combofix log:ComboFix 08-07-27.5 - Administrator 2008-07-28 11:28:11.3 - NTFSx86
Windows Windows Vista™ Extreme Edition 6.0.6001.1.1252.1.1033.18.852 [GMT -4:00]
Running from: D:\Downloads\ComboFix.exe
Command switches used :: D:\Downloads\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\546637617
C:\cuhv.exe
C:\Windows\System32\winfsy32.rom
C:\xxdxsn.exe
.
/wow section - STAGE 40
SED: can't read MWindows.dat: No such file or directory
pv: No matching processes found
SED: can't read MWindows.dat: No such file or directory
The syntax of the command is incorrect.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\546637617
C:\cuhv.exe
C:\VundoFix Backups
C:\Windows\System32\349168
C:\Windows\System32\371186
C:\Windows\System32\winfsy32.rom
C:\xxdxsn.exe
.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))
.
2008-07-28 10:29 . <DIR> C:\Windows\LastGood.Tmp
2008-07-28 09:54 . 2008-07-28 09:54 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-28 09:16 . 2008-07-28 09:16 120 --a------ C:\4223.bat
2008-07-27 18:16 . 2008-07-27 18:16 <DIR> d-------- C:\Deckard
2008-07-26 21:36 . 2008-07-26 21:36 91 --a------ C:\Windows\wininit.ini
2008-07-26 21:01 . 2008-07-26 21:21 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-07-26 21:01 . 2008-07-26 21:21 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-07-26 21:01 . 2008-07-26 21:01 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-26 20:30 . 2008-03-03 14:25 5,702 --ah----- C:\Windows\nod32restoretemdono.reg
2008-07-26 18:05 . 2008-07-28 08:50 145 --a------ C:\Windows\System32\winver.bat
2008-07-25 19:02 . 2008-07-25 19:02 <DIR> d-------- C:\Program Files\Live Mesh
2008-07-25 19:02 . 2008-07-25 19:02 121,984 --a------ C:\Windows\System32\rdpdispd.dll
2008-07-25 19:02 . 2008-07-25 19:02 12,288 --a------ C:\Windows\System32\drivers\rdpdispm.sys
2008-07-24 19:45 . 2008-07-24 19:45 <DIR> d-------- C:\Users\Administrator\AppData\Roaming\Orca Profiles
2008-07-24 19:44 . 2008-07-24 19:45 <DIR> d-------- C:\Program Files\Orca
2008-07-24 18:09 . 2008-07-24 18:11 210,454,727 --a------ C:\Windows\MEMORY.DMP
2008-07-15 17:51 . 2008-07-15 17:54 <DIR> d-------- C:\Program Files\cryptload
2008-07-11 23:22 . 2008-07-11 23:22 <DIR> d-------- C:\Users\All Users\Last.fm
2008-07-11 23:22 . 2008-07-11 23:22 <DIR> d-------- C:\ProgramData\Last.fm
2008-07-11 23:21 . 2008-07-11 23:21 <DIR> d-------- C:\Program Files\Last.fm
2008-07-11 19:15 . 2008-06-25 21:45 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-07-11 19:15 . 2008-06-25 21:45 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-07-11 19:15 . 2008-06-25 23:29 801,280 --a------ C:\Windows\System32\NaturalLanguage6.dll
2008-07-08 22:42 . 2007-05-16 16:45 3,497,832 --a------ C:\Windows\System32\d3dx9_34.dll
2008-07-06 21:58 . 2008-07-12 12:25 <DIR> d-------- C:\Users\Administrator\AppData\Roaming\Twessenger
2008-07-06 21:54 . 2008-07-06 21:54 <DIR> d-------- C:\Program Files\Twessenger
2008-07-06 18:38 . 2008-07-06 18:38 <DIR> d-------- C:\Program Files\Vista Rainbar
2008-07-06 13:48 . 2008-07-06 13:48 <DIR> d-------- C:\Windows\Sun
2008-07-04 22:13 . 2008-04-01 15:41 <DIR> d-------- C:\temp\utilities
2008-07-04 22:13 . 2008-04-01 15:41 <DIR> d-------- C:\temp\lr_skins
