Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:50:48 AM, on 2/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\explorer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-2025429265-412668190-682003330-1003\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User '?')
O4 - S-1-5-21-2025429265-412668190-682003330-1003 Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User '?')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Launch PicLens - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\PicLens.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} -
http://downloads.ewi...oOnlineScan.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1215048687258O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: System Restore Service (srservice) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 5840 bytes
ComboFix 09-02-06.01 - andrew 2009-02-08 7:36:18.3 - NTFSx86 MINIMAL
Running from: c:\documents and settings\andrew\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\andrew\Desktop\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Cache\
00047878
c:\program files\AskBarDis\bar\Cache\
00047CAE.bin
c:\program files\AskBarDis\bar\Cache\
00047FBB.bin
c:\program files\AskBarDis\bar\Cache\
000482B9.bin
c:\program files\AskBarDis\bar\Cache\
0004845F.bin
c:\program files\AskBarDis\bar\Cache\
0004878B.bin
c:\program files\AskBarDis\bar\Cache\
00048A2B.bin
c:\program files\AskBarDis\bar\Cache\
00048B25.bin
c:\program files\AskBarDis\bar\Cache\
00048C1F.bin
c:\program files\AskBarDis\bar\Cache\
00048D48.bin
c:\program files\AskBarDis\bar\Cache\
00048E52.bin
c:\program files\AskBarDis\bar\Cache\files.ini
c:\program files\AskBarDis\bar\History\search
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevcfg.htm
c:\program files\AskBarDis\bar\Settings\prevCfg2.htm
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ATI_SMART
-------\Legacy_DOT3SVC
-------\Legacy_EAPHOST
-------\Service_Cdcolpcbadsi
-------\Service_Eventlog
((((((((((((((((((((((((( Files Created from 2009-01-08 to 2009-02-08 )))))))))))))))))))))))))))))))
.
2009-02-07 08:14 . 2009-02-07 08:14 <DIR> d-------- c:\program files\ESET
2009-02-07 08:14 . 2009-02-07 08:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2009-02-07 05:42 . 2009-02-07 05:44 <DIR> d--h-c--- c:\windows\ie8
2009-02-07 05:40 . 2009-01-10 23:00 79,360 -----c--- c:\windows\system32\dllcache\iecompat.dll
2009-02-07 05:29 . 2009-02-07 05:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\McAfee
2009-02-06 13:33 . 2009-02-06 13:33 <DIR> d-------- c:\documents and settings\andrew\Application Data\Apple Computer
2009-02-06 04:45 . 2009-02-07 06:54 <DIR> d-------- c:\program files\SpywareBlaster
2009-02-06 04:45 . 2009-02-07 06:55 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-06 04:45 . 2005-08-25 19:18 118,784 --a------ c:\windows\system32\MSSTDFMT.DLL
2009-02-05 18:01 . 2009-02-05 18:01 67,585 --a------ c:\windows\system32\67.tmp
2009-02-05 16:11 . 2009-02-06 15:44 <DIR> d-------- c:\windows\system32\CatRoot_bak
2009-02-05 16:10 . 2008-06-13 07:10 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-02-05 16:09 . 2009-02-05 16:09 67,585 --a------ c:\windows\system32\E4.tmp
2009-02-05 16:09 . 2009-02-05 16:09 23,553 --a------ c:\windows\system32\E3.tmp
