 175616 ----a-w- c:\windows\system32\MPG4DMOD32.dll
2011-06-12 03:36 . 2011-06-12 03:36 350720 ----a-w- c:\windows\system32\azroles32.dll
2011-06-10 02:20 . 2011-06-10 02:20 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-06-06 04:12 . 2011-06-06 04:12 -------- d-----w- c:\documents and settings\XP PRO SP3 User\Local Settings\Application Data\Citrix
2011-06-02 21:54 . 2011-06-02 21:54 -------- d-----w- C:\NVIDIA
2011-06-02 21:24 . 2011-06-02 21:24 -------- d-----w- c:\documents and settings\LocalService\Application Data\Xfire
2011-06-02 02:26 . 2011-06-02 02:26 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2011-06-02 02:25 . 2011-06-02 02:25 -------- d-----w- c:\documents and settings\XP PRO SP3 User\Local Settings\Application Data\Funcom
2011-06-02 02:21 . 2011-06-04 01:01 -------- d-----w- c:\documents and settings\XP PRO SP3 User\Application Data\Xfire
2011-06-02 02:21 . 2011-06-02 02:21 -------- d-----w- c:\program files\Xfire
2011-06-02 02:18 . 2009-09-04 21:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-06-02 02:13 . 2011-06-02 02:13 -------- d-----w- c:\documents and settings\All Users\Application Data\media center programs
2011-06-02 02:13 . 2011-06-02 02:13 -------- d-----w- c:\program files\Funcom
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-25 06:09 . 2009-04-14 00:03 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-05-25 06:09 . 2009-04-14 00:03 154728 ----a-w- c:\windows\system32\nvsvc32.exe
2011-05-25 06:09 . 2009-04-14 00:03 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-05-25 06:09 . 2009-04-14 00:03 13895272 ----a-w- c:\windows\system32\nvcpl.dll
2011-05-25 06:09 . 2009-04-14 00:03 2808936 ----a-w- c:\windows\system32\nvcuvid.dll
2011-05-25 06:09 . 2009-04-14 00:03 16068608 ----a-w- c:\windows\system32\nvoglnt.dll
2011-05-25 06:09 . 2009-04-14 00:03 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-05-25 06:09 . 2009-04-14 00:03 5332992 ----a-w- c:\windows\system32\nvcuda.dll
2011-05-25 06:09 . 2009-04-14 00:03 4198272 ----a-w- c:\windows\system32\nv4_disp.dll
2011-05-25 06:09 . 2009-04-14 00:03 2328576 ----a-w- c:\windows\system32\nvapi.dll
2011-05-25 06:09 . 2009-04-14 00:03 12753664 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-05-02 15:31 . 2009-07-21 14:58 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2008-04-14 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 15:49 . 2008-06-19 20:42 841216 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 15:49 . 2008-04-14 12:00 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 15:49 . 2010-07-28 13:41 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-04-25 15:49 . 2008-06-19 20:42 17408 ----a-w- c:\windows\system32\corpol.dll
2011-04-25 11:36 . 2008-06-19 20:42 389120 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2008-04-14 12:00 105472 ----a-w- c:\windows\system32\drivers\mup.sys
2011-05-01 11:11 . 2011-03-31 18:31 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((
SnapShot@2011-06-22_03.16.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-06-26 13:28 . 2011-06-26 13:28 16384 c:\windows\temp\Perflib_Perfdata_5a4.dat
+ 2011-06-26 13:28 . 2011-06-26 13:28 16384 c:\windows\temp\Perflib_Perfdata_44c.dat
+ 2008-04-14 12:00 . 2011-04-25 15:49 44544 c:\windows\system32\pngfilt.dll
- 2008-04-14 12:00 . 2010-01-05 09:57 44544 c:\windows\system32\pngfilt.dll
- 2009-07-21 14:57 . 2010-01-05 09:57 52224 c:\windows\system32\msfeedsbs.dll
+ 2009-07-21 14:57 . 2011-04-25 15:49 52224 c:\windows\system32\msfeedsbs.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 27648 c:\windows\system32\jsproxy.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 27648 c:\windows\system32\jsproxy.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 44544 c:\windows\system32\iernonce.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 44544 c:\windows\system32\iernonce.dll
- 2008-06-19 20:42 . 2010-01-01 06:55 70656 c:\windows\system32\ie4uinit.exe
+ 2008-06-19 20:42 . 2011-04-25 11:35 70656 c:\windows\system32\ie4uinit.exe
- 2008-06-19 20:42 . 2010-01-05 09:57 63488 c:\windows\system32\icardie.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 63488 c:\windows\system32\icardie.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-12-31 15:33 . 2011-04-25 11:35 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2009-12-31 15:33 . 2010-01-01 06:55 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2010-01-05 10:00 . 2010-01-05 09:57 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 44544 c:\windows\system32\dllcache\iernonce.dll
- 2010-07-28 13:41 . 2010-01-05 09:57 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2010-07-28 13:41 . 2011-04-25 15:49 78336 c:\windows\system32\dllcache\ieencode.dll
- 2009-12-31 15:33 . 2010-01-01 06:55 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-12-31 15:33 . 2011-04-25 11:35 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2010-01-05 10:00 . 2011-04-25 15:49 63488 c:\windows\system32\dllcache\icardie.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 63488 c:\windows\system32\dllcache\icardie.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 17408 c:\windows\system32\dllcache\corpol.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 17408 c:\windows\system32\dllcache\corpol.dll
