ComboFix LogComboFix 09-03-04.01 - Tony Yuwono 2009-03-06 1:27:45.3 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.932.1.1033.18.1022.706 [GMT 0:00]
Running from: c:\documents and settings\Tony Yuwono\Desktop\ComboFix.exe
.
The following files were disabled during the run:c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekaslvtvouo.sys
c:\windows\system32\prunnet.exe
c:\windows\system32\senekaaoyknltb.dll
c:\windows\system32\senekaiyegryju.dll
c:\windows\system32\senekaldwrthrk.dll
c:\windows\system32\senekaodcsbiqq.dat
c:\windows\system32\senekapjxvmsot.dat
c:\windows\system32\senekapop.dll
c:\windows\system32\wupobolo.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
-------\Service_SENEKA
((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.
2009-03-06 00:47 . 2009-03-06 00:47 0 --a------ c:\windows\system32\drivers\senekalmplwgot.sys
2009-03-05 23:38 . 2009-03-05 23:38 84,992 --ahs---- c:\windows\system32\gopigede.dll
2009-03-05 23:33 . 2009-03-06 01:27 6,456 --ah----- c:\windows\system32\kebobavi
2009-03-05 23:18 . 2009-03-05 23:18 <DIR> d--hs---- c:\windows\system32\lowsec
2009-02-20 04:04 . 2009-02-20 04:04 <DIR> d-------- c:\program files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 02:02 --------- d-----w c:\program files\SnailWeb
2009-01-16 21:35 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
2009-01-14 02:59 --------- d-----w c:\program files\Veoh Networks
2009-01-12 20:29 --------- d-----w c:\program files\Common Files\xing shared
2009-01-12 20:28 --------- d-----w c:\program files\Real
2009-01-06 16:21 --------- d-----w c:\program files\RedBanana
2009-01-06 03:00 --------- d-----w c:\program files\MSXML 4.0
2009-01-06 00:04 15,232 ----a-w c:\windows\system32\drivers\Neo_0083.sys
2009-01-06 00:03 15,232 ----a-w c:\windows\system32\drivers\Neo_0091.sys
2008-12-19 09:10 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\dllcache\srv.sys
2008-12-11 00:33 86,016 ----a-w c:\windows\system32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\system32\dtu100.dll
2008-12-09 02:28 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w c:\windows\system32\dpu11.dll
2005-05-13 17:12 217,073 --sha-r c:\windows\meta4.exe
2005-02-28 13:16 240,128 --sha-r c:\windows\system32\x.264.exe
2005-07-14 12:31 27,648 --sha-r c:\windows\system32\AVSredirect.dll
2005-06-26 15:32 616,448 --sha-r c:\windows\system32\cygwin1.dll
2005-06-21 22:37 45,568 --sha-r c:\windows\system32\cygz.dll
2004-01-25 00:00 70,656 --sha-r c:\windows\system32\i420vfw.dll
2008-04-13 17:49 2,828 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-04-13 17:49 168 --sh--r c:\windows\system32\F1386A55A7.sys
2006-05-03 11:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 12:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2007-12-17 14:43 27,648 --sha-w c:\windows\system32\Smab0.dll
.