2009-02-05 16:08 . 2008-08-14 04:00 2,180,352 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-05 16:08 . 2008-08-14 03:58 2,136,064 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-05 16:08 . 2008-08-14 03:22 2,057,728 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-05 16:08 . 2008-08-14 03:22 2,015,744 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-05 16:05 . 2008-10-24 05:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-02-05 16:04 . 2009-02-05 16:09 162,948 --a------ c:\windows\system32\84.tmp
2009-02-05 16:04 . 2009-02-05 16:04 168 --a------ c:\windows\system32\83.tmp
2009-02-05 16:03 . 2009-02-05 16:03 67,585 --a------ c:\windows\system32\6D.tmp
2009-02-05 16:03 . 2009-02-05 16:03 616 --a------ c:\windows\system32\6F.tmp
2009-02-05 16:03 . 2009-02-05 16:03 130 --a------ c:\windows\adobe.bat
2009-02-05 16:03 . 2009-02-05 16:03 0 --a------ c:\windows\_id.dat
2009-02-05 15:54 . 2004-08-10 04:13 73,728 --a--c--- c:\windows\system32\dllcache\ehresja.dll
2009-02-05 15:54 . 2004-08-10 04:13 69,632 --a--c--- c:\windows\system32\dllcache\ehresko.dll
2009-02-05 15:54 . 2004-08-10 04:13 69,632 --a--c--- c:\windows\system32\dllcache\ehresfr.dll
2009-02-05 15:54 . 2004-08-10 04:13 69,632 --a--c--- c:\windows\system32\dllcache\ehresde.dll
2009-02-05 15:52 . 2004-08-10 06:00 1,875,968 --a--c--- c:\windows\system32\dllcache\msir3jp.lex
2009-02-05 15:51 . 2004-08-10 06:00 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2009-02-05 15:50 . 2004-05-13 00:39 876,653 --a--c--- c:\windows\system32\dllcache\fp4awel.dll
2009-02-05 15:49 . 2009-02-05 15:49 749 -rah----- c:\windows\WindowsShell.Manifest
2009-02-05 15:49 . 2009-02-05 15:49 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2009-02-05 15:49 . 2009-02-05 15:49 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2009-02-05 15:49 . 2009-02-05 15:49 749 -rah----- c:\windows\system32\nwc.cpl.manifest
2009-02-05 15:49 . 2009-02-05 15:49 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2009-02-05 15:49 . 2009-02-05 15:49 488 -rah----- c:\windows\system32\logonui.exe.manifest
2009-02-05 15:48 . 2004-08-10 06:00 36,864 --a--c--- c:\windows\system32\dllcache\isignup.exe
2009-02-05 15:43 . 2007-06-26 02:27 363,520 --a--c--- c:\windows\system32\dllcache\w3svc.dll
2009-02-05 15:43 . 2004-08-10 06:00 25,088 --a--c--- c:\windows\system32\dllcache\inetmgr.exe
2009-02-05 09:19 . 2009-02-07 08:42 1,071,841,280 --a------ c:\windows\MEMORY.DMP
2009-02-04 19:52 . 2009-02-04 19:52 <DIR> d-------- c:\program files\Ahead
2009-02-04 19:52 . 2009-02-04 19:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-02-04 11:06 . 2009-02-04 11:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-04 05:03 . 2009-02-04 05:03 32,768 --ah----- c:\documents and settings\LocalService\qmhp.exe
2009-02-04 04:54 . 2004-03-22 11:24 4,272 -ra------ c:\windows\system32\drivers\bvrp_pci.sys.bak
2009-02-04 04:49 . 2009-02-05 16:03 66,560 ---h----- c:\windows\system32\secupdat.dat
2009-02-04 04:49 . 2009-02-04 04:49 32,768 --ah----- c:\documents and settings\NetworkService\iapbc.exe
2009-02-03 04:55 . 2009-02-04 19:52 <DIR> d-------- c:\program files\SUPERAntiSpyware
2009-02-03 04:55 . 2009-02-03 04:55 <DIR> d-------- c:\documents and settings\andrew\Application Data\SUPERAntiSpyware.com