+ 2011-06-25 13:55 . 2011-06-25 14:16 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-21 15:05 . 2009-07-21 15:06 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-07-21 15:05 . 2011-06-25 14:16 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-06-25 13:55 . 2011-06-25 14:16 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-06-23 10:41 . 2010-01-05 09:57 44544 c:\windows\ie7updates\KB2530548-IE7\pngfilt.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 52224 c:\windows\ie7updates\KB2530548-IE7\msfeedsbs.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 27648 c:\windows\ie7updates\KB2530548-IE7\jsproxy.dll
+ 2011-06-23 10:41 . 2010-01-01 06:55 13824 c:\windows\ie7updates\KB2530548-IE7\ieudinit.exe
+ 2011-06-23 10:41 . 2010-01-05 09:57 44544 c:\windows\ie7updates\KB2530548-IE7\iernonce.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 78336 c:\windows\ie7updates\KB2530548-IE7\ieencode.dll
+ 2011-06-23 10:41 . 2010-01-01 06:55 70656 c:\windows\ie7updates\KB2530548-IE7\ie4uinit.exe
+ 2011-06-23 10:41 . 2010-01-05 09:57 63488 c:\windows\ie7updates\KB2530548-IE7\icardie.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 17408 c:\windows\ie7updates\KB2530548-IE7\corpol.dll
- 2008-04-14 12:00 . 2010-01-05 09:57 233472 c:\windows\system32\webcheck.dll
+ 2008-04-14 12:00 . 2011-04-25 15:49 233472 c:\windows\system32\webcheck.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 434176 c:\windows\system32\vbscript.dll
+ 2008-04-14 12:00 . 2011-03-04 06:45 434176 c:\windows\system32\vbscript.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 105984 c:\windows\system32\url.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 105984 c:\windows\system32\url.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 102912 c:\windows\system32\occache.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 102912 c:\windows\system32\occache.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 671232 c:\windows\system32\mstime.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 671232 c:\windows\system32\mstime.dll
+ 2008-04-14 12:00 . 2011-04-25 15:49 193024 c:\windows\system32\msrating.dll
- 2008-04-14 12:00 . 2010-01-05 09:57 193024 c:\windows\system32\msrating.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 478208 c:\windows\system32\mshtmled.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 468480 c:\windows\system32\msfeeds.dll
- 2008-04-14 12:00 . 2009-08-13 15:16 512000 c:\windows\system32\jscript.dll
+ 2008-04-14 12:00 . 2011-03-04 06:45 512000 c:\windows\system32\jscript.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 268288 c:\windows\system32\iertutil.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 268288 c:\windows\system32\iertutil.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 193024 c:\windows\system32\iepeers.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 388608 c:\windows\system32\iedkcs32.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 388608 c:\windows\system32\iedkcs32.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 380928 c:\windows\system32\ieapfltr.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 380928 c:\windows\system32\ieapfltr.dll
- 2008-06-19 20:42 . 2009-12-18 06:58 161792 c:\windows\system32\ieakui.dll
+ 2008-06-19 20:42 . 2011-04-21 10:33 161792 c:\windows\system32\ieakui.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 230400 c:\windows\system32\ieaksie.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 230400 c:\windows\system32\ieaksie.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 153088 c:\windows\system32\ieakeng.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 153088 c:\windows\system32\ieakeng.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 132608 c:\windows\system32\extmgr.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 132608 c:\windows\system32\extmgr.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 214528 c:\windows\system32\dxtrans.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 214528 c:\windows\system32\dxtrans.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 347136 c:\windows\system32\dxtmsft.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 347136 c:\windows\system32\dxtmsft.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 841216 c:\windows\system32\dllcache\wininet.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 841216 c:\windows\system32\dllcache\wininet.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 233472 c:\windows\system32\dllcache\webcheck.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2008-05-09 10:53 . 2011-03-04 06:45 434176 c:\windows\system32\dllcache\vbscript.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 105984 c:\windows\system32\dllcache\url.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 105984 c:\windows\system32\dllcache\url.