((((((((((((((((((((((((((((( snapshot_2009-01-05_23.39.27.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-11 10:24:44 333,184 ------w c:\windows\$hf_mig$\KB958687\SP2QFE\srv.sys
+ 2008-12-11 10:57:10 333,952 ------w c:\windows\$hf_mig$\KB958687\SP3GDR\srv.sys
+ 2008-12-11 12:34:00 333,952 ------w c:\windows\$hf_mig$\KB958687\SP3QFE\srv.sys
+ 2007-11-30 12:39:22 17,272 ------w c:\windows\$hf_mig$\KB958687\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ------w c:\windows\$hf_mig$\KB958687\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ------w c:\windows\$hf_mig$\KB958687\update\spcustom.dll
+ 2007-11-30 11:18:52 755,576 ------w c:\windows\$hf_mig$\KB958687\update\update.exe
+ 2007-11-30 11:18:52 382,840 ------w c:\windows\$hf_mig$\KB958687\update\updspapi.dll
+ 2007-11-30 12:39:22 231,288 ------w c:\windows\$NtUninstallKB958687$\spuninst\spuninst.exe
+ 2007-11-30 11:18:52 382,840 ------w c:\windows\$NtUninstallKB958687$\spuninst\updspapi.dll
+ 2008-08-28 10:04:18 333,056 ------w c:\windows\$NtUninstallKB958687$\srv.sys
+ 2008-03-12 16:20:28 266,240 ----a-w c:\windows\Downloaded Program Files\RedbananaAutoPlay.dll
+ 2008-10-16 20:38:34 124,928 ------w c:\windows\ie7updates\KB961260-IE7\advpack.dll
+ 2008-10-16 20:38:34 347,136 ------w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 ------w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-10-16 20:38:36 133,120 ------w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-10-16 20:38:36 63,488 ------w c:\windows\ie7updates\KB961260-IE7\icardie.dll
+ 2008-10-16 13:11:10 70,656 ------w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-10-16 20:38:36 153,088 ------w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-10-16 20:38:36 230,400 ------w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-10-15 07:04:54 161,792 ------w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-10-16 20:38:36 383,488 ------w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-10-16 20:38:36 384,512 ------w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-16 20:38:38 6,066,176 ------w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-10-16 20:38:38 44,544 ------w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-10-16 20:38:38 267,776 ------w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-10-16 13:11:10 13,824 ------w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-10-15 07:06:26 633,632 ------w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-10-16 20:38:38 27,648 ------w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-10-16 20:38:38 459,264 ------w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-10-16 20:38:38 52,224 ------w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-12-13 06:40:02 3,593,216 ------w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-10-16 20:38:38 477,696 ------w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-10-16 20:38:38 193,024 ------w c:\windows\ie7updates\KB961260-IE7\msrating.dll
+ 2008-10-16 20:38:40 671,232 ------w c:\windows\ie7updates\KB961260-IE7\mstime.dll
+ 2008-10-16 20:38:40 102,912 ------w c:\windows\ie7updates\KB961260-IE7\occache.dll
+ 2008-10-16 20:38:40 44,544 ------w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:42 213,216 ------w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:52 371,424 ------w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:40 105,984 ------w c:\windows\ie7updates\KB961260-IE7\url.dll
+ 2008-10-16 20:38:40 1,160,192 ------w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-10-16 20:38:40 233,472 ------w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-10-16 20:38:40 826,368 ------w c:\windows\ie7updates\KB961260-IE7\wininet.dll
+ 2006-10-26 20:12:56 396,592 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\MOC.EXE
+ 2007-05-08 11:10:18 16,874,376 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\MSO.DLL
+ 2007-03-21 18:56:50 8,425,856 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\OARTCONV.DLL
+ 2006-10-27 15:18:34 1,658,152 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\OGL.DLL
+ 2007-05-10 09:04:28 846,248 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\OICE.EXE
+ 2007-05-10 10:11:42 1,767,256 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\PPCNV.DLL
+ 2007-03-21 19:00:06 72,096 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\PXBCOM.EXE
+ 2007-03-21 18:58:40 4,145,520 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\WRD12CNV.DLL
+ 2007-03-21 18:58:46 24,416 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\WRD12EXE.EXE
+ 2007-05-10 10:25:40 14,677,368 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6021\XL12CNV.EXE