2008-07-04 22:13 . 2008-04-01 15:41 <DIR> d-------- C:\temp\icons
2008-07-04 22:13 . 2008-04-01 15:41 <DIR> d-------- C:\temp\hr_skins
2008-07-04 22:13 . 2008-04-01 15:41 <DIR> d-------- C:\temp\clock_skins
2008-07-04 22:13 . 2006-03-09 21:42 357,888 --a------ C:\temp\CSCPDA.exe
2008-07-04 21:00 . 2008-07-04 21:00 <DIR> d-------- C:\Program Files\TapTarget.com
2008-07-04 21:00 . 2004-01-19 12:12 122,880 --a------ C:\Windows\ctpu.exe
2008-07-04 21:00 . 2002-06-19 04:32 57,344 --a------ C:\Windows\System32\CiAPI.dll
2008-07-04 20:59 . 2004-01-10 10:50 57,344 --a------ C:\Windows\ResENU.dll
2008-07-04 19:39 . 2008-07-04 19:39 <DIR> d-------- C:\temp\ZLTCrystal
2008-07-04 17:41 . 2008-07-12 08:04 15 --a------ C:\Windows\MobilePaint.ini
2008-07-04 17:39 . 2008-07-04 22:14 <DIR> d-------- C:\temp
2008-07-04 16:53 . 2008-07-04 16:58 <DIR> d-------- C:\Program Files\SplashData
2008-07-03 17:26 . 2008-07-03 17:33 <DIR> d-------- C:\Program Files\QTTabbar
2008-07-03 13:36 . 2008-07-03 13:36 <DIR> d-------- C:\Users\Administrator\AppData\Roaming\GeoVid
2008-07-03 13:02 . 2008-07-03 13:02 <DIR> d-------- C:\Users\All Users\GeoVid
2008-07-03 13:02 . 2008-07-03 13:02 <DIR> d-------- C:\ProgramData\GeoVid
2008-07-03 13:02 . 2008-07-03 13:02 <DIR> d-------- C:\Program Files\Common Files\GeoVid
2008-07-03 13:02 . 2004-08-18 16:00 1,712,128 --a------ C:\Windows\System32\gdiplus.dll
2008-07-03 13:02 . 2003-03-19 09:12 1,047,552 --a------ C:\Windows\System32\mfc71u.dll
2008-07-03 13:02 . 2007-06-28 19:52 765,952 --a------ C:\Windows\System32\xvidcore.dll
2008-07-03 13:02 . 2007-06-28 19:54 180,224 --a------ C:\Windows\System32\xvidvfw.dll
2008-07-03 13:02 . 2003-03-19 07:05 89,088 --a------ C:\Windows\System32\atl71.dll
2008-07-03 13:02 . 2005-06-07 16:11 60,416 --a------ C:\Windows\System32\dsetup.dll
2008-07-03 13:00 . 2008-07-03 13:00 <DIR> d-------- C:\Program Files\GeoVid
2008-07-02 22:20 . 2008-07-26 20:23 69 --a------ C:\Windows\NeroDigital.ini
2008-07-02 22:18 . 2008-07-02 22:18 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-29 18:13 . 2008-06-29 18:13 140,288 --a------ C:\Windows\System32\COMDLG32.OCX
2008-06-29 18:05 . 2008-06-29 18:05 <DIR> d-------- C:\Program Files\zSuite
2008-06-29 13:20 . 2008-06-29 13:20 <DIR> d-------- C:\Program Files\ThatLook
2008-06-29 13:20 . 1996-07-18 13:06 297,472 --a------ C:\Windows\uninst.exe
2008-06-29 13:20 . 2000-07-19 14:42 126 --a------ C:\Windows\TL_Image.ini
2008-06-29 12:58 . 2008-06-29 13:12 <DIR> d-------- C:\Program Files\VPSS
2008-06-28 11:24 . 2008-06-30 20:26 <DIR> d-------- C:\Users\Administrator\AppData\Roaming\gtk-2.0
2008-06-28 11:24 . 2008-06-28 11:24 <DIR> d-------- C:\Users\Administrator\.thumbnails
2008-06-28 11:21 . 2008-06-30 21:20 <DIR> d-------- C:\Users\Administrator\.gimp-2.4
2008-06-28 11:20 . 2008-06-28 11:21 <DIR> d-------- C:\Program Files\GIMP-2.0
2008-06-28 01:32 . 2008-06-28 01:32 <DIR> d-------- C:\Users\All Users\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 14:46 --------- d-----w C:\Users\Administrator\AppData\Roaming\uTorrent
2008-07-28 14:38 --------- d-----w C:\ProgramData\FLEXnet
2008-07-28 13:51 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-28 01:40 --------- d-----w C:\ProgramData\Rosetta Stone