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 102912 c:\windows\system32\dllcache\occache.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 102912 c:\windows\system32\dllcache\occache.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 671232 c:\windows\system32\dllcache\mstime.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 671232 c:\windows\system32\dllcache\mstime.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 193024 c:\windows\system32\dllcache\msrating.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 193024 c:\windows\system32\dllcache\msrating.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 478208 c:\windows\system32\dllcache\mshtmled.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 468480 c:\windows\system32\dllcache\msfeeds.dll
- 2010-03-02 12:14 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
+ 2010-03-02 12:14 . 2011-03-04 06:45 512000 c:\windows\system32\dllcache\jscript.dll
+ 2009-12-18 13:05 . 2011-04-21 10:34 634648 c:\windows\system32\dllcache\iexplore.exe
+ 2010-01-05 10:00 . 2011-04-25 15:49 268288 c:\windows\system32\dllcache\iertutil.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 193024 c:\windows\system32\dllcache\iepeers.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 388608 c:\windows\system32\dllcache\iedkcs32.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 388608 c:\windows\system32\dllcache\iedkcs32.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 380928 c:\windows\system32\dllcache\ieapfltr.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 380928 c:\windows\system32\dllcache\ieapfltr.dll
- 2009-12-18 13:04 . 2009-12-18 06:58 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2009-12-18 13:04 . 2011-04-21 10:33 161792 c:\windows\system32\dllcache\ieakui.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 132608 c:\windows\system32\dllcache\extmgr.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 132608 c:\windows\system32\dllcache\extmgr.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 124928 c:\windows\system32\dllcache\advpack.dll
- 2010-01-05 10:00 . 2010-01-05 09:57 124928 c:\windows\system32\dllcache\advpack.dll
- 2008-06-19 20:42 . 2010-01-05 09:57 124928 c:\windows\system32\advpack.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 124928 c:\windows\system32\advpack.dll
+ 2011-06-23 10:41 . 2008-06-19 20:42 765952 c:\windows\ie7updates\KB2544521-IE7\vgx.dll
+ 2011-06-23 10:41 . 2010-07-05 13:16 382840 c:\windows\ie7updates\KB2544521-IE7\spuninst\updspapi.dll
+ 2011-06-23 10:41 . 2010-07-05 13:15 231288 c:\windows\ie7updates\KB2544521-IE7\spuninst\spuninst.exe
+ 2011-06-23 10:41 . 2010-01-05 09:57 841216 c:\windows\ie7updates\KB2530548-IE7\wininet.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 233472 c:\windows\ie7updates\KB2530548-IE7\webcheck.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 105984 c:\windows\ie7updates\KB2530548-IE7\url.dll
+ 2011-06-23 10:41 . 2010-07-05 13:16 382840 c:\windows\ie7updates\KB2530548-IE7\spuninst\updspapi.dll
+ 2011-06-23 10:41 . 2010-07-05 13:15 231288 c:\windows\ie7updates\KB2530548-IE7\spuninst\spuninst.exe
+ 2011-06-23 10:41 . 2010-01-05 09:57 102912 c:\windows\ie7updates\KB2530548-IE7\occache.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 671232 c:\windows\ie7updates\KB2530548-IE7\mstime.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 193024 c:\windows\ie7updates\KB2530548-IE7\msrating.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 477696 c:\windows\ie7updates\KB2530548-IE7\mshtmled.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 459264 c:\windows\ie7updates\KB2530548-IE7\msfeeds.dll
+ 2011-06-23 10:41 . 2009-12-18 07:00 634632 c:\windows\ie7updates\KB2530548-IE7\iexplore.exe
+ 2011-06-23 10:41 . 2010-01-05 09:57 268288 c:\windows\ie7updates\KB2530548-IE7\iertutil.dll
+ 2011-06-23 10:41 . 2010-01-05 10:00 192512 c:\windows\ie7updates\KB2530548-IE7\iepeers.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 388608 c:\windows\ie7updates\KB2530548-IE7\iedkcs32.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 380928 c:\windows\ie7updates\KB2530548-IE7\ieapfltr.dll
+ 2011-06-23 10:41 . 2009-12-18 06:58 161792 c:\windows\ie7updates\KB2530548-IE7\ieakui.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 230400 c:\windows\ie7updates\KB2530548-IE7\ieaksie.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 153088 c:\windows\ie7updates\KB2530548-IE7\ieakeng.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 132608 c:\windows\ie7updates\KB2530548-IE7\extmgr.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 214528 c:\windows\ie7updates\KB2530548-IE7\dxtrans.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 347136 c:\windows\ie7updates\KB2530548-IE7\dxtmsft.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 124928 c:\windows\ie7updates\KB2530548-IE7\advpack.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 1172480 c:\windows\system32\urlmon.dll