+ 2007-09-14 21:45:58 16,901,168 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6215\MSO.DLL
+ 2007-08-29 00:19:24 1,654,648 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6215\OGL.DLL
+ 2007-08-24 05:00:34 1,767,768 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6215\PPCNV.DLL
+ 2007-08-24 05:00:48 72,096 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6215\PXBCOM.EXE
+ 2007-10-02 20:00:06 14,708,760 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109020011400000000000F01FEC\12.0.6215\XL12CNV.EXE
+ 2009-01-06 03:00:42 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 2008-12-18 03:05:40 593,920 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-02-12 17:34:32 593,920 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-12-18 03:05:40 12,288 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-02-12 17:34:32 12,288 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-12-18 03:05:40 86,016 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-02-12 17:34:34 86,016 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-12-18 03:05:40 135,168 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-02-12 17:34:32 135,168 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-12-18 03:05:40 11,264 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-02-12 17:34:34 11,264 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-12-18 03:05:40 27,136 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-02-12 17:34:34 27,136 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-12-18 03:05:40 4,096 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-02-12 17:34:34 4,096 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-12-18 03:05:40 794,624 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-02-12 17:34:34 794,624 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-12-18 03:05:40 249,856 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2009-02-12 17:34:32 249,856 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-12-18 03:05:40 61,440 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2009-02-12 17:34:32 61,440 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-12-18 03:05:40 23,040 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-02-12 17:34:34 23,040 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-12-18 03:05:40 286,720 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-02-12 17:34:32 286,720 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-12-18 03:05:40 409,600 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-02-12 17:34:32 409,600 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-02-03 03:01:54 38,240 ----a-r c:\windows\Installer\{90120000-0020-0411-0000-0000000FF1CE}\O12ConvIcon.exe
+ 1998-11-11 20:35:46 306,688 ----a-w c:\windows\IsUn0411.exe
- 2000-08-31 08:00:00 28,672 ----a-w c:\windows\Nircmd.exe
+ 2000-08-31 08:00:00 29,696 ----a-w c:\windows\Nircmd.exe
- 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2008-12-20 23:15:12 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2008-09-17 15:29:12 20,040 ----a-w c:\windows\system32\config\systemprofile\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
- 2007-05-17 20:05:10 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-03-06 01:33:38 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-05-17 20:05:10 32,768 ------w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-06 01:33:38 32,768 ------w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-05-17 20:05:10 32,768 ------w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-06 01:33:38 32,768 ------w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-06 16:33:52 684,032 ----a-w c:\windows\system32\DivX.dll
+ 2008-11-06 16:33:54 823,296 ----a-w c:\windows\system32\divx_xx07.dll
+ 2008-11-06 16:33:54 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
+ 2008-11-06 16:33:54 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
+ 2008-11-06 16:33:54 802,816 ----a-w c:\windows\system32\divx_xx11.dll
+ 2008-11-06 16:37:36 524,288 ----a-w c:\windows\system32\DivXsm.exe
+ 2008-11-06 16:33:02 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
- 2008-10-16 20:38:34 124,928 ------w c:\windows\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:12 124,928 ------w c:\windows\system32\dllcache\advpack.dll
- 2008-10-16 20:38:34 347,136 ------w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 ------w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 ------w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:14 214,528 ------w c:\windows\system32\dllcache\dxtrans.dll
