ComboFix 09-04-25.A3 - Nickolaus Bruce 04/26/2009 11:14.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2579 [GMT -7:00]
Running from: c:\documents and settings\Nickolaus Bruce\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-05-26 to 2009-4-26 )))))))))))))))))))))))))))))))
.
2009-04-24 15:18 . 2008-04-14 00:11 21504 ----a-w c:\windows\system32\hidserv.dll
2009-04-24 15:18 . 2008-04-14 00:11 21504 ----a-w c:\windows\system32\dllcache\hidserv.dll
2009-04-24 15:18 . 2008-04-13 18:45 10368 ----a-w c:\windows\system32\drivers\hidusb.sys
2009-04-24 15:18 . 2008-04-13 18:45 10368 ----a-w c:\windows\system32\dllcache\hidusb.sys
2009-04-24 15:18 . 2008-04-13 18:45 60032 ----a-w c:\windows\system32\drivers\USBAUDIO.sys
2009-04-24 15:18 . 2008-04-13 18:45 60032 ----a-w c:\windows\system32\dllcache\usbaudio.sys
2009-04-24 15:17 . 2008-04-13 18:45 32128 ----a-w c:\windows\system32\drivers\usbccgp.sys
2009-04-24 15:17 . 2008-04-13 18:45 32128 ----a-w c:\windows\system32\dllcache\usbccgp.sys
2009-04-23 02:57 . 2009-04-23 02:57 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\ESET
2009-04-23 00:26 . 2009-04-23 00:26 -------- d-----w c:\program files\Trend Micro
2009-04-22 22:45 . 2009-04-22 22:45 -------- d-----w c:\program files\EsetOnlineScanner
2009-04-22 21:35 . 2009-04-22 21:03 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-22 21:03 . 2009-04-22 21:03 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-22 20:59 . 2009-04-22 20:59 -------- d--h--w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-22 20:59 . 2009-04-22 20:59 -------- d-----w c:\program files\Lavasoft
2009-04-22 20:59 . 2009-04-22 20:59 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-22 20:47 . 2009-04-22 20:47 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-04-22 20:43 . 2009-04-22 20:43 1152 ----a-w c:\windows\system32\windrv.sys
2009-04-22 20:41 . 2009-04-22 20:41 -------- d-----w c:\documents and settings\Nickolaus Bruce\Application Data\GetRightToGo
2009-04-22 02:57 . 2009-04-22 02:57 -------- d-----w c:\windows\system32\xlib254.dll
2009-04-22 02:57 . 2009-04-22 02:57 -------- d-----w c:\windows\system32\append.dll
2009-04-22 02:57 . 2009-04-22 02:57 -------- d-----w c:\documents and settings\Nickolaus Bruce\Local Settings\Application Data\Logitech-LS
2009-04-22 02:54 . 2006-08-19 20:21 57344 ----a-w c:\windows\system32\digest32.dll
2009-04-22 02:45 . 2005-07-20 00:31 53248 ----a-r c:\windows\system32\InstMed.exe
2009-04-22 02:45 . 2009-04-22 02:45 -------- d-----w c:\program files\Common Files\Logitech
2009-04-20 15:26 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-20 15:26 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-20 15:26 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-20 15:26 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-20 15:26 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-20 15:26 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-20 15:25 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-20 15:25 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-20 15:25 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 18:17 . 2009-04-14 18:17 41808 ----a-w c:\windows\system32\xfcodec.dll
2009-04-09 04:44 . 2009-04-09 04:44 -------- d-----w C:\website
2009-04-08 20:53 . 2009-04-08 20:53 -------- d-----w c:\program files\Common Files\Macromedia
2009-04-08 20:52 . 2009-04-08 20:52 -------- d-----w c:\windows\Downloaded Installations
2009-04-04 07:58 . 2006-08-10 07:09 659456 ----a-w c:\windows\system32\snapapi32.dll
2009-03-31 01:09 . 2009-03-31 01:09 -------- d-----w c:\program files\THQ
2009-03-31 01:09 . 2009-03-31 01:09 -------- d-----w c:\documents and settings\Nickolaus Bruce\Application Data\InstallShield
2009-03-30 23:44 . 2009-03-30 23:45 43520 ----a-w c:\windows\system32\CmdLineExt03.dll
2009-03-30 23:26 . 2009-03-31 17:19 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-03-28 23:19 . 2009-03-28 23:19 -------- d-----w c:\documents and settings\Nickolaus Bruce\Application Data\Hamachi
2009-03-28 23:19 . 2009-03-28 23:19 25280 ----a-w c:\windows\system32\drivers\hamachi.sys
2009-03-28 23:19 . 2009-03-28 23:19 -------- d-----w c:\program files\Hamachi
2009-03-28 07:10 . 2009-03-28 07:10 -------- d-----w c:\documents and settings\Nickolaus Bruce\Application Data\GameRanger
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-26 18:17 . 2009-04-22 21:38 3354 ----a-w C:\aaw7boot.log
2009-04-23 01:06 . 2009-04-23 00:00 2171 ----a-w C:\rapport.txt
