(((((((((((((((((((((((((((((
SnapShot@2009-05-21_06.24.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-28 08:30 . 2009-05-28 08:30 16384 c:\windows\temp\Perflib_Perfdata_ec.dat
+ 2009-05-28 08:30 . 2009-05-28 08:30 16384 c:\windows\temp\Perflib_Perfdata_5e0.dat
+ 2009-05-26 05:31 . 2005-12-06 01:07 61136 c:\windows\system32\xinput9_1_0.dll
+ 2009-05-26 05:32 . 2006-03-31 19:39 62672 c:\windows\system32\xinput1_1.dll
+ 2009-05-26 05:31 . 2006-02-03 15:41 14032 c:\windows\system32\x3daudio1_0.dll
+ 2009-05-21 06:57 . 2006-12-01 15:45 20480 c:\windows\system32\wltrysvc.exe
+ 2009-05-21 06:57 . 2006-12-01 15:45 44032 c:\windows\system32\wltrynt.dll
+ 2002-12-31 12:00 . 2009-05-21 07:07 63334 c:\windows\system32\perfc009.dat
- 2002-12-31 12:00 . 2009-05-19 23:31 63334 c:\windows\system32\perfc009.dat
+ 2009-05-21 06:57 . 2006-12-01 15:45 33664 c:\windows\system32\drivers\bcmwlnpf.sys
+ 2009-05-21 06:57 . 2005-02-02 01:18 17992 c:\windows\system32\drivers\bcm42rly.sys
+ 2009-05-21 06:57 . 2006-12-01 15:45 69632 c:\windows\system32\bcmwlpkt.dll
+ 2009-05-21 06:57 . 2006-12-01 15:45 81920 c:\windows\system32\bcmwliss.dll
+ 2009-05-26 05:32 . 2005-03-18 23:23 12800 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2009-05-26 05:32 . 2005-03-18 23:23 53248 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-05-27 00:08 . 2009-05-27 00:08 10134 c:\windows\Installer\{7396F7C8-EDD8-4473-BF6A-2CE4996716E1}\SystemFolder_msiexec.exe
+ 2009-05-26 05:32 . 2009-05-26 05:32 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-05-26 05:32 . 2006-05-31 14:24 230168 c:\windows\system32\xactengine2_2.dll
+ 2009-05-26 05:32 . 2006-03-31 19:39 229584 c:\windows\system32\xactengine2_1.dll
+ 2009-05-26 05:31 . 2006-02-03 15:42 230096 c:\windows\system32\xactengine2_0.dll
+ 2009-05-21 07:06 . 2006-11-30 23:53 610816 c:\windows\system32\ReinstallBackups\
0013\DriverFiles\BCMWL5.SYS
+ 2002-12-31 12:00 . 2009-05-21 07:07 403858 c:\windows\system32\perfh009.dat
- 2002-12-31 12:00 . 2009-05-19 23:31 403858 c:\windows\system32\perfh009.dat
+ 2009-05-21 06:57 . 2006-11-30 23:53 610816 c:\windows\system32\drivers\BCMWL5.SYS
+ 2009-05-21 06:57 . 2006-12-01 15:45 184320 c:\windows\system32\bcmwlu00.exe
+ 2009-05-21 06:57 . 2006-12-01 15:45 700416 c:\windows\system32\BCMLogon.dll
+ 2009-05-21 06:57 . 2007-03-06 17:14 765952 c:\windows\system32\bcm1xsup.dll
+ 2009-05-26 05:32 . 2006-03-31 18:27 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2006-02-03 14:40 578560 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2005-12-06 00:20 577536 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2005-09-28 21:11 577536 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2005-07-23 00:21 577024 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2005-05-26 22:15 576000 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2005-03-19 00:23 567296 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2005-02-06 02:32 563712 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2005-03-18 23:23 223232 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2009-05-26 05:32 . 2005-03-18 23:23 178176 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2009-05-26 05:32 . 2005-03-18 23:23 364544 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2009-05-26 05:32 . 2005-03-18 23:23 159232 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2009-05-26 05:32 . 2005-03-18 23:23 145920 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2009-05-26 05:32 . 2005-03-18 23:23 473600 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-05-21 06:57 . 2007-03-02 18:20 1282048 c:\windows\system32\wltray.exe
+ 2009-05-21 06:57 . 2006-12-01 15:45 2129920 c:\windows\system32\WLBCGCBPRO731.DLL