- 2008-10-16 20:38:36 133,120 ------w c:\windows\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:14 133,120 ------w c:\windows\system32\dllcache\extmgr.dll
- 2008-10-16 20:38:36 63,488 ------w c:\windows\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:14 63,488 ------w c:\windows\system32\dllcache\icardie.dll
- 2008-10-16 20:38:36 153,088 ------w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 ------w c:\windows\system32\dllcache\ieakeng.dll
- 2008-10-16 20:38:36 230,400 ------w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 ------w c:\windows\system32\dllcache\ieaksie.dll
- 2008-10-16 20:38:36 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:16 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-10-16 20:38:36 384,512 ------w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 ------w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-16 20:38:38 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:22 6,066,688 ------w c:\windows\system32\dllcache\ieframe.dll
- 2008-10-16 20:38:38 44,544 ------w c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:22 44,544 ------w c:\windows\system32\dllcache\iernonce.dll
- 2008-10-16 20:38:38 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
- 2008-10-16 20:38:38 27,648 ------w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:24 27,648 ------w c:\windows\system32\dllcache\jsproxy.dll
- 2008-10-16 20:38:38 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:24 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
- 2008-10-16 20:38:38 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-10-16 20:38:38 477,696 ------w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 ------w c:\windows\system32\dllcache\mshtmled.dll
- 2008-10-16 20:38:38 193,024 ------w c:\windows\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:32 193,024 ------w c:\windows\system32\dllcache\msrating.dll
- 2008-10-16 20:38:40 671,232 ------w c:\windows\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 ------w c:\windows\system32\dllcache\mstime.dll
- 2008-10-16 20:38:40 102,912 ------w c:\windows\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 ------w c:\windows\system32\dllcache\occache.dll
- 2008-10-16 20:38:40 44,544 ------w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 ------w c:\windows\system32\dllcache\pngfilt.dll
- 2007-10-26 04:34:02 8,460,288 ----a-w c:\windows\system32\dllcache\shell32.dll
+ 2008-07-03 13:03:30 8,460,800 ----a-w c:\windows\system32\dllcache\shell32.dll
- 2008-10-16 20:38:40 105,984 ------w c:\windows\system32\dllcache\url.dll
+ 2008-12-20 23:15:40 105,984 ------w c:\windows\system32\dllcache\url.dll
- 2008-10-16 20:38:40 1,160,192 ------w c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 ------w c:\windows\system32\dllcache\urlmon.dll
- 2008-10-16 20:38:40 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
- 2008-10-16 20:38:40 826,368 ------w c:\windows\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:42 826,368 ------w c:\windows\system32\dllcache\wininet.dll
- 2008-02-22 04:32:28 15,232 ----a-w c:\windows\system32\drivers\Neo_0069.sys
+ 2009-01-05 23:47:44 15,232 ----a-w c:\windows\system32\drivers\Neo_0069.sys
- 2008-08-28 10:04:18 333,056 ----a-w c:\windows\system32\drivers\srv.sys
+ 2008-12-11 11:57:22 333,184 ----a-w c:\windows\system32\drivers\srv.sys
- 2008-10-16 20:38:34 347,136 ------w c:\windows\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 ------w c:\windows\system32\dxtrans.dll
+ 2008-12-20 23:15:14 214,528 ----a-w c:\windows\system32\dxtrans.dll
- 2008-10-16 20:38:36 133,120 ------w c:\windows\system32\extmgr.dll
+ 2008-12-20 23:15:14 133,120 ------w c:\windows\system32\extmgr.dll
- 2008-06-12 18:36:38 7,680 ----a-w c:\windows\system32\ff_vfw.dll
+ 2008-08-22 17:57:52 14,336 ----a-w c:\windows\system32\ff_vfw.dll
- 2008-10-15 15:30:36 271,784 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-02-03 13:24:42 290,888 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2007-06-15 10:36:16 229,376 ----a-w c:\windows\system32\GameLink.dll
- 2008-10-16 20:38:36 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2008-12-20 23:15:14 63,488 ----a-w c:\windows\system32\icardie.dll
- 2008-10-16 13:11:10 70,656 ------w c:\windows\system32\ie4uinit.exe
+ 2008-12-19 09:10:16 70,656 ------w c:\windows\system32\ie4uinit.exe
- 2008-10-16 20:38:36 153,088 ------w c:\windows\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 ------w c:\windows\system32\ieakeng.dll
- 2008-10-16 20:38:36 230,400 ------w c:\windows\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 ------w c:\windows\system32\ieaksie.dll