2009-04-22 02:24 . 2009-02-13 19:54 13544 ----a-w c:\documents and settings\Nickolaus Bruce\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-25 23:09 . 2009-03-25 23:09 1149754 ----a-w c:\windows\GPS 2008 ENGLISH DL Uninstaller.exe
2009-03-25 23:08 . 2009-03-25 23:08 -------- d-----w c:\program files\Common Files\Thraex Software
2009-03-22 22:35 . 2009-03-22 22:35 -------- d-----w c:\documents and settings\Nickolaus Bruce\Application Data\Datarescue
2009-03-22 01:29 . 2009-02-13 15:01 98304 ----a-w c:\windows\DUMP575a.tmp
2009-03-21 22:51 . 2009-03-21 22:51 -------- d-----w c:\program files\Xvid
2009-03-21 14:06 . 2009-03-21 14:06 989696 ------w c:\windows\system32\dllcache\kernel32.dll
2009-03-18 23:31 . 2009-03-18 23:31 -------- d-----w c:\program files\MagicISO
2009-03-09 12:19 . 2009-02-25 17:02 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-07 13:27 . 2009-03-07 13:27 -------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles
2009-03-06 14:22 . 2004-08-04 19:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 06:12 . 2009-03-03 06:12 -------- d-----w c:\program files\SystemRequirementsLab
2009-03-03 06:12 . 2009-03-03 06:12 -------- d-----w c:\documents and settings\Nickolaus Bruce\Application Data\SystemRequirementsLab
2009-03-03 00:18 . 2009-02-13 14:53 826368 ------w c:\windows\system32\dllcache\wininet.dll
2009-03-03 00:18 . 2004-08-04 19:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-02 07:39 . 2009-02-17 06:29 138624 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-03-02 07:39 . 2009-02-17 06:28 202352 ----a-w c:\windows\system32\PnkBstrB.exe
2009-02-28 04:54 . 2007-08-14 01:43 636072 ------w c:\windows\system32\dllcache\iexplore.exe
2009-02-20 10:20 . 2009-02-13 20:14 13824 ------w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2007-08-14 01:39 70656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2004-08-04 19:00 161792 ------w c:\windows\system32\dllcache\ieakui.dll
2009-02-18 03:07 . 2009-02-13 15:01 98304 ----a-w c:\windows\DUMP4963.tmp
2009-02-17 06:28 . 2009-02-17 06:28 66872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-02-13 20:42 . 2009-02-13 20:42 5740 ----a-w c:\windows\system32\d3d9caps.dat
2009-02-13 15:22 . 2009-02-13 14:37 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-02-13 15:16 . 2004-08-04 19:00 250048 --sha-r C:\ntldr
2009-02-13 14:34 . 2009-02-13 14:34 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-02-09 12:10 . 2004-08-04 19:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-04 19:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-04 19:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 19:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2009-02-13 14:53 1846784 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-04 19:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-08 02:02 . 2009-02-13 14:52 2066048 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-08 02:02 . 2004-08-04 05:59 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-04 19:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2009-02-13 14:53 2189056 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 11:08 . 2004-08-04 19:00 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 11:06 . 2009-02-13 14:53 2145280 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 10:39 . 2004-08-04 19:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:39 . 2004-08-04 19:00 35328 ----a-w c:\windows\system32\dllcache\sc.exe
2009-02-06 10:32 . 2009-02-13 14:53 2023936 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-03 19:59 . 2009-02-03 19:59 56832 ------w c:\windows\system32\dllcache\secur32.dll
2009-02-03 19:59 . 2004-08-04 19:00 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-23_08.04.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-26 18:18 . 2009-04-26 18:18 16384 c:\windows\Temp\Perflib_Perfdata_d60.dat
+ 2009-04-26 18:18 . 2009-04-26 18:18 16384 c:\windows\Temp\Perflib_Perfdata_130.dat
+ 2009-02-13 14:51 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2009-02-13 14:51 . 2007-07-27 16:41 26488 c:\windows\system32\spupdsvc.exe
+ 2009-02-13 20:07 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
- 2009-02-13 20:07 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
+ 2004-08-04 19:00 . 2009-04-23 10:50 78114 c:\windows\system32\perfc009.dat
- 2004-08-04 19:00 . 2009-03-10 23:47 78114 c:\windows\system32\perfc009.dat
+ 2009-02-13 14:33 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