2008-07-27 00:25 --------- d-----w C:\ProgramData\ESET
2008-07-27 00:25 --------- d-----w C:\Program Files\ESET
2008-07-26 19:40 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-07-24 21:10 --------- d-----w C:\Program Files\Google
2008-07-12 12:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-12 12:04 --------- d-----w C:\Program Files\Palm
2008-07-12 12:03 --------- d-----w C:\Users\Administrator\AppData\Roaming\Flock
2008-07-11 23:21 --------- d-----w C:\ProgramData\Microsoft Help
2008-07-10 07:12 --------- d-----w C:\Program Files\Windows Mail
2008-07-09 02:07 --------- d-----w C:\Program Files\Picasa2
2008-07-01 01:58 140 ----a-w C:\Users\Administrator\.hemsFavorites.dat
2008-06-28 01:22 --------- d-----w C:\Program Files\Rosetta Stone
2008-06-28 01:13 --------- d-----w C:\Program Files\Nero
2008-06-28 01:06 --------- d-----w C:\Users\Administrator\AppData\Roaming\Nero
2008-06-28 01:03 --------- d-----w C:\Program Files\Common Files\Nero
2008-06-28 01:01 --------- d-----w C:\ProgramData\Nero
2008-06-26 15:01 --------- d-----w C:\ProgramData\ALM
2008-06-26 13:57 --------- d-----w C:\Program Files\Bonjour
2008-06-26 13:44 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-06-26 03:34 662 ---ha-w C:\os049389.bin
2008-06-26 00:50 --------- d-----w C:\Program Files\Common Files\Vbox
2008-06-26 00:04 --------- d-----w C:\Program Files\%temp&
2008-06-25 23:54 --------- d-----w C:\Users\Administrator\AppData\Roaming\ESET
2008-06-25 22:05 130,208 ------r C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
2008-06-24 04:28 127,034 ------r C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2008-06-24 04:28 --------- d-----w C:\Program Files\Logitech
2008-06-24 04:25 --------- d-----w C:\Program Files\Common Files\LogiShrd
2008-06-24 04:25 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-24 04:23 --------- d-----w C:\ProgramData\Logitech
2008-06-24 04:23 --------- d-----w C:\ProgramData\LogiShrd
2008-06-24 04:23 --------- d-----w C:\Program Files\QuickCam
2008-06-23 23:42 --------- d-----w C:\Users\Administrator\AppData\Roaming\Notepad++
2008-06-23 22:10 --------- d-----w C:\Program Files\Notepad++
2008-06-23 20:59 --------- d-----w C:\Program Files\Java
2008-06-23 20:55 --------- d-----w C:\Program Files\Common Files\Java
2008-06-23 20:20 --------- d-----w C:\Users\Administrator\AppData\Roaming\GetRightToGo
2008-06-23 17:58 --------- d-----w C:\Program Files\1Time
2008-06-23 00:42 --------- d-----w C:\Users\Administrator\AppData\Roaming\MessengerGadget
2008-06-22 23:50 --------- d-----w C:\Program Files\1Click DVD Copy Pro
2008-06-22 23:34 --------- d-----w C:\ProgramData\vsosdk
2008-06-22 23:07 --------- d-----w C:\Users\Administrator\AppData\Roaming\Vso
2008-06-22 23:06 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys
2008-06-22 23:06 47,360 ----a-w C:\Users\Administrator\AppData\Roaming\pcouffin.sys
2008-06-22 05:10 --------- d-----w C:\Program Files\Real Alternative
2008-06-22 04:34 --------- d-----w C:\Program Files\Essentials Codec Pack
2008-06-21 22:47 --------- d-----w C:\Users\Administrator\AppData\Roaming\muvee Technologies
2008-06-21 15:01 --------- d-----w C:\Program Files\Cucusoft