2009-02-02 19:14 . 2001-07-09 04:50 176,128 -ra------ c:\windows\system32\NeroCheck.exe
2009-02-01 22:54 . 2009-02-01 22:54 0 --a------ c:\windows\system32\6CB.tmp
2009-01-31 19:39 . 2009-02-04 19:52 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-01-31 19:39 . 2009-01-31 19:39 <DIR> d-------- C:\Downloads
2009-01-29 19:10 . 2009-01-31 19:38 <DIR> d-------- c:\program files\IDA
2009-01-29 19:10 . 2009-01-31 19:38 <DIR> d-------- c:\documents and settings\andrew\Application Data\Internet Download Accelerator
2009-01-29 16:24 . 2009-01-31 19:38 <DIR> d-------- c:\program files\PicLensIE
2009-01-29 16:20 . 2009-01-29 16:20 <DIR> d--hs---- c:\documents and settings\andrew\IECompatCache
2009-01-29 16:15 . 2009-01-29 16:15 <DIR> d--hs---- c:\documents and settings\andrew\IETldCache
2009-01-27 20:36 . 2009-01-27 20:36 <DIR> d-------- c:\program files\JRE
2009-01-25 08:38 . 2009-01-25 08:38 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-24 19:49 . 2009-01-24 19:49 <DIR> d-------- c:\program files\Safari
2009-01-24 19:38 . 2009-01-24 19:38 <DIR> d-------- c:\program files\QuickTime
2009-01-24 19:38 . 2009-01-24 19:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-23 14:52 . 2009-02-06 04:43 <DIR> d-------- c:\program files\Mozilla Firefox 3.1 Beta 2
2009-01-23 14:12 . 2009-01-23 14:12 <DIR> d-------- c:\documents and settings\andrew\Application Data\Move Networks
2009-01-22 15:44 . 2009-01-22 15:44 <DIR> d-------- c:\program files\Alwil Software
2009-01-19 15:59 . 2009-01-29 17:28 <DIR> d-------- c:\program files\Flickr Uploadr
2009-01-19 14:51 . 2009-01-19 14:51 <DIR> d-------- c:\documents and settings\andrew\Application Data\Flickr
2009-01-17 16:55 . 2009-01-17 16:55 <DIR> d-------- c:\documents and settings\andrew\Application Data\Foxit
2009-01-17 16:42 . 2009-01-17 17:27 <DIR> d-------- c:\documents and settings\andrew\Contacts
2009-01-17 14:26 . 2009-01-17 14:26 268 --ah----- C:\sqmdata03.sqm
2009-01-17 14:26 . 2009-01-17 14:26 244 --ah----- C:\sqmnoopt03.sqm
2009-01-17 13:36 . 2006-06-29 13:07 14,048 --a------ c:\windows\system32\spmsg2.dll
2009-01-16 21:25 . 2009-02-05 16:03 <DIR> d-------- c:\program files\MSN Messenger
2009-01-15 02:22 . 2009-01-15 02:22 49,152 --------- c:\windows\system32\msrating.dll.mui
2009-01-15 02:21 . 2009-01-15 02:21 2,560 --------- c:\windows\system32\mshta.exe.mui
2009-01-15 02:19 . 2009-01-15 02:19 81,920 --------- c:\windows\system32\iedkcs32.dll.mui
2009-01-15 02:19 . 2009-01-15 02:19 4,096 --------- c:\windows\system32\ie4uinit.exe.mui
2009-01-13 14:08 . 2009-01-13 14:08 <DIR> d-------- c:\program files\HP
2009-01-13 14:08 . 2009-01-13 14:08 <DIR> d-------- c:\program files\Common Files\HP
2009-01-13 14:08 . 2009-01-13 14:08 <DIR> d-------- c:\documents and settings\andrew\Application Data\Printer Info Cache
2009-01-13 14:08 . 2009-01-13 14:08 <DIR> d-------- c:\documents and settings\andrew\Application Data\Image Zone Express
2009-01-11 16:02 . 2009-01-11 16:02 <DIR> d-------- c:\documents and settings\andrew\Application Data\CyberLink
2009-01-11 16:00 . 2009-01-11 16:00 <DIR> d-------- c:\program files\CyberLink
2009-01-10 14:26 . 2009-01-16 21:26 <DIR> d-------- c:\program files\Real
2009-01-10 14:26 . 2009-01-10 14:26 <DIR> d-------- c:\program files\Common Files\xing shared