- 2009-02-13 14:33 . 2008-04-14 00:12 91648 c:\windows\system32\mtxoci.dll
- 2004-08-04 19:00 . 2008-04-14 00:12 66560 c:\windows\system32\mtxclu.dll
+ 2004-08-04 19:00 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
+ 2007-08-14 01:54 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
- 2007-08-14 01:54 . 2008-12-20 23:15 52224 c:\windows\system32\msfeedsbs.dll
+ 2009-02-13 14:33 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
- 2009-02-13 14:33 . 2008-04-14 00:12 58880 c:\windows\system32\msdtclog.dll
+ 2009-02-13 14:33 . 2004-08-04 12:00 19429 c:\windows\system32\MsDtc\Trace\msdtcvtr.bat
+ 2004-08-04 19:00 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 27648 c:\windows\system32\jsproxy.dll
+ 2007-08-14 01:39 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
- 2007-08-14 01:39 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
+ 2004-08-04 19:00 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 44544 c:\windows\system32\iernonce.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 78336 c:\windows\system32\ieencode.dll
+ 2004-08-04 19:00 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2004-08-04 19:00 . 2008-12-19 09:10 70656 c:\windows\system32\ie4uinit.exe
+ 2007-08-14 01:36 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
- 2007-08-14 01:36 . 2008-12-20 23:15 63488 c:\windows\system32\icardie.dll
+ 2007-08-14 01:36 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2007-08-14 01:36 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2009-02-13 20:14 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2009-02-13 20:14 . 2008-12-20 23:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2007-08-14 01:54 . 2008-12-20 23:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2007-08-14 01:54 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2007-08-14 01:39 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
- 2007-08-14 01:39 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\iernonce.dll
- 2007-08-14 01:45 . 2007-08-14 01:45 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2007-08-14 01:45 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2009-02-13 20:14 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2009-02-13 20:14 . 2008-12-20 23:15 63488 c:\windows\system32\dllcache\icardie.dll
+ 2009-04-23 10:46 . 2009-04-26 18:17 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-13 14:45 . 2009-04-26 18:17 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-13 14:45 . 2009-04-23 02:55 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-13 14:45 . 2009-04-26 18:17 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-13 14:45 . 2009-04-23 02:55 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-04-23 10:27 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-23 10:27 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-23 10:27 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-23 10:27 . 2008-04-14 00:11 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-23 10:27 . 2008-12-19 09:10 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-23 10:27 . 2008-12-20 23:15 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2008-01-18 15:13 . 2008-01-18 15:13 2247 c:\windows\ServicePackFiles\i386\tscdsbl.bat
+ 2008-01-18 15:13 . 2008-01-18 15:13 2247 c:\windows\Installer\tsclientmsitrans\tscdsbl.bat
- 2004-08-04 19:00 . 2008-04-14 00:12 354304 c:\windows\system32\winhttp.dll
+ 2004-08-04 19:00 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 233472 c:\windows\system32\webcheck.dll
+ 2009-02-13 14:32 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2009-02-13 14:32 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2009-02-13 14:32 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 105984 c:\windows\system32\url.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
- 2004-08-04 19:00 . 2009-03-10 23:47 462168 c:\windows\system32\perfh009.dat
+ 2004-08-04 19:00 . 2009-04-23 10:50 462168 c:\windows\system32\perfh009.dat
+ 2004-08-04 19:00 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 102912 c:\windows\system32\occache.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 671232 c:\windows\system32\mstime.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 193024 c:\windows\system32\msrating.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 477696 c:\windows\system32\mshtmled.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
+ 2007-08-14 01:54 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