2008-06-21 14:27 --------- d-----w C:\Program Files\QuickTime
2008-06-21 14:25 --------- d-----w C:\ProgramData\Apple Computer
2008-06-21 14:24 --------- d-----w C:\ProgramData\Apple
2008-06-21 14:24 --------- d-----w C:\Program Files\Apple Software Update
2008-06-21 14:21 --------- d-----w C:\Program Files\Common Files\muvee Technologies
2008-06-21 14:20 --------- d-----w C:\Program Files\muvee Technologies
2008-06-21 14:19 --------- d-----w C:\ProgramData\muvee Technologies
2008-06-20 13:33 0 ---ha-w C:\Windows\system32\drivers\Msft_User_ZuneDriver_01_00_00.Wdf
2008-06-19 07:01 --------- d-----w C:\Program Files\MSXML 4.0
2008-06-19 06:30 --------- d-----w C:\Program Files\Palm Inc
2008-06-19 06:24 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-06-19 06:07 --------- d-----w C:\Users\Administrator\AppData\Roaming\Arcsoft
2008-06-19 06:06 --------- d-----w C:\Users\Administrator\AppData\Roaming\HotSync
2008-06-19 06:06 --------- d-----w C:\ProgramData\HotSync
2008-06-19 05:47 --------- d-----w C:\ProgramData\Messenger Plus!
2008-06-19 05:45 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-19 03:07 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-06-19 02:15 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-19 02:15 --------- d-----w C:\Program Files\Windows Live
2008-06-19 02:02 --------- d-----w C:\ProgramData\WLInstaller
2008-06-17 01:40 --------- d-----w C:\Program Files\Microsoft Games
2008-06-17 01:15 --------- d-----w C:\Program Files\CONEXANT
2008-06-17 00:38 --------- d-----w C:\Program Files\Hawking
2008-06-16 22:47 --------- d-----w C:\Users\Administrator\AppData\Roaming\InstallShield
2008-06-16 22:47 --------- d-----w C:\Program Files\Evernote
2008-06-16 22:24 --------- d-----w C:\Program Files\Zune
2008-06-16 22:21 --------- d-----w C:\Program Files\uTorrent
2008-06-16 22:03 --------- d-----w C:\Users\Administrator\AppData\Roaming\Intel
2008-06-16 22:03 --------- d-----w C:\ProgramData\Roaming
2008-06-16 22:02 --------- d-----w C:\ProgramData\Intel
2008-06-16 22:02 --------- d-----w C:\Program Files\PROnetworks
2008-06-16 22:01 --------- d-----w C:\Program Files\Intel
2008-06-16 21:33 --------- d-----w C:\Users\Administrator\AppData\Roaming\Launchy
2008-06-16 21:33 --------- d-----w C:\Program Files\Launchy
2008-06-16 21:32 --------- d-----w C:\Program Files\RocketDock
2008-06-16 21:09 --------- d-----w C:\Program Files\MSBuild
2008-06-16 21:05 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-16 21:05 --------- d-----w C:\Program Files\Microsoft Works
2008-06-16 19:05 --------- d-----w C:\Program Files\7-Zip
2008-06-16 19:04 --------- d-----w C:\ProgramData\Stardock
2008-06-16 19:04 --------- d-----w C:\Program Files\Stardock
2008-06-16 18:58 174 --sha-w C:\Program Files\desktop.ini
2008-05-10 03:35 564,736 ----a-w C:\Windows\System32\emdmgmt.dll
2008-05-08 21:59 90,112 ----a-w C:\Windows\System32\wshext.dll
2008-05-08 21:59 430,080 ----a-w C:\Windows\System32\vbscript.dll
2008-05-08 21:59 180,224 ----a-w C:\Windows\System32\scrobj.dll
2008-05-08 21:59 172,032 ----a-w C:\Windows\System32\scrrun.dll
2008-05-08 21:59 155,648 ----a-w C:\Windows\System32\wscript.exe
2008-05-08 21:58 135,168 ----a-w C:\Windows\System32\cscript.exe
.