2009-01-10 14:13 . 2009-01-10 14:26 <DIR> d-------- c:\program files\Common Files\Real
2009-01-09 16:49 . 2009-01-09 16:49 <DIR> d-------- c:\program files\Stardock
2009-01-09 16:49 . 2009-01-09 16:49 <DIR> d-------- c:\program files\Common Files\Stardock
2009-01-09 16:48 . 2009-01-09 16:48 <DIR> d-------- c:\program files\Secunia
2009-01-09 16:46 . 2009-01-09 16:46 <DIR> d-------- c:\program files\RogueRemover FREE
2009-01-09 16:46 . 2009-01-09 16:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\ATI
2009-01-09 15:35 . 2009-01-09 15:35 <DIR> d-------- C:\ATI(2)
2009-01-09 14:28 . 2009-02-05 19:55 664 --a------ c:\windows\system32\d3d9caps.dat
2009-01-09 12:53 . 2009-01-09 12:53 <DIR> d-------- c:\program files\Innovative Solutions
2009-01-09 12:36 . 2009-01-09 12:36 <DIR> d-------- c:\documents and settings\andrew\Application Data\Uniblue
2009-01-09 12:36 . 2009-01-09 12:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\DriverScanner
2009-01-09 12:34 . 2009-01-09 16:43 <DIR> d----c--- c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 21:03 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-06 21:03 --------- d-----w c:\program files\Broadcom
2009-02-05 01:52 --------- d-----w c:\program files\Panda Security
2009-02-05 01:52 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-01 02:08 --------- d-----w c:\program files\OpenOffice.org 3
2009-02-01 02:04 --------- d-----w c:\program files\hp deskjet 990c series
2009-02-01 02:04 --------- d-----w c:\program files\GemMaster
2009-02-01 02:03 --------- d-----w c:\program files\EnglishOtto
2009-01-31 13:27 --------- d-----w c:\program files\Foxit Software
2009-01-31 12:17 --------- d-----w c:\documents and settings\andrew\Application Data\Smart Panel
2009-01-25 14:38 --------- d-----w c:\program files\Java
2009-01-24 14:29 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-14 22:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 22:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-14 21:03 --------- d-----w c:\program files\Glary Utilities
2009-01-10 13:51 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-01-09 23:11 101,776 -c--a-w c:\windows\system32\drivers\cmdguard.sys
2009-01-09 22:51 --------- d-----w c:\program files\Bible
2009-01-09 22:49 --------- d-----w c:\program files\Garmin GPS Plugin
2009-01-09 22:48 --------- d-----w c:\program files\Secunia(2)
2009-01-09 22:46 --------- d-----w c:\program files\VS Revo Group
2009-01-09 22:46 --------- d-----w c:\program files\Mozilla Firefox 3.1 Beta 1
2009-01-09 22:46 --------- d-----w c:\program files\ATI Technologies
2009-01-09 22:46 --------- d-----w c:\program files\Amazon
2009-01-09 22:46 --------- d-----w c:\documents and settings\andrew\Application Data\Amazon
2009-01-09 22:45 --------- d-----w c:\program files\Mozilla Sunbird
2008-12-28 22:57 --------- d-----w c:\program files\Datel
2008-12-23 12:05 --------- d-----w c:\documents and settings\All Users\Application Data\PCPitstop
2008-12-20 00:26 --------- d-----w c:\program files\Hewlett-Packard
2008-12-14 15:19 --------- d-----w c:\documents and settings\andrew\Application Data\MSNGames
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-06-29 13:43 1,704,944 -c--a-w c:\program files\mbam-setup.exe
2008-06-27 23:42 7,496,920 -c--a-w c:\program files\Firefox Setup 3.0.exe
.