+ 2008-04-14 12:00 . 2011-04-25 15:49 3610624 c:\windows\system32\mshtml.dll
+ 2008-06-19 20:42 . 2011-04-25 15:49 6081024 c:\windows\system32\ieframe.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 1172480 c:\windows\system32\dllcache\urlmon.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 3610624 c:\windows\system32\dllcache\mshtml.dll
+ 2010-01-05 10:00 . 2011-04-25 15:49 6081024 c:\windows\system32\dllcache\ieframe.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 1170944 c:\windows\ie7updates\KB2530548-IE7\urlmon.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 3602944 c:\windows\ie7updates\KB2530548-IE7\mshtml.dll
+ 2011-06-23 10:41 . 2010-01-05 09:57 6071296 c:\windows\ie7updates\KB2530548-IE7\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D7F23B4-52D8-4281-9049-59E58F87FA04}]
2011-06-12 03:36 350720 ----a-w- c:\windows\system32\azroles32.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D1875F6F-629F-1803-DEA7-6D668C1CD327}]
2011-06-12 03:36 175616 ----a-w- c:\windows\system32\MPG4DMOD32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 139264]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-06-25 2424192]
"DVDXGhost"="" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"SkyTel"="SkyTel.EXE" [2007-11-20 1826816]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-05-21 1501064]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 1468296]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-06-01 33624064]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-22 221184]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"VERIZONDM"="c:\program files\VERIZONDM\bin\sprtcmd.exe" [2010-09-29 206120]
"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 243544]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-05-25 13895272]
"NvMediaCenter"="NvMCTray.dll" [2011-05-25 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-05-05 1632360]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [2011-04-25 124928]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{569DAC0F-2791-46ab-8EFC-A54B77C04C20}"= "c:\program files\DVD X Studios\DVD X Utilities V2.1.1\DVDGhost\ExecuteHooker.dll" [2005-11-14 90112]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKLM\~\startupfolder\C:^Documents and Settings^XP PRO SP3 User^Start Menu^Programs^Startup^Styler.lnk]
path=c:\documents and settings\XP PRO SP3 User\Start Menu\Programs\Startup\Styler.lnk
backup=c:\windows\pss\Styler.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sony\\EverQuest II\\EQ2VoiceService.exe"=
"c:\\Documents and Settings\\XP PRO SP3 User\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Funcom\\Age of Conan\\ConanPatcher.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Funcom\\Age of Conan\\AgeOfConan.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"50000:UDP"= 50000:UDP:IHA_MessageCenter
"67:UDP"= 67:UDP:DHCP Server
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
R2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [10/13/2010 6:06 PM 118784]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [6/2/2011 5:55 PM 2214504]
R2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\VERIZONDM\bin\sprtsvc.exe [9/29/2010 7:00 AM 206120]
R2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\VERIZONDM\bin\tgsrvc.exe [9/29/2010 7:00 AM 185640]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/25/2011 6:34 PM 22712]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [8/9/2009 9:35 AM 1358720]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/25/2011 6:34 PM 366640]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/25/2011 6:34 PM 39984]
S3 XDva296;XDva296;\??\c:\windows\system32\XDva296.sys --> c:\windows\system32\XDva296.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WUAUSERV
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 11:50]
.
2010-02-25 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2009-05-26 19:16]
.
2011-06-26 c:\windows\Tasks\User_Feed_Synchronization-{479ED8AD-700D-40D2-AAC4-5341B9455E95}.job
- c:\windows\system32\msfeedssync.exe [2009-07-21 17:36]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.msn.comuInternet Settings,ProxyOverride =
TCP: DhcpNameServer = 192.168.1.1 71.252.0.12
FF - ProfilePath - c:\documents and settings\XP PRO SP3 User\Application Data\Mozilla\Firefox\Profiles\fmorhb5n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=SOLTDF&PC=SUN1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.unlimitedcomputers.co.uk/
FF - prefs.js: network.proxy.type - 0
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-26 09:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\WININET.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
- - - - - - - > 'lsass.exe'(740)
c:\windows\system32\WININET.dll
.
Completion time: 2011-06-26 09:43:03
ComboFix-quarantined-files.txt 2011-06-26 13:42
ComboFix2.txt 2011-06-22 03:19
ComboFix3.txt 2010-08-14 01:53
ComboFix4.txt 2010-08-14 01:27
.
Pre-Run: 946,152,046,592 bytes free
Post-Run: 946,152,148,992 bytes free
.
- - End Of File - - 361127DD53C083C9518BC81A4086FC97