+ 2009-05-26 05:31 . 2006-03-31 19:40 2388176 c:\windows\system32\d3dx9_30.dll
+ 2009-05-26 05:31 . 2006-02-03 15:43 2332368 c:\windows\system32\d3dx9_29.dll
+ 2009-05-26 05:31 . 2005-12-06 01:09 2323664 c:\windows\system32\d3dx9_28.dll
+ 2009-05-26 05:31 . 2005-07-23 02:59 2319568 c:\windows\system32\d3dx9_27.dll
+ 2009-05-26 05:31 . 2005-03-19 00:19 2337488 c:\windows\system32\d3dx9_25.dll
+ 2009-05-26 05:31 . 2005-02-06 02:45 2222800 c:\windows\system32\d3dx9_24.dll
+ 2009-05-21 06:57 . 2007-03-06 17:24 1146880 c:\windows\system32\bcmwltry.exe
+ 2009-05-26 05:32 . 2004-12-01 22:53 2846720 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2004-09-29 19:38 2676224 c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:32 . 2009-05-26 05:32 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-26 05:31 . 2009-05-26 05:31 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7c5c0f58-e061-457d-9033-77307f5ed00c}]
2008-05-21 08:43 1526296 -c--a-w c:\program files\TorrentMan\tbTorr.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-03-02 1282048]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dynex Wireless Networking Utility.lnk - c:\program files\Dynex G Desktop Card Adapter\DynexWCUI.exe [2009-5-21 1462272]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 -c--a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
[BU]
[HKLM\~\startupfolder\C:^Documents and Settings^Rayne^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
backup=c:\windows\pss\PowerReg Scheduler V3.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Rayne^Start Menu^Programs^Startup^Ultra Hal Assistant Startup.lnk]
backup=c:\windows\pss\Ultra Hal Assistant Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\InterVideo\\DVD5\\WinDVD.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\NeverwinterNights\\NWN\\nwmain.exe"=
"c:\\KARI3PRO\\Kari3Pro.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Dynex G Desktop Card Adapter\\DynexWCUI.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\SDUpdate.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/21/2009 12:59 AM 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/21/2009 12:59 AM 20560]
R2 Cepstral License Server;Cepstral License Server;c:\program files\Cepstral\bin\CepstralLicSrv.exe [6/25/2008 6:18 PM 57344]
R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [6/30/2008 8:09 PM 72672]
S0 Ramdisk;Ramdisk Driver;c:\windows\system32\drivers\RamDsk.sys [9/27/2004 7:00 PM 26240]
S3 FileObjInfo;STFileDriver;\??\c:\documents and settings\All Users\Application Data\Spyware Terminator\FileObjInfo.sys --> c:\documents and settings\All Users\Application Data\Spyware Terminator\FileObjInfo.sys [?]
S3 jgameenp;jgameenp;\??\c:\docume~1\Rayne\LOCALS~1\Temp\jgameenp.sys --> c:\docume~1\Rayne\LOCALS~1\Temp\jgameenp.sys [?]
S3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [5/17/2008 5:04 PM 7548]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [3/10/2009 10:58 PM 0]
S4 Stuffit Archive Name Service;Stuffit Archive Name Service;"c:\program files\Smith Micro\StuffIt 2009\ArcNameService.exe" --> c:\program files\Smith Micro\StuffIt 2009\ArcNameService.exe [?]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page =
www.google.commSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.htmlDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: SOFTWARE
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-28 01:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(864)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-28 1:45
ComboFix-quarantined-files.txt 2009-05-28 08:45
ComboFix2.txt 2009-05-21 06:27
ComboFix3.txt 2009-05-18 17:27
ComboFix4.txt 2009-04-07 23:06
ComboFix5.txt 2009-05-28 08:34
Pre-Run: 834,002,944 bytes free
Post-Run: 877,174,784 bytes free
297