((((((((((((((((((((((((((((( snapshot@2008-07-28_ 8.44.21.80 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-28 15:26:55 6,365,184 ----a-w C:\Windows\ERDNT\Hiv-backup\SCHEMA.DAT
- 2008-07-26 20:41:47 51,200 ----a-w C:\Windows\inf\infpub.dat
+ 2008-07-28 14:29:16 51,200 ----a-w C:\Windows\inf\infpub.dat
- 2008-07-26 20:41:47 86,016 ----a-w C:\Windows\inf\infstor.dat
+ 2008-07-28 14:29:16 86,016 ----a-w C:\Windows\inf\infstor.dat
- 2008-07-26 20:41:47 86,016 ----a-w C:\Windows\inf\infstrng.dat
+ 2008-07-28 14:29:15 86,016 ----a-w C:\Windows\inf\infstrng.dat
+ 2008-07-28 14:29:06 295,606 ----a-r C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe
+ 2008-07-28 14:29:08 295,606 ----a-r C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat_3D.exe
+ 2008-07-28 14:29:07 295,606 ----a-r C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat_Standard.exe
+ 2008-07-28 14:29:07 25,214 ----a-r C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Distiller.exe
+ 2008-07-28 14:29:07 7,278 ----a-r C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_ELEMENTS_DT.exe
+ 2008-07-28 14:29:06 23,558 ----a-r C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\SC_Designer_PFM.70DBED24_B579_40CB_AB0B_F1221A3E9EC5.exe
+ 2007-12-12 19:06:42 295,606 ----a-r C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
- 2008-07-28 12:36:35 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-07-28 15:34:10 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-07-28 15:34:10 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1
- 2008-07-28 12:36:35 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-07-28 15:34:10 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-07-28 15:34:10 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1
+ 2006-09-29 10:56:38 28,248 ----a-r C:\Windows\System32\AdobePDF.dll
- 2008-07-28 12:36:28 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-07-28 15:34:01 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-07-28 12:36:28 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-28 15:34:01 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-07-28 12:36:28 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-07-28 15:34:01 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-09-29 10:55:52 24,456 ------w C:\Windows\System32\DriverStore\FileRepository\adobepdf.inf_97e81172\I386\ADREGP.DLL
+ 2006-09-29 10:56:06 190,072 ------w C:\Windows\System32\DriverStore\FileRepository\adobepdf.inf_97e81172\I386\ADUIGP.DLL
- 2008-06-28 19:03:29 1,631,760 ----a-w C:\Windows\System32\FNTCACHE.DAT
+ 2008-07-28 15:34:11 1,631,816 ----a-w C:\Windows\System32\FNTCACHE.DAT
+ 2004-02-20 20:15:42 40,960 ----a-r C:\Windows\System32\MFC71CHS.DLL
+ 2004-02-20 20:15:42 45,056 ----a-r C:\Windows\System32\MFC71CHT.DLL
+ 2004-02-20 20:15:42 65,536 ----a-r C:\Windows\System32\MFC71DEU.DLL
+ 2003-10-17 16:44:08 57,344 ----a-r C:\Windows\System32\MFC71ENU.DLL
+ 2004-02-20 20:15:42 61,440 ----a-r C:\Windows\System32\MFC71ESP.DLL
+ 2004-02-20 20:15:42 61,440 ----a-r C:\Windows\System32\MFC71FRA.DLL
+ 2004-02-20 20:15:42 61,440 ----a-r C:\Windows\System32\MFC71ITA.DLL
+ 2004-02-20 20:15:42 49,152 ----a-r C:\Windows\System32\MFC71JPN.DLL
+ 2004-02-20 20:15:42 49,152 ----a-r C:\Windows\System32\MFC71KOR.DLL
- 2008-07-28 12:14:58 102,194 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-07-28 13:12:14 102,194 ----a-w C:\Windows\System32\perfc009.dat
- 2008-07-28 12:14:58 598,588 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-07-28 13:12:15 598,588 ----a-w C:\Windows\System32\perfh009.dat