- 2008-10-15 07:04:54 161,792 ------w c:\windows\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 ------w c:\windows\system32\ieakui.dll
- 2008-10-16 20:38:36 383,488 ----a-w c:\windows\system32\ieapfltr.dll
+ 2008-12-20 23:15:16 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2008-10-16 20:38:36 384,512 ------w c:\windows\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 ------w c:\windows\system32\iedkcs32.dll
- 2008-10-16 20:38:38 6,066,176 ----a-w c:\windows\system32\ieframe.dll
+ 2008-12-20 23:15:22 6,066,688 ----a-w c:\windows\system32\ieframe.dll
- 2008-10-16 20:38:38 44,544 ------w c:\windows\system32\iernonce.dll
+ 2008-12-20 23:15:22 44,544 ------w c:\windows\system32\iernonce.dll
- 2008-10-16 20:38:38 267,776 ----a-w c:\windows\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2008-10-16 13:11:10 13,824 ----a-w c:\windows\system32\ieudinit.exe
+ 2008-12-19 09:10:16 13,824 ----a-w c:\windows\system32\ieudinit.exe
- 2008-10-16 20:38:38 27,648 ------w c:\windows\system32\jsproxy.dll
+ 2008-12-20 23:15:24 27,648 ------w c:\windows\system32\jsproxy.dll
+ 2008-11-06 16:35:00 1,044,480 ----a-w c:\windows\system32\libdivx.dll
- 2008-10-16 20:38:38 459,264 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-12-20 23:15:24 459,264 ----a-w c:\windows\system32\msfeeds.dll
- 2008-10-16 20:38:38 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll
+ 2009-01-16 21:35:14 3,594,752 ----a-w c:\windows\system32\mshtml.dll
- 2008-10-16 20:38:38 477,696 ------w c:\windows\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 ------w c:\windows\system32\mshtmled.dll
- 2008-10-16 20:38:38 193,024 ------w c:\windows\system32\msrating.dll
+ 2008-12-20 23:15:32 193,024 ------w c:\windows\system32\msrating.dll
- 2008-10-16 20:38:40 671,232 ------w c:\windows\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 ------w c:\windows\system32\mstime.dll
- 2007-05-08 15:03:04 1,275,392 ----a-w c:\windows\system32\msxml4.dll
+ 2008-09-30 16:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
- 2007-05-15 15:43:10 1,320,800 ----a-w c:\windows\system32\msxml6.dll
+ 2008-08-29 20:06:44 1,350,664 ----a-w c:\windows\system32\msxml6.dll
- 2008-10-16 20:38:40 102,912 ------w c:\windows\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 ------w c:\windows\system32\occache.dll
- 2007-11-06 14:30:38 278,528 ----a-w c:\windows\system32\pncrt.dll
+ 2009-01-12 20:28:46 278,528 ----a-w c:\windows\system32\pncrt.dll
- 2007-11-06 14:30:40 6,656 ----a-w c:\windows\system32\pndx5016.dll
+ 2009-01-12 20:28:48 6,656 ----a-w c:\windows\system32\pndx5016.dll
- 2007-11-06 14:30:40 5,632 ----a-w c:\windows\system32\pndx5032.dll
+ 2009-01-12 20:28:48 5,632 ----a-w c:\windows\system32\pndx5032.dll
- 2008-10-16 20:38:40 44,544 ------w c:\windows\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 ------w c:\windows\system32\pngfilt.dll
+ 2008-08-10 11:55:30 60,273 ----a-w c:\windows\system32\pthreadGC2.dll
- 2007-03-08 07:51:00 547,576 ----a-w c:\windows\system32\px.dll
+ 2008-11-06 16:37:28 551,672 ------w c:\windows\system32\px.dll
- 2007-03-08 07:51:00 129,784 ----a-w c:\windows\system32\pxafs.dll
+ 2008-11-06 16:37:28 129,784 ------w c:\windows\system32\pxafs.dll
- 2007-03-08 07:51:00 64,760 ----a-w c:\windows\system32\pxcpya64.exe
+ 2008-11-06 16:37:28 66,296 ------w c:\windows\system32\pxcpya64.exe
+ 2008-11-06 16:37:28 120,056 ------w c:\windows\system32\pxcpyi64.exe
- 2007-03-08 07:51:00 510,712 ----a-w c:\windows\system32\pxdrv.dll
+ 2008-11-06 16:37:28 518,904 ------w c:\windows\system32\pxdrv.dll
- 2007-03-08 07:51:00 72,440 ----a-w c:\windows\system32\pxhpinst.exe
+ 2008-11-06 16:37:30 72,440 ------w c:\windows\system32\pxhpinst.exe
- 2007-03-08 07:51:00 64,760 ----a-w c:\windows\system32\pxinsa64.exe
+ 2008-11-06 16:37:28 64,760 ------w c:\windows\system32\pxinsa64.exe
+ 2008-11-06 16:37:28 118,520 ------w c:\windows\system32\pxinsi64.exe
- 2007-03-08 07:51:00 187,128 ----a-w c:\windows\system32\pxmas.dll
+ 2008-11-06 16:37:30 187,128 ------w c:\windows\system32\pxmas.dll
- 2007-03-08 07:51:00 1,628,920 ----a-w c:\windows\system32\pxsfs.dll
+ 2008-11-06 16:37:28 1,628,920 ------w c:\windows\system32\pxsfs.dll
- 2007-03-08 07:51:00 379,640 ----a-w c:\windows\system32\pxwave.dll
+ 2008-11-06 16:37:28 379,640 ------w c:\windows\system32\pxwave.dll
+ 2008-11-06 16:37:32 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
+ 2009-01-06 00:04:12 15,232 ----a-w c:\windows\system32\ReinstallBackups\
0020\DriverFiles\Neo_0083.sys
+ 2009-01-05 23:47:24 15,232 ----a-w c:\windows\system32\ReinstallBackups\
0021\DriverFiles\Neo_0069.sys