- 2007-08-14 01:54 . 2008-12-20 23:15 459264 c:\windows\system32\msfeeds.dll
- 2009-02-13 14:33 . 2008-04-14 00:12 161792 c:\windows\system32\msdtcuiu.dll
+ 2009-02-13 14:33 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
+ 2009-02-13 14:33 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
- 2009-02-13 14:33 . 2008-04-14 00:12 956928 c:\windows\system32\msdtctm.dll
+ 2009-02-13 14:33 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
- 2004-08-04 19:00 . 2008-04-14 00:11 989696 c:\windows\system32\kernel32.dll
+ 2004-08-04 19:00 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
+ 2007-08-14 01:34 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
+ 2007-07-11 19:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
- 2007-07-11 19:27 . 2008-12-20 23:15 383488 c:\windows\system32\ieapfltr.dll
+ 2004-08-04 19:00 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2004-08-04 19:00 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 153088 c:\windows\system32\ieakeng.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 133120 c:\windows\system32\extmgr.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
+ 2007-08-14 01:54 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-14 01:54 . 2008-12-20 23:15 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-14 01:44 . 2008-12-20 23:15 105984 c:\windows\system32\dllcache\url.dll
+ 2007-08-14 01:44 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-14 01:44 . 2008-12-20 23:15 102912 c:\windows\system32\dllcache\occache.dll
+ 2007-08-14 01:44 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
+ 2007-08-14 01:54 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2007-08-14 01:54 . 2008-12-20 23:15 671232 c:\windows\system32\dllcache\mstime.dll
+ 2007-08-14 01:44 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2007-08-14 01:44 . 2008-12-20 23:15 193024 c:\windows\system32\dllcache\msrating.dll
- 2007-08-14 01:54 . 2008-12-20 23:15 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-08-14 01:54 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-02-13 20:14 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2009-02-13 20:14 . 2008-12-20 23:15 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2009-02-13 20:14 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2007-08-14 01:39 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2009-02-13 20:14 . 2008-12-20 23:15 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2009-02-13 20:14 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2007-08-14 01:39 . 2008-12-20 23:15 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2007-08-14 01:39 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-14 01:39 . 2008-12-20 23:15 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2007-08-14 01:39 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2007-08-14 01:54 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2007-08-14 01:54 . 2008-12-20 23:15 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2007-08-14 01:35 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2007-08-14 01:35 . 2008-12-20 23:15 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2007-08-14 01:35 . 2008-12-20 23:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2007-08-14 01:35 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2007-08-14 01:39 . 2008-12-20 23:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2007-08-14 01:39 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 124928 c:\windows\system32\advpack.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-23 10:27 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-23 10:27 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-23 10:27 . 2008-12-20 23:15 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-23 10:27 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-23 10:27 . 2008-12-20 23:15 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-23 10:27 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2004-08-04 19:00 . 2008-12-20 23:15 1160192 c:\windows\system32\urlmon.dll
- 2004-08-04 19:00 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2004-08-04 19:00 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
+ 2004-08-04 19:00 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2007-08-14 01:54 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2007-02-12 23:10 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
- 2007-02-12 23:10 . 2007-04-17 09:32 2455488 c:\windows\system32\ieapfltr.dat