------- Sigcheck -------
2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-10 06:00 577024 c72661f8552ace7c5c85e16a3cf505c4 c:\windows\$NtUninstallKB890859$\user32.dll
2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\SoftwareDistribution\Download\4d9d678c0d8af22c04a4a7fc7f1ff86c\sp2gdr\user32.dll
2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2gdr\user32.dll
2008-04-13 18:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\dllcache\user32.dll
2008-04-13 18:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\ws2_32.dll
2004-08-10 06:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2004-08-10 06:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\dllcache\ws2_32.dll
2008-04-21 00:56 666624 2e7de1bf9418b071799eb53de8cc22f5 c:\windows\$hf_mig$\KB950759\SP2QFE\wininet.dll
2008-04-21 00:44 666112 2b0c24aa747a93a28987b6d65a4a74bc c:\windows\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-21 00:24 666624 26f240c250e5b4b395cb4b178ba75437 c:\windows\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-04-22 21:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 10:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-08-26 03:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2008-10-16 14:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
2008-04-21 01:04 659456 1efb8a3ea8454aec1bb8a240a2845598 c:\windows\ie7\wininet.dll
2007-08-13 17:54 818688 a4a0fc92358f39538a6494c42ef99fe9 c:\windows\ie7updates\KB950759-IE7\wininet.dll
2008-04-22 22:16 826368 f6589be784647cfdbc22ea51ccb1a57a c:\windows\ie7updates\KB953838-IE7\wininet.dll
2008-06-23 10:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
2008-08-26 01:24 826368 ef8eba98145bfa44e80d17a3b3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
2004-08-10 06:00 656384 c0823fc5469663ba63e7db88f9919d70 c:\windows\ie8\wininet.dll
2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\SoftwareDistribution\Download\1aada90d3aca2362b0231ac90aa9a9fd\SP2GDR\wininet.dll
2008-10-16 14:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\SoftwareDistribution\Download\1aada90d3aca2362b0231ac90aa9a9fd\SP2QFE\wininet.dll
2008-04-13 18:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\wininet.dll
2009-01-15 02:05 911872 203c05a174a45270a30cdd593092d91e c:\windows\system32\wininet.dll
2009-01-15 02:05 911872 203c05a174a45270a30cdd593092d91e c:\windows\system32\dllcache\wininet.dll
2007-10-30 10:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 04:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 05:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 05:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2004-08-10 06:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB941644$\tcpip.sys
2004-08-10 06:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB951748$\tcpip.sys
2007-10-30 11:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2gdr\tcpip.sys
2008-04-13 13:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys
2008-04-13 18:12 525312 568113d807a0acc496a90bc81c91e569 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\winlogon.exe
2004-08-10 06:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\winlogon.exe
2004-08-10 06:00 519680 f63316e5271ebda12a52a390c9636004 c:\windows\system32\dllcache\winlogon.exe
2008-04-13 13:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\ndis.sys
2004-08-10 06:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\dllcache\ndis.sys
2004-08-10 06:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2008-04-13 12:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\ip6fw.sys
2004-08-10 06:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\dllcache\ip6fw.sys
2004-08-10 06:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2005-03-01 18:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2005-03-01 18:34 2015232 3cd941e472ddf3534e53038535719771 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
2004-08-10 06:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntkrnlpa.exe
2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntkrnlpa.exe
2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntkrnlpa.exe
2008-04-13 12:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\ntkrnlpa.exe
2008-08-14 03:22 2015744 dc097a896a03b8277457d228fd12d4e6 c:\windows\system32\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\dllcache\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\ReinstallBackups\
0015\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 19:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2005-03-01 18:57 2135552 48b3e89af7074cee0314a3e0c7faffdb c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
2004-08-10 06:00 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\Driver Cache\i386\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntoskrnl.exe
2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntoskrnl.exe
2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntoskrnl.exe
2008-04-13 13:27 2188928 0c89243c7c3ee199b96fcc16990e0679 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\ntoskrnl.exe