- 2007-11-06 14:30:46 185,688 ----a-w c:\windows\system32\rmoc3260.dll
+ 2009-01-12 20:28:56 185,920 ----a-w c:\windows\system32\rmoc3260.dll
+ 2004-08-10 20:00:00 286,208 ----a-r c:\windows\system32\sdra64.exe
- 2007-10-26 04:34:02 8,460,288 ----a-w c:\windows\system32\shell32.dll
+ 2008-07-03 13:03:30 8,460,800 ----a-w c:\windows\system32\shell32.dll
- 2007-07-27 09:41:40 16,760 ------w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll
+ 2008-11-06 16:35:00 200,704 ----a-w c:\windows\system32\ssldivx.dll
- 2008-10-16 20:38:40 105,984 ----a-w c:\windows\system32\url.dll
+ 2008-12-20 23:15:40 105,984 ----a-w c:\windows\system32\url.dll
- 2008-10-16 20:38:40 1,160,192 ----a-w c:\windows\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 ----a-w c:\windows\system32\urlmon.dll
- 2007-03-08 07:51:00 39,672 ----a-w c:\windows\system32\vxblock.dll
+ 2008-11-06 16:37:28 88,824 ------w c:\windows\system32\vxblock.dll
- 2008-10-16 20:38:40 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 ----a-w c:\windows\system32\webcheck.dll
- 2008-10-16 20:38:40 826,368 ----a-w c:\windows\system32\wininet.dll
+ 2008-12-20 23:15:42 826,368 ----a-w c:\windows\system32\wininet.dll
+ 2009-03-06 01:33:38 16,384 --sha-w c:\windows\Temp\Cookies\index.dat
+ 2009-03-06 01:33:38 16,384 --sha-w c:\windows\Temp\History\History.IE5\index.dat
+ 2009-03-06 01:33:44 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_f4c.dat
+ 2009-03-06 01:33:38 32,768 --sha-w c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-06 01:33:32 2,240,512 ----a-w c:\windows\Temp\VPN_68D3\9218E5A4.dll
+ 2008-09-30 16:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 16:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2005-09-22 23:48:08 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-22 23:48:08 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-22 23:48:06 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-19 53248]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-13 118784]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2006-06-23 225280]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-21 7581696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-21 86016]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-07-12 438272]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-13 77824]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-13 94208]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"CPM4c26d50c"="c:\windows\system32\gopigede.dll" [2009-03-05 84992]
"SkyTel"="SkyTel.EXE" [2006-07-19 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2006-07-21 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2004-08-10 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-14 1694208]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\gopigede.dll" [2009-03-05 84992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gopigede.dll [2009-03-05 84992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk
backup=c:\windows\pss\Acer Empowering Technology.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PacketiX VPN Client タスクトレイ常駐.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PacketiX VPN Client タスクトレイ常駐.lnk
backup=c:\windows\pss\PacketiX VPN Client タスクトレイ常駐.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Tony Yuwono^Start Menu^Programs^Startup^フレムカQQ.lnk]
path=c:\documents and settings\Tony Yuwono\Start Menu\Programs\Startup\フレムカQQ.lnk
backup=c:\windows\pss\フレムカQQ.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]
--a------ 2006-06-07 20:18 208896 c:\acer\Empowering Technology\ePresentation\ePresentation.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]
--a------ 2006-03-15 22:12 579584 c:\acer\Empowering Technology\ePower\Boot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
--a------ 2006-03-17 15:00 345088 c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]
--a------ 2006-07-12 15:48 438272 c:\acer\Empowering Technology\ePower\ePower_DMC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
--a------ 2006-06-01 14:40 413696 c:\acer\Empowering Technology\eRecovery\eRAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
--a------ 2006-07-14 12:13 471040 c:\progra~1\LAUNCH~1\QtZgAcer.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
--a------ 2006-06-26 15:47 331776 c:\program files\Acer\OrbiCam\CameraAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
--a------ 2006-06-26 15:55 73728 c:\program files\Acer\OrbiCam\InstallHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-14 00:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntiMUI]