- 2009-02-13 14:53 . 2008-12-20 23:15 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2009-02-13 14:53 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2009-02-13 14:52 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2009-02-13 20:14 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
- 2009-02-13 20:14 . 2007-04-17 09:32 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-02-13 20:14 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-04-23 10:27 . 2008-12-20 23:15 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-23 10:27 . 2009-01-17 04:35 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-23 10:27 . 2008-12-20 23:15 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-23 10:27 . 2007-04-17 09:32 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2009-02-13 14:53 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-02-13 14:53 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-02-13 14:53 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-02-13 14:52 . 2009-02-08 02:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-02-13 14:52 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-02-13 14:53 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-02-13 14:53 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-02-13 20:10 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-02-13 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-02-13 486856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-04 4363504]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-03-17 4608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-06 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-04-06 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-20 221184]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-22 516440]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-04-06 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-10-12 439568]
c:\documents and settings\Nickolaus Bruce\Start Menu\Programs\Startup\
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2009-3-28 625952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, snapapi32.dll, digest32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Activision\\Star Trek Armada II Fleet Operations\\Data\\armada2.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\System32\\dpnsvr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"f:\\AA\\AADeployClient.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"f:\\AA\\System\\ArmyOps.exe"=
"c:\\WINDOWS\\System32\\javaw.exe"=
"f:\\IDA\\idag.exe"=
"f:\\IDA\\idag64.exe"=
"h:\\Supreme ruler GC\\SupremeRuler2020GC.exe"=
"C:0\\Supreme ruler GC\\SupremeRuler2020GC.exe"=
"c:\\Documents and Settings\\Nickolaus Bruce\\Application Data\\GameRanger\\GameRanger\\GameRanger.exe"=
"h:\\Supreme ruler GC\\SupremeRuler2020.exe"=
"f:\\Supreme ruler GC\\SupremeRuler2020GC.exe"=
"h:\\40\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"h:\\40\\Soulstorm.exe"=
"c:\\WINDOWS\\system32\\nvsvc32.exe"=
"c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\ekrn.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4719:TCP"= 4719:TCP:4719
R2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2004-08-04 3584]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-22 64160]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-02-20 33800]
S2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-22 953168]
.
Contents of the 'Scheduled Tasks' folder
2009-04-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 21:02]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Nickolaus Bruce\Application Data\Mozilla\Firefox\Profiles\vf0sko8i.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=101760&l=dis
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-26 11:18
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2984)
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\RUNDLL32.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\windows\SYSTEM32\NVSVC32.EXE
c:\windows\SYSTEM32\PNKBSTRA.EXE
c:\windows\SYSTEM32\SEARCHINDEXER.EXE
c:\windows\SYSTEM32\WBEM\UNSECAPP.EXE
c:\windows\SYSTEM32\WSCNTFY.EXE
.
**************************************************************************
.
Completion time: 2009-04-26 11:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-26 18:20
ComboFix2.txt 2009-04-23 08:06
Pre-Run: 3,966,337,024 bytes free
Post-Run: 4,016,373,760 bytes free
424 --- E O F --- 2009-04-23 10:39
Edited by nick443, 26 April 2009 - 12:22 PM.