2008-08-14 03:58 2136064 dd31ab4b91c2605601a3c108af57a0c9 c:\windows\system32\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\dllcache\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\ReinstallBackups\
0015\DriverFiles\i386\ntoskrnl.exe
2007-06-13 04:23 1050624 2a42fef7dd93185d5755a08e70229191 c:\windows\explorer.exe
2007-06-13 05:26 1050624 ae041c5ee05dedfd6ce029ffa0d4f5a9 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 06:00 1049600 8db835008d5aac0dd020a13b2df328d0 c:\windows\$NtUninstallKB938828$\explorer.exe
2007-06-13 04:23 1050624 2a42fef7dd93185d5755a08e70229191 c:\windows\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2007-06-13 05:26 1050624 ae041c5ee05dedfd6ce029ffa0d4f5a9 c:\windows\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2008-04-13 18:12 1051136 50fefc6f53e4917073699c0a93c01f9a c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\explorer.exe
2007-06-13 04:23 1050624 2a42fef7dd93185d5755a08e70229191 c:\windows\system32\dllcache\explorer.exe
2008-04-13 18:12 125952 b2bfe3a5681f10e24ee273fccd1f503d c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\services.exe
2004-08-10 06:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\services.exe
2004-08-10 06:00 125440 638e87c7f951ae5899586f6fcfd24ea2 c:\windows\system32\dllcache\services.exe
2008-04-13 18:12 30720 2024477d899ef02a0294cf3ca802d21d c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\lsass.exe
2004-08-10 06:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe
2004-08-10 06:00 30720 f96f303dbf375a7811ef4ba244f7e05f c:\windows\system32\dllcache\lsass.exe
2008-04-13 18:12 32768 c51c383d18e7181bc6861f3f0f8b8009 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\ctfmon.exe
2004-08-10 06:00 32768 4d55ee0db9fb3c97c8f4d6fafd98a1a4 c:\windows\system32\ctfmon.exe
2004-08-10 06:00 32768 c17a958e934c00de4e33884eb0ba6daa c:\windows\system32\dllcache\ctfmon.exe
2005-06-10 18:17 75264 88d68e59e353d188e2517789406e8d4b c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2004-08-10 06:00 75264 97c0348c89a4f729d855e90926953d78 c:\windows\$NtUninstallKB896423$\spoolsv.exe
2005-06-10 17:53 75264 3c96ec6e66dc9680bb8ae543b6e2969b c:\windows\SoftwareDistribution\Download\
0fd33c77398fa2b50df56456525ef5c3\sp2gdr\spoolsv.exe
2005-06-10 18:17 75264 88d68e59e353d188e2517789406e8d4b c:\windows\SoftwareDistribution\Download\
0fd33c77398fa2b50df56456525ef5c3\sp2qfe\spoolsv.exe
2008-04-13 18:12 75264 15d17af8f395e0cc7652cce98274b664 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\spoolsv.exe
2005-06-10 17:53 75264 3c96ec6e66dc9680bb8ae543b6e2969b c:\windows\system32\spoolsv.exe
2005-06-10 17:53 75264 3c96ec6e66dc9680bb8ae543b6e2969b c:\windows\system32\dllcache\spoolsv.exe
2008-04-13 18:12 43520 71d4c672d8524080e4d1f13286754796 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\userinit.exe
2004-08-10 06:00 41984 28d83dac264f73050782a8e8ce6bdf54 c:\windows\system32\userinit.exe
2004-08-10 06:00 41984 eaacbfe425f06756fa102cb9cd29b247 c:\windows\system32\dllcache\userinit.exe
2004-08-10 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\termsrv.dll
2004-08-10 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\termsrv.dll
2004-08-10 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
2007-04-16 10:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
2004-08-10 06:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB935839$\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\SoftwareDistribution\Download\c1835c8cb0bb13f938a8a983ca5edea4\sp2gdr\kernel32.dll
2008-04-13 18:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\dllcache\kernel32.dll
2008-04-13 18:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\powrprof.dll
2004-08-10 06:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
2004-08-10 06:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\dllcache\powrprof.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-02-07_20.55.16.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-19 15:43:08 1,163,960 ----a-w c:\windows\system32\aswBoot.exe
+ 2008-07-19 15:30:53 94,392 ----a-w c:\windows\system32\AvastSS.scr
- 2009-02-08 02:51:41 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-08 13:42:19 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-08 02:51:41 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-08 13:42:19 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-08 02:51:41 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-08 13:42:19 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-19 15:32:15 26,944 ----a-w c:\windows\system32\drivers\aavmker4.sys
+ 2008-07-19 15:37:42 20,560 ----a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2008-01-17 17:34:01 93,264 ----a-w c:\windows\system32\drivers\aswmon.sys
+ 2008-07-19 15:37:21 94,416 ----a-w c:\windows\system32\drivers\aswmon2.sys
+ 2008-07-19 15:33:42 23,152 ----a-w c:\windows\system32\drivers\aswRdr.sys
+ 2008-07-19 15:35:18 78,416 ----a-w c:\windows\system32\drivers\aswSP.sys
+ 2008-07-19 15:32:36 42,912 ----a-w c:\windows\system32\drivers\aswTdi.sys
- 2004-08-10 12:00:00 36,096 ----a-w c:\windows\system32\drivers\intelppm.sys