--a------ 2006-05-15 11:15 45056 c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2006-04-29 06:13 766041 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
--a------ 2008-12-16 17:07 3528440 c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2004-08-04 00:56 110592 c:\windows\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2006-07-19 09:42 16248320 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\NeffyManSp\\NeffyManSp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\PacketiX VPN Client\\vpncmd.exe"=
"c:\\Program Files\\PacketiX VPN Client\\vpncmgr.exe"=
"c:\\Program Files\\PacketiX VPN Client\\vpnclient.exe"=
"c:\\Program Files\\Nexon\\MapleStory\\MapleStory.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\HighStreet 5\\5street\\Film.exe"=
"d:\\HighStreet 5\\5street\\Launch.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"94:TCP"= 94:TCP:VRS Recording System Web Control Panel
"81:TCP"= 81:TCP:Axon Virtual PBX Web Server
R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2007-05-18 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2007-05-18 78208]
R2 npkcjpn;npkcjpn;c:\program files\Nexon\MapleStory\npkcjpn.sys [2008-12-17 54824]
R2 vpnclient;PacketiX VPN Client;c:\program files\PacketiX VPN Client\vpnclient.exe [2007-10-22 2191360]
R3 Neo_VPN;VPN Client Device Driver - VPN;c:\windows\system32\drivers\Neo_0069.sys [2008-02-22 15232]
S2 npkjmsvc;npkjmsvc; [x]
S3 libusb0;LibUsb-Win32 - Kernel Driver 08/27/2006, 0.1.12.0;c:\windows\system32\drivers\libusb0.sys [2008-08-15 28672]
S3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [2006-06-20 1097728]
S3 Neo_VPN 2;VPN Client Device Driver - VPN 2;c:\windows\system32\drivers\Neo_0083.sys [2009-01-06 15232]
S3 Neo_VPN Client Adapter 2;VPN Client Device Driver - VPN Client Adapter 2;c:\windows\system32\drivers\Neo_0091.sys [2009-01-06 15232]
S3 npkcujpn;npkcujpn;c:\program files\Nexon\MapleStory\npkcujpn.sys [2008-12-17 44800]
S3 Revolution1;Revolution1; [x]
S3 sejt1;sejt1; [x]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{386b4906-d59f-11dc-9f06-0019d22b4461}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70a00c1e-55db-11dd-9f73-0019d22b4461}]
\Shell\AutoRun\command - g:\wd_windows_tools\Setup.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{224f0037-e35b-4bc5-8ee2-6a98aa5d58fc} - c:\windows\system32\wegabalu.dll
HKCU-Run-prunnet - c:\windows\system32\prunnet.exe
HKLM-Run-prunnet - c:\windows\system32\prunnet.exe
HKLM-Run-lejopugizi - c:\windows\system32\nuyajuku.dll
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.jp/
mStart Page = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyServer = 210.254.61.227:3370
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: c:\program files\Tencent\QQ\SendMMS.htm
IE: Add to QQ Customized Panel - c:\program files\Tencent\QQ\AddPanel.htm
IE: Add to QQ Emoticons - c:\program files\Tencent\QQ\AddEmotion.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send picture by MMS - c:\program files\Tencent\QQ\SendMMS.htm
IE: Send the Picture by QQ MMS - c:\program files\Tencent\QQ\SendMMS.htm
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
LSP: %SystemRoot%\system32\PrxerDrv.dll
Trusted Zone: clubhanbit.jp\x3
Trusted Zone: gamania.co.jp\kd
DPF: {8D9E639C-110C-4F85-9067-3B97C0BDE9C0} - hxxp://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP25.cab
DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://dist.cdnetworks.co.jp/cdndist/neffy/NeffyLauncher.cab
DPF: {C8F5F737-2683-40B8-BFB6-47B15AC20A79} - hxxps://gash.gamania.co.jp/acxauth/cab/1_2_38/lcjggame.cab
DPF: {CD043AC3-CCA0-4415-8BAA-C61A2A7C0A19} - hxxp://pp.clubhanbit.jp/Game/ATL_ElevationLauncher.cab
DPF: {D6440B15-8FD8-455C-AE55-8D3198F49638} - hxxp://x3.clubhanbit.jp/Game/X3Launcher.cab
DPF: {D6855164-25C2-40D2-BA39-D8A57FF0B49C} - hxxp://sangokushi-hero.redbanana.jp/_include/_common/cab/RedbananaAutoPlay.cab
DPF: {F58E877C-4F14-4805-B2D2-EB48927C7580} - hxxp://dist.cdnetworks.co.jp/cdndist/streamport/SPort.cab
.
.
------- File Associations -------
.
chm.file="hh.exe" %1
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-06 01:33:37
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1192)
c:\windows\system32\imjp81.ime
c:\windows\system32\imjp81k.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\conime.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\PSIService.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2009-03-06 1:36:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-06 01:36:28
ComboFix3.txt 2008-10-04 16:19:26
ComboFix2.txt 2009-01-05 23:39:58
Pre-Run: 22,138,552,320 bytes free
Post-Run: 22,115,188,736 バイトの空き領域
548 --- E O F --- 2009-03-05 01:08:06