- 2008-07-11 23:49:17 6,553,600 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2008-07-28 15:32:31 6,553,600 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-09-29 10:55:52 24,456 ----a-w C:\Windows\System32\spool\drivers\w32x86\3\ADREGP.DLL
+ 2006-09-29 10:56:06 190,072 ----a-w C:\Windows\System32\spool\drivers\w32x86\3\ADUIGP.DLL
+ 2008-04-04 09:39:35 731,648 ----a-w C:\Windows\System32\spool\drivers\w32x86\3\PS5UI.DLL
+ 2008-04-04 09:39:36 543,744 ----a-w C:\Windows\System32\spool\drivers\w32x86\3\PSCRIPT5.DLL
+ 2006-10-23 03:37:38 24,456 ----a-w C:\Windows\System32\spool\drivers\w32x86\ADReGP.dll
+ 2006-10-23 03:37:52 190,072 ----a-w C:\Windows\System32\spool\drivers\w32x86\ADUIGP.DLL
+ 2003-05-05 20:47:20 129,024 ----a-w C:\Windows\System32\spool\drivers\w32x86\PS5UI.DLL
+ 2003-05-05 20:47:20 455,168 ----a-w C:\Windows\System32\spool\drivers\w32x86\PSCRIPT5.DLL
- 2008-07-28 12:26:43 6,934 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-492835491-2563465948-1679816886-500_UserData.bin
+ 2008-07-28 13:07:07 7,394 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-492835491-2563465948-1679816886-500_UserData.bin
- 2008-07-28 12:26:43 50,006 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-07-28 13:07:07 50,410 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-07-28 12:27:09 6,340 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-07-28 12:54:21 6,442 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-07-28 12:26:38 35,830 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-07-28 12:57:49 36,262 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-07-11 23:23:45 34,683,214 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-07-28 14:29:58 34,687,099 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-07-28 14:29:39 1,093,632 ----a-w C:\Windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.163_none_0c187ef99ee1d25a\mfc80.dll
+ 2008-07-28 14:29:39 1,080,320 ----a-w C:\Windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.163_none_0c187ef99ee1d25a\mfc80u.dll
+ 2008-07-28 14:29:38 69,632 ----a-w C:\Windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.163_none_0c187ef99ee1d25a\mfcm80.dll
+ 2008-07-28 14:29:39 57,856 ----a-w C:\Windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.163_none_0c187ef99ee1d25a\mfcm80u.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-09-02 16:58 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 23:24 620152]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2008-07-28 10:29:06 295606]
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableInstallerDetection"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{73526E5A-FD53-4BE7-B5E2-D3C89D7413DC}"= "C:\Windows\System32\Branding\folderbg\VistaFolderBackground.dll" [2008-04-05 06:04 90112]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-492835491-2563465948-1679816886-500]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A0F5032C-562E-4294-88F4-23F3551F3821}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{DD0B86FB-66AF-43B7-A884-CF1EB496B133}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{51EC491B-CE04-4F8A-8A0B-1C40AD06FB7D}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{71D074E8-D0C2-41B2-B9C0-F5EB2CC1C14A}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3B658EE7-0523-45EA-9D28-915E3369399B}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0641A39D-23C9-412E-B46D-3C66F3CD3EF0