+ 2004-08-04 04:59:20 36,096 ----a-w c:\windows\system32\drivers\intelppm.sys
- 2004-08-10 12:00:00 131,968 ----a-w c:\windows\system32\hal.dll
+ 2004-08-04 04:59:14 134,400 ----a-w c:\windows\system32\hal.dll
+ 2004-08-10 12:00:00 131,968 ----a-w c:\windows\system32\ReinstallBackups\
0015\DriverFiles\i386\halaacpi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1850608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1425408]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-01-09 1797880]
"COMODO Internet Security"="c:\program files\COMODO\Firewall\cfp.exe" [2009-01-09 1797880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-25 136600]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-09-24 206064]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 176128]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 76800]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-10 389186]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Enable Context Menu"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverMax]
--a------ 2009-01-07 13:10 5385560 c:\program files\Innovative Solutions\DriverMax\devices.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a--c--- 2007-02-26 00:01 437160 c:\progra~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
"YBrowser"=c:\progra~1\Yahoo!\browser\ybrwicon.exe
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"Motive SmartBridge"=c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe"
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe"
"ehTray"=c:\windows\ehome\ehtray.exe
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Sony\\Media Manager for WALKMAN\\MediaManager.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\WINDOWS\\system32\\verclsid.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R1 aswSP;avast! Self Protection; [x]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2009-01-09 101776]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-01-15 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
R2 YahooAUService;Yahoo! Updater;c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2008-11-18 7808]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
S1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-11-21 31504]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
--- Other Services/Drivers In Memory ---
*Deregistered* - AFD
*Deregistered* - aswTdi
*Deregistered* - Beep
*Deregistered* - Cdfs
*Deregistered* - cmdHlp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - epfwtdir
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - Inspect
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - MountMgr
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - PCIIde
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - sr
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - WS2IFSL
*Deregistered* - WudfPf
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-01-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-02-04 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
2009-02-04 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-01-10 17:02]
2009-02-07 c:\windows\Tasks\User_Feed_Synchronization-{976D1549-DB5B-42A6-971C-6BB5DF727974}.job
- c:\windows\system32\msfeedssync.exe [2009-01-15 02:01]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://yahoo.sbc.com/dsl
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
FF - ProfilePath - c:\documents and settings\andrew\Application Data\Mozilla\Firefox\Profiles\u4qzpz6c.default\
FF - prefs.js: browser.startup.homepage - hxxp://att.my.yahoo.com/
FF - component: c:\documents and settings\andrew\Application Data\Mozilla\Firefox\Profiles\u4qzpz6c.default\extensions\
[email protected]\platform\WINNT_x86-msvc\components\WinKiosk.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\nppl3260.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\nprjplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 1\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\OpenOffice.org 3\program\npsoplugin.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-08 07:44:03
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2025429265-412668190-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-2025429265-412668190-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1F9E8B93-350C-6BB4-C000-05C69F796531}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(576)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-02-08 7:47:04 - machine was rebooted [andrew]
ComboFix-quarantined-files.txt 2009-02-08 13:47:02
ComboFix2.txt 2009-02-08 02:56:07
ComboFix3.txt 2009-02-07 01:44:39
Pre-Run: 87,558,352,896 bytes free
Post-Run: 87,537,823,744 bytes free
539 --- E O F --- 2009-02-07 13:54:05
Don't understand how I can have internet and then I don't the next. Now when I boot up I see my desktop for a second a pop up comes up and says logging off and closing network connections and then computer reboots and the process starts all over again. I had to buy a external hard drive ( good price ) so I could transfer files to post.