}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{0F01261E-C68F-4DEE-8594-A0DF45C9256A}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{2D5149EF-A948-431F-93F8-CA5AC3CA2D0B}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{BB9E8F01-821C-4D58-8841-843F8BF7AAAC}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{3F8DCEF5-D661-475D-92B6-43DA4AD71EEF}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{C3A210CE-0C7B-41DE-AA2B-3BAE0F87FCD8}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{1DA3B0D0-8DC8-40AA-A077-CFB5FB88860C}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{50C81BF6-A385-49A2-BA0B-398FED93468F}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{B01104F4-0737-4CD7-9162-40B15939262F}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{92DEBC75-C669-49E6-A1D5-39AB667A73A3}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{169EBD80-FA5B-42C9-AE37-2924F8E00438}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{25E240E7-C831-4AF5-B78F-36C59F3980D6}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{18AA2D5D-4F75-4C1F-BB17-87059D1FEEBC}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{3EF9A686-2521-446A-8ADC-7FCE1E3FC131}"= inRosettaStoneLtdServices.exe:Rosetta Stone Online Component (inbound)
"{1BC7ABBC-4A34-497B-8584-2C2A7C5F274D}"= RosettaStoneVersion3.exe:Rosetta Stone V3 Application (inbound)
"{5B23BFAB-E7CA-4FB3-9A79-9F3D6F4AB95C}"= UDP:C:\Users\Administrator\AppData\Local\Microsoft\Live Mesh\GacBase\Moe.exe:Live Mesh
"{69AD61A0-D3D6-46F7-9B9E-F12DB51CB888}"= TCP:C:\Users\Administrator\AppData\Local\Microsoft\Live Mesh\GacBase\Moe.exe:Live Mesh
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
"DisabledInterfaces"= {7A113B22-EF58-4F8A-A63E-FB8639E5E7FC},{A9AE043F-3ED2-48E9-92C9-DCC9846E28A0}
R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-02-20 11:11]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 09:42]
R2 wlcrasvc;Live Mesh Remote Desktop;C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe [2008-07-25 19:02]
R3 HSFHWATI;HSFHWATI;C:\Windows\system32\DRIVERS\HSFHWATI.sys [2005-01-25 16:26]
R3 RDPDISPM;RDPDISPM;C:\Windows\system32\DRIVERS\rdpdispm.sys [2008-07-25 19:02]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 03:30]
S2 gupdate1c8d8e04ad8f56d;Google Update Service (gupdate1c8d8e04ad8f56d);C:\Program Files\Google\Update\GoogleUpdate.exe [2008-07-25 17:09]
S3 athrusb;Atheros Wireless LAN USB device driver;C:\Windows\system32\DRIVERS\athrusb.sys [2006-12-22 23:05]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\Windows\system32\ZuneWlanCfgSvc.exe [2008-04-29 22:56]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-04-04 05:39]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-04-04 05:41]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MSSMSGS - winfsy32.rom
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-28 11:34:27
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\RocketDock\RocketDock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\IoctlSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Windows\System32\dllhost.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
.
**************************************************************************
.
Completion time: 2008-07-28 11:41:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-28 15:41:04
ComboFix2.txt 2008-07-28 13:12:37
ComboFix3.txt 2008-07-28 12:45:37
Pre-Run: 833,495,040 bytes free
Post-Run: 586,903,552 bytes free
388 --- E O F --- 2008-07-